Japan's crypto overhaul and the widening gap with the US: what to watch
Japan has moved crypto under securities rules and plans a 20% tax rate, but ETFs and lower taxes are not yet in force; the US still leads.
With withdrawals restored after the $387.5M Bitget hack, CEO Gracy Chen says the exchange could absorb another major loss.
On September 24, attackers took approximately $387.5 million from Bitget by tampering with the exchange's internal withdrawal procedure. Chainalysis has blamed North Korean hackers for the incident.
Is Bitget safe to use now? What would happen if the next attack were bigger? And what is the exchange doing to tighten security? BeInCrypto spoke with CEO Gracy Chen on these points.
October 6 brought withdrawals back online at Bitget, while investigators kept following the stolen assets:
An exclusive interview with BeInCrypto, conducted before withdrawals were fully restored, found Chen defending Bitget's financial standing. She also accepted that its understanding of the attack was incomplete.
After Bitget drew on bitcoin in its protection fund to handle withdrawals, Chen said, the fund was rebuilt to above $300 million. She saw that level as sufficient for now even though the recent theft went beyond it.
The company also kept more than $1 billion in capital outside that fund, she said.
“I can’t tell you the exact number, but it’s for sure more than one billion.”
If another loss reached several hundred million dollars, she said Bitget could handle it. The interview never established how much of that capital was readily available.
Chen described the damage to day-to-day operations and profitability as limited.
A pair of institutional clients made large withdrawals when Bitcoin withdrawals reopened, she said, but customers had already started coming back.
“Just within the last few days, many of them came back already.”
Within an hour of Ethereum withdrawals being restored, inflows were greater than outflows, according to Chen. She also mentioned heavy inflows after USDT withdrawals became available again.
She did not supply figures on the size of those deposits or on how much of the withdrawn capital had returned.
Chen said an early internal probe found no insider involvement. But she could not account for how the attackers learned so much about Bitget's systems.
“I actually don’t know. I wish I can ask them and get an answer there.”
The investigation is still under way, she said, and might take longer than the Bybit inquiry because the Bitget incident involved a more intricate set of systems.
Her reply leaves a central question unresolved: what degree of access did the attackers hold before the theft?
An internal review at Bitget had not turned up any sign of insider participation up to that point, Chen said.
“The preliminary investigation so far is telling us there’s no internal sort of involvement.”
She described how affected systems were isolated and internal credentials were reset. She said Bitget had restricted access to sensitive systems and added extra approval steps for withdrawals.
The exchange was also increasing scrutiny of outside security products. She identified the entry point as a previously unknown vulnerability in a third-party product, with the affected functionality switched off.
She admitted that alerts had to be interpreted correctly and that monitoring needed to react faster.
“No system, no security infrastructure is perfect or impenetrable.”
Chen dismissed the suggestion that THORChain was mostly to blame for exchange hacks. Protocols have different technical capabilities, she said, and she respected their permissionless design.
Still, she wanted operators to set out what intervention was possible. She cited NEAR Intents as an example of action taken where the infrastructure permitted it.
“I’m not blaming THORChain for sure.”
Her position is that exchanges need to work with protocols to make laundering harder, while accepting responsibility for their own security.
Chen said Bitget had discussed an alliance of exchanges and major protocols, though the talks are still preliminary.
She conceded that aligning participants' interests was difficult. Useful intelligence sharing would also force companies to disclose more about internal security.
“You want to share enough information, but not too much information.”
What the interview makes clear is how much the response rests on an exchange's ability to cover losses while investigators pursue the money, and prevention remains an open question.
Certora, in an analysis published after the interview, estimated that about $238 million exited after Bitget's first withdrawal freeze. That estimate sets up the next test of Chen's assurances: whether the new controls can stop fake internal transfers once an alert sounds.
Share to
Disclaimer: this article comes from third-party media and is provided for reference only. It does not constitute investment advice. Crypto and other financial products carry significant price volatility risk, so please make your own decisions carefully.
Japan has moved crypto under securities rules and plans a 20% tax rate, but ETFs and lower taxes are not yet in force; the US still leads.
Jonathan Spalletta convicted for stealing $53.3M from Uranium Finance, used funds on collectibles.
CFTC Chair Mike Selig said new rules will prevent another FTX-style collapse as the agency seeks comments on a new crypto exchange registration category.
Sberbank has become Russia's first bank approved by the central bank to custody bitcoin and other cryptocurrencies.