18:31 UTC. One alert fires. Not a seed phrase walking out of a vault — a trade ticket that never existed.
That is the shape of the Bitget breach as it stands right now. $387.5 million gone. Hot wallets and warm wallets touched. Cold storage untouched. A withdrawal gate closed. Detection at 18:31 UTC. Notification to users and the wider market roughly three hours later, near 21:30 UTC. In between, somebody spent $19.67 million in USDT0 to buy 7,111 ETH inside six minutes, paying a premium that reached 5 percent above spot.
I have been tracing exchange incidents since the 0x flash loan exploit in late 2020, when I pulled a transaction hash by hand and published a thread before the official post-mortem existed. The first thing I check is never the headline number. It is the mechanism. And this mechanism is not cryptographic. It is procedural. An internal backend system was fed false transaction data, and that system then triggered Bitget's own authorization flow to release funds.
The exchange says private keys were not stolen. Read that sentence twice, because it is carrying more weight than any other line in the disclosure.
The vault held. The approval logic did not.
Why this one matters more than the last one
There is a reflex in this industry that treats every exchange breach as a variation on the same story: hacker finds hole, hacker drains funds, exchange pauses withdrawals, everyone promises to do better. That reflex is lazy, and in a bear market it is expensive. The Bitget incident is not a variation. It sits in a different failure class than the events that dominated 2022 and 2024.
Look at where the money actually sat. Hot wallets and warm wallets were affected. Cold storage was not. That tells you the exposure boundary immediately: the attacker reached online operational capital, the funds an exchange keeps liquid so that withdrawals clear and market makers can settle. Those wallets exist precisely because an exchange cannot serve customers out of a vault that never touches the internet. Warm wallets sit one layer back — medium-frequency, medium-balance, still online.
So the attacker did not get everything. But the attacker got the layer that matters for the next seventy-two hours.
And the second detail matters just as much. The attacker did not steal a key. The attacker convinced the system that a legitimate transfer was happening. According to the disclosed sequence, a backend system was compromised, false transaction data was injected, and Bitget's own authorization process approved the outbound movement. Private keys stayed where they were.
I want to sit on that for a moment, because it reframes the entire incident. An exchange's private keys are the vault door. Its authorization workflow is the person who decides whether to open the door. The Bitget event is a case where the door was fine and the person was fooled. And the person, in this architecture, is not a person at all — it is a sequence of internal checks that were designed to validate data they assumed was honest.
That assumption is the vulnerability. And it is not unique to Bitget.
The comparison everyone is reaching for — and why it only half-fits
The market has already started calling this "Bybit 2.0." The comparison is not lazy. There are real structural overlaps with the February 2025 Bybit incident, which the FBI ultimately attributed to North Korean actors. Both events routed around key theft. Both leaned on manipulating a legitimate authorization or signing path. Both saw the stolen assets converted into ETH or other liquid crypto quickly. Both sent funds scattering across multiple wallets. Both leaned on THORChain as a cross-chain exit. Both triggered a withdrawal pause and a trust crisis measured in hours, not days.
Bitget's CEO, Gracy Chen, has pointed at IP behavior and on-chain activity consistent with North Korean-linked groups, while stopping short of a formal attribution. That is the correct posture, and it deserves credit. Attribution is a forensic conclusion, not a press-release conclusion.
But here is where the comparison becomes a trap. Tradecraft similarity is not identity. A crew that copies another crew's playbook is not the same crew. Sophisticated laundering patterns propagate through the ecosystem like open-source code — once a method works, it gets reused, adapted, and rented. Treating "looks like Bybit" as "is Bybit's attacker" is the same analytical error as treating two exploits that use the same reentrancy pattern as the work of one developer.
I learned that lesson the hard way. In mid-2025 I ran a custom AI agent against a set of new DeFi lending protocols for forty-eight hours, letting it flag anything that looked anomalous rather than anything that looked familiar. It surfaced a reentrancy path in a protocol that had already passed two human audits, precisely because the agent was not pattern-matching against known incidents. It was pattern-matching against behavior. The distinction between "this looks like X" and "this behaves like an exploit" is the difference between noise and a finding.
Apply that to Bitget. The Bybit parallels are useful as investigative leads. They are useless as conclusions.
What the three-hour gap actually tells us
Detection at 18:31 UTC. Notification around 21:30 UTC. The market reads that as a three-hour delay. I read it as a three-hour window that tells us almost nothing about the intrusion itself.

