1 min read

Bitget Completes Vulnerability Repairs, Adds Four Security Controls

The exchange isolated affected systems, invalidated and reissued internal credentials, and required independent verification for subsequent withdrawals.

A sealed access door secured inside a quiet exchange facility / TokenPost.ai
A sealed access door secured inside a quiet exchange facility / TokenPost.ai

Bitget completed repairs for a vulnerability involved in a recent security incident and implemented four corrective measures Sept. 28.

The exchange isolated affected servers from its network to contain the attack and preserve evidence for tracing. It also invalidated and reissued all internal login credentials, rendering stolen credentials unusable.

Bitget withdrew and reorganized high-sensitivity permissions, while separating critical access so key operations require approval from multiple people. It notified the relevant third-party security vendor, shared vulnerability details and assisted with analysis and remediation. Related functions remained suspended until repairs were completed.

The attack involved exploiting a vulnerability in a third-party security product to obtain credentials for Bitget’s internal network and forge withdrawal instructions for its wallet system.

All subsequent withdrawals must undergo independent verification. The incident is under control, and no further unauthorized transfers have been found. Withdrawals on each blockchain will resume only after multiple core checks are completed.

Loading…