Binance Square
#bitgetdetailssecurityincidenttimeline

bitgetdetailssecurityincidenttimeline

Faizan Crypto Learner
·
--
Bullish
#bitgetdetailssecurityincidenttimeline 🚨 BITGET JUST REVEALED THE FULL SECURITY INCIDENT TIMELINE. On September 24, Bitget detected unauthorized transfers from part of its hot and warm wallet infrastructure. The estimated affected amount was later revised from $351.6M to $387.5M after additional transactions were identified. ⏰ 18:31 UTC: Unauthorized transfers detected 🛑 Same day: Withdrawals temporarily suspended 🔍 Sept. 25: Attack path identified and vulnerability fixed 💰 $387.5M: Revised total affected amount 🛡️ Cold wallets: Not affected 🏦 Protection Fund: Over $464M 📅 Sept. 28: BTC withdrawals scheduled to begin returning in phases Bitget says the incident is contained, user account balances remain unaffected, and Mandiant + SlowMist are assisting with the investigation. 🔥 Now the big question: Will Bitget's phased withdrawal restart restore confidence — or will traders remain cautious? 👀 #Bitget #crypto #security
#bitgetdetailssecurityincidenttimeline
🚨 BITGET JUST REVEALED THE FULL SECURITY INCIDENT TIMELINE.
On September 24, Bitget detected unauthorized transfers from part of its hot and warm wallet infrastructure. The estimated affected amount was later revised from $351.6M to $387.5M after additional transactions were identified.
⏰ 18:31 UTC: Unauthorized transfers detected
🛑 Same day: Withdrawals temporarily suspended
🔍 Sept. 25: Attack path identified and vulnerability fixed
💰 $387.5M: Revised total affected amount
🛡️ Cold wallets: Not affected
🏦 Protection Fund: Over $464M
📅 Sept. 28: BTC withdrawals scheduled to begin returning in phases
Bitget says the incident is contained, user account balances remain unaffected, and Mandiant + SlowMist are assisting with the investigation.
🔥 Now the big question:
Will Bitget's phased withdrawal restart restore confidence — or will traders remain cautious? 👀
#Bitget #crypto #security
fjag2000:
Si se restaura o no la confianza de los usuarios eso dependerá de cómo entró el hacker esa misma gente de bitget dijo que nadie había robado claves privadas de los usuarios… eso quiere decir que entraron con una vulnerabilidad del sistema, es decir algo que era responsabilidad de ellos!! por lo tanto no creo que la confianza se recupere aunque esto no es más que en mi humilde opinión …ya veremos que pasa
·
--
Bullish
#BitgetCEOConfirms$388MStolenInHack 🚨 Bitget CEO Confirms $388M Stolen in Major Hack: Protection Fund to Fully Cover Losses 🛡️💥 Bitget CEO Gracy Chen has officially clarified that the recent exchange exploit resulted in approximately $387.5 million to $388 million in stolen digital assets—up from initial lower estimates. The breach occurred after attackers compromised a critical backend system and manipulated transaction data, tricking internal systems into approving unauthorized transfers across multiple blockchains (including XRP Ledger, TRON, and Zcash). Investigators have linked the IP patterns and on-chain signatures to DPRK-affiliated hacking groups. 📰 Key Takeaways & Official Response: Full Fund Guarantee: Bitget confirmed that its $464M+ Protection Fund will fully absorb the loss, ensuring user account balances remain safe and backed 1:1. Recovery Operations: Bitget is collaborating with law enforcement, on-chain analytics teams, and cross-chain protocols like THORChain to track and freeze exploited wallet addresses. System Hardening: Backend signing modules are undergoing comprehensive security revamps to prevent future spoofing vulnerabilities. 📍#BitgetDetailsSecurityIncidentTimeline #BitgetToken
#BitgetCEOConfirms$388MStolenInHack

🚨 Bitget CEO Confirms $388M Stolen in Major Hack: Protection Fund to Fully Cover Losses 🛡️💥

Bitget CEO Gracy Chen has officially clarified that the recent exchange exploit resulted in approximately $387.5 million to $388 million in stolen digital assets—up from initial lower estimates.

The breach occurred after attackers compromised a critical backend system and manipulated transaction data, tricking internal systems into approving unauthorized transfers across multiple blockchains (including XRP Ledger, TRON, and Zcash). Investigators have linked the IP patterns and on-chain signatures to DPRK-affiliated hacking groups.

📰 Key Takeaways & Official Response:
Full Fund Guarantee: Bitget confirmed that its $464M+ Protection Fund will fully absorb the loss, ensuring user account balances remain safe and backed 1:1.

Recovery Operations: Bitget is collaborating with law enforcement, on-chain analytics teams, and cross-chain protocols like THORChain to track and freeze exploited wallet addresses.

System Hardening: Backend signing modules are undergoing comprehensive security revamps to prevent future spoofing vulnerabilities.

📍#BitgetDetailsSecurityIncidentTimeline #BitgetToken
#BitgetDetailsSecurityIncidentTimeline 🚨 Bitget Security Incident Update: What You Need to Know 🚨 Bitget has officially released the detailed timeline regarding the recent $387.5 million hot wallet exploit that happened on September 24–25. Here are the quick facts to keep you informed: 📅 Withdrawal Reopening Schedule: 1.Sept 28 (Today): Native Bitcoin ($BTC ) withdrawals are resuming. 2.$ETH , $BSCZ.ETF , Arbitrum, Base, and Optimism networks. 3.USDT (across Ethereum, Solana, BSC, Tron) 4.Oct 2: All other altcoins and P2P trading.
#BitgetDetailsSecurityIncidentTimeline
🚨 Bitget Security Incident Update: What You Need to Know 🚨
Bitget has officially released the detailed timeline regarding the recent $387.5 million hot wallet exploit that happened on September 24–25. Here are the quick facts to keep you informed:
📅 Withdrawal Reopening Schedule:
1.Sept 28 (Today): Native Bitcoin ($BTC ) withdrawals are resuming.
2.$ETH , $BSCZ.ETF , Arbitrum, Base, and Optimism networks.
3.USDT (across Ethereum, Solana, BSC, Tron)
4.Oct 2: All other altcoins and P2P trading.
·
--
Bullish
#BitgetDetailsSecurityIncidentTimeline Bitget has published a timeline of its September 24 security incident. According to Bitget, unauthorized transfers were detected at 18:31 UTC, after which its emergency response was activated and withdrawals were temporarily suspended. Sept. 24: Unauthorized transfers detected; withdrawals paused while trading and deposits remained available. Initial estimate: About $351.6M in affected assets. Sept. 25: Bitget said the attack path and underlying vulnerability had been identified and remediated. Further on-chain classification revised the affected amount to about $387.5M. Investigation: Mandiant and SlowMist are assisting with forensic investigation and fund tracing. Sept. 26: Bitget announced a phased withdrawal-restoration plan. Sept. 28 onward: Withdrawals are scheduled to resume progressively, beginning with BTC, followed by ETH, USDT, and other assets. Bitget says its cold wallets were not affected and that the financial impact is covered by its User Protection Fund. The company also says the incident remains contained while recovery and investigation efforts continue. Discussion: The key focus now is transparency around the attack path, the effectiveness of the security fixes, the recovery of affected assets, and whether the phased withdrawal process proceeds without further issues.
#BitgetDetailsSecurityIncidentTimeline