Detection time is not intrusion time. This is the single most misunderstood number in every post-mortem I have ever read, and it is the number every exchange press release quietly hopes you will misread. The18:31 UTC stamp is the moment the system noticed something wrong. It is not the moment the attacker first gained access to the backend. Those are different clocks, and the gap between them is called dwell time.
Dwell time matters because it determines what else the attacker touched. If the intrusion happened minutes before 18:31, the damage surface is the wallets. If it happened days or weeks before, the damage surface includes whatever else that access could reach — internal documentation, API credential stores, monitoring gaps, staff communication channels. The disclosed timeline does not answer this. It cannot, yet. But it is the question that should be driving every Bitget depositor's decision right now, and it is the question the next disclosure needs to close.

The mechanics of how a backend system gets fed false transaction data are also conspicuously absent. Was it a credential compromise? A supply-chain foothold in third-party tooling? A social-engineering path through an operator with approval rights? Each of those implies a different remediation, and none of them are addressed by the phrase "the vulnerability has been fixed."
Here is what I will say plainly, because it is the kind of thing the marketing layer of this industry avoids. An authorization system that can be triggered into releasing a nine-figure sum by injected data is a system with too few human checkpoints and too much automation trust. The attacker's job is to find the seam between the automated check and the human check. Whoever designed Bitget's flow left that seam wide enough to walk a trade ticket through.
The cold wallet held. That is a genuine architectural win, and it should be stated as one. But the warm wallet exposure shows the boundary the attacker was aiming at was not the vault. It was the settlement layer. And the settlement layer is what keeps the lights on.
The number moved. That is not an accounting footnote.
Initial loss estimate: $351.6 million. Revised estimate: $387.5 million. A roughly 10.2 percent upward revision, framed by the company as reflecting a more complete accounting.
I have seen this movie. The revision is not the scandal. The revision is the signal.
When an exchange publishes a loss figure within hours of an incident, that figure is not a measurement. It is a disclosure decision — the most defensible number a team can stand behind while the situation is still moving. The gap between the first number and the final number is an estimate of how much the team did not yet know, or was not yet prepared to say.
A $35.9 million gap is not rounding. It is the distance between what Bitget could defend publicly and what Bitget actually lost. And every depositor should now ask the obvious follow-up: if the first number was incomplete, what makes the second number complete? The honest answer is nothing yet. Only an independent forensic report or a reconciled on-chain accounting closes that loop, and neither has been produced.
This matters more in a bear market than any of us would like to admit. In a bull market, a $36 million revision gets absorbed by inflows and narrative momentum. In a bear market, there are no inflows to absorb it. Losing 10 percent of an already-large figure in a market where liquidity is thin and confidence is thinner is qualitatively different from the same revision at the top of a cycle.
The revision also directly implicates the user protection fund. If the fund is sized against the first estimate, the second estimate creates a shortfall. If the fund is sized against the second, the market has to trust a number that already moved once.
The protection fund is the real balance-sheet question
Bitget says the user protection fund will cover platform-level impact. It has not disclosed the fund's size, its composition, or its payout priority.
Those three omissions are the whole ballgame.
Size determines whether the promise is credible. A protection fund that covers $387.5 million in a single incident is a different institution than one that covers a fraction of it. Without a number, "covered" is a word, not a guarantee.
Composition determines whether the fund is actually money. A protection fund can hold stablecoins and fiat, or it can hold platform tokens, receivables, affiliated-entity equity, and illiquid positions. I have audited enough treasury statements to know that the difference between a fund worth $400 million in cash and a fund worth $400 million on paper is the difference between a payout in days and a payout that never fully arrives. If any material portion of the fund sits in a native token, the fund's value is correlated with the very event it exists to insure against. That is not a hedge. That is doubling down.
Payout priority determines who eats first. Do retail depositors come before market makers and institutional counterparties? Do project teams whose tokens were custodied on the exchange get made whole before individual users? Priority order is usually where the real disclosure risk lives, and it is almost always the last thing an exchange wants to publish.
I have spent the last several years building editorial workflows around real-time data — dashboards that update hourly, fund-flow trackers that pull from public chains. The lesson from that work is blunt: the market does not price promises. It prices verifiable numbers. Until Bitget publishes fund size, composition, and priority, the market is pricing a promise, and it is pricing that promise at a discount.
