TL;DR
- Bitget suffered a hack in September that resulted in the theft of approximately $387.5 million, with little prospect of full recovery.
- Only around $1.1 million of the stolen funds were frozen, though CEO Gracy Chen clarified that this does not imply their effective return.
- The exchange’s Protection Fund was replenished above $300 million and the suspended withdrawals were restored on October 2.
Bitget, the crypto exchange that suffered one of the most significant hacks of the year, acknowledged that it will likely not recover most of the approximately $387.5 million stolen in September.
CEO Gracy Chen told CNBC that the exchange does not expect to recover a considerable portion of the funds involved in the attack. Tracing efforts continue alongside external investigators.
During recovery operations, around $1.1 million in assets were frozen. However, Chen clarified that frozen funds do not necessarily imply restitution. The executive emphasized that user account balances were not affected at any point and that Bitget used its own capital to replenish its Protection Fund, which had plummeted to below $200 million following the attack, down from more than $464 million recorded before the incident.


Bitget Investigates the Attack’s Trail
Cybersecurity firms Mandiant and SlowMist published their investigation reports on September 30, revealing that the attackers initially compromised two third-party security products to gain access to the exchange’s internal wallet production systems.
SlowMist identified the first malicious activity recorded on August 31 and determined that the attackers exploited a zero-day vulnerability previously unknown in one of those products, which allowed them to gain privileged internal access.
According to Mandiant, the attackers managed to bypass Bitget’s standard withdrawal process without stealing private keys and erased their tracks after transferring the funds. Neither firm publicly identified the affected security products, and Chen declined to provide additional details about the vendors, citing potential security risks.


The North Korea Lead Remains Unconfirmed
The investigations did not formally attribute the attack to North Korea. However, Chen had previously noted that preliminary technical indicators matched known patterns of North Korean hacker groups. Investigators indicated that additional data is needed before any definitive determination can be made.
The Proof of Reserves report from September 29 showed a self-reported global reserve ratio of 131%, with all 19 affected assets covered above 100%, according to Bitget.




Be the first to comment