Bitget has published a timeline of its September 24 security incident. According to Bitget, unauthorized transfers were detected at 18:31 UTC, after which its emergency response was activated and withdrawals were temporarily suspended.

Sept. 24: Unauthorized transfers detected; withdrawals paused while trading and deposits remained available.

Initial estimate: About $351.6M in affected assets.

Sept. 25: Bitget said the attack path and underlying vulnerability had been identified and remediated. Further on-chain classification revised the affected amount to about $387.5M.

Investigation: Mandiant and SlowMist are assisting with forensic investigation and fund tracing.

Sept. 26: Bitget announced a phased withdrawal-restoration plan.

Sept. 28 onward: Withdrawals are scheduled to resume progressively, beginning with BTC, followed by ETH, USDT, and other assets.

Bitget says its cold wallets were not affected and that the financial impact is covered by its User Protection Fund. The company also says the incident remains contained while recovery and investigation efforts continue.

Discussion: The key focus now is transparency around the attack path, the effectiveness of the security fixes, the recovery of affected assets, and whether the phased withdrawal process proceeds without further issues.
#bitgetdetailssecurityincidenttimeline 🚨 Bitget just revealed the full timeline of the security incident. On September 24, Bitget discovered unauthorized transfers from part of the infrastructure of its hot and warm wallets. The estimated affected amount was later adjusted from $351.6 million to $387.5 million after additional transactions were identified. ⏰ 18:31 UTC: Unauthorized transfers were detected 🛑 Same day: Withdrawals were temporarily suspended 🔍 September 25: The attack path was identified and the vulnerability was fixed 💰 $387.5 million: Total affected amount after review 🛡️ Cold wallets: Not affected 🏦 Protection fund: Over $464 million 📅 September 28: The phased resumption of BTC withdrawals is scheduled to begin Bitget says the incident was contained, that users’ account balances were not affected, and that Mandiant + SlowMist are assisting in the investigation. 🔥 The big question now: Will the phased resumption of withdrawals restore confidence — or will traders remain cautious? 👀 Please continue to follow up #Bitget #crypto #security
#bitgetdetailssecurityincidenttimeline
🚨 Bitget just revealed the full timeline of the security incident.
On September 24, Bitget discovered unauthorized transfers from part of the infrastructure of its hot and warm wallets. The estimated affected amount was later adjusted from $351.6 million to $387.5 million after additional transactions were identified.
⏰ 18:31 UTC: Unauthorized transfers were detected
🛑 Same day: Withdrawals were temporarily suspended
🔍 September 25: The attack path was identified and the vulnerability was fixed
💰 $387.5 million: Total affected amount after review
🛡️ Cold wallets: Not affected
🏦 Protection fund: Over $464 million
📅 September 28: The phased resumption of BTC withdrawals is scheduled to begin
Bitget says the incident was contained, that users’ account balances were not affected, and that Mandiant + SlowMist are assisting in the investigation.
🔥 The big question now:
Will the phased resumption of withdrawals restore confidence — or will traders remain cautious? 👀

Please continue to follow up

#Bitget #crypto #security
Felipe-Brayner:
Esse desgoverno, conseguiu atingir os investidores da Binance e outras corretoras no Brasil.
Bitget timeline still trending on the square’s hot list | Using a recovery platform doesn’t mean confirming the attacker | ETH around $2,664 — I’ll wait My attitude is to first separate facts and evidence. Don’t label an attacker based on the recovery platform name, and don’t go long or short ETH because of that. Binance Square #BitgetDetailsSecurityIncidentTimeline has 45 people discussing; when switching tags on the homepage, you can’t compare discussion counts across tabs as “heat” can be accelerated. The first-hand facts come from Bitget’s official event statement updated on the platform: the platform uses Bybit’s LazarusBounty as one of the asset-recovery channels, and it explicitly states that an independent evidence-gathering investigation is still underway. Findings that have not been formally verified should not be treated as definitive conclusions. During the investigation period, it does not speculate or attribute the attack to any party. Detailed findings will be disclosed through an official security report. The tool name and the incident attribution are two different categories of information, and you can’t write “already confirmed that some organization is responsible” based on the name alone. I cross-checked Bybit’s official help center. It explains LazarusBounty as a rewards program designed to help identify and freeze illegal funds, and it explicitly distinguishes it from a Bug Bounty that targets vulnerabilities in reporting platforms. This explanation was updated in 2025—not a newly released investigation result today. It helps understand the tool’s purpose, but it cannot replace the forensic evidence for this incident. I also checked Bitget’s September 25 security update; its investigation and fund tracing are still ongoing. Why does this matter to trading? Wrong attribution may expand a platform-custody incident into threats facing all chains. But since we don’t know who the attacker is, we also can’t ignore the confirmed risks related to certain funds and channels. I’ll first verify the asset location, required permissions, and exit paths, then decide whether to add risk—no need to guess a name first. Take ETH separately. The official impacted assets include ETH, which does not mean the Ethereum consensus has been breached. Even using recovery channels, there’s no proof that all frozen funds have been returned to users, so it can’t be counted as新增买盘. I’ll wait for the official report and recovery status. I won’t use unverified attribution to endorse a rebound, nor treat tracing work as a liquidity fix. How has the market responded? I re-check Kraken’s ETH/USD around $2,664.20. Over the past 24 hours it ranged from 2,635.57 to 2,716.32. It has left the low point but hasn’t reached my confirmation threshold, so I can’t attribute it to security-related news. 2,670 is the participation condition; 2,630 is the cancel line before entry. It’s not a guarantee of effective support/resistance. Only if the official report changes the risk assessment or there’s an abnormality in the channels—then if the price condition is met, it can participate. If I were trading this myself, I wouldn’t participate. Position size is zero—no shorting, no leverage. Only if the hourly candles close above $2,670, and on the retest from $2,665 to $2,670 it holds, and the quoted price and the actual deposit/withdrawal channels are functioning normally, then I would use at most 0.3% of total funds to try a spot long. At $2,690, I’d cut the position in half; at $2,710, I’d close the remaining position. If after entry the price hits a hard stop-loss at $2,648, or if two consecutive hourly candles close below $2,665, I would close everything remaining. If it breaks below $2,630 before entry, I cancel the plan and don’t average down. Plans that haven’t been triggered are not “filled,” and can’t be written as profit. Sources: Bitget official event statement and the September 25 security update; Bybit official LazarusBounty Q&A; Kraken market data. #BitgetDetailsSecurityIncidentTimeline #ETH The above is for personal market observation only and does not constitute investment advice.
Bitget timeline still trending on the square’s hot list | Using a recovery platform doesn’t mean confirming the attacker | ETH around $2,664 — I’ll wait

