Bitget CEO Says Limited Recovery Expected After $388M Hack
Highlights
Approximately $1.1 million of nearly $388 million stolen from crypto exchange Bitget in a recent cyberattack has been frozen, though that does not mean the funds have been returned. CEO Gracy Chen said she is not expecting to recover a lot of the stolen assets, citing historically low recovery rates from similar breaches. Bitget says user balances remain intact and that it restored its protection fund using the company’s own capital, keeping those replenished amounts publicly verifiable on-chain.
Sentiment Analysis
- Overall sentiment: Mixed to cautious. The announcement balances reassurance about user account safety and fund restoration with sober expectations around asset recovery. The tone is pragmatic: the CEO acknowledges limited prospects for reclaiming most stolen funds while emphasizing steps taken to protect customers and restore the protection fund. Confidence in operational continuity is underscored by resumed withdrawals for major tokens and scheduled rollouts for other services. However, concerns remain due to the sophisticated nature of the attack and unresolved forensic details about the compromised third-party security products. Investigative reports pointed to a zero-day exploitation and privileged access without private key theft, which complicates remediation and attribution. The communication aims to restore trust but leaves open questions about vendor vulnerabilities and long-term implications.
Article Text
Crypto exchange Bitget disclosed that roughly $1.1 million of the nearly $388 million stolen in a recent cyberattack has been frozen, though the company cautioned that frozen funds are not necessarily equivalent to recovered assets. In communications with CNBC, CEO Gracy Chen noted that she does not expect a significant portion of the stolen funds to be retrieved, based on precedents from past exchange breaches. Despite bleak recovery expectations, Bitget has worked to reassure customers that account balances were not impacted by the theft.
Bitget maintained that its protection fund, which had been valued at more than $464 million before the incident, was drawn down following the theft but subsequently replenished. According to on-chain wallet data calculated by Bloomberg, the fund dropped below $200 million immediately after the breach before being restored to above $300 million. Chen emphasized that the replenished funds were provided by Bitget itself and are publicly verifiable on-chain, separate from the reserves that back customer balances.
The company’s published Proof of Reserves snapshot from Sept. 29 showed a self-reported reserve ratio of 131%, with the 19 covered assets each reported as more than 100% backed. Chen stated that Bitget absorbed the financial impact internally rather than passing costs onto users, signaling an attempt to shield customers from the direct consequences of the attack.
Independent investigation reports released at the end of September by Mandiant (part of Google Cloud) and blockchain security firm SlowMist described the attackers’ method. Both firms found that the intruders compromised two third-party security products, gaining privileged internal access to Bitget’s production wallet systems. SlowMist traced malicious activity back to Aug. 31, alleging exploitation of a previously unknown zero-day vulnerability in one of the products. Mandiant reported that attackers bypassed the normal customer withdrawal processes and avoided stealing private keys, indicating a sophisticated approach.
Chen described the method as "quite sophisticated," noting that attackers deleted traces after transferring funds to impede the investigation. The published reports did not name the affected third-party products, and Chen declined requests to disclose vendor or product identities, saying further detail could introduce additional security risks beyond what the published findings already reveal.
On the question of attribution, neither report directly linked the attack to North Korean actors. Chen acknowledged that early technical indicators were highly consistent with known North Korean hacking groups but said that definitive attribution requires more evidence and time. She advised patience as investigators continue to analyze logs and trace the flow of funds.
Operationally, Bitget has resumed withdrawals for bitcoin, ether and USDT and scheduled the resumption of withdrawals for the remaining crypto assets, along with fiat and peer-to-peer services. The company’s public communications have aimed to combine transparency about the incident with reassurance that customer funds and platform operations remain protected and verifiable on-chain.
Going forward, the exchange will likely face scrutiny over third-party vendor security, incident response practices, and the efficacy of its protective measures. The incident highlights the complexity of modern exchange breaches, where attackers can leverage vulnerabilities in security products to attain high privileges without directly compromising private keys. For users and stakeholders, the immediate priority is clarity around ongoing investigations and confirmation that measures taken to restore funds and services are robust and independently verifiable.
Key Insights Table
| Aspect | Description |
|---|---|
| Frozen Funds | Approximately $1.1 million frozen; freezing does not equal recovery. |
| Recovery Expectations | CEO does not expect to recover a large share of the stolen assets due to historical patterns. |
| Protection Fund | Fund was replenished by Bitget using company capital and is verifiable on-chain. |
| Investigation Findings | Reports indicate compromise of two third-party security products and exploitation of a zero-day, enabling privileged access. |
| Operational Status | Withdrawals for BTC, ETH, and USDT resumed; other services scheduled to restart. |
Last edited at:2026/10/2
