Bitget freezes $1.1 million of $388 million stolen in cyberattack, CEO says recovery unlikely
Quick Look
- Approximately $1.1 million of the nearly $388 million stolen from crypto exchange Bitget in a recent cyberattack has been frozen, CEO Gracy Chen told CNBC, though she said she does not expect to recover a significant portion of the funds.
- The exchange confirmed user balances were unaffected and that its protection fund, initially over $464 million, was restored to over $300 million using company capital.
- Investigations by Mandiant and SlowMist revealed attackers exploited a zero-day vulnerability in third-party security products to gain privileged access and bypass withdrawal processes, deleting traces after transfers.
AI-generated summary
Why It Matters
Bitget is a cryptocurrency exchange that maintains a protection fund to cover potential losses from security breaches. Prior to the attack, the fund was valued at over $464 million. The exchange publishes Proof of Reserves to demonstrate backing of user assets.
Approximately $1.1 million of the nearly $388 million stolen from crypto exchange Bitget in last week’s cyberattack has been frozen, as the platform continues efforts to trace and recover the assets.
Frozen assets had not necessarily been returned to the exchange, CEO Gracy Chen told CNBC in an email interview. She did not disclose how much had been recovered.
Speaking on CNBC’s “Squawk Box Europe” on Wednesday, Chen said she was “not expecting to recover a lot of funds,” citing the limited recovery from previous cryptocurrency exchange hacks. However, “exchanges have a responsibility to demonstrate how they protect users, particularly when something goes wrong,” she said.
Bitget said user account balances were unaffected.
The exchange valued its protection fund at more than $464 million before the theft. It was drawn down to below $200 million following the hack, according to Bloomberg's calculation of the fund's disclosed wallet addresses, before being restored to more than $300 million. Chen said the replenished fund remained publicly verifiable on-chain and was separate from the reserves backing customer balances.
Bitget’s latest Proof of Reserves, based on a Sept. 29 snapshot, showed a self-reported overall reserve ratio of 131%, with all 19 covered assets backed above 100%.
“We restored the Fund using Bitget’s own capital,” Chen said. “The financial impact is being absorbed by Bitget rather than passed on to our users.”
Investigation reports released Sept. 30 by Mandiant, part of Google Cloud, and blockchain security firm SlowMist found that the attackers compromised two third-party security products before gaining access to Bitget’s production wallet systems.
SlowMist traced the earliest malicious activity in available logs to Aug. 31, when a previously unknown, or zero-day, vulnerability was exploited in one of the products.
The attackers were then able to obtain privileged internal access and bypass the normal customer-facing withdrawal process without stealing private keys, Mandiant reported.
“The method, I would say, is quite sophisticated,” Chen said on “Squawk Box Europe,” adding that the attackers deleted traces after transfers to hinder the investigation.
Neither report identified the affected security products. When asked, Chen declined to disclose further vendor or product details, citing the potential to introduce additional security risks by releasing information beyond the published findings.
The reports did not attribute the attacks to North Korea. Chen had previously said preliminary technical indicators were highly consistent with known North Korean hacking groups.
"We will have to wait further for further details on this," she told CNBC.
What to Watch
AI outlook — possibilities, not facts
Bitget will continue to work with blockchain forensic firms to trace and attempt to recover additional stolen funds.
Likely · Within weeks
Bitget will not disclose the names of the compromised third-party security products due to security risk concerns.
Very likely · Within days
Open Questions
- Which specific third-party security products were compromised in the attack?
- What is the exact amount of funds recovered or returned to Bitget beyond the frozen $1.1 million?
- Will Bitget pursue legal action against the vendors of the compromised security products?
- Are there any ongoing efforts to identify or apprehend the attackers?





