Bitget Expects Limited Recovery After $388 Million Crypto Hack

date
22:04 02/10/2026
avatar
GMT Eight
Crypto exchange Bitget expects to recover only a limited portion of the nearly $388 million stolen in last week’s cyberattack, CEO Gracy Chen said, with approximately $1.1 million of the stolen assets frozen so far. Investigations found that attackers compromised two third-party security products before gaining privileged access to Bitget’s production wallet systems, without stealing private keys. Bitget says customer balances remain unaffected and that it is absorbing the financial loss with its own capital while gradually restoring withdrawal services.

Around $1.1 million of the stolen cryptocurrency has been frozen as Bitget and its partners continue tracing the assets. Chen cautioned that frozen funds have not necessarily been returned to the exchange and declined to disclose the amount recovered so far. Based on the recovery rates seen after previous major crypto hacks, she said the company does not expect to retrieve a large portion of the stolen assets.

Bitget maintains that customers will not bear the financial impact of the attack. Its protection fund, valued at more than $464 million before the breach, reportedly fell below $200 million after the incident before being replenished to more than $300 million. Chen said Bitget used its own capital to restore the fund, which remains separate from reserves backing customer assets.

The exchange’s latest Proof of Reserves, based on a Sept. 29 snapshot, reported an overall reserve ratio of 131%. Bitget said all 19 assets covered by the report were backed at more than 100%. The company maintains that user account balances remained intact throughout the incident.

Investigations by Google Cloud’s Mandiant and blockchain security firm SlowMist have provided additional details about how the attack occurred. Their reports found that hackers first compromised two third-party security products before gaining access to Bitget’s production wallet infrastructure. SlowMist traced the earliest malicious activity in available logs to Aug. 31, when attackers exploited a previously unknown, or zero-day, vulnerability in one of the products.

The attackers subsequently obtained privileged internal access and bypassed Bitget’s normal customer-facing withdrawal process, according to Mandiant. Private keys were not compromised. Chen described the attack as sophisticated and said the hackers also deleted traces of their activity after transferring assets, complicating efforts to reconstruct the breach and trace the stolen funds.

Neither investigation identified the two affected security products, and Bitget has declined to disclose the vendors involved, citing concerns that releasing additional technical details could create further security risks. The reports also stopped short of attributing the attack to North Korea. Bitget had previously said preliminary indicators were highly consistent with techniques associated with known North Korean hacking groups, but Chen said further investigation is needed before reaching a conclusion.

Bitget has begun restoring services as its security work continues. Withdrawals for bitcoin, ether and USDT have resumed, while withdrawals for remaining cryptocurrencies, fiat transactions and peer-to-peer services are scheduled to return on Friday. With recovery of the stolen assets expected to be limited, the focus is increasingly shifting toward how the exchange strengthens its security architecture and restores confidence following one of the largest crypto breaches of the year.