Bitget executive says private key leak and insider involvement have been ruled out

Bitget executive says private key leak and insider involvement have been ruled out

N
News Editor
2026-09-28 08:13:01
Bitget Chinese-language regional head Xie Jiayin said in a livestream reviewing the incident that the attacker exploited a vulnerability in a third-party security product to steal internal network access credentials and forge withdrawal instructions to the wallet system. According to Xie, the forged requests were able to trick the wallet into executing abnormal transfers that had passed risk checks, which ultimately allowed the attack to succeed. He said the attacker did not rely on common viruses or malware during the operation. Instead, the intruder allegedly used real identities and routine operations and maintenance procedures throughout the process to disguise activity and erase traces, which Xie described as a relatively sophisticated targeted attack. Xie also said Bitget has completed its internal review after the incident and has fully ruled out the possibility of a private key leak as well as any insider involvement. He added that the hacker took advantage of a flaw in a third-party security product, stole Bitget’s internal credentials, and impersonated identities to carry out the attack.

On Sept. 28, Bitget Chinese-language regional head Xie Jiayin said during a livestream titled 「Bitget Incident Review」 that the attacker in the incident exploited a vulnerability in a third-party security product to steal internal network access credentials.

He said the attacker then forged withdrawal instructions to the wallet system, tricking the wallet into executing abnormal transfers that had passed risk checks, which ultimately enabled the attack.

According to Xie, the attacker did not use common viruses or malware. Instead, the operation was disguised through the use of real identities and routine operations and maintenance procedures, while traces were removed during the process. He described it as a relatively sophisticated targeted attack.

Xie also said that after the incident, Bitget completed its review and fully ruled out the possibility of a private key leak, as well as any insider involvement. He added that the hacker exploited a flaw in a third-party security product, stole Bitget’s internal credentials, and impersonated identities to carry out the attack.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.