My attitude is to first separate facts and evidence. Don’t label an attacker based on the recovery platform name, and don’t go long or short ETH because of that. Binance Square #BitgetDetailsSecurityIncidentTimeline has 45 people discussing; when switching tags on the homepage, you can’t compare discussion counts across tabs as “heat” can be accelerated.

The first-hand facts come from Bitget’s official event statement updated on the platform: the platform uses Bybit’s LazarusBounty as one of the asset-recovery channels, and it explicitly states that an independent evidence-gathering investigation is still underway. Findings that have not been formally verified should not be treated as definitive conclusions. During the investigation period, it does not speculate or attribute the attack to any party. Detailed findings will be disclosed through an official security report. The tool name and the incident attribution are two different categories of information, and you can’t write “already confirmed that some organization is responsible” based on the name alone.

I cross-checked Bybit’s official help center. It explains LazarusBounty as a rewards program designed to help identify and freeze illegal funds, and it explicitly distinguishes it from a Bug Bounty that targets vulnerabilities in reporting platforms. This explanation was updated in 2025—not a newly released investigation result today. It helps understand the tool’s purpose, but it cannot replace the forensic evidence for this incident. I also checked Bitget’s September 25 security update; its investigation and fund tracing are still ongoing.

Why does this matter to trading? Wrong attribution may expand a platform-custody incident into threats facing all chains. But since we don’t know who the attacker is, we also can’t ignore the confirmed risks related to certain funds and channels. I’ll first verify the asset location, required permissions, and exit paths, then decide whether to add risk—no need to guess a name first.

Take ETH separately. The official impacted assets include ETH, which does not mean the Ethereum consensus has been breached. Even using recovery channels, there’s no proof that all frozen funds have been returned to users, so it can’t be counted as新增买盘. I’ll wait for the official report and recovery status. I won’t use unverified attribution to endorse a rebound, nor treat tracing work as a liquidity fix.

How has the market responded? I re-check Kraken’s ETH/USD around $2,664.20. Over the past 24 hours it ranged from 2,635.57 to 2,716.32. It has left the low point but hasn’t reached my confirmation threshold, so I can’t attribute it to security-related news. 2,670 is the participation condition; 2,630 is the cancel line before entry. It’s not a guarantee of effective support/resistance. Only if the official report changes the risk assessment or there’s an abnormality in the channels—then if the price condition is met, it can participate.

If I were trading this myself, I wouldn’t participate. Position size is zero—no shorting, no leverage. Only if the hourly candles close above $2,670, and on the retest from $2,665 to $2,670 it holds, and the quoted price and the actual deposit/withdrawal channels are functioning normally, then I would use at most 0.3% of total funds to try a spot long. At $2,690, I’d cut the position in half; at $2,710, I’d close the remaining position. If after entry the price hits a hard stop-loss at $2,648, or if two consecutive hourly candles close below $2,665, I would close everything remaining. If it breaks below $2,630 before entry, I cancel the plan and don’t average down. Plans that haven’t been triggered are not “filled,” and can’t be written as profit.

Sources: Bitget official event statement and the September 25 security update; Bybit official LazarusBounty Q&A; Kraken market data.
#BitgetDetailsSecurityIncidentTimeline #ETH
The above is for personal market observation only and does not constitute investment advice.
Bitget timeline is still trending on the forum hot list|Publicly sharing a ZEC address does not mean the privacy protocol has been broken|Around $1,588, I’ll wait My stance: I won’t swap a custodial incident for a claim that the protocol has failed, and I won’t chase pumps. The “forum safety timeline” topic has 249 views and 45 participants—same as the previous round; ZEC appears in a six-hour search list, but there’s no rapid upward marker. Hype is not proof of buy pressure. Verified facts: Bitget’s official update on September 25 lists ZEC involved receiving addresses starting with “t1,” confirming that the affected assets include ZEC. Investigation and tracking are still ongoing; the updated version explained on September 27 also lists the Zcash network. The event scope is some exchanges’ hot wallets and the base infrastructure of warm wallets. This is not another attack today, and it’s not an already published, system-wide cryptography vulnerability. Zcash official explanation and technical glossary: Transparent addresses that start with “t” have their address and related amounts publicly recorded on-chain. Shielded transaction protection corresponds to privacy data; mixed transactions can’t be broadly said to hide everything. This is an existing mechanism, not a feature added today; a receiving address is not a complete conclusion for “tracking the funds back.” Why does this affect the market? This is my judgment: If you interpret “ZEC address disclosed” as “privacy technology has failed,” it’s easy to panic-sell for the wrong reason. Conversely, if you interpret “coin name includes privacy” as “every transfer is inherently not visible,” you may also underestimate information exposure. Publishing a portion of a transparent record cannot prove that all fund paths have been fully identified, nor can it prove that the shielding mechanism has been compromised. Custody permissions, transaction privacy, and an exchange’s withdrawal capability must be verified separately; privacy does not replace account security. As for actual market quotes: Kraken’s ZEC/USD is rechecked at $1,588.40. The 24-hour range is $1,536.24 to $1,678.70. The price has rebounded somewhat from the low point, but the quote is still below my set confirmation line of $1,595; changes in the quote cannot prove that this old announcement is the cause of the reaction. I’m not fabricating institutional inflows, and I’m not saying other coins restored withdrawals means ZEC has already restored withdrawals. If this were my own trading: I won’t participate. Position 0%, no shorting. I’d only consider testing long positions under unleveraged spot conditions. If the hourly close is above 1,595, then it pulls back to 1,590–1,595 and holds there—and the platform quotes and deposits/withdrawals are normal—then I would participate with up to 0.3% of total funds. After 1,610, halve the position; close the rest at 1,630. After entry, a hard stop-loss at 1,575, or if two consecutive hourly closes fall below 1,590, exit everything. Before entry, if it breaks below 1,550, I cancel the order and do not add. A valid recovery and confirmation above the line would overturn the “not participating” judgment. If an official technical report confirms a protocol-level issue, or if the transaction channel is abnormal, even if it breaks above, I will cancel the plan. If none of the triggers are hit, it doesn’t count as a fill, let alone a profit. Sources: [Bitget update](https://www.bitget.com/support/articles/12560603896108), [Zcash transparent vs. shielded explanation](https://z.cash/learn/what-is-the-difference-between-shielded-and-transparent-zcash/), [Technical glossary](https://zcash.readthedocs.io/en/latest/rtd_pages/glossary.html); market data: Kraken. #BitgetDetailsSecurityIncidentTimeline #ZEC The above is only personal market observation and does not constitute investment advice.
Bitget timeline is still trending on the forum hot list|Publicly sharing a ZEC address does not mean the privacy protocol has been broken|Around $1,588, I’ll wait

