Here is what we can confirm at this stage:
On the attack:
Our security team has made initial progress in tracing the source. The attacker compromised a critical backend system within our wallet infrastructure, used it to spoof transaction data, and triggered our authorization process to move funds out. Private key compromise has been ruled out — this excludes the more severe risk scenarios. Loss containment is confirmed. No further unauthorized transfers are possible. The specific method of system intrusion remains under active investigation. A full technical report will follow once confirmed.
On withdrawal restoration:
Multiple technical teams are working in parallel on system remediation and security hardening. Withdrawal restoration is being prepared in parallel. We will announce a timeline as soon as one is confirmed — we will not commit to a window we cannot guarantee.