Inside the Bitget Security Incident: CEO Explains Attack and Road to Recovery

On September 25, Bitget CEO Gracy Chen addressed users via a live stream, providing details on a recent security incident and the platform's response plan.

Nature of the Attack and Current Status

During the stream, Chen clarified the distinctive nature of this breach. Preliminary findings suggest the attackers did not gain access to sensitive private keys, a common vector in many exchange hacks.

"A private key compromise represents a worst-case scenario," Chen stated, "but that is not what happened here. The perpetrators found a way to bypass certain system components to illicitly initiate withdrawals."

She assured users that immediate action was taken following the incident. The situation is now fully contained, with further losses prevented, and no additional attacks are expected.

Challenges and Plan for Restoring Withdrawals

While the breach is contained, the restoration of withdrawal services requires more time. Chen explained that the delay stems from an abundance of caution regarding user asset security.

The incident's complexity is heightened because it affected multiple cryptocurrency types across various blockchain networks. Bitget's internal team, alongside external security experts, is concurrently focused on:

  • Pinpointing the exact technical vulnerability and attack pathway.
  • Developing a robust and verified plan for asset handling and system recovery.

"We will only reopen withdrawals once we are certain all funds are secure and we have a thoroughly vetted solution in place," Chen emphasized. Consequently, the platform cannot provide a specific timeline for resuming withdrawals at this moment, though teams are working to restore services as swiftly as possible.

This event underscores the ongoing security challenges in the crypto exchange landscape. Bitget has committed to providing transparent updates as the situation evolves.