Six minutes, 7,111 ETH, and a 5 percent premium
Now to the on-chain signal that I think is being under-read.
A newly flagged wallet spent $19.67 million in USDT0 to acquire 7,111 ETH inside six minutes, paying a premium that reached 5 percent above market. Analysts have flagged the motive as unclear. I do not think it is as unclear as it looks.
A 5 percent premium is not a market participant expressing a view. It is a counterparty paying for speed and settlement certainty, and paying through the nose to get it. On-chain buyers who move at that premium are not accumulating. They are converting into a form that travels better.
Think about what the attacker actually needs in the hours after a drain. They need to move value out of assets that can be frozen. USDT0, TRON-based assets, and anything with an issuer-controlled freeze function are liabilities in the attacker's hands. ETH is not frozen by a central issuer. ETH is the working currency of the next hop — and the next hop here points squarely at THORChain.
MistTrack's reporting that stolen funds entered THORChain is the piece that ties the whole sequence together, because THORChain is the exit ramp from ETH into BTC and other chains without touching a centralized order book. Every cross-chain swap through THORChain converts an identifiable, freezable, traceable asset into something that fragments across chains and wallets.
And it is the same ramp used in the Bybit drain. That repetition is not coincidence. The efficiency of cross-chain liquidity protocols is the single largest threat multiplier in crypto theft today. We built open, permissionless, capital-efficient swap infrastructure to solve a real problem — fragmented liquidity across chains — and in doing so we built the cleanest laundering rail the industry has ever had.
Bitget's assets complicate this further in ways that deserve their own paragraph. Zcash was among the affected assets. Zcash's privacy properties are designed to break linkability. TRON-based assets live on a chain where a centralized entity can, in some circumstances, intervene. USDT0's freeze mechanics are not publicly detailed in what has been released. Three different asset classes, three different recovery probabilities, and the disclosure has treated them as one line item.
Recovery, if it happens at all, will be asset-by-asset and jurisdiction-by-jurisdiction. Anyone modeling a clean full recovery is modeling a scenario that does not exist.
The $180 million that went to one address
Bubblemaps' finding that roughly $180 million moved into a common receiving address before dispersing is the kind of detail that sounds technical and is actually narrative-defining.
Consolidation into a single address is a confidence move. It means the attacker was willing to pool funds — a step that creates an obvious focal point for investigators, exchanges, and chain-analytics firms. Any actor who consolidates at that scale is either confident in their ability to move fast, or operating on a timeline where the pool is temporary by design.
Given what followed — dispersion across wallets, the ETH conversion, the THORChain hop — the answer is clearly both. The consolidation was a staging step. The dispersion was the launch.
This is the pattern I would flag to anyone still holding assets on a centralized venue during this cycle. Traceability and recoverability are not the same thing. Almost every large theft in the last four years has been traceable. Very few have been recoverable. Bubblemaps and MistTrack are doing excellent work, and their work is producing evidence, not restitution. The gap between those two things is where depositors get hurt.
The withdrawal pause is not a safety feature. It is a statement.
Here is the part of this story that I think the market is misreading most, and it is the part I want to argue with.
The consensus read on Bitget's withdrawal pause is that it is a prudent defensive measure — stop the bleed, get control of the situation, reopen when it is safe. That read is generous. It is also probably wrong.
A withdrawal pause is not primarily a security measure. It is a liquidity statement. Exchanges do not pause withdrawals because they cannot verify who owns what. They pause withdrawals when the liabilities they owe could exceed the assets they can move right now. That can be because funds were stolen, or because funds are locked in strategies and counterparties, or because the act of mass withdrawal would force the exchange to liquidate positions at a loss. The pause is what protects the exchange from having to answer that question in real time.
Look at what Bitget actually committed to. It promised to publish a withdrawal plan by September 26, 04:00 UTC. It did not commit to resuming withdrawals on that date. That distinction is load-bearing, and it is exactly the kind of precise language that lawyers write and readers skip.
I have written through one of these in real time. During the Terra collapse in May 2022, I spent a week verifying on-chain liquidity burns on Solana while mainstream coverage was still describing UST as a stablecoin with a temporary problem. The thing that mattered in those first hours was not the mechanism. It was the withdrawal behavior. When a venue stops letting people leave, the mechanism stops mattering and the queue starts mattering.
