Bitget CEO Gracy Chen expresses skepticism on recovering $387.5M in stolen funds
The exchange's chief executive drew parallels to the Bybit hack, where recovery efforts yielded limited results
Bitget lost $387.5 million in a security breach on September 24, and CEO Gracy Chen isn’t sugarcoating the odds of getting it back. Drawing a direct comparison to the February 2025 Bybit hack, where recovery efforts produced underwhelming results, Chen signaled that the exchange is preparing for the possibility that most of those funds are gone for good.
How the attack unfolded
The breach was detected at approximately 18:31 UTC on September 24, when unauthorized transfers began draining assets from Bitget’s hot and warm wallets. Attackers executed 19 transactions across multiple blockchain networks, exploiting a vulnerability in a backend system tied to a third-party security vendor.
Spoofed transaction data was deployed to circumvent the exchange’s authorization processes, essentially tricking the system into approving transfers it should have flagged. Cold wallets, the offline storage systems that hold the bulk of exchange reserves, were not compromised. No private keys were exposed. The initial loss estimate came in at $351.6 million, but more thorough on-chain accounting later revised the figure upward to $387.5 million.
Investigators have flagged suspicious activities potentially linked to North Korean entities, though the precise attribution remains under investigation.
User funds safe, but confidence takes a hit
Bitget’s User Protection Fund absorbed the full loss. Prior to the breach, the fund held over $464 million, comfortably covering the $387.5 million deficit. Customer account balances remained intact throughout the incident. The exchange’s overall reserve ratio stayed above 100% despite the hack.
The news moving money, markets, and the world—before your day starts.
Daily. Free. Join 34,000+ readers across crypto, finance, and policy.
Bitget temporarily paused withdrawals to conduct a security review. Withdrawals have since resumed in phases, and the exchange has committed to replenishing its User Protection Fund to over $300 million within a week of the incident.
The bounty program and recovery prospects
Bitget launched a bounty program in the wake of the breach, offering a 5% reward for freezing stolen assets and another 5% for successfully recovering them. The exchange also brought in forensic firms and is working with law enforcement agencies across jurisdictions.
Chen’s reference to the Bybit hack is instructive. That incident, which occurred in February 2025, demonstrated how little exchanges can realistically claw back once sophisticated attackers have moved stolen assets through the blockchain equivalent of a shell company network.
What this means for exchange security
The vulnerability sat in a third-party security vendor’s system, meaning Bitget’s own infrastructure was breached through a supply chain weakness. Third-party dependencies are a persistent blind spot across the industry. Exchanges routinely outsource security components, wallet infrastructure, and monitoring tools to specialized vendors, and the vetting processes for these vendors vary wildly across the industry.
Bitget had a protection fund large enough to cover the loss, which puts it in a better position than many competitors would be in the same situation. But the incident highlights that even well-capitalized exchanges with reserves above 100% can suffer breaches that test the limits of their safety nets.