Bitget lost ~$351.6M from hot and warm wallets on Sep 24, and no smart contract was involved.
Per Bitget, attackers compromised a wallet-backend system, spoofed the transaction data, and passed the normal authorization flow. Bitget says keys weren't stolen and cold wallets are safe.
Trackers have followed $183M+ out across ETH, Arbitrum, BNB, and AVAX, with stables swapped to ETH.
The lesson: if the data going into the signer is compromised, it will sign whatever it's shown.