We watched this in 2022 and 2023. Withdrawal gates close. Timelines slip. The first deadline becomes a status update, the status update becomes a revised timeline, and the revised timeline becomes a restructuring. Not every time. Not automatically. But the base rate is not friendly, and it should be stated plainly rather than softened.
Here is the irony that I have not seen anyone name yet. The user protection fund and the withdrawal pause are the same disclosure with two different faces. Both are statements that the exchange has enough. Neither is accompanied by the numbers that would let depositors verify it. If the fund is real and sized to cover $387.5 million, the pause should be short and the plan should be specific. If the pause is long and the plan is vague, the fund has told you what it is without telling you what it is.
Watch the deadline. Watch what comes with it. A plan that includes a resumption date, a payout schedule, and a fund reconciliation is a different animal from a plan that includes a commitment to keep communicating.
Bitget Wallet, self-custody, and the spillover question
The CEO's emphasis that Bitget Wallet is a self-custody product is a positioning move, and a smart one. It creates a clean line between the exchange's custodial exposure and a product where keys stay with the user. Great for narrative. Less obviously true in practice.
Brand association is a one-way valve. A user who trusts the Bitget name enough to install Bitget Wallet does not run a separate risk model for it. If the exchange arm is in crisis, the brand-level trust that drives wallet adoption is under the same pressure. A self-custody product with a distressed parent name does not automatically absorb users fleeing that parent. It can just as easily be pulled down with it.
That said, there is a real structural argument here, and I would not dismiss it. The event is a strong commercial argument for self-custody generally. When an exchange pauses withdrawals, every user who has been meaning to move to a hardware wallet suddenly has a very specific reason to do it. The beneficiary is not necessarily Bitget Wallet. It is whichever self-custody stack has the cleanest security story and the least exchange-shaped branding.
The one thing I would not do is assume the self-custody line is a firewall. It is a marketing boundary. Boundaries get tested by events, not by positioning.
CZ's offer and what ecosystem solidarity is actually worth
Binance and the BNB Chain ecosystem, along with the broader community, have been offered as support by CZ. In the immediate term, that is worth something real. A credible industry player publicly offering help shifts the emotional register of a crisis from abandonment to coordination, and that has measurable effects on social sentiment and on how institutional counterparties behave in the first forty-eight hours.
In the medium term, it is worth less than the headline suggests. Ecosystem solidarity does not reconcile a balance sheet, does not unfreeze a THORChain hop, and does not produce the independent forensic accounting that would let depositors size their risk. It buys time. Time is only useful if you spend it on disclosure.
There is also a subtler dynamic worth naming. Every crisis that ends with one large player offering to help another is a small consolidation event in the collective mind of the market. The venue that shows up as the adult in the room accrues narrative capital. That is not a criticism. It is an observation about how trust migrates during downturns — and this is a downturn.
The regulatory layer nobody is pricing yet
If North Korean involvement is formally confirmed, this stops being a commercial security incident and becomes a sanctions and geopolitical enforcement matter. That is not a rhetorical escalation. It is a change in which agencies, statutes, and consequences apply.
Bitget's CEO has cited IP behavior and on-chain activity consistent with North Korean-linked groups. The FBI previously attributed the Bybit theft to North Korean actors. The structural parallels — authorization manipulation, rapid conversion, dispersion, THORChain routing — make attribution a live hypothesis rather than a stretch.
If that hypothesis firms up, three things follow.
First, the addresses involved become candidates for sanctions listing. Any entity that interacts with them inherits compliance risk, and that includes exchanges, OTC desks, market makers, bridge front-ends, and liquidity providers. This is not a hypothetical. It is how the enforcement layer works.
Second, THORChain's position gets uncomfortable. A fully decentralized protocol is not easily sanctioned, but its touch points are — front-ends, node operators in specific jurisdictions, liquidity providers with KYC'd relationships elsewhere. Being repeatedly used as the exit ramp for attributed state-linked theft is not a neutral fact. It is a regulatory magnet.
Third, the affected asset classes get sorted by regulatory friction. TRON-based assets with identifiable issuers can be frozen under pressure. Zcash's privacy design makes compliance-driven tracing structurally harder, which will push it further toward the edges of institutional acceptability in exactly the moment when it needs the opposite. USDT0's mechanics are the open question, and the disclosure has not closed it.
