Bitget `not expecting to recover a lot’ from $388 million hack, CEO tells CNBC
Business News and FinanceVIEW IN APPMarketsBusinessInvestingTechPoliticsSelectMake ItTechBitget 'not expecting to recover a lot' from $388 million hack, CEO tells CNBCPublished Fri, Oct 2 2026 1:25 AM EDTUpdated 26 Min AgoMatthew Tan@in/matthewtmyWATCH LIVEKEY POINTS Bitget has frozen approximately $1.1 million of the nearly $388 million stolen in last week’s cyberattack, CEO Gracy Chen told CNBC.Bitget has replenished the Protection Fund used to cover the losses back up to $300 million, using its own reserves.Chen declined to identify the third-party vendors breached, citing security risks.The logo of Bitget is displayed on a smartphone screen with a stock market chart in the background, in Créteil, France, on June 30, 2026. The MiCA (Markets in Crypto-Assets) regulation is set to fully enter into force, requiring major cryptocurrency platforms to adapt to new standards imposed by the European Union or cease operations in the EU. (Photo Illustration by Samuel Boivin/NurPhoto via Getty Images)Nurphoto | Nurphoto | Getty ImagesApproximately $1.1 million of the nearly $388 million stolen from crypto exchange Bitget in last week’s cyberattack has been frozen, as the platform continues efforts to trace and recover the assets.
Frozen assets had not necessarily been returned to the exchange, CEO Gracy Chen told CNBC in an email interview. She did not disclose how much had been recovered.
Speaking on CNBC’s “Squawk Box Europe” on Wednesday, Chen said she was “not expecting to recover a lot of funds,” citing the limited recovery from previous cryptocurrency exchange hacks. However, “exchanges have a responsibility to demonstrate how they protect users, particularly when something goes wrong,” she said.
Bitget said user account balances were unaffected.
The exchange valued its protection fund at more than $464 million before the theft. It was drawn down to below $200 million following the hack, according to Bloomberg's calculation of the fund's disclosed wallet addresses, before being restored to more than $300 million. Chen said the replenished fund remained publicly verifiable on-chain and was separate from the reserves backing customer balances.
Bitget’s latest Proof of Reserves, based on a Sept. 29 snapshot, showed a self-reported overall reserve ratio of 131%, with all 19 covered assets backed above 100%.
“We restored the Fund using Bitget’s own capital,” Chen said. “The financial impact is being absorbed by Bitget rather than passed on to our users.”
Investigation reports released Sept. 30 by Mandiant, part of Google Cloud, and blockchain security firm SlowMist found that the attackers compromised two third-party security products before gaining access to Bitget’s production wallet systems.
SlowMist traced the earliest malicious activity in available logs to Aug. 31, when a previously unknown, or zero-day, vulnerability was exploited in one of the products.
The attackers were then able to obtain privileged internal access and bypass the normal customer-facing withdrawal process without stealing private keys, Mandiant reported.
“The method, I would say, is quite sophisticated,” Chen said on “Squawk Box Europe,” adding that the attackers deleted traces after transfers to hinder the investigation.
Neither report identified the affected security products. When asked, Chen declined to disclose further vendor or product details, citing the potential to introduce additional security risks by releasing information beyond the published findings.
The reports did not attribute the attacks to North Korea. Chen had previously said preliminary technical indicators were highly consistent with known North Korean hacking groups.
"We will have to wait further for further details on this," she told CNBC.
Withdrawals for bitcoin, ether and USDT have resumed. Bitget has scheduled withdrawals for its remaining cryptocurrencies, along with fiat and peer-to-peer services, to resume on Friday.