Crypto exchange Bitget suffered a major cyberattack last week, resulting in the theft of nearly $388 million in digital assets. As of October 2, approximately $1.1 million of the stolen funds have been frozen, though these assets have not necessarily been returned to Bitget, according to CEO Gracy Chen. Chen stated she is 'not expecting to recover a lot of funds,' referencing the limited recovery seen in previous cryptocurrency exchange hacks [1].
Despite the breach, Bitget confirmed that user account balances were unaffected. The exchange's protection fund, which was valued at over $464 million before the hack, was drawn down to below $200 million but has since been replenished to more than $300 million using Bitget's own capital. Chen emphasized that the financial impact is being absorbed by the company and not passed on to users. The protection fund remains publicly verifiable on-chain and is separate from the reserves backing customer balances. Bitget's latest Proof of Reserves, based on a September 29 snapshot, showed a self-reported overall reserve ratio of 131%, with all 19 covered assets backed above 100% [1].
Investigation reports released on September 30 by Mandiant (Google Cloud) and SlowMist revealed that attackers compromised two third-party security products, exploiting a zero-day vulnerability as early as August 31. This allowed them to gain privileged internal access and bypass normal withdrawal processes without stealing private keys. The attackers also deleted traces after transferring the assets to hinder the investigation. Neither report identified the affected security products, and Chen declined to provide further details, citing security risks. The reports did not attribute the attack to North Korea, though Chen noted that preliminary technical indicators were consistent with known North Korean hacking groups, pending further details [1].
Withdrawals for bitcoin, ether, and USDT have resumed on the platform [1].
CONCLUSION
Bitget has responded to the $388 million hack by freezing a small portion of the stolen assets and replenishing its protection fund, ensuring user balances remain unaffected. While the likelihood of recovering significant funds is low, the exchange has taken steps to restore confidence and maintain operational stability. The incident highlights ongoing cybersecurity risks in the crypto sector and the importance of robust user protection mechanisms.
