Binance Co-CEO Teng: Collaborating with Bitget to Track Stolen Funds
Binance Co-CEO Richard Teng stated that following recent events at Bitget, they stand together with the exchange and its users. The security teams have been collaborating since the incident was discovered, sharing intelligence, tracking funds, and assisting in recovery.
On September 24 at 18:31 UTC, Bitget's security system detected unauthorized transfers from some hot wallets, later confirming that both hot and warm wallets were affected, while cold wallets remained untouched. The company estimated the loss at approximately $351.6 million and stated that user account balances are accurate, with deposits and trading still open, while withdrawals are paused pending security review.
Bitget CEO Gracy Chen explained the attack path: the attackers breached key backend systems in the wallet infrastructure, forged transaction data, and triggered the exchange's own authorization processes to transfer funds, ruling out private key theft. The transfers affected networks including Ethereum, XRP Ledger, Avalanche, BNB Smart Chain, and Arbitrum, with assets including Ethereum, XRP, USDT, USDC, AVAX, BNB, and tokenized gold, among which XRP was the largest single asset.
The company stated that the user protection fund holds over $464 million, sufficient to cover the losses. Preliminary investigations indicated that some IPs matched common VPN paths used by specific North Korean groups, and the attack methods were similar to previous North Korean-related actions, but the entry point of the intrusion is still under technical investigation. On-chain monitoring shows that the funds have begun to be exchanged and split across chains.
Teng positioned this as a collective industry response against attackers, rather than an isolated incident within a single exchange. Exchanges are sharing address tags, flow diagrams, and freezing clues to shorten the window for funds entering mixing services and over-the-counter cashing.
From a market mechanism perspective, this is a liquidity contraction driven by custodial risk events: Bitget users are temporarily unable to withdraw, leading some traders to turn to other platforms for cashing out and hedging; market making and arbitrage activities reduce depth supply to the exchange's order book when withdrawal gates are closed. Funds are flowing from the affected hot wallets to the attack addresses, then spreading to decentralized exchanges and cross-chain bridges. The beneficiaries are platforms that can maintain cold wallet isolation and fulfill protection fund commitments; the pressured parties are smaller exchanges and high-leverage users reliant on hot wallet turnover. Industry collaboration in tracking has increased the friction costs for stolen assets to be cashed out through compliant channels.
Source: Public Information
ABAB AI Insight
Teng has previously been known for regulatory communication and license expansion. After Binance completed its compliance framework across multiple jurisdictions, its public statements have increasingly leaned towards "industry joint defense" rather than isolated competition. Bitget, on the other hand, has taken a different path: starting with contracts and then expanding into multi-asset and tokenized stocks, using the user protection fund as a backing for payouts. The simultaneous appearance of both in the intelligence collaboration regarding the same hot wallet incident indicates that leading exchanges have begun to treat on-chain asset recovery as interchangeable infrastructure rather than merely a public relations stance.
The capital path involves the internal transfer of the protection fund to cover hot wallet losses: Bitget is using a fund valued at approximately 5,500 bitcoins to cover the $351.6 million gap, effectively turning reserve assets on the exchange's balance sheet into rigid payouts to users. The attackers forged backend authorizations rather than copying private keys, with funds subsequently split and exchanged across multiple chains. The motivation for collaborative tracking is straightforward: once stolen assets enter compliant deposit channels, they can contaminate the entire industry's banking and stablecoin channels, making individual recovery efforts less efficient than shared tagging.
Similar structures have emerged after the Bybit hack and the establishment of reserve and insurance funds by exchanges following Mt. Gox. The current stage sees centralized exchanges moving from "proving reserves" to "proving that hot wallet authorizations cannot be forged." Platforms that still treat hot wallets as cash drawers and authorization systems as internal processes are positioned to be repeatedly priced by the same attack surface; those that have implemented cold-hot isolation, multi-signature, and independent authorization audits as products can convert their opponents' incidents into trust premiums.
The structural judgment reflects a combination of regulatory changes and the reconstruction of the industry chain. Forged authorizations in hot wallets expose not the chain itself, but the centralized custody that binds "signature rights" and "instruction rights" to the same backend. The mechanism is that attackers do not need to steal private keys; they only need to convince the system of a legitimate withdrawal. Exchange joint defense, protection fund payouts, and on-chain freezes are transforming this vulnerability from an isolated incident into an insurable and auditable industry standard. Pricing power thus shifts from "who has the largest trading volume" to "who can still maintain withdrawal commitments after being hacked."