Approximately $1.1 million of the nearly $388 million that was taken from the crypto platform Bitget during a recent cyberattack has been frozen, as the exchange actively works to trace and reclaim the stolen funds.
According to CEO Gracy Chen in an email interview with CNBC, the frozen assets have not necessarily been returned to Bitget. She refrained from disclosing the total amount recovered so far.
In a Wednesday appearance on CNBC’s “Squawk Box Europe,” Chen expressed that she “is not expecting to recover substantial funds,” referencing the minimal recoveries seen from previous attacks on cryptocurrency exchanges. Nonetheless, she emphasized that “exchanges must show how they protect users, especially in the event of breaches.”
Bitget confirmed that user account balances remained unaffected by the incident.
Before the theft, the exchange had estimated its protection fund at over $464 million. Following the breach, this figure reportedly fell below $200 million, based on Bloomberg’s analysis of disclosed wallet addresses, but it has since been restored to over $300 million. Chen noted that the refreshed fund remains publicly verifiable on-chain and is distinct from the reserves supporting customer balances.
In the most recent Proof of Reserves, taken from a snapshot on September 29, Bitget reported an overall reserve ratio of 131%, with all 19 supported assets having backing exceeding 100%.
“We replenished the Fund using our own capital,” Chen explained. “Bitget is absorbing the financial impact rather than passing it onto our users.”
Reports from September 30 by Mandiant, a division of Google Cloud, alongside blockchain security company SlowMist, revealed that the hackers first compromised two third-party security tools before accessing Bitget’s production wallet systems.
SlowMist identified the initial malicious activity in logs dating back to August 31, where a previously unknown vulnerability was exploited in one of the tools.
The hackers were able to gain privileged access and circumvent the standard customer withdrawal process without needing to steal private keys, according to Mandiant’s report.
“The attack method was quite sophisticated,” Chen noted during her segment on “Squawk Box Europe,” adding that the perpetrators removed evidence after making transfers to complicate investigations.
Neither report specified which security products were affected. When asked for more details, Chen opted not to disclose any vendor information, as doing so could pose additional security threats.
The investigations did not attribute the attack to North Korea, although Chen had previously stated that the initial technical signs strongly resembled those associated with known North Korean hacking initiatives.
“We will need to wait for more details,” she mentioned to CNBC.
Withdrawals for bitcoin, ether, and USDT have resumed. Bitget has also scheduled withdrawals for other cryptocurrencies, in addition to fiat and peer-to-peer services, to start again on Friday.
