Jon Tetreault

Writing · September 2026

The approval was real.

A table saw cuts exactly where the fence is set. It doesn't know whether you set the fence or somebody else did. Move it an inch while nobody's looking and every cut after that is clean, square and wrong.

Three weeks ago I wrote about Liquid, where about $320 million left a sidechain with every signature valid. Last Thursday it happened at a bigger number, in a different kind of system. This time the thing that signed was an exchange.

What Bitget says happened

At 18:31 UTC on September 24, according to Bitget's security notice, its monitoring caught unauthorized transfers leaving some of its hot wallets. The notice put the loss at about $351.6 million. The next day, during what Fortune describes as a three-hour livestream, CEO Gracy Chen raised it to $387.5 million. Fortune calls it the largest crypto hack of the year so far.

How it happened is the part worth slowing down on. Chen, as quoted by CoinDesk: "The attacker compromised a critical backend system within our wallet infrastructure, used it to spoof transaction data, and triggered our authorization process to move funds out." To Decrypt she said the attackers "did not forge user withdrawal requests, nor did they obtain our private keys."

So, by the company's account, nobody stole a key and nobody faked a customer. The exchange's own approval process looked at what it was handed and said yes. The system feeding it had been made to lie.

That's Bitget's description, not an established fact yet. Per The Block, Bitget expects to finish an official security report this week.

Where the accounts don't match

Bitget's notice says "Cold wallets remain fully secure," and that the breach touched only part of the hot and warm layers of a three-tier setup. CoinDesk's first report quoted Arkham analyst Emmett Gallic saying the transactions involved "three Bitget hot wallets and one cold wallet."

Both can be true. Outside analysts label wallets by how they behave, and where "warm" ends and "cold" begins is the exchange's own definition. But nobody has reconciled the two in public. The report should.

On who did it: Chen has pointed to IP addresses and patterns that resemble a North Korean group, but Decrypt reports she also said the attacker's identity "hasn't been confirmed." No government has attributed it. I won't either.

A signature proves less than you think

Signing is the last step in the pipeline, and the easiest one to trust. Multi-party signing, hardware modules and approval policies all check whether a request is authorized. None of them can check whether it's true. Poison the data upstream and every control downstream works perfectly, and moves the money anyway.

A signature proves who approved it. It doesn't prove what they were shown.

It's the same shape as the attacks I teach people to spot on their own screens: the display says one thing, the signature authorizes another. Bitget is that pattern at institutional scale.

For an exchange customer, it means something plainer. A balance on an exchange isn't coins you hold. It's an entry in the exchange's records and a promise to honor it. Bitget says its User Protection Fund, which it puts at over $464 million, covers the loss. Per The Block, BTC withdrawals reopened at 08:00 UTC today. Per crypto.news, ETH follows on September 29, USDT on September 30, and everything else, including fiat and P2P, on October 2.

That's the promise being kept. But whether you got your coins back was never in your hands. It was in theirs. Fortune notes that Bitget Wallet, the company's self-custodial app, wasn't affected. The keys users held themselves weren't in the pipeline that got fooled.

What I'd do

  1. Keep on an exchange only what you're actively using there. Everything else belongs in a wallet where you hold the keys. That's not a view on any exchange or any asset. It's about who controls the approval.
  2. If you're a Bitget customer, don't do anything the platform didn't ask for. crypto.news reports Bitget told users they don't need to take any action before withdrawals resume, and to rely on its official channels. So an email, DM or "support agent" asking you to verify, re-link or claim anything to get your funds out isn't the process. Type the site address yourself.
  3. When you withdraw, slow down. Check the destination address on the device that will hold the coins, and send a small test first. After a week of waiting, speed is exactly what a scammer would sell you.

Check the fence before you make the cut.

Verify everything, especially the parts of the system that are supposed to verify for you.

— Jon Tetreault, September 2026. The habits, tools, and checks behind this piece are what I teach in Crypto Security Mastery.