Bitget Repairs Vulnerability, Implements New Security Controls After Recent Incident
Bitget has completed repairs on a vulnerability that was exploited in a recent security incident. The exchange isolated affected servers from its network to contain the attack and preserve evidence for tracing.
The attack involved exploiting a vulnerability in a third-party security product to obtain credentials for Bitget's internal network and forge withdrawal instructions for its wallet system.
To rectify the situation, Bitget invalidated and reissued all internal login credentials, rendering stolen credentials unusable. High-sensitivity permissions were withdrawn and reorganized, while critical access was separated so key operations require approval from multiple people.
Bitget also notified the relevant third-party security vendor, shared vulnerability details, and assisted with analysis and remediation. Related functions remained suspended until repairs were completed.
Withdrawals on each blockchain will resume only after multiple core checks are completed.