My stance: I won’t swap a custodial incident for a claim that the protocol has failed, and I won’t chase pumps. The “forum safety timeline” topic has 249 views and 45 participants—same as the previous round; ZEC appears in a six-hour search list, but there’s no rapid upward marker. Hype is not proof of buy pressure.

Verified facts: Bitget’s official update on September 25 lists ZEC involved receiving addresses starting with “t1,” confirming that the affected assets include ZEC. Investigation and tracking are still ongoing; the updated version explained on September 27 also lists the Zcash network. The event scope is some exchanges’ hot wallets and the base infrastructure of warm wallets. This is not another attack today, and it’s not an already published, system-wide cryptography vulnerability.

Zcash official explanation and technical glossary: Transparent addresses that start with “t” have their address and related amounts publicly recorded on-chain. Shielded transaction protection corresponds to privacy data; mixed transactions can’t be broadly said to hide everything. This is an existing mechanism, not a feature added today; a receiving address is not a complete conclusion for “tracking the funds back.”

Why does this affect the market? This is my judgment: If you interpret “ZEC address disclosed” as “privacy technology has failed,” it’s easy to panic-sell for the wrong reason. Conversely, if you interpret “coin name includes privacy” as “every transfer is inherently not visible,” you may also underestimate information exposure. Publishing a portion of a transparent record cannot prove that all fund paths have been fully identified, nor can it prove that the shielding mechanism has been compromised. Custody permissions, transaction privacy, and an exchange’s withdrawal capability must be verified separately; privacy does not replace account security.

As for actual market quotes: Kraken’s ZEC/USD is rechecked at $1,588.40. The 24-hour range is $1,536.24 to $1,678.70. The price has rebounded somewhat from the low point, but the quote is still below my set confirmation line of $1,595; changes in the quote cannot prove that this old announcement is the cause of the reaction. I’m not fabricating institutional inflows, and I’m not saying other coins restored withdrawals means ZEC has already restored withdrawals.

If this were my own trading: I won’t participate. Position 0%, no shorting. I’d only consider testing long positions under unleveraged spot conditions. If the hourly close is above 1,595, then it pulls back to 1,590–1,595 and holds there—and the platform quotes and deposits/withdrawals are normal—then I would participate with up to 0.3% of total funds. After 1,610, halve the position; close the rest at 1,630. After entry, a hard stop-loss at 1,575, or if two consecutive hourly closes fall below 1,590, exit everything. Before entry, if it breaks below 1,550, I cancel the order and do not add. A valid recovery and confirmation above the line would overturn the “not participating” judgment. If an official technical report confirms a protocol-level issue, or if the transaction channel is abnormal, even if it breaks above, I will cancel the plan. If none of the triggers are hit, it doesn’t count as a fill, let alone a profit.

