Bitget has completed a full fix for the security flaw involved in its recent incident and has already put four rectification measures in place, according to Xie Jiayin, head of Bitget’s Chinese-speaking market, speaking during a livestream titled “Bitget Incident Review” on Sept. 28. He said the exchange isolated the affected systems and disconnected related servers from the network to stop the attack from spreading while preserving evidence for tracing.
Xie also said Bitget invalidated and reissued all internal login credentials, rendering stolen credentials unusable, and tightened control over highly sensitive permissions by revoking and repartitioning them. Critical operations now require approval from multiple people. In addition, the company disclosed the vulnerability details to the relevant third-party security vendor and worked with it on analysis and remediation, while suspending related functions until the fix was completed. All future withdrawals will now go through independent verification.
According to Xie, the incident occurred after an attacker exploited a vulnerability in a third-party security product, stole credentials granting access to Bitget’s internal network, and forged withdrawal instructions to the wallet system. He said the incident is now fully under control, no new unauthorized transfers have been detected, all affected systems have been isolated, and each blockchain must still pass multiple core checks before withdrawals are restored.
Bitget has completed a full fix for the security flaw tied to its recent incident and has implemented four rectification measures, according to Xie Jiayin, head of Bitget’s Chinese-speaking market.
Speaking during a Sept. 28 livestream titled “Bitget Incident Review,” Xie said the first step was to isolate the affected systems. The related servers were disconnected from the network to contain the spread of the attack, while evidence was preserved for traceability.
The second measure was to reset internal credentials and tighten access to highly sensitive permissions. All internal login credentials were invalidated and reissued, making the credentials stolen by the attacker unusable. Highly sensitive permissions were fully revoked and repartitioned, and critical operations now require approval from multiple people.
Xie said the third step was to notify the relevant third-party security vendor of the vulnerability details and assist with analysis and remediation. Related functions were suspended before the fix was completed.
The fourth rectification measure requires independent verification for all future withdrawals.
According to Xie, the incident was caused by an attacker exploiting a vulnerability in a third-party security product, stealing Bitget internal network access credentials, and forging withdrawal instructions to the wallet system. He said Bitget contacted the vendor immediately, shared the details of the incident, and assisted with remediation.
Xie added that the incident is now fully under control and that no new unauthorized transfers have been found. All affected systems have been isolated and the vulnerability has been fully fixed. Each blockchain will still need to pass multiple core checks before withdrawals are restored.
This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan. Disclaimer:
The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.
Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.