Read as article
Bitget CEO Doubles Down: Most of $388M Hack Is Gone
By @sharedot · · 8 pages
- Crypto
- Bitget
- Hack
- Gracy Chen
- Lazarus Group
Gracy Chen told CNBC she is not expecting to recover much of the stolen $388 million, after freezing only $1.1 million so far.
Chen's stark admission
Bitget CEO Gracy Chen told CNBC on "Squawk Box Europe" that she is "not expecting to recover a lot of funds" from the nearly $388 million stolen in last week's cyberattack, citing the limited recovery results from previous exchange hacks. So far only about $1.1 million has been frozen, and frozen assets have not necessarily been returned to the exchange. She declined to disclose how much has actually been recovered, while stressing that user account balances were unaffected and that exchanges have a responsibility to demonstrate how they protect users when something goes wrong.
Why 3.5% is the benchmark
According to Startup Fortune, Chen pointed to Bybit's experience after its own $1.5 billion Ether theft in February 2025: a full year later, Bybit had frozen and recovered a combined $80 million, roughly 3.5% of what it lost. Chen implied Bitget should expect something similar, which Startup Fortune calls a quiet admission that the stolen funds are headed toward a write-off dressed up as an ongoing investigation. The exchange has also launched a recovery bounty, offering 5% of any funds white hats help freeze and another 5% for funds they help fully recover, an admission that Bitget's own reach ends at the blockchain's edge.
The evidence: a vendor zero-day
Investigation reports released September 30 by Mandiant, part of Google Cloud, and blockchain security firm SlowMist found the attackers compromised two third-party security products before reaching Bitget's production wallet systems. SlowMist traced the earliest malicious activity to August 31, when a zero-day vulnerability in one of the products was exploited. Mandiant reported the attackers gained privileged internal access and bypassed the normal customer-facing withdrawal process without stealing private keys. Chen called the method "quite sophisticated," noting the attackers deleted traces after transfers, and declined to name the breached vendors, citing additional security risks.
Where the money is going
The recovery odds are worsened by how quickly the stolen assets are moving. Startup Fortune, citing CoinDesk, reports the hacker moved roughly $83 million in stolen XRP out of three holding wallets entirely, leaving another $75 million sitting in accounts that cannot be frozen under Ripple's existing network rules. Once funds clear into wallets or protocols lacking a freeze mechanism, cooperation from exchanges and blockchain firms stops mattering. On-chain trackers have pointed toward North Korea's Lazarus Group, and Chen said preliminary indicators were highly consistent with known DPRK-linked groups, though no formal attribution exists yet.
What the fund covers — and what it can't
The financial fallout is being absorbed internally. Bitget valued its protection fund at more than $464 million before the theft; Bloomberg's calculation of disclosed wallet addresses put it below $200 million afterward, before Bitget restored it to more than $300 million using its own capital, Chen told CNBC. The fund is publicly verifiable on-chain and separate from reserves backing customer balances, which showed a self-reported reserve ratio of 131% on a September 29 Proof of Reserves snapshot. But as Startup Fortune notes, a protection fund covers depositors — it does not get the $388 million back.
Trust drain and what comes next
Customer behavior showed the real cost fast: Startup Fortune reports roughly $463 million in net outflows in the 24 hours after the hack became public — users pulling assets faster than the stolen total itself. Bitget has closed the specific vulnerability, restricted internal access, added independent verification steps for withdrawals, and resumed bitcoin, ether and USDT withdrawals, with remaining crypto, fiat and P2P services scheduled to return Friday, according to CNBC. The exchange's transparency contrasts with more secretive responses elsewhere, but rebuilding trust after a near-total write-off of stolen funds could take months or years.