Sources: [Bitget update](https://www.bitget.com/support/articles/12560603896108), [Zcash transparent vs. shielded explanation](https://z.cash/learn/what-is-the-difference-between-shielded-and-transparent-zcash/), [Technical glossary](https://zcash.readthedocs.io/en/latest/rtd_pages/glossary.html); market data: Kraken.
#BitgetDetailsSecurityIncidentTimeline #ZEC
The above is only personal market observation and does not constitute investment advice.
Bitget timeline is still trending|Not having your private key leaked doesn’t mean the authorization pathway is secure|If ETH hits $2,649, I’ll wait My stance is to first verify the authorization process. I won’t loosen custody discipline just because “the private key wasn’t leaked.” On the forum this round, #BitgetDetailsSecurityIncidentTimeline is still on the homepage, showing 45 people discussing—consistent with the previous round. This is topic continuity, not a brand-new attack. ETH hasn’t appeared on this round’s six-hour search list, and I also won’t write the security incident’s heat as if Ethereum funds are pouring in. What can be verified comes from Bitget’s official incident statement dated September 27. The platform says that, based on investigations to date, the possibility of a private key leak or being compromised has been ruled out. However, the critical backend system underlying wallet infrastructure was compromised, which was used to forge transaction data and trigger unauthorized asset transfers. On September 25, the support center update also stated that the attacker bypassed existing security controls. A report by Binance News about the CEO livestream also mentioned forged withdrawal instructions. Several pieces of material point in the same direction, but the investigation is still ongoing. The platform’s current conclusion is not a permanent guarantee of safety, and it’s not something I’ve seen in full from an independent forensic report. Here’s the mechanism that affects transaction decisions—not just where the keys are kept. In my view, protecting the keys and protecting “who can make the system sign what” are two separate controls. If the first control hasn’t been breached, the backend instructions and authorization path can still be problematic. You can’t conclude that all hardware wallets or multisigs are invalid based on this, and you also can’t pin an individual platform’s process risks onto the Ethereum consensus. The materials don’t prove that the Ethereum mainnet became invalid because of this incident. The incident involves assets like ETH, but it’s not the same as “the Ethereum protocol was broken.” Why does this impact the crypto market? Custody trust affects where users place their balances, how fast funds can be moved across platforms, and whether stop-loss orders can be executed. Risk budgeting shouldn’t only consider price volatility; it should also leave room for abnormal channel behavior. My actions aren’t about guessing the attacker’s identity. It’s about reducing reliance on a single channel and checking the actual usable status. Services showing normal operation is only the operational prerequisite—it doesn’t mean no further risks can occur. Safety discussions also can’t automatically become a reason to short ETH. How has the market reacted? Kraken published ETH/USD around $2,649.25, with the rolling 24 hours moving from $2,635.57 to $2,716.32—still on the lower side of the range. I don’t have evidence to attribute the pullback to this timeline. The U.S. spot ETH ETF page latest completed day is still September 25, so it can’t be used as if it were today’s new subscriptions. For the short term, I’ll watch whether $2,665 can reclaim. $2,630 is the condition to cancel the entry—not a support level that will never be broken. If I were trading myself: I wouldn’t participate, my position would be zero. No shorting, no leverage. Only if the hourly close is above $2,665, then it retests and holds $2,655 to $2,665, and the quotes and deposits/withdrawals through the chosen channel are normal—I would use up to 0.3% of total funds to try a spot long. At $2,685, halve. At $2,700, close the remaining position. Hard stop-loss at $2,640 after entry, or if two consecutive hourly candles close below $2,655, close everything. If it breaks $2,630 before entry, I cancel the plan and don’t add to the loss. If later official investigation changes the current conclusion about the authorization path, or if the channel shows abnormal behavior, cancel participation. Not triggering the plan doesn’t count as executed trades, and it can’t be replayed into profits. Source: Bitget official incident statement, support center update; Kraken.#BitgetDetailsSecurityIncidentTimeline #ETH The above is only my personal market observation and does not constitute investment advice.
Bitget timeline is still trending|Not having your private key leaked doesn’t mean the authorization pathway is secure|If ETH hits $2,649, I’ll wait

My stance is to first verify the authorization process. I won’t loosen custody discipline just because “the private key wasn’t leaked.” On the forum this round, #BitgetDetailsSecurityIncidentTimeline is still on the homepage, showing 45 people discussing—consistent with the previous round. This is topic continuity, not a brand-new attack.
ETH hasn’t appeared on this round’s six-hour search list, and I also won’t write the security incident’s heat as if Ethereum funds are pouring in.

What can be verified comes from Bitget’s official incident statement dated September 27. The platform says that, based on investigations to date, the possibility of a private key leak or being compromised has been ruled out. However, the critical backend system underlying wallet infrastructure was compromised, which was used to forge transaction data and trigger unauthorized asset transfers.
On September 25, the support center update also stated that the attacker bypassed existing security controls. A report by Binance News about the CEO livestream also mentioned forged withdrawal instructions.
Several pieces of material point in the same direction, but the investigation is still ongoing. The platform’s current conclusion is not a permanent guarantee of safety, and it’s not something I’ve seen in full from an independent forensic report.

Here’s the mechanism that affects transaction decisions—not just where the keys are kept. In my view, protecting the keys and protecting “who can make the system sign what” are two separate controls. If the first control hasn’t been breached, the backend instructions and authorization path can still be problematic.
You can’t conclude that all hardware wallets or multisigs are invalid based on this, and you also can’t pin an individual platform’s process risks onto the Ethereum consensus. The materials don’t prove that the Ethereum mainnet became invalid because of this incident. The incident involves assets like ETH, but it’s not the same as “the Ethereum protocol was broken.”

Why does this impact the crypto market? Custody trust affects where users place their balances, how fast funds can be moved across platforms, and whether stop-loss orders can be executed. Risk budgeting shouldn’t only consider price volatility; it should also leave room for abnormal channel behavior.
My actions aren’t about guessing the attacker’s identity. It’s about reducing reliance on a single channel and checking the actual usable status. Services showing normal operation is only the operational prerequisite—it doesn’t mean no further risks can occur. Safety discussions also can’t automatically become a reason to short ETH.

How has the market reacted? Kraken published ETH/USD around $2,649.25, with the rolling 24 hours moving from $2,635.57 to $2,716.32—still on the lower side of the range. I don’t have evidence to attribute the pullback to this timeline.
The U.S. spot ETH ETF page latest completed day is still September 25, so it can’t be used as if it were today’s new subscriptions.
For the short term, I’ll watch whether $2,665 can reclaim. $2,630 is the condition to cancel the entry—not a support level that will never be broken.

If I were trading myself: I wouldn’t participate, my position would be zero. No shorting, no leverage. Only if the hourly close is above $2,665, then it retests and holds $2,655 to $2,665, and the quotes and deposits/withdrawals through the chosen channel are normal—I would use up to 0.3% of total funds to try a spot long.
At $2,685, halve. At $2,700, close the remaining position. Hard stop-loss at $2,640 after entry, or if two consecutive hourly candles close below $2,655, close everything. If it breaks $2,630 before entry, I cancel the plan and don’t add to the loss.
If later official investigation changes the current conclusion about the authorization path, or if the channel shows abnormal behavior, cancel participation. Not triggering the plan doesn’t count as executed trades, and it can’t be replayed into profits.

