Bitget CEO Gracy addressed the exchange’s recent security incident and the company’s financial position during a community livestream on Sept. 28, calling it the first security incident in Bitget’s eight-year history.
Gracy said a full trace of the attack found that hackers exploited a vulnerability in a third-party security product to steal internal network credential permissions. They then forged withdrawal instructions to the wallet system, causing the wallet to execute abnormal transfers that bypassed risk checks.
She said private keys were not leaked and cold wallets were not affected. More technical details will be disclosed in a formal security report, according to her remarks.
On the financial impact, Gracy said the verified losses from the incident fall within the coverage range of the protection fund, and that user funds remain safe.
She also said Bitget holds more than $1.4 billion in proprietary funds, including about $464 million in its user protection fund. The platform will continue to honor the security commitment tied to the protection fund launched in 2022, and plans to replenish the fund to the $300 million baseline within one week.
"The protection fund is not just a slogan. It is an important mechanism that provides real protection for users when extreme security incidents occur," Gracy said.
She added that when sudden security challenges emerge, a platform’s overall strength and willingness to take responsibility are important measures of its ability to respond to risk and maintain long-term credibility. Bitget, she said, will continue to uphold its long-term commitment to putting user interests first.

