Gate Square “Creator Certification Incentive Program” — Recruiting Outstanding Creators!
Join now, share quality content, and compete for over $10,000 in monthly rewards.
How to Apply:
1️⃣ Open the App → Tap [Square] at the bottom → Click your [avatar] in the top right.
2️⃣ Tap [Get Certified], submit your application, and wait for approval.
Apply Now: https://www.gate.com/questionnaire/7159
Token rewards, exclusive Gate merch, and traffic exposure await you!
Details: https://www.gate.com/announcements/article/47889
SlowMist discovers serious vulnerability in HitBTC with no response, exchange security rings the alarm again
Security team SlowMist issued a notice on January 4th, stating that a potentially serious vulnerability has been identified on the HitBTC trading platform. More concerning is that, despite SlowMist’s responsible disclosure through private channels, they have yet to receive any response from HitBTC. This incident once again highlights the importance of security protection in exchanges.
Incident Overview: Responsible Disclosure Meets Cold Response
Discovery and Disclosure Process
As a well-known security research organization in the industry, SlowMist followed industry standards for responsible disclosure:
This approach aligns with industry-standard security disclosure procedures, aiming to protect users while providing the company a reasonable window to address the issue.
Key Risk Points
The most worrying aspect is not just the vulnerability itself, but HitBTC’s unresponsive attitude:
Background Analysis: Why Is Exchange Security So Critical?
As a trading platform, HitBTC carries users’ assets and information. Based on historical experience, vulnerabilities in exchanges often become prime targets for hackers. Similar security incidents are not rare in the industry, and each vulnerability could lead to user asset losses.
SlowMist’s proactive disclosure reflects the industry’s emphasis on security, but rapid response from the platform is equally important. A responsible exchange should:
Follow-up Focus Points
The development of this incident warrants close attention:
Summary
SlowMist’s security notice reminds us that exchange vulnerabilities are no trivial matter. The core issue of this incident is not just the discovery of the vulnerability itself, but the platform’s attitude towards response. For users, choosing a trading platform that values security and responds swiftly is crucial. For HitBTC, responding promptly to SlowMist’s disclosure and formulating a fix plan is an urgent task to restore user trust. The entire industry also needs more oversight from security research organizations like SlowMist, along with active cooperation from more exchanges, to jointly maintain the security of the cryptocurrency ecosystem.