Source: Bitget official incident statement, support center update; Kraken.#BitgetDetailsSecurityIncidentTimeline #ETH
The above is only my personal market observation and does not constitute investment advice.
Bitget Incident Timeline Rises on Hot List|Loss Estimate Raised Again—Or Another Theft?|BTC at 82,700 yuan? I’ll wait My approach is cautious: I won’t re-calculate old events and mistakenly turn them into something that happened today—only to be attacked again. On the Bitget forum homepage this round, the post #BitgetDetailsSecurityIncidentTimeline shows 45 people discussing; the topic page shows 78. The page snapshots are different, so you can’t treat the difference as a measure of fund flows. The hot discussion about BTC falling below 83,000 climbed to 73 people, but panic and “dip-buying” posts can’t replace evidence. I cross-checked this round by comparing Bitget’s official academy event explanation dated September 27, the September 25 support-center update, and the original announcement: the platform first roughly estimated the affected amount at about $351.6 million, then updated it to about $387.5 million. The difference of $35.9 million comes from more complete categorization of the transfers from the original incident, including adding related Zcash and TRON transactions that were not counted initially. The official statement is clear: this revision of the figure is not additional unauthorized transfers that occurred after the incident was controlled, and it is not another security incident. The amount is not a new loss announced today—so you can’t remove the date just to make the headline more sensational. However, “not stolen again” doesn’t mean risk has already been fully eliminated. Bitget says the incident is under control and the vulnerability has been patched, and that Mandiant and SlowMist continue to support the investigation. These are the platform’s disclosures at present—not an independent security audit I personally completed. On-chain fund tracking, actual recoveries, and service restoration each have their own validation standards. The revision of the loss estimate is only one part of that. My view is that transparent disclosure can help reduce false expectations, but rebuilding trust still depends on later verification—you can’t derive an investable setup from a single timeline. Why the impact on BTC? Traders may adjust platform balances and cross-platform positions due to custodial risk. That can change local liquidity, quotes, and friction in capital routing—but it doesn’t necessarily mean the entire market is uniformly selling BTC. A more accurate trading question is: can the channel I plan to use execute normally, and is there continuous bid support at the price? Platform incident details and Bitcoin protocol risks also can’t be lumped into one thing. I didn’t find this round’s materials showing that the Bitcoin main chain became invalid due to this incident. How has the market reacted? Before Kraken published, BTC/USD was around $82,704.5. In the rolling 24 hours, it moved from $82,566.4 to $85,142.8. It’s below $83,000 and close to the lower edge of the range. These are quoting facts—they don’t prove that “the timeline release caused the drop.” The latest completed day for U.S. spot ETF fund flows is still September 25. You can’t use last week’s inflows to prop up today’s downside. $83,000 is only an integer level to observe whether it can be reclaimed. I won’t place high-leverage long orders below it just because it’s trending on the hot list. If I were trading on my own: I wouldn’t participate right now. My position is zero—I won’t short or add leverage. Only if the hourly chart closes back above $83,300, then retests and holds between $83,150 and $83,300—and the actual quotes and deposit/withdrawal channels I use are functioning normally—would I use up to 0.3% of total funds to try a spot long. If it reaches $83,800, I’d cut the position by half; at $84,300 I’d close the remaining lot. After entering, I’d place a hard stop-loss at $82,800, or if two consecutive hourly candles close below $83,150, I’d close everything. If the market breaks below $82,200 before entry, I cancel the plan and don’t average down. If official subsequent verification changes the conclusion that the incident is under control, or if the channels show abnormalities—then even if price triggers it, I would cancel participation. These plans aren’t trade records, and there is no realized profit. Source: Bitget official incident explanation on its website and support-center announcement; Kraken quotes. #BitgetDetailsSecurityIncidentTimeline #BTC The above is only my personal market observation and does not constitute investment advice.
Bitget Incident Timeline Rises on Hot List|Loss Estimate Raised Again—Or Another Theft?|BTC at 82,700 yuan? I’ll wait

My approach is cautious: I won’t re-calculate old events and mistakenly turn them into something that happened today—only to be attacked again. On the Bitget forum homepage this round, the post #BitgetDetailsSecurityIncidentTimeline shows 45 people discussing; the topic page shows 78. The page snapshots are different, so you can’t treat the difference as a measure of fund flows. The hot discussion about BTC falling below 83,000 climbed to 73 people, but panic and “dip-buying” posts can’t replace evidence.

I cross-checked this round by comparing Bitget’s official academy event explanation dated September 27, the September 25 support-center update, and the original announcement: the platform first roughly estimated the affected amount at about $351.6 million, then updated it to about $387.5 million. The difference of $35.9 million comes from more complete categorization of the transfers from the original incident, including adding related Zcash and TRON transactions that were not counted initially. The official statement is clear: this revision of the figure is not additional unauthorized transfers that occurred after the incident was controlled, and it is not another security incident. The amount is not a new loss announced today—so you can’t remove the date just to make the headline more sensational.

However, “not stolen again” doesn’t mean risk has already been fully eliminated. Bitget says the incident is under control and the vulnerability has been patched, and that Mandiant and SlowMist continue to support the investigation. These are the platform’s disclosures at present—not an independent security audit I personally completed. On-chain fund tracking, actual recoveries, and service restoration each have their own validation standards. The revision of the loss estimate is only one part of that. My view is that transparent disclosure can help reduce false expectations, but rebuilding trust still depends on later verification—you can’t derive an investable setup from a single timeline.

Why the impact on BTC? Traders may adjust platform balances and cross-platform positions due to custodial risk. That can change local liquidity, quotes, and friction in capital routing—but it doesn’t necessarily mean the entire market is uniformly selling BTC. A more accurate trading question is: can the channel I plan to use execute normally, and is there continuous bid support at the price? Platform incident details and Bitcoin protocol risks also can’t be lumped into one thing. I didn’t find this round’s materials showing that the Bitcoin main chain became invalid due to this incident.

How has the market reacted? Before Kraken published, BTC/USD was around $82,704.5. In the rolling 24 hours, it moved from $82,566.4 to $85,142.8. It’s below $83,000 and close to the lower edge of the range. These are quoting facts—they don’t prove that “the timeline release caused the drop.” The latest completed day for U.S. spot ETF fund flows is still September 25. You can’t use last week’s inflows to prop up today’s downside. $83,000 is only an integer level to observe whether it can be reclaimed. I won’t place high-leverage long orders below it just because it’s trending on the hot list.

If I were trading on my own: I wouldn’t participate right now. My position is zero—I won’t short or add leverage. Only if the hourly chart closes back above $83,300, then retests and holds between $83,150 and $83,300—and the actual quotes and deposit/withdrawal channels I use are functioning normally—would I use up to 0.3% of total funds to try a spot long. If it reaches $83,800, I’d cut the position by half; at $84,300 I’d close the remaining lot. After entering, I’d place a hard stop-loss at $82,800, or if two consecutive hourly candles close below $83,150, I’d close everything. If the market breaks below $82,200 before entry, I cancel the plan and don’t average down. If official subsequent verification changes the conclusion that the incident is under control, or if the channels show abnormalities—then even if price triggers it, I would cancel participation. These plans aren’t trade records, and there is no realized profit.

