The exchange said it has patched the vulnerability, and losses from the incident will be fully covered by a user protection fund.