Here is the part that ties back to my audit background. The SEC's regulatory-by-enforcement posture is not a failure to understand this technology. It is a deliberate refusal to write rules that would let exchanges plan around it. When the rules are the enforcement action, every operator is guessing at what the last enforcement action implied. That ambiguity is not neutral — it is a cost, and in a bear market it is a cost that shows up as slower remediation and less disclosure, not more.
The same logic applies internationally. Without clear guidance on cross-chain protocol responsibilities, THORChain and its contributors are left to interpret risk from headlines. Nobody plans well from headlines.
Governance when the governance is a multi-sig
Bitget is a centralized exchange, so DAO-governance critique does not apply on the surface. But the underlying structural point does, and it is one I have been making since I started covering governance systems.
"Code is law" has never survived contact with an upgrade key. In DAO structures, the upgrade right almost always sits with a small multi-sig. In exchange structures, the approval right sits with a small set of operators and internal systems. Both are the same thing wearing different clothes: a narrow group with unilateral authority over large value, protected by process rather than by cryptographic constraint.
The Bitget incident is what that architecture looks like when the process is fooled. A narrow authorization path approved a fraudulent transfer because the data feeding it was falsified. No multi-sig threshold was breached, because the threshold was never the obstacle. The obstacle, if there was one, was human review — and the disclosed sequence suggests human review either did not exist at that step or was presented with data that looked legitimate.
That is the governance lesson, and it is bigger than Bitget. Every centralized venue runs this pattern. Every one of them has an approval surface where a sufficiently convincing input produces an outbound transfer. The number of human checkpoints in that path is a design decision that almost never gets audited publicly, and it is the single highest-value piece of information a depositor could have.
Bitget has now fixed the specific vulnerability. It has not described the approval architecture. Those are different sentences.
Risk, ranked by what actually threatens depositors
The technology risk here has already migrated from potential to realized. The backend authorization path was deceived. Hot and warm wallets were exposed. That is not a future risk. It is a present fact.
What remains open is everything downstream, and I would rank it by how directly it threatens the person holding a balance.
First: the withdrawal timeline. This is the only risk that determines whether a depositor sees their money this quarter. A published plan with a resumption date and a payout schedule defuses it. A plan that is a communication commitment does not.
Second: the true loss figure. The number has already moved once by more than 10 percent. A second revision is not a tail scenario. It is a continuation of an established pattern.
Third: the recovery path. Funds have consolidated, dispersed, converted to ETH, and entered THORChain. Each step reduces the probability of recovery. The next step — a privacy chain or a mixer — reduces it sharply.
Fourth: attribution and sanctions. Formal North Korean attribution triggers a different enforcement regime and a different set of counterparty behaviors. It also extends the news cycle from days to quarters.
Fifth: competitive migration. Users who cannot withdraw do not wait indefinitely. Some portion of the balance sheet leaves the moment the gate opens, and it does not come back. This is the risk that hurts Bitget the most in the twelve months after the headlines stop.
Sixth: the narrative. The "Bybit 2.0" framing will keep circulating regardless of whether it is accurate, because it is a useful shorthand and because the structural overlaps are real. Narrative risk is real risk in a market where confidence is the primary asset.
I would note one thing about this ranking. The risks that get the most airtime — attribution, geopolitics, the hacker's identity — are the ones that matter least to a depositor trying to decide whether to hold or to wait for the gate. The unglamorous operational question is always the one that decides outcomes.
What the contagion map looks like from here
The transmission path runs from infrastructure through the exchange into users, and each link behaves differently.
The exchange layer takes the direct hit. Bitget's balance sheet, reputation, and user base are all affected simultaneously. Peripheral venues pick up a short-term competitive benefit as users seek alternatives, but they also inherit a security-review burden. Every exchange re-examining its own approval architecture right now is an exchange that is spending money on something other than growth, in a market with no growth to spend on.
The infrastructure layer absorbs reputational and regulatory pressure. THORChain is the pressure point — repeatedly used as an exit ramp, increasingly on the wrong side of compliance conversations. Privacy assets face a similar squeeze from the opposite direction: their design makes them structurally attractive to attackers and structurally difficult for compliance, and that combination tends to get resolved by exclusion rather than accommodation.
The DeFi layer gets a narrative re-run. Cross-chain bridge security was the dominant theme of the last cycle's failures, and this event pulls it back to the front of the conversation, even though the mechanism here was authorization, not bridge logic. Narratives do not require mechanical accuracy to move capital.
