Bitget Wallet Chief Advocates for Stronger Self-Custody Security Measures
Bitget Wallet’s Chief Operating Officer, Alvin Kan, has called for better transaction approvals and recovery tools for self-custody wallet users. His remarks come after a security breach at the Bitget exchange, which resulted in unauthorized transfers totaling around $388 million from certain hot and warm exchange wallets. The incident, detected on September 24, involved attackers using compromised credentials obtained through a vulnerability in a third-party security product. Bitget emphasizes that its wallet systems and users’ self-custodied assets were unaffected, as the wallet and exchange operate on separate infrastructures.
Kan’s proposals focus on enhancing user understanding of transaction authorizations. He suggests that wallets should clearly display the amount being transferred and specify whether an approval is for a single payment or ongoing access. He also advocates for tools to revoke permissions and guidance on recovering access after losing a device or backup. Self-custody places full responsibility on users to manage their private keys and authorize transactions, eliminating intermediaries but requiring heightened security awareness.
The European Securities and Markets Authority (ESMA) is conducting a review of crypto-asset service providers’ custody and operational controls, including key management and transaction controls. This review, scheduled to conclude in the second half of 2027, aims to assess incident response and third-party dependencies. Meanwhile, the U.S. Securities and Exchange Commission (SEC) has proposed new rules for registered investment advisers managing client crypto assets, though these do not apply to individuals handling their own wallets. SEC Commissioner Hester Peirce noted that the proposal targets different arrangements than self-custody, acknowledging that it may not suit everyone.