Oct 2, 2026
ManyPress

Advertisement

Technology

Bitget CEO Gracy Chen stated the exchange is not expecting to recover most of the $388 million stolen in a recent cyberattack, though user balances remain unaffected.

ManyPress

ManyPress

ManyPress Editorial

2 min readSource:CNBC Technology
Bitget CEO Says Recovery Unlikely After $388 Million Hack

Key facts

  • •Bitget has frozen about $1.1 million of the $388 million stolen in the attack.
  • •The exchange restored its protection fund to over $300 million using internal capital.
  • •Investigations found that attackers exploited a zero-day vulnerability in third-party security products.
  • •Bitget's latest Proof of Reserves report from September 29 shows a 131% reserve ratio.
  • •Withdrawals for major cryptocurrencies have resumed, with remaining services scheduled to return Friday.

Crypto exchange Bitget has frozen approximately $1.1 million of the nearly $388 million stolen during a cyberattack last week. CEO Gracy Chen stated in an email interview that she does not expect to recover a significant portion of the lost funds, citing the limited recovery rates seen in previous industry hacks.

By the numbers

$388 million
total value of stolen assets
$1.1 million
value of frozen assets
131%
self-reported reserve ratio
$300 million
restored protection fund value

Financial Impact and Protection

Bitget reported that user account balances were not affected by the theft. The exchange’s protection fund, which was valued at over $464 million before the incident, dropped below $200 million before being restored to more than $300 million using the company's own capital. Chen stated that the financial impact is being absorbed by the firm rather than passed to users.

Investigation Findings

Security reports from Mandiant and SlowMist, released on September 30, indicated that attackers compromised two third-party security products to gain access to Bitget’s production wallet systems. The breach began on August 31 through a zero-day vulnerability. While Chen previously noted technical indicators consistent with North Korean hacking groups, the reports did not confirm this attribution.

Timeline

  1. August 31
    Attackers exploited a zero-day vulnerability in a third-party security product.
  2. September 29
    Bitget conducted a snapshot for its latest Proof of Reserves report.
  3. September 30
    Mandiant and SlowMist released investigation reports on the security breach.

Advertisement

This article was independently rewritten by ManyPress editorial AI from reporting originally published by CNBC Technology.

Technology