Bitget CEO Gracy Chen told CNBC that her company is “not expecting to recover a lot of funds” from the $388 million hack that struck the exchange last week. The admission comes as investigators continue to trace how the stolen assets moved and as the exchange rebuilds its protection fund with its own money.
Chen spoke on CNBC’s “Squawk Box Europe” on Wednesday, offering a blunt assessment of recovery chances. “Exchanges have a responsibility to demonstrate how they protect users, particularly when something goes wrong,” she said, even as she acknowledged limited prospects for getting back the lost money.
What Was Stolen
Bloomberg cites figures showing that Bitget lost nearly $388 million in the attack. Around $1.1 million of that sum has since been frozen. That amount makes up a small share of the total loss, and the frozen funds have not yet been restored to the exchange.
Beyond the initial freeze, Chen did not reveal how much had been recovered. What matters here is the difference between the two actions: a freeze keeps an asset from being moved, while recovery actually returns it to its original owner.
Users Were Not Affected
The exchange’s statement claimed user account balances were spared from the breach. No customer funds vanished from individual accounts overnight. The damage instead fell on exchange’s own reserves rather than its customers’ accounts.
Wallet addresses were revealed through the exchange’s protection fund, which stood at more than $464 million before the theft, was drawn down to below $200 million following the hack. Bloomberg calculated that figure from the fund’s, and the fund has since been brought back to more than $300 million.
Chen said the replenished fund remains publicly verifiable on-chain and is separate from the reserves backing customer balances. “We restored the Fund using Bitget’s own capital,” she said. “The financial impact is being absorbed by Bitget rather than passed on to our users.”
How the Attack Worked
Released Sept. 30, two investigation reports have made public details about the attack’s technical path. Mandiant, part of Google Cloud, and blockchain security firm SlowMist found that the attackers compromised two third-party security products before gaining access to Bitget’s production wallet systems.
According to Mandiant, SlowMist found the first sign of malicious activity in available records on Aug. 31. At that point, a previously unknown vulnerability in one of the products was exploited, which Mandiant describes as a zero-day flaw. From there, the attackers gained privileged internal access and skipped the usual customer-facing withdrawal procedure without taking private keys.
“The method, I would say, is quite sophisticated,” Chen said on “Squawk Box Europe.” She added that the attackers deleted traces after transfers to hinder the investigation.
The Zero-Day Exploit
The Aug. 31 log entry records the attack’s core weakness was a vulnerability that had never been seen before. SlowMist’, even though the source never states when the attackers first started using it.
The technique’s refinement stands out. Instead of cracking the system from the outside to steal private keys, the attackers discovered a path through the withdrawal process that let them bypass it entirely.
What Is Unknown
The two reports did not name the security products that were affected. When questioned, Chen refused to reveal more vendor or product details, saying that sharing such information could increase security risks beyond what the published findings already cover.
There was no attribution of the attacks to North Korea in the reports. Chen had earlier stated that preliminary technical indicators were highly consistent with known North Korean hacking groups, a claim she made on record. “We will have to wait further for further details on this,”
Withdrawal Timeline
Bitget has restarted withdrawals for bitcoin, ether and USDT. The remaining cryptocurrencies, along with fiat and peer-to-peer services, are set to resume their withdrawals on Friday.
| Asset Type | Withdrawal Status |
|---|---|
| Bitcoin, Ether, USDT | Resumed |
| Remaining cryptocurrencies, fiat, peer-to-peer | Scheduled for Friday |
The Fund’s New Position
Since the hack, the fund’s standing has changed greatly. This is the course it took:
- Pre-hack: More than $464 million
- Post-hack drawdown: Below $200 million
- Restored: More than $300 million
- Current: Publicly verifiable on-chain, separate from customer reserves
The exchange chose to absorb the financial loss from the breach instead of charging its users for it, according to Chen. That decision suggests customers will probably not face any increased costs tied to the incident, at least not through direct adjustments to their accounts.
The Recovery Question
Chen pointed to the partial recovery from earlier cryptocurrency exchange hacks as the foundation of her doubt. The frozen $1.1 million marks a modest beginning, yet it does not constitute a recovery.
There has been no announcement from the exchange about which of the frozen assets might come back onto its balance sheet. That difference is important for customers following the situation.
What Comes Next
The probe continues to unfold. SlowMist’s remarks, along with those from Mandiant’s reports provide a technical picture, but attribution remains open. Chen’, point to the exchange facing a drawn-out recovery effort instead of a swift one.
The protection fund has been brought back, some withdrawals have resumed, and the rest of them are set to reopen on Friday. These actions resolve the immediate operational issue: customers can now move their funds once more.
The fate of the recovered funds from the stolen $388 million is still uncertain, with the CEO’s own statements offering scant reason to expect a full recovery.
Here is the revised version: The attack’s exchange’s response so far has been transparent about the fund’ position and the technical specifics behind it have been laid bare. Whether that openness extends to recovery efforts has yet to be determined.
Source material: “Bitget `not expecting to recover a lot' from $388 million hack, CEO tells CNBC,” CNBC.
Get the Notebook.
The day's best stories and every fresh verdict, in plain English, in your inbox by seven. One email a day, no more.

