0x48ce7a2848ce…48ce7a2b
Bitget CEO Doubts Recovery of $387.5M Stolen in September Breach
Bitget CEO Gracy Chen says the exchange is bracing for permanent loss of the $387.5M stolen on September 24, citing the Bybit hack as precedent.

Outputs
Bitget lost $387.5 million in a September 24 breach via 19 unauthorized transactions exploiting a third-party vendor vulnerability; the initial estimate of $351.6 million was revised upward after on-chain accounting.
The exchange's User Protection Fund, which held over $464 million, absorbed the full loss; customer balances stayed intact and the reserve ratio remained above 100%.
Bitget is offering a 5% bounty for freezing and 5% for recovering stolen assets, and has committed to replenishing its protection fund to over $300 million within a week of the incident.
Bitget CEO Gracy Chen has signaled that the exchange is preparing for the likelihood that most of the $387.5 million stolen in its September 24 security breach will not be recovered, drawing a direct comparison to the February 2025 Bybit hack, where recovery efforts produced limited results.
The breach was detected at approximately 18:31 UTC on September 24, when unauthorized transfers began draining assets from Bitget's hot and warm wallets. Attackers executed 19 transactions across multiple blockchain networks after exploiting a vulnerability in a backend system tied to a third-party security vendor, according to the exchange's account of the incident.
The attackers deployed spoofed transaction data to circumvent Bitget's authorization processes, effectively tricking the system into approving transfers that should have been flagged. Cold wallets — the offline storage systems holding the bulk of exchange reserves — were not compromised, and no private keys were exposed.
Initial loss estimates put the figure at $351.6 million. More thorough on-chain accounting later revised it upward to $387.5 million. Investigators have flagged suspicious activity potentially linked to North Korean entities, though precise attribution remains under investigation.
User funds intact, but confidence dented
Bitget's User Protection Fund absorbed the full loss. The fund held over $464 million before the breach, comfortably covering the $387.5 million deficit. Customer account balances remained intact throughout the incident, and the exchange says its overall reserve ratio stayed above 100% despite the hack.
Bitget temporarily paused withdrawals to conduct a security review. Withdrawals have since resumed in phases. The exchange has committed to replenishing its User Protection Fund to more than $300 million within a week of the incident — a compressed timeline that will test its treasury operations and capital access.
Bounty program and the Bybit precedent
Bitget has launched a bounty program offering a 5% reward for freezing stolen assets and a further 5% for successfully recovering them. The exchange has also engaged forensic firms and is coordinating with law enforcement agencies across multiple jurisdictions.
Chen's reference to Bybit is instructive. The February 2025 incident demonstrated how little exchanges can realistically claw back once sophisticated attackers move stolen assets through mixers, bridges and intermediary wallets — the blockchain equivalent of a shell company network. Laundering infrastructure has grown faster than tracing and freezing capabilities, and exchanges that publicize recovery efforts often recoup only a fraction of the total.
If Bitget's experience mirrors Bybit's, the bounty program may yield freezes of some assets but full recovery remains improbable — a reality Chen appears to acknowledge by framing the exchange's preparations around absorbing the loss rather than reversing it.
Supply chain exposure
The vulnerability sat in a third-party security vendor's system, meaning Bitget's own infrastructure was breached through a supply chain weakness. Third-party dependencies remain a persistent blind spot across the industry. Exchanges routinely outsource security components, wallet infrastructure and monitoring tools to specialized vendors, and vetting processes for those vendors vary widely.
Bitget's protection fund was large enough to cover the loss, placing it in a stronger position than many competitors would face in identical circumstances. But the incident demonstrates that even well-capitalized exchanges with reserves above 100% remain exposed to breaches that test the limits of their safety nets — and that the point of failure may sit outside their own perimeter entirely.
The operational consequences extend beyond Bitget. Expect renewed pressure on exchanges to audit third-party integrations, publish vendor security attestations, and disclose reserve composition in finer detail as regulators and institutional clients reassess counterparty risk in the wake of the breach.
via Crypto Briefing (Source)
More from Daniel Okafor
Show full bio
Correspondent covering industry trends and analytics at Mempool Brief.
435 articles