Bitget CEO Gracy addressed the exchange’s recent security incident and its financial position during a community livestream, saying the case was the first security incident in Bitget’s eight-year history.
Gracy said a full trace of the incident found that hackers exploited a vulnerability in a third-party security product to steal internal network permission credentials. They then forged withdrawal instructions to the wallet system, tricking the wallet into carrying out abnormal transfers that bypassed risk checks.
She said private keys were not leaked and cold wallets were not affected. More technical details will be disclosed in a formal security report, according to Gracy.
Gracy also said the verified losses from the incident are within the coverage range of the protection fund, and user funds were not affected. She added that Bitget has more than $1.4 billion in proprietary capital, including about $464 million in its user protection fund.
According to Gracy, the exchange will continue to honor the security commitment it made when the protection fund was established in 2022 and plans to replenish the fund to the $300 million baseline within one week.
“The protection fund is not a slogan, but an important mechanism that provides real safeguards for users when extreme security incidents occur,” Gracy said. She added that when sudden security challenges emerge, a platform’s overall strength and willingness to take responsibility are important measures of its risk response capability and long-term credibility, and that Bitget will continue to uphold its long-term commitment to putting user interests first.

