Bitget’s $387.5 million loss this week is being read as a shocking, outsized breach. It is not shocking. It is the base rate, and the data backing that claim comes from the industry’s own security researchers, not from hindsight.

Bitget itself was clear about what happened: no private keys were stolen. An attacker compromised a backend system, spoofed transaction data and tricked the exchange’s own authorization process into approving withdrawals it should have blocked. That is not a customer failing to secure a seed phrase. It is an operational and infrastructure control failure inside the exchange, and TRM Labs’ own numbers show exactly how much that category of failure now dominates crypto theft.

The Numbers Say This Was Coming

TRM Labs tracked $972 million stolen across 207 incidents in the first half of 2026 alone. Smart contract exploits made up roughly 60% of those incidents, 125 of 207, but accounted for only a small share of the dollars lost. Infrastructure and operational compromises, the category Bitget’s breach falls into, made up only around 15% of incidents but drove roughly 76% of total losses. That is the pattern worth sitting with: attackers are not winning more often through this route, they are winning far bigger when they do, because a backend authorization failure hands them the exchange’s own approval process rather than a single user’s wallet.

Advertisement

300 × 250

The Counter-Argument, and Why It Does Not Hold

The defense every exchange gives is some version of “cold storage is safer, but our customers want instant withdrawals.” That is true as far as it goes. Segmenting nearly all funds into cold storage and forcing withdrawal delays would blunt this attack pattern, and it would also send customers to a faster competitor overnight. No exchange wants to be first, and the H1 2026 data backs up why: total dollars stolen actually fell by more than half year over year even as the number of incidents more than doubled, from 83 in H1 2025 to 207 in H1 2026, which is exactly the pattern you would expect if exchanges are getting better at stopping small attacks while remaining exposed to the rare, large one. That is a real trade-off, not a strawman.

But the argument treats the choice as binary, hot wallets with instant liquidity versus cold storage with friction, when the real failure in Bitget’s case was narrower than that: a single backend system had enough authority to approve fraudulent transfers across at least five blockchains. The fix is not necessarily less liquidity. It is fewer systems capable of unilaterally authorizing a withdrawal, which is a design question about internal authorization architecture, not a customer-facing speed question at all. An exchange can keep instant withdrawals for customers while still requiring that no single backend service can single-handedly approve a large outbound transfer without an independent check.

Banks piloting tokenized deposits are already building toward that narrower fix, even if the crypto exchange world has not borrowed the lesson yet. IBM and Swift’s new tokenized deposit infrastructure is built so institutions can move digital assets continuously while keeping settlement authority inside existing, audited compliance processes rather than a single internal system. “The financial services industry is entering a new era where tokenized and traditional assets will need to move side by side,” IBM Z and LinuxONE general manager Tom McPherson said of that shift. That is precisely the kind of separation crypto exchanges have not built: an architecture where no one backend component can spoof its way into moving customer funds.

Newsletter

Get the week's best tech coverage.

Free. Read by thousands of HR, tech, and business leaders.

What It Means for the Finance Leader

For any institution now evaluating a crypto exchange as a counterparty, custodian or on-ramp, the diligence question is not “do they use cold storage.” Every exchange will say yes. The question is how many systems can independently authorize a withdrawal, and whether that number has gone down since the exchange’s last audited breach, not just whether the exchange bought a bigger insurance fund.

Until exchanges treat custody architecture as a compliance-grade requirement rather than a competitive user-experience trade-off, the next $300 million number is not a surprise. It is the base rate, repeating.

To be clear about what would change my mind here: if the next several large exchange breaches trace back to genuinely novel attack techniques rather than the same authorization and infrastructure weaknesses TRM Labs keeps documenting, the industry-wide argument weakens and this becomes a story about a handful of unlucky platforms instead. Nothing in Bitget’s own account of what happened points that way. A backend system with too much unilateral authority is not a novel attack surface. It is the oldest one in software security, and crypto exchanges are still relearning it one nine-figure loss at a time.

Source: TRM Labs