Bitget has traced the cause of a recent $388 million exploit to a weakness in a third-party security product, according to the exchange’s CEO Gracy Chen. In an interview with Cointelegraph, Chen said the attacker gained access to “high-level internal credentials” and then used them to send fraudulent withdrawal requests. Chen emphasized that Bitget’s private keys were not compromised and that its cold wallets were not affected. She added that the exchange has already fixed the underlying security flaw and tightened withdrawal procedures, including stricter internal access controls, additional independent withdrawal verification, and increased monitoring for unusual activity. Key takeaways Bitget says the exploit relied on compromised “high-level internal credentials” tied to a third-party security product vulnerability. According to CEO Gracy Chen, Bitget’s private keys and cold wallets were not compromised. Bitget detected unauthorized transfers from multiple hot wallets on Sept...
The U.S. Securities and Exchange Commission (SEC) has updated its guidance on how federal securities laws apply to “certain types of crypto assets and certain transactions involving crypto assets,” expanding on the framework it outlined in March. The new clarification arrived via an update to the agency’s frequently asked questions, and it follows a similar move from the Commodity Futures Trading Commission (CFTC) earlier last week. In the Friday update to its crypto FAQs, the SEC emphasized that the guidance is non-binding. The agency said the interpretation has “no legal force or effect,” does not amend existing law, and does not create additional obligations for any person. The FAQ material is intended to explain how the SEC would analyze whether certain digital asset products could be considered investment contracts under the Howey test. Key takeaways The SEC’s refreshed crypto FAQ reiterates that it is non-binding and does not change applicable securities laws. The SEC’s Howey...