Science and Technology
Bitget’s Breach Exposes Crypto’s Dangerous Illusion of Safety, by Fransiscus Nanga Roka
The Bitget breach should make industry to give up on security theater Customers trust exchanges with their assets because they expect competent custody, easy access/withdrawals and good accountability.
Hundreds of Millions Dollar Lost Even If A Cryptocurrency Exchange Keep Its Private Keys Safe That is the lamentable question of governance behind Bitget’s September hack: if criminals are able to manipulate the very machines that have been empowered to move money, then what does “secure” even mean?
On 24 September 2026, at 18:31 UTC, there were unauthorized transfers of wallets that were acting as thieves. And Bitget issued a suspension to all withdrawals. Its original estimate of $351.6 million was later revised up to roughly $387.5 million after discovering other impacted assets. The exchange revision noted a fuller accounting, rather than another assault. All of these were assets moving between many blockchain networks as part of a decentralized global platform for finance.
In a statement on Sept 30, Bitget said they are working with investigators including Mandiant and SlowMist who identified that attacked third-party security products were used to gain access to its wallet environment without authorization. Attackers modified backend transaction data and activated the authorization process to transfer funds, according to a Financial Times report. So the failure rightly extended past real key custody to the systems that decided what transactions were worthy of being approved.
The implication is brutal. Good operational judgment cannot be compensated by cryptographic strength. The blockchain will execute a theft as faithfully as it would execute an actual authorized command, if the malicious instructions are properly authorized.
Kudos to Bitget, who have pledged to cover the losses. Its first notice pointed to a User Protection Fund of more than $464 million, as well as guaranteeing customers that balances were correct. However, independent auditing is necessary to assure the coverage of a company. Customers require visibility around the assets, liabilities and payment obligations a fund has access to post its repayment capability. You may see a number on a screen, but we cannot withdraw that number into the real world.
If suspicion of North Korea deals with it, it should not replace institutional scrutiny either. Read more – Bitget boss likened attack pattern to North Korean hackers That is, at best, an investigative lead not a judicial finding. But even if state sponsorship is eventually proven, regulators must determine whether adequate defenses were in place against foreseeable threats.
Security outsourcing should never be equivalently security accountability outsourcing. Who had privileged access, what protections faltered, what warning signals were present, and whether vendor oversight was sufficient are among the questions investigators should answer. Liability should follow evidence, law and contract obligations not public relations statements.
The strategic response has to be tangible.
Regulators must start by requiring forensic reports to be conducted independently, mandating the preservation of transaction and access logs, and establishing strict deadlines for disclosure. Entity-level failures are publicly reported with holdings that protect specific details.
Second, separating transaction creation from approval across exchanges, limiting privileged credentials to only the most necessary accounts; forcing limits on exposures as well as testing that internal systems are secure and if attacked can not make a transfer.
The third is that protection funds be subjected to independent audits and stress testing against the scenario of simultaneous theft, falling asset prices (and) mass withdrawals. Finally, the rules surrounding reimbursement need to lay out definitive rights which customers can enforce.
Fourth, cross-border recovery should be based on amalgamation of rapid tracing and legal freezing, preservation of evidence and procedures to contest incorrect restrictions.
At last, boards should face real consequences where investigations confirm major control failings. But it cannot buy you immunity from scrutiny simply by replenishing a fund.
The Bitget breach should make industry to give up on security theater Customers trust exchanges with their assets because they expect competent custody, easy access/withdrawals and good accountability.
A model of a platform that is able to refund theft has proven its financial viability. And it still has to show that the conditions for the theft have been corrected.
Fransiscus Nanga Roka
Faculty of Law University 17 August 1945 Surabaya and Managing Partner Law Firm Victorious Indonesia

You must be logged in to post a comment Login