Bitget Wallet COO says self-custody must make asset ownership safer

Bybit
Changelly



Bitget Wallet COO Alvin Kan has called for clearer transaction permissions and wallet recovery controls following Bitget Exchange’s reported $387.5 million breach, saying direct ownership must come with safeguards users can understand.

Summary

  • Kan says shared signing and administrative systems can expose many users to one breach.
  • Bitget Wallet says its separate self-custodial service was unaffected by the exchange incident.
  • Wallet builders should explain spending permissions and recovery authority, according to Kan.
  • European supervisors and the SEC are examining custody controls through separate regulatory initiatives.

Alvin Kan, chief operating officer of Bitget Wallet, told crypto.news in exclusive comments that self-custody should reduce the damage a single security failure can cause without requiring users to become security specialists.

Tokenmetrics

In his account, giving people control over their assets also places more responsibility on the wallet they use, their device, and their own decisions. Kan said wallet developers must address those risks as part of the product, including how users approve payments and regain access after losing a device.

According to the company’s accompanying statement, Bitget Wallet was not affected by the exchange incident. The company described the wallet as a separate self-custodial service in which users retain control of their assets onchain.

Bitget Wallet COO puts shared-system risk at the center of custody

For Kan, the central custody question concerns how many people can be affected when a shared system fails. Large asset pools that depend on common signing or administrative controls can expose multiple users to the same breach, he said.

“The lesson from recent security incidents is that custody risk is ultimately about blast radius,” Kan said.

Rather than treating exchanges and self-custodial wallets as competing answers to every financial need, he argued that users should have direct ownership while limiting the consequences of any single point of failure.

Reporting published Sep. 28 on the Bitget withdrawal restart detailed the exchange’s account of how attackers obtained high-level internal credentials through a vulnerability in a third-party security product. Bitget said the credentials allowed fraudulent withdrawal instructions to bypass existing controls.

According to the exchange, the Sep. 24 incident affected portions of its hot and warm wallet infrastructure, while cold wallets remained secure and private keys were not leaked. Bitget revised its initial $351.6 million estimate to approximately $387.5 million.

The exchange said Bitcoin withdrawals reopened at 08:00 UTC on Sep. 28 after security checks. In the same update, Bitget said user account balances remained unaffected, and its User Protection Fund would cover the financial loss, with Mandiant and SlowMist assisting the investigation.

Clear approvals and recovery rules can reduce self-custody risks

Before a user signs, Kan said a wallet should explain how much money will leave and whether the action authorizes one payment or allows an application to move funds later. In his view, users also need an easy way to revoke permissions they have already granted.

“A warning that people cannot interpret offers little protection,” Kan said.

For access recovery, he called for similarly clear explanations of what happens when a device or backup is lost. Users should know who can help restore access and what authority each party holds, according to Kan.

“Easier access should not quietly recreate the same concentrated control that self-custody is designed to avoid.”

Looking beyond asset storage, Kan expects self-custodial wallets to become more common as accounts for receiving money, holding balances, making payments and accessing investments. He attributed that expectation to demand for those services in one interface while users keep control of their assets.

Exchanges still serve trading, liquidity and fiat-access needs, he said, but using those services should not require a customer to entrust all their assets to an exchange. He described his preferred custody model as “direct ownership alongside services people choose for specific needs.”

ESMA’s custody review tests transaction controls and outside providers

European supervision already includes several of the operational issues raised by Kan. Coverage published Jul. 11 examined ESMA’s crypto custodian resilience review, including key management, transaction controls and dependence on outside technology providers.

In its July 8 announcement, ESMA said the exercise would assess governance, key and storage management, incident detection and response, smart-contract risks and third-party dependencies. National authorities will examine a risk-based sample of authorized crypto-asset service providers, according to the regulator.

ESMA said the work would run from the second half of 2026 through the first half of 2027. Its announced timetable places submission of a final report to the Board of Supervisors in the second half of 2027.

On incident response, Kan called for faster sharing of threat intelligence and coordinated efforts to trace stolen assets. He said prevention and response both need improvement, rather than leaving users responsible for understanding every security threat.

An Oct. 2 report on stolen Bitget fund movements cited BlockSec’s finding that attackers quickly converted assets that issuers could freeze, moved value across chains into Bitcoin and sent some BTC into CoinJoin transactions. BlockSec based its analysis on published attacker addresses and a Sep. 29 snapshot.

The SEC proposal treats institutional self-custody separately

For U.S. investors using advisers or regulated funds, the SEC has proposed a different custody framework. An Oct. 3 report detailed the agency’s conditional crypto custody proposal, issued Oct. 1 for investment advisers and regulated funds, including registered investment companies and business development companies.

In her Oct. 1 statement, Commissioner Hester Peirce explained that institutional “self-custody” means an adviser holding assets for clients. She distinguished that arrangement from individual investors keeping their own assets without an intermediary.

Under the proposal as Peirce described it, an adviser would first need to determine that no permitted custodian is available for the asset and repeat the assessment quarterly. For state trust company custody, she said advisers and funds would assess state authorization and written safeguards before appointment, then repeat those checks annually.

According to the SEC’s rulemaking docket, the changes remain proposed rules, with public comments accepted for 60 days after Federal Register publication under file number S7-2026-35.

Disclosure: This article does not represent investment advice. The content and materials featured on this page are for educational purposes only.



Source link

Binance

Be the first to comment

Leave a Reply

Your email address will not be published.


*