Source: Bitget official incident explanation on its website and support-center announcement; Kraken quotes. #BitgetDetailsSecurityIncidentTimeline #BTC
The above is only my personal market observation and does not constitute investment advice.
The security incident timeline is still trending|See the protection fund and reserve proof separately|ZEC at $1,559—I’ll wait My position is clear: a funds-protection statement cannot directly become a reason to buy; first check assets, liabilities, and the withdrawal path, then look for any rebound. On the Binance Square for this round, the topic still shows Bitget’s timeline; it has 249 views and 45 participants, the same as the previous round, which does not mean the heat is accelerating. ZEC is on the search list, but there’s no rapid rise indicator—attention is not net buy evidence. The one-hand fact is this: on September 27, Bitget’s official notice explicitly distinguishes user protection funds from reserve proof. The former is additional资金保障 for qualifying platform security incidents; the latter is used to improve transparency regarding the platform’s assets relative to user balances. The latest reserve information after the incident must also be completed with relevant verification before being published. An official update on September 25 also confirmed that the affected assets include ZEC. What I cross-check is the platform’s two documents—not conclusions from any third-party audit. Why does this affect the crypto market? Here is my independent take: traders easily string together “has a fund,” “has reserves,” and “can withdraw” into a single safety promise—but these three issues need to be verified separately. The fund’s eligibility conditions, whether the assets are fully covered, and whether the specific coin and network you use are supported/open are not the same piece of evidence. A total amount or a ratio cannot replace concrete到账 testing; even if balances appear on the books, it doesn’t make liquidity costs during the waiting period disappear automatically. For ZEC, I don’t frame the custody incident as a privacy protocol being hacked, and I don’t derive an inevitable price recovery from the funds-protection statement. I need to verify separately the platform announcement dates, supported networks, and withdrawal status. Different platforms’ arrangements cannot be used interchangeably. Even self-custody requires backups and operational discipline—not “risk zeroing.” How has the market reacted? Before publication, Kraken rechecked the ZEC/USD price at $1,558.63, with a 24-hour low of $1,536.24 and a high of $1,678.70. The price is still in the lower part of its range; it has not broken above my set confirmation line at $1,565. This only describes the current quote—it cannot prove that this volatility was caused by a security news event. The trending list also provides no data on fund flows or cross-platform buy/sell spreads, so I won’t write a “market rushes in” story. If I were trading myself, I would not participate: position 0%. My direction would only consider taking long positions under unleveraged spot conditions; no shorting. If the hourly close is above 1,565, then pull back to 1,558–1,565 and hold, and if the exchange and deposit/withdrawal channels being used are正常, then I would participate with up to 0.3% of total capital; halve at 1,580 and close the remaining position at 1,600. After entry, use a hard stop at 1,545; or if two consecutive hourly closes fall below 1,558, exit everything. Before entry, if it first breaks down below 1,530 and you invalidate the plan to try longs, don’t average down. Standing firm above 1,565 and verifying the channel would overturn the “not participating for now” decision. Even if the price breaks out, if the channel has issues, cancel entry. If the plan is not triggered, there is no trade—so I don’t write it as profit. Sources: [Bitget official notice](https://www.bitget.com/zh-CN/amp/academy/bitget-security-incident-what-happened-timeline-impact-response), [Official update](https://www.bitget.com/support/articles/12560603896108); market data: Kraken; topic: Binance Square. #BitgetDetailsSecurityIncidentTimeline #ZEC The above is only my personal market observation and does not constitute investment advice.
The security incident timeline is still trending|See the protection fund and reserve proof separately|ZEC at $1,559—I’ll wait

My position is clear: a funds-protection statement cannot directly become a reason to buy; first check assets, liabilities, and the withdrawal path, then look for any rebound. On the Binance Square for this round, the topic still shows Bitget’s timeline; it has 249 views and 45 participants, the same as the previous round, which does not mean the heat is accelerating. ZEC is on the search list, but there’s no rapid rise indicator—attention is not net buy evidence.

The one-hand fact is this: on September 27, Bitget’s official notice explicitly distinguishes user protection funds from reserve proof. The former is additional资金保障 for qualifying platform security incidents; the latter is used to improve transparency regarding the platform’s assets relative to user balances. The latest reserve information after the incident must also be completed with relevant verification before being published. An official update on September 25 also confirmed that the affected assets include ZEC. What I cross-check is the platform’s two documents—not conclusions from any third-party audit.

Why does this affect the crypto market? Here is my independent take: traders easily string together “has a fund,” “has reserves,” and “can withdraw” into a single safety promise—but these three issues need to be verified separately. The fund’s eligibility conditions, whether the assets are fully covered, and whether the specific coin and network you use are supported/open are not the same piece of evidence. A total amount or a ratio cannot replace concrete到账 testing; even if balances appear on the books, it doesn’t make liquidity costs during the waiting period disappear automatically.

For ZEC, I don’t frame the custody incident as a privacy protocol being hacked, and I don’t derive an inevitable price recovery from the funds-protection statement. I need to verify separately the platform announcement dates, supported networks, and withdrawal status. Different platforms’ arrangements cannot be used interchangeably. Even self-custody requires backups and operational discipline—not “risk zeroing.”

How has the market reacted? Before publication, Kraken rechecked the ZEC/USD price at $1,558.63, with a 24-hour low of $1,536.24 and a high of $1,678.70. The price is still in the lower part of its range; it has not broken above my set confirmation line at $1,565. This only describes the current quote—it cannot prove that this volatility was caused by a security news event. The trending list also provides no data on fund flows or cross-platform buy/sell spreads, so I won’t write a “market rushes in” story.

If I were trading myself, I would not participate: position 0%. My direction would only consider taking long positions under unleveraged spot conditions; no shorting. If the hourly close is above 1,565, then pull back to 1,558–1,565 and hold, and if the exchange and deposit/withdrawal channels being used are正常, then I would participate with up to 0.3% of total capital; halve at 1,580 and close the remaining position at 1,600. After entry, use a hard stop at 1,545; or if two consecutive hourly closes fall below 1,558, exit everything. Before entry, if it first breaks down below 1,530 and you invalidate the plan to try longs, don’t average down. Standing firm above 1,565 and verifying the channel would overturn the “not participating for now” decision. Even if the price breaks out, if the channel has issues, cancel entry. If the plan is not triggered, there is no trade—so I don’t write it as profit.

