Tag: security incident

  • Bitget CEO Confirms Hack, Reveals Massive Losses; Withdrawals Suspended

    Bitget CEO Confirms Hack, Reveals Massive Losses; Withdrawals Suspended

    Key Highlights

    • Cryptocurrency exchange Bitget detected unauthorized transfers from hot wallets totaling approximately $351.6 million on September 24, 2026, at 18:31 UTC.
    • Cold wallets remain secure and the loss is fully covered by Bitget’s User Protection Fund, which holds over $464 million in assets.
    • Withdrawals are temporarily suspended as a precaution; deposits and trading continue normally with hourly updates promised and a full incident report due within 24 hours.

    Breach Detection and Emergency Response

    Cryptocurrency exchange Bitget released an official statement on September 24, 2026, confirming that its security systems detected unauthorized transfers from several hot wallets at 6:31 PM UTC. According to a statement by Bitget CEO Gracy Chen, the company’s security team activated emergency response protocols immediately upon detection. The exchange announced that its emergency response team was activated within minutes, the addresses where the unusual transfers occurred were identified and marked, and relevant parties were notified. Law enforcement and security companies have been officially involved in the investigation process.

    [SECURITY NOTICE] Bitget Hot Wallet Incident — September 24, 2026
    At 18:31 UTC on September 24, 2026, Bitget’s security systems detected unauthorized transfers from some of our hot wallets. Our security team activated emergency response protocols immediately.
    What we have…
    — Gracy Chen @Bitget (@GracyBitget) September 24, 2026

    Wallet Architecture Limits Impact

    Bitget emphasized that the incident was limited to only a portion of the hot and warm wallet layers. The company operates a three-layered wallet architecture, and cold wallets were not affected by the breach. This structural segregation prevented the compromise from extending to the majority of user funds held in offline storage. The exchange maintained that account balances are accurate and user assets are protected despite the hot wallet losses.

    User Protection Fund Coverage

    The company stated that the entire approximately $351.6 million loss could be covered by Bitget’s User Protection Fund, which holds over $464 million in assets. This reserve mechanism is designed to absorb losses from security incidents without impacting individual user holdings. Bitget reiterated that user funds are safe and the protection fund has sufficient capacity to cover the full extent of the unauthorized transfers.

    Operational Status and Next Steps

    As a precautionary measure while a security review is underway, Bitget has temporarily suspended withdrawal transactions. However, deposits and trading continue as normal. The exchange announced that withdrawals will be reopened after the security review is complete. The company committed to sharing updates on the incident hourly and publishing a comprehensive incident report detailing the cause of the attack, the method used, and corrective measures taken within 24 hours. The method used in the attack has not been disclosed at this stage, and Bitget stated it will not speculate on the attack vector until the investigation is complete.

    Why This Matters

    The Bitget incident highlights the persistent security challenges facing centralized cryptocurrency exchanges, particularly regarding hot wallet management. Hot wallets, which remain connected to the internet to facilitate rapid withdrawals and trading operations, represent a concentrated attack surface. The exchange’s three-layered architecture—segregating cold, warm, and hot wallets—demonstrates a defense-in-depth approach that successfully contained the breach to the most exposed layer. The existence of a substantial User Protection Fund, capitalized at over $464 million, reflects an industry trend toward self-insurance mechanisms that can absorb losses without requiring bailouts or socialized loss distribution among users. The temporary withdrawal suspension, while disruptive, follows standard incident response protocols to prevent further outflows during forensic analysis. The promised transparency—hourly updates and a detailed post-mortem within 24 hours—sets a benchmark for crisis communication in the digital asset sector. Regulators and industry observers will likely scrutinize the attack vector once disclosed, as it may inform evolving security standards for custodial platforms.

    Frequently Asked Questions

    Are user funds on Bitget safe after this incident?

    Yes. Bitget has confirmed that cold wallets were not affected and the approximately $351.6 million loss is fully covered by its User Protection Fund, which holds over $464 million in assets. Account balances remain accurate and user assets are protected.

    Can I still trade and deposit on Bitget?

    Yes. Deposits and trading continue as normal. Only withdrawal transactions have been temporarily suspended as a precautionary measure while the security review is conducted.

    When will withdrawals resume and when will we know how the attack happened?

    Bitget states withdrawals will reopen after the security review is complete. The company will provide hourly updates and publish a comprehensive incident report detailing the cause, method, and corrective measures within 24 hours of the initial detection.

  • Crypto Exchange Recovery Rules Divide NES Holders Into Winners, Losers After $286M Exploit Fallout

    Crypto Exchange Recovery Rules Divide NES Holders Into Winners, Losers After $286M Exploit Fallout

    NES Token Resumes Trading on Binance Alpha and Kraken After Security Incident

    Nesa’s NES token returned to trading on Binance Alpha and regained Ethereum funding support on Kraken on September 10, following exchange-specific interruptions tied to an August 24 token-contract security incident. The restorations are not a network-wide relaunch or a single recovery plan, and they do not establish a universal migration process for NES held in private wallets.

    Binance Alpha: Two-Snapshot System for Swaps and Refunds

    Binance Alpha is using two separate snapshots to determine eligibility for a 1:1 token swap versus refund treatment on its platform. According to the exchange’s announcement, users who held NES before August 24 at 14:51 UTC must also have held an eligible portion when trading was suspended on September 5 at 04:00 UTC to qualify for the 1:1 swap for that portion.

    Any additional NES acquired after the August 24 cutoff is excluded from the 1:1 swap and will be subject to separate refund treatment. Binance stated that users with eligible net purchases during the specified window would receive an email with refund details within seven business days. The announcement does not disclose the complete refund formula or support a claim that every affected holder will be made whole.

    Trading was scheduled to reopen at 08:00 UTC on September 10. Users should check which snapshot category applies to their balance and monitor the email address linked to their account.

    Kraken: Ethereum-Only Migration, BNB Chain Funding Disabled

    Kraken’s incident page confirmed that NES covered by its funding incident would migrate 1:1 to a new Ethereum contract. The exchange scheduled Ethereum deposits and withdrawals to resume at 14:00 UTC on September 10 and marked the funding incident resolved 12 minutes later.

    Kraken explicitly stated that NES funding on BNB Chain would remain disabled and only Ethereum-based NES would be supported going forward. Customers moving NES to or from Kraken should select Ethereum and verify the new contract details in Kraken’s official notice before transferring funds.

    No Universal Migration for Self-Custodied Holders

    The exchange-managed actions do not determine what happens to NES held outside Binance Alpha or Kraken. Self-custodied holders should not assume that Binance’s snapshot windows or Kraken’s automatic migration apply to tokens in their own wallets.

    As of press time, Nesa’s public official site and general wallet documentation did not provide incident-specific self-custody migration steps. Until Nesa publishes or directly verifies a route, holders should verify any contract address and migration process through official Nesa channels before approving a contract interaction or moving old-contract tokens.