Bitget said it has partly identified the route used in a recent large-scale fund outflow incident. The company said it has ruled out the possibility that private keys were leaked and has blocked any further risk of funds leaving the platform.
Bitget Chief Executive Officer Gracy Chen wrote on X on Sept. 25 that the security team had identified the source of the attack at an early stage. The hacker breached a core backend system for the wallet service, then used that system to generate fake transfer information and invoke the approval-signing process to move funds out.
Chen stressed that the possibility of a private key leak can be ruled out. That means a more severe risk scenario did not occur.
Measures to prevent further losses have already been completed, she said, and there is no risk of additional funds leaving the platform. Technical verification is still underway to determine exactly how the hacker penetrated the system, and the full findings will be disclosed later in an incident report.
Work to resume withdrawals is also under way. Multiple technical teams are working simultaneously on system recovery and security upgrades while preparing to restart withdrawal services, Chen said.
She did not provide a specific timeline. Chen added that the company would provide an update as soon as a clear schedule is set and would not promise a timetable it could not keep.