Sources: [Bitget official notice](https://www.bitget.com/zh-CN/amp/academy/bitget-security-incident-what-happened-timeline-impact-response), [Official update](https://www.bitget.com/support/articles/12560603896108); market data: Kraken; topic: Binance Square.
#BitgetDetailsSecurityIncidentTimeline #ZEC
The above is only my personal market observation and does not constitute investment advice.
XRP$XRP is around $1.48–$1.49, down roughly 3% over 24 hours at the time of reporting. MarketBeat +1 ETF demand: U.S. spot XRP ETFs reportedly hold about 1.18 billion XRP. Pluang$XRP {future}(XRPUSDT) Ripple escrow: Ripple is scheduled to unlock up to 1 billion XRP on October 1; the amount actually reaching the market can be lower because some XRP is typically re-escrowed. Pluang Evernorth: Shareholders of Armada Acquisition Corp. II are scheduled to vote September 30 on the proposed transaction that could take XRP-focused Evernorth public. CryptoRank Security issue: Around $83 million in stolen XRP from the Bitget hack has reportedly been moved between external wallets, while XRP itself cannot be frozen by Ripple at the protocol level. $XAU {future}(XAUUSDT) #QNTFallsOver40%FromMorningHigh #ChinaMayLetAlibabaByteDanceBuyNvidiaChips #BitgetDetailsSecurityIncidentTimeline #BitgetDetailsSecurityIncidentTimeline
XRP$XRP is around $1.48–$1.49, down roughly 3% over 24 hours at the time of reporting.
MarketBeat +1
ETF demand: U.S. spot XRP ETFs reportedly hold about 1.18 billion XRP.
Pluang$XRP

Ripple escrow: Ripple is scheduled to unlock up to 1 billion XRP on October 1; the amount actually reaching the market can be lower because some XRP is typically re-escrowed.
Pluang
Evernorth: Shareholders of Armada Acquisition Corp. II are scheduled to vote September 30 on the proposed transaction that could take XRP-focused Evernorth public.
CryptoRank
Security issue: Around $83 million in stolen XRP from the Bitget hack has reportedly been moved between external wallets, while XRP itself cannot be frozen by Ripple at the protocol level. $XAU
#QNTFallsOver40%FromMorningHigh #ChinaMayLetAlibabaByteDanceBuyNvidiaChips #BitgetDetailsSecurityIncidentTimeline #BitgetDetailsSecurityIncidentTimeline
·
--
Bearish
$TAO REJECTED FROM THE DESCENDING TRENDLINE. TAO is showing a clear rejection from the higher-timeframe descending trendline, with price now back around $301 after failing to hold the $320–$330 area. The 4H structure is turning bearish, while the daily and weekly charts show the same descending resistance still acting as a major ceiling. If $300 breaks with confirmation, the next levels I’m watching are $290 → $278. And i am personally looking at the 260$ for a long shoot cause majors like $BTC and $SOL are bledding so eyes on the berish side till majors shows some buyings! For the bullish side, TAO needs to reclaim the $330 zone and break the descending trendline with a strong close before the structure can shift back upward. Key levels: Support: $300 / $290 / $278 Resistance: $320 / $330 The rejection is in now we watch whether 277$ holds or the next leg down begins. {future}(BTCUSDT) {future}(TAOUSDT) {future}(SOLUSDT) #GoldFallsTo$4144 #QNTFallsOver40%FromMorningHigh #BitgetCEOConfirms$388MStolenInHack #BTCFallsBelow$83000 #BitgetDetailsSecurityIncidentTimeline
$TAO REJECTED FROM THE DESCENDING TRENDLINE.
TAO is showing a clear rejection from the higher-timeframe descending trendline, with price now back around $301 after failing to hold the $320–$330 area.
The 4H structure is turning bearish, while the daily and weekly charts show the same descending resistance still acting as a major ceiling.

If $300 breaks with confirmation, the next levels I’m watching are $290 → $278. And i am personally looking at the 260$ for a long shoot cause majors like $BTC and $SOL are bledding so eyes on the berish side till majors shows some buyings!

For the bullish side, TAO needs to reclaim the $330 zone and break the descending trendline with a strong close before the structure can shift back upward.

Key levels:
Support: $300 / $290 / $278
Resistance: $320 / $330

The rejection is in now we watch whether 277$ holds or the next leg down begins.



#GoldFallsTo$4144 #QNTFallsOver40%FromMorningHigh #BitgetCEOConfirms$388MStolenInHack #BTCFallsBelow$83000 #BitgetDetailsSecurityIncidentTimeline
FBDunless498:
sir short entry price when..?
🧠 High volume ≠ strong buying pressure Have you ever seen a candle with a sudden spike in volume, but the price barely moves? This is interesting because *volume only shows how much trading activity took place*. It doesn’t tell you who is winning. For example, aggressive buyers may enter with large orders, but at the same time, sellers continue absorbing that buying pressure. The result? Very high volume, but only a small price movement. This phenomenon is often referred to as *absorption*. So instead of only asking: > “Is the volume high or low?” Try asking: “With that much volume, how far did the price actually move?” Sometimes, *high volume + small price movement* can be much more interesting than high volume followed by a huge candle. 👀 $XRP $BTC $DOGE #CryptoAnalysis #BitgetDetailsSecurityIncidentTimeline #FedProposesPaymentStablecoinRules
🧠 High volume ≠ strong buying pressure

Have you ever seen a candle with a sudden spike in volume, but the price barely moves?

This is interesting because *volume only shows how much trading activity took place*. It doesn’t tell you who is winning.

For example, aggressive buyers may enter with large orders, but at the same time, sellers continue absorbing that buying pressure.

The result?

Very high volume, but only a small price movement.

This phenomenon is often referred to as *absorption*.

So instead of only asking:

> “Is the volume high or low?”

Try asking:

“With that much volume, how far did the price actually move?”

Sometimes, *high volume + small price movement* can be much more interesting than high volume followed by a huge candle. 👀
$XRP $BTC $DOGE
#CryptoAnalysis #BitgetDetailsSecurityIncidentTimeline #FedProposesPaymentStablecoinRules
Log in to explore more content
Join global crypto users on Binance Square
⚡️ Get latest and useful information about crypto.
💬 Trusted by the world’s largest crypto exchange.
👍 Discover real insights from verified creators.
Email / Phone number