Bitget CEO Says Limited Recovery Expected After $388 Million Hack, Details on Frozen Assets and Protections
Table of Contents
You might want to know
1. How much of the nearly $388 million stolen from Bitget has been frozen and what does that mean for recovery?
2. What steps did Bitget take to protect user funds and what are the implications for future exchange security?
Main Topic
Last week’s cyberattack on crypto exchange Bitget resulted in the theft of almost $388 million. The company has since reported that roughly $1.1 million of those stolen funds have been frozen by authorities or on-chain controls. According to CEO Gracy Chen, who spoke to CNBC and responded via email, frozen assets are not necessarily equivalent to funds already returned to the exchange; they represent assets that have been identified and temporarily immobilized while tracing and recovery efforts continue. Chen did not specify the precise amount of recovered funds beyond the figure for frozen assets.
When describing Bitget’s expectations for recovery, Chen told CNBC that she was "not expecting to recover a lot of funds." Her outlook was informed by historical patterns: past breaches of cryptocurrency platforms have often yielded only limited recoveries. This realism reflects the challenges of tracking and reclaiming assets once they move through multiple wallets, mixers, or privacy-preserving services. Even when frozen assets are located on-chain, legal, technical and jurisdictional hurdles can slow or prevent return to victims.
Despite the breach, Bitget emphasized that customer account balances remained intact and unaffected. Before the theft, the company maintained a protection fund valued at over $464 million. Bloomberg's analysis of publicly disclosed wallet addresses indicated the protection fund fell to under $200 million immediately after the theft, before Bitget later restored it to over $300 million. Chen stated that the replenishment was performed using Bitget’s own capital, and that the restored fund is verifiable on-chain and kept separate from the reserves backing customer balances. The company’s September 29 Proof of Reserves snapshot reported a self-declared overall reserve ratio of 131%, with all covered assets reported above 100% backing.
Two independent post-incident reports—one by Mandiant (a Google Cloud unit) and another by blockchain security firm SlowMist—provided technical context on how the attackers gained access. Both firms concluded that the threat actors compromised two third-party security products, enabling privileged access to Bitget’s production wallet systems. SlowMist traced malicious activity in available logs back to August 31, when a previously unknown (zero-day) vulnerability was exploited in one of the vendor products. The reports indicate attackers were able to bypass standard withdrawal controls and conduct transfers without exfiltrating private keys, and that they took steps to remove forensic traces after executing transfers to obscure investigative leads.
Neither report publicly named the specific vendors or security products involved. Chen declined to release additional vendor or product details beyond the published findings, explaining that doing so might introduce further security risks. The incident reports did not attribute the attack to any particular nation-state; while Chen previously noted that preliminary indicators were highly consistent with certain known North Korean hacking groups, she cautioned that attribution requires more data and said more information would be needed to draw firm conclusions.
On the operational side, Bitget has resumed withdrawals for bitcoin, ether and USDT. The exchange announced plans to reopen withdrawals for remaining cryptocurrencies as well as fiat and peer-to-peer services on Friday following the incident. Chen reiterated the company’s commitment to absorbing the financial impact internally rather than passing it on to users, framing the replenishment of the protection fund as a measure to maintain customer confidence and demonstrate responsibility in the wake of the breach.
From a broader perspective, this incident highlights several recurring themes in major crypto exchange intrusions. First, reliance on third-party products and integrations can introduce supply-chain-style risks: a vulnerability in an ancillary product can cascade into a compromise of critical infrastructure. Second, proof-of-reserves snapshots and separate protection funds matter as tangible risk-management tools that exchanges can deploy to preserve customer balances and market trust. Third, the ability to freeze some assets on-chain illustrates how blockchain transparency can aid mitigation, but also underscores limits—frozen balances are not identical to recovered assets and may require complex legal action to repatriate.
Finally, the attack underscores the evolving sophistication of cybercriminals targeting crypto platforms. The reports describe a coordinated exploitation chain exploiting zero-day vulnerabilities and leveraging privileged access to circumvent normal controls. The attackers’ post-transfer deletion of logs and traces further complicated forensic work. This sophistication increases the difficulty of successful recovery and of timely attribution, and it pressures exchanges to continuously strengthen vendor oversight, operational security, and incident response capabilities.
Key Insights Table
| Aspect | Description |
|---|---|
| Stolen Amount | Nearly $388 million taken in the cyberattack. |
| Frozen Assets | Approximately $1.1 million identified and frozen. |
| Recovery Expectation | CEO: not expecting to recover a large portion, based on prior incidents. |
| Protection Fund | Fund valued >$464M pre-theft; dipped below $200M, later restored to >$300M using Bitget capital. |
| Proof of Reserves | Sept. 29 snapshot: self-reported reserve ratio of 131%. |
| Cause / Method | Attackers exploited zero-day(s) in two third-party security products to access production wallets and delete traces. |
| Attribution | Reports did not attribute to North Korea; preliminary indicators were consistent with known North Korean groups per CEO. |
| Service Status | BTC, ETH, USDT withdrawals resumed; remaining assets and fiat/peer-to-peer withdrawals scheduled to resume Friday. |
Afterwards...
Looking forward, exchanges and infrastructure providers will likely increase focus on vendor risk management and rapid incident response. The Bitget event highlights the need for continuous security assessments of third-party components and for layered defenses that can limit the impact of supply-chain style compromises. Regulators and industry groups may press for clearer standards around proof-of-reserves transparency, emergency liquidity measures, and cross-border coordination for asset freezes and recoveries. For users, the episode reinforces the importance of understanding exchange protections and the trade-offs inherent in different custody models. While on-chain transparency enables some mitigation steps—such as freezing and tracking funds—effective recovery often remains difficult, making prevention and preparedness essential priorities for the crypto ecosystem.
Last edited at:2026/10/2
