Bitget CEO Gracy said in a community livestream that the exchange’s recent security incident was its first in eight years. According to Odaily, she said hackers exploited a vulnerability in a third-party security product to steal internal access credentials and forged withdrawal instructions to trick the wallet system into executing abnormal transfers that bypassed risk checks.
Gracy said private keys were not leaked and cold wallets were not affected. She added that the technical details will be disclosed in a formal security report.
She said the confirmed losses from the incident are covered by the protection fund and user funds remain safe. Bitget’s own funds exceed $1.4 billion, including about $464 million in the user protection fund. The company plans to replenish the fund to a $300 million baseline within one week.