The institutional layer is where the slowest and most durable change happens. Post-Bybit, post-FTX, post-Terra, the institutions that stayed in crypto have already built custodian-diversification models. This event validates them and gives allocators one more data point for the case that qualified custody and self-custody infrastructure deserve a larger share of the stack. That shift is measured in quarters, not days, and it does not reverse when the news cycle turns.
The service layer is where the opportunity sits. Security firms, chain-analytics providers, and incident-response specialists have a demand tailwind that will outlast the incident itself. Mandiant and SlowMist being on this case is not a footnote. It is the industry's functioning incident-response chain — investigate, trace, disclose — and it is becoming the standard operating model for exchange breaches.
The contrarian read: the pause is the story, and the hacker is the distraction
Here is where I will part company with most of the coverage.
Every analysis of this event is organized around the attacker. Who they are, where they came from, which crew they belong to, what they will do next. That framing is intuitive and it is also, for the purposes of anyone with money on the line, misleading.
The attacker's identity does not change the outcome. It does not recover the funds. It does not determine when the withdrawal gate opens. It is a narrative product that serves the news cycle rather than the depositor.
What actually determines outcomes is the exchange's response architecture, and the most informative signal in that architecture is the withdrawal pause and the language around it. A venue that pauses withdrawals and publishes a resumption date with a payout reconciliation is telling you it has the balance sheet and the accounting. A venue that pauses withdrawals and publishes a commitment to publish a plan is telling you it is still counting.
Both are rational behaviors. They are not the same behavior.
There is a second contrarian point, and it is the one I would push hardest. The industry has spent a decade hardening cryptographic key management. Multi-sig, HSM, air-gapped cold storage, MPC — enormous effort and enormous progress, and the cold wallet on this incident is proof that the effort worked. The vault held.
And the attacker went around the vault and fooled the approval logic instead.
This is the third consecutive cycle in which the exchange failure mode was authorization, not cryptography. Bybit. Bitget. The pattern is not that our locks are weak. The pattern is that we keep investing in locks while leaving the person who approves the transfer untrained, under-instrumented, and over-trusted.
Gravity always wins, even in a vertical chain. The hard constraint here is not cryptographic entropy. It is the human and procedural layer that decides whether an outbound transfer is legitimate — and that layer has been the softest part of the stack for years, because it is the hardest part to audit and the easiest part to market around.
That is the blind spot, and it is an industry-wide one. Every CEX with a functioning withdrawal system has an approval path with some number of human checkpoints. Almost none of them have published that number. Almost none of them have stress-tested it against a competent adversary feeding them plausible data.
Bitget just ran that test for everyone, involuntarily and at a cost of $387.5 million and rising.
What I would watch, and what would change my read
A few specific things, and I will be concrete about why each one matters.
Watch whether the September 26, 04:00 UTC communication contains a resumption date or a timeline update. That is the difference between a liquidity event and a solvency event, and it is the single highest-information data point of the next week.

Watch whether the loss figure moves again. If it does, the pattern is established and the protection fund's coverage claim needs to be re-tested against the newest number, not the original one.
Watch whether any independent forensic reconciliation of the authorization path gets published. A fix without a described architecture is a patch, not an answer. The question — how many human checkpoints stood between the injected data and the outbound transfer — has not been asked publicly yet. It should be.
Watch whether any address enters a mixer or a privacy chain. If it does, recovery probability moves from low to negligible, and the conversation shifts from restitution to insurance and litigation.
Watch whether attribution becomes formal. A confirmed state-linked attribution changes the regulatory regime, extends the news cycle, and creates a durable compliance burden for every protocol in the exit path.
Watch the peers. Every major exchange's security spend just got repriced by this event, and the ones that publish reserve attestations and approval-architecture details in the next ninety days will have earned a real competitive advantage — not in marketing, but in the only currency that matters right now, which is depositor confidence.
Takeaway
Speed is the asset, but silence is the warning. The Bitget incident moved from alert to notification in three hours, and from notification to a promise of a plan within days. The fast part is done. What comes next is the slow part — and the slow part is where depositors find out whether the protection fund is a balance sheet or a slogan.
For anyone holding on that platform, the question is no longer whether the vault held. It held. The question is whether the process that opens it can be trusted with a second attempt.
And that question — not the hacker's identity, not the attribution, not the narrative — is the one the entire centralized exchange sector should be answering this quarter. Gravity always wins. The approval layer is where it lands.