The post HitBTC Exchange put on security alert by SlowMist analysts appeared on BitcoinEthereumNews.com. Blockchain security firm SlowMist has found a vulnerabilityThe post HitBTC Exchange put on security alert by SlowMist analysts appeared on BitcoinEthereumNews.com. Blockchain security firm SlowMist has found a vulnerability

HitBTC Exchange put on security alert by SlowMist analysts

Blockchain security firm SlowMist has found a vulnerability on cryptocurrency exchange HitBTC.

The firm shared the alert on X on Sunday, stating, “We have identified a potential critical vulnerability and reached out via DM in advance under responsible disclosure, but have not yet received a response.

SlowMist also added that the exchange should contact them “promptly to coordinate next steps.”

How did HitBTC respond to the security threat disclosure?

Going by recent public announcements from SlowMist security analysts, exchanges don’t tend to act with the level of urgency one would expect from custodians of user funds.

The latest one involving HitBTC is at least the third time in recent weeks that SlowMist has publicly disclosed attempted security warnings after failing to establish contact with cryptocurrency exchanges.

In December, the security firm issued similar notices to Seychelles-registered Azbit and Turkish exchange ICRYPEX Global, both of which handle significant daily trading volumes but failed to acknowledge the warnings.

HitBTC is one of the oldest cryptocurrency exchanges still in business since its founding in 2013. The platform, registered in the British Virgin Islands, has a trading volume of over $110 million in the past 24 hours as of the time of writing. Over 250 cryptocurrencies and 800 trading pairs are available on the exchange.

Security concerns are persistent

SlowMist’s 2025 annual security report documented 200 security incidents resulting in losses of approximately $2.935 billion, representing a 46% increase in financial damage compared with the previous year, despite fewer total incidents being recorded as opposed to 2024.

According to SlowMist’s report, “Exchange-related incidents numbered only 12 but caused staggering losses of up to USD 1.809 billion.”

By comparison, decentralized finance (DeFi) protocols experienced 126 incidents resulting in $649 million in losses.

According to data shared by security firm Certik, around $117.8 million was lost to exploits in the crypto space in December 2025 alone.

The shift from higher incident counts to larger individual losses shows that these attacks are becoming more sophisticated and targeted.

Security analysts note that professionalized hacker groups, including state-sponsored actors with alleged North Korean links, are moving from opportunistic attacks to systematic, multi-step operations designed to extract maximum value from fewer high-profile targets.

As Cryptopolitan reported yesterday, one crypto user lost approximately $1.08 million worth of Aave-wrapped Ethereum LBTC (aEthLBTC) in a phishing attack after signing a malicious “permit” signature.

Major AI companies like Anthropic, OpenAI, and Google have also reported that criminals are tapping into their platforms to orchestrate complex phishing operations, develop harmful software, and execute various digital attacks. Security specialists warn that criminals are also producing fake audio and video clips of company leaders to trick employees into giving up sensitive information.

How should crypto exchanges respond to threat warnings?

Security experts usually recommend that cryptocurrency platforms establish clear contact points for reporting vulnerabilities, including publicly available security email addresses and long-term public keys for encrypted communication. Industry guidelines expect that affected parties respond within two working days of initial contact.

When security researchers like SlowMist in this case struggle to establish contact after multiple attempts, they are left with no other option than public disclosure to ensure transparency, especially when user funds face potential risk.

SlowMist has built a reputation for lending weight to the blockchain security apparatus.

The firm assisted in freezing or recovering approximately $19.29 million in stolen funds during 2025 through its threat intelligence network and MistTrack analysis platform. Across 18 major incidents, roughly $387 million of $1.957 billion in stolen funds was frozen or recovered, yielding a recovery rate of 13.2%.

Join Bybit now and claim a $50 bonus in minutes

Source: https://www.cryptopolitan.com/hitbtc-exchange-security-alert-by-slowmist/

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

SEC Grants WisdomTree Relief for 24/7 Trading of Tokenized Fund Shares

SEC Grants WisdomTree Relief for 24/7 Trading of Tokenized Fund Shares

TLDR WisdomTree’s WTGXX fund now trades 24/7 with instant blockchain settlement. SEC issued exemptive relief to allow tokenized fund shares to trade anytime. FINRA
Share
Coincentral2026/02/25 02:29
The Daily: OG bitcoin whale’s 1,000 BTC move, XRP treasury firm’s 65% discount, Forward Industries’ $4B ATM for SOL, and more

The Daily: OG bitcoin whale’s 1,000 BTC move, XRP treasury firm’s 65% discount, Forward Industries’ $4B ATM for SOL, and more

The following article is adapted from The Block’s newsletter, The Daily, which comes out on weekday afternoons.
Share
Coinstats2025/09/18 01:31
First U.S. XRP ETF Launches Sept. 18, CME to List Options on XRP Futures Oct. 13

First U.S. XRP ETF Launches Sept. 18, CME to List Options on XRP Futures Oct. 13

XRP is drawing fresh attention from traditional finance as new products roll out in both securities and derivatives markets, broadening access points for exposure to the token.At the time of writing, according to CoinDesk Data, XRP was trading around $3.0263, down nearly 1% over the past 24 hours.On Sept. 18, REX Shares and Osprey Funds will debut the first U.S.-listed exchange-traded funds (ETFs) tied to XRP and Dogecoin (DOGE) on the Cboe BZX Exchange, under the tickers XRPR and DOJE. These products are not entirely “pure” spot funds, however. Bloomberg Intelligence analyst James Seyffart wrote on X that the funds aren’t “pure” spot products. Instead, they are structured to hold XRP and DOGE directly, while also investing in other spot ETFs from outside the U.S. to achieve exposure. Their filings also include language that would allow the use of derivatives for exposure if needed, though Seyffart emphasized that this is not the primary approach.The structure reflects the realities of building regulated crypto ETFs in the U.S., where sponsors have sometimes layered in indirect exposure. Even so, the launches mark the first time American brokerage accounts will have access to XRP- and DOGE-focused ETFs, expanding beyond bitcoin and ether, which dominate the ETF landscape.Less than a month later, CME Group plans to deepen its crypto derivatives lineup by listing options on XRP and Solana (SOL) futures, targeted for Oct. 13 pending regulatory review. Options will be listed on both the standard contracts and their smaller “micro” versions, designed to serve institutions, trading desks, and active individuals alike. Expiry choices will include every business day, each month, and each quarter, creating a wider term structure for managing exposures.The exchange said the decision follows strong growth in its newer altcoin futures. Since March, SOL futures have logged over 540,000 contracts traded (about $22.3 billion notional), while XRP futures, introduced in May, have seen more than 370,000 contracts change hands (roughly $16.2 billion notional). Market participants including Cumberland and FalconX welcomed the additions, citing the need for hedging tools beyond bitcoin and ether.Headquartered in Chicago, CME Group runs the world’s largest regulated derivatives marketplace, where listed crypto futures and options allow participants to hedge positions with central clearing and margining. Adding XRP and SOL options builds on the firm’s progression from bitcoin and ether into a wider set of liquid tokens.
Share
Coinstats2025/09/18 05:30