Bitget CEO says protection fund will be restored to more than $300 million within a week

Bitget CEO says protection fund will be restored to more than $300 million within a week

N
News Editor
2026-09-28 07:47:36
Bitget CEO Gracy Chen said during a livestream reviewing the incident that unauthorized transfers took place at 2:31 a.m. Beijing time on Sept. 25 across multiple chains, affecting assets held in parts of the exchange’s hot-wallet and warm-wallet infrastructure. According to the company’s investigation, the attacker exploited a vulnerability in a third-party security product, stole internal credential access, and forged withdrawal instructions to the wallet system, bypassing risk-control checks. Chen said private keys were not compromised and cold wallets were not affected. She added that the attack path has been identified, the vulnerability has been fixed, and the situation is now fully under control. Bitget said about $388 million in assets was transferred out. The attacker’s addresses and on-chain tracking data have already been disclosed. Chen also said the full loss will be covered by Bitget’s user protection fund, and the company will replenish that fund to at least $300 million within one week after it is used. Bitget has also started an asset recovery plan and said it will share confirmed vulnerability and attack details with relevant industry parties while continuing to disclose tracking updates.

Bitget CEO Gracy Chen said in a livestream reviewing the incident on Sept. 28 that unauthorized transfers took place at 2:31 a.m. Beijing time on Sept. 25 across multiple chains, involving assets in parts of Bitget’s hot-wallet and warm-wallet infrastructure.

According to Chen, the investigation found that the attacker exploited a vulnerability in a third-party security product, obtained internal credential access, forged withdrawal instructions to the wallet system, and bypassed risk-control checks. She said private keys were not leaked and cold wallets were not affected. Chen added that the attack path has been identified, the vulnerability has been fixed, and the incident is now fully under control.

Bitget said about $388 million in assets was transferred out, and that the attacker’s addresses and related on-chain tracking data have already been made public.

Chen also said the entire loss will be covered by the user protection fund. Bitget plans to restore the fund to at least $300 million within one week after using it. The company has also launched an asset recovery plan, will share confirmed vulnerability and attack information with relevant industry participants, and said it will continue to disclose progress on asset tracing.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.