Bitget CEO Gracy Chen expresses skepticism on recovering $387.5M in stolen funds

Bitget CEO Gracy Chen expresses skepticism on recovering $387.5M in stolen funds

The exchange's chief executive drew parallels to the Bybit hack, where recovery efforts yielded limited results

Bitget lost $387.5 million in a security breach on September 24, and CEO Gracy Chen isn’t sugarcoating the odds of getting it back. Drawing a direct comparison to the February 2025 Bybit hack, where recovery efforts produced underwhelming results, Chen signaled that the exchange is preparing for the possibility that most of those funds are gone for good.

How the attack unfolded

The breach was detected at approximately 18:31 UTC on September 24, when unauthorized transfers began draining assets from Bitget’s hot and warm wallets. Attackers executed 19 transactions across multiple blockchain networks, exploiting a vulnerability in a backend system tied to a third-party security vendor.

Spoofed transaction data was deployed to circumvent the exchange’s authorization processes, essentially tricking the system into approving transfers it should have flagged. Cold wallets, the offline storage systems that hold the bulk of exchange reserves, were not compromised. No private keys were exposed. The initial loss estimate came in at $351.6 million, but more thorough on-chain accounting later revised the figure upward to $387.5 million.

Advertisement

Investigators have flagged suspicious activities potentially linked to North Korean entities, though the precise attribution remains under investigation.

User funds safe, but confidence takes a hit

Bitget’s User Protection Fund absorbed the full loss. Prior to the breach, the fund held over $464 million, comfortably covering the $387.5 million deficit. Customer account balances remained intact throughout the incident. The exchange’s overall reserve ratio stayed above 100% despite the hack.

Bitget temporarily paused withdrawals to conduct a security review. Withdrawals have since resumed in phases, and the exchange has committed to replenishing its User Protection Fund to over $300 million within a week of the incident.

The bounty program and recovery prospects

Bitget launched a bounty program in the wake of the breach, offering a 5% reward for freezing stolen assets and another 5% for successfully recovering them. The exchange also brought in forensic firms and is working with law enforcement agencies across jurisdictions.

Chen’s reference to the Bybit hack is instructive. That incident, which occurred in February 2025, demonstrated how little exchanges can realistically claw back once sophisticated attackers have moved stolen assets through the blockchain equivalent of a shell company network.

What this means for exchange security

The vulnerability sat in a third-party security vendor’s system, meaning Bitget’s own infrastructure was breached through a supply chain weakness. Third-party dependencies are a persistent blind spot across the industry. Exchanges routinely outsource security components, wallet infrastructure, and monitoring tools to specialized vendors, and the vetting processes for these vendors vary wildly across the industry.

Bitget had a protection fund large enough to cover the loss, which puts it in a better position than many competitors would be in the same situation. But the incident highlights that even well-capitalized exchanges with reserves above 100% can suffer breaches that test the limits of their safety nets.

Disclosure: This article was edited by John Chen. For more information on how we create and review content, see our Editorial Policy.
Bitget CEO Gracy Chen expresses skepticism on recovering $387.5M in stolen funds
Bitget CEO Gracy Chen expresses skepticism on recovering $387.5M in stolen funds

The exchange's chief executive drew parallels to the Bybit hack, where recovery efforts yielded limited results

Share

Add us on Google

Bitget lost $387.5 million in a security breach on September 24, and CEO Gracy Chen isn’t sugarcoating the odds of getting it back. Drawing a direct comparison to the February 2025 Bybit hack, where recovery efforts produced underwhelming results, Chen signaled that the exchange is preparing for the possibility that most of those funds are gone for good.

How the attack unfolded

The breach was detected at approximately 18:31 UTC on September 24, when unauthorized transfers began draining assets from Bitget’s hot and warm wallets. Attackers executed 19 transactions across multiple blockchain networks, exploiting a vulnerability in a backend system tied to a third-party security vendor.

Spoofed transaction data was deployed to circumvent the exchange’s authorization processes, essentially tricking the system into approving transfers it should have flagged. Cold wallets, the offline storage systems that hold the bulk of exchange reserves, were not compromised. No private keys were exposed. The initial loss estimate came in at $351.6 million, but more thorough on-chain accounting later revised the figure upward to $387.5 million.

Advertisement

Investigators have flagged suspicious activities potentially linked to North Korean entities, though the precise attribution remains under investigation.

User funds safe, but confidence takes a hit

Bitget’s User Protection Fund absorbed the full loss. Prior to the breach, the fund held over $464 million, comfortably covering the $387.5 million deficit. Customer account balances remained intact throughout the incident. The exchange’s overall reserve ratio stayed above 100% despite the hack.

Bitget temporarily paused withdrawals to conduct a security review. Withdrawals have since resumed in phases, and the exchange has committed to replenishing its User Protection Fund to over $300 million within a week of the incident.

The bounty program and recovery prospects

Bitget launched a bounty program in the wake of the breach, offering a 5% reward for freezing stolen assets and another 5% for successfully recovering them. The exchange also brought in forensic firms and is working with law enforcement agencies across jurisdictions.

Chen’s reference to the Bybit hack is instructive. That incident, which occurred in February 2025, demonstrated how little exchanges can realistically claw back once sophisticated attackers have moved stolen assets through the blockchain equivalent of a shell company network.

What this means for exchange security

The vulnerability sat in a third-party security vendor’s system, meaning Bitget’s own infrastructure was breached through a supply chain weakness. Third-party dependencies are a persistent blind spot across the industry. Exchanges routinely outsource security components, wallet infrastructure, and monitoring tools to specialized vendors, and the vetting processes for these vendors vary wildly across the industry.

Bitget had a protection fund large enough to cover the loss, which puts it in a better position than many competitors would be in the same situation. But the incident highlights that even well-capitalized exchanges with reserves above 100% can suffer breaches that test the limits of their safety nets.

Disclosure: This article was edited by John Chen. For more information on how we create and review content, see our Editorial Policy.