Bitget used a livestream reviewing its recent security incident to outline how it is handling remediation and withdrawal recovery. Xie Jiayin, head of Bitget Greater China, said the exchange has isolated affected systems by taking all related servers off the network to stop the attack from spreading while preserving evidence for tracing. He also said Bitget invalidated and reissued all internal login credentials, making any stolen credentials unusable, and pulled back and restructured highly sensitive permissions so that key actions now require multi-person approval.
Xie added that Bitget has shared vulnerability details with relevant third-party security vendors to support analysis and remediation, and has stopped using the related function until fixes are complete. The exchange also plans to strengthen withdrawal checks so every withdrawal goes through an independent verification process.
Bitget CEO Gracy Chen said BTC withdrawals resumed first because that withdrawal channel was not affected by the attack and completed verification earliest. ETH and USDT withdrawals were restored later based on verification progress and stronger user demand. She also said the withdrawal recovery plan applies equally to all users, with no separate channel or priority access for institutions, VIP clients, or Bitget employees.
Bitget said its withdrawal recovery plan applies to all users and does not provide a separate channel or priority access for institutions, VIP clients, or Bitget employees.
Remediation and risk-control measures
During a livestream titled 「Bitget Security Incident Review」, Xie Jiayin, head of Bitget Greater China, outlined the exchange’s progress on vulnerability fixes and risk-control adjustments.
Xie said Bitget has isolated the affected systems, with all related servers taken off the network to prevent the attack from spreading while preserving evidence for tracing.
He said the company also reset internal credentials and tightened highly sensitive permissions. All internal login credentials were invalidated and reissued, and any credentials stolen by the attacker are no longer valid. Highly sensitive permissions were fully revoked and split up again, with key operations now requiring approval from multiple people.
Bitget has also reported the vulnerability details to relevant third-party security vendors to assist with analysis and remediation, according to Xie. The related function has been suspended until the fix is completed.
The exchange also plans to strengthen withdrawal verification, with every withdrawal subject to an independent check.
Why BTC withdrawals resumed first
Bitget CEO Gracy Chen said BTC withdrawals were restored first because that withdrawal channel was not affected by the attack and completed verification ahead of the others.
She said ETH and USDT withdrawals resumed later after considering both verification progress and relatively strong user demand.
No priority lane for any user group
Bitget said the withdrawal resumption arrangement applies to all users and does not create a separate withdrawal channel or priority rights for institutions, VIPs, or company employees.
This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan. Disclaimer:
The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.
Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.