SINGAPORE — Cryptocurrency exchange Bitget has admitted that most of the nearly $388 million stolen in one of the biggest crypto hacks of 2026 may never be recovered, even as the exchange restores withdrawals, replenishes its user-protection fund and says customers will not bear the financial loss.
Bitget CEO Gracy Chen said the exchange has managed to freeze only about:
$1.1 million
of the stolen assets.
That represents less than:
0.3%
of the total amount taken.
And frozen does not necessarily mean:
recovered.
The exchange has not disclosed how much money has actually been returned to its control.
Chen told CNBC she is:
“not expecting to recover a lot of funds.”
That admission makes the Bitget attack one of the clearest examples yet of a brutal reality in cryptocurrency security:
once digital assets move through enough wallets, blockchains and conversion services, recovering them can become extraordinarily difficult.
THE FINAL LOSS IS ABOUT $387.5 MILLION
Bitget initially estimated the theft at approximately:
$351.6 million.
Further reconciliation increased the figure to about:
$387.5 million.
Some reporting rounds that to:
$388 million.
The stolen assets were moved across:
11 blockchains
and included cryptocurrencies such as:
Ethereum
XRP
USDT
USDC
BNB
Avalanche
TRON
and
Zcash.
The breach affected:
hot wallets
and
warm wallets.
Bitget says its:
cold wallets
were not compromised.
THE ATTACK DID NOT BEGIN WITH A STOLEN PRIVATE KEY
This is one of the most important technical findings.
Many major crypto hacks involve the theft of:
private keys
or
seed phrases.
Those credentials effectively give the attacker control over blockchain assets.
But the Bitget attack appears to have taken a different route.
Independent investigations by:
Mandiant, part of Google Cloud,
and
SlowMist
found that attackers compromised third-party security products connected to Bitget’s infrastructure.
They then moved deeper into the exchange’s production wallet systems.
The attackers ultimately used Bitget’s own internal logic against it.
INVESTIGATORS FOUND A ZERO-DAY VULNERABILITY
The earliest known malicious activity dates to:
August 31, 2026.
SlowMist reported that attackers exploited a:
zero-day vulnerability
in a third-party security product.
A zero-day is a software flaw that is unknown to the vendor or has no available fix at the time it is exploited.
That makes these vulnerabilities especially dangerous.
Attackers can use them before defenders even know a weakness exists.
In Bitget’s case, the hackers may have maintained access for weeks before moving any money.
THE ATTACKERS HID INSIDE THE SYSTEM FOR ALMOST A MONTH
The main theft occurred on:
September 24.
But forensic logs indicate malicious activity began nearly:
four weeks earlier.
That means the attackers had time to:
study the environment
collect credentials
understand wallet workflows
and
prepare the withdrawal mechanism.
This kind of long dwell time is common in sophisticated cyberattacks.
The attacker does not immediately steal.
They first learn how the system works.
Then they strike.
TWO THIRD-PARTY SECURITY PRODUCTS WERE COMPROMISED
Investigators identified involvement from two unnamed external security products.
Reports refer to them only as:
Product A
and
Product B.
The vendors have not been publicly identified.
That is important because these were products designed to help protect infrastructure.
Instead, they became part of the attack path.
This turns the Bitget breach into more than a cryptocurrency-wallet problem.
It is also a:
software supply-chain security problem.
THE ATTACKERS MOVED LATERALLY INTO BITGET’S WALLET SYSTEM
After compromising the third-party security products, the attackers gained access to Bitget’s internal environment.
They then moved into a:
production wallet job server.
Malware was reportedly deployed.
Investigators also recovered a customized withdrawal tool.
That tool appears to have been built specifically around Bitget’s internal withdrawal logic.
Instead of simply stealing a key and signing transactions externally, the attackers made the exchange’s own systems generate unauthorized withdrawals.
THE FAKE WITHDRAWALS LOOKED LEGITIMATE TO THE SYSTEM
The attackers allegedly forged withdrawal requests that Bitget’s wallet infrastructure accepted as valid.
Those requests bypassed normal:
risk controls
and
verification systems.
That is a serious security lesson.
An exchange can protect private keys perfectly and still lose money if an attacker gains enough trusted access to make legitimate systems perform illegitimate actions.
The Bitget incident demonstrates why crypto security cannot rely only on key protection.
It also requires strong controls around:
Identity
Permissions
Third-party products
and
Withdrawal authorization.
THE MAIN THEFT LASTED LESS THAN THREE HOURS
SlowMist said the major unauthorized transfers ran for approximately:
2 hours and 52 minutes.
Once the attackers began moving funds, they operated rapidly across multiple blockchain networks.
Speed matters enormously in crypto theft.
Stablecoins can potentially be frozen if issuers or exchanges act quickly.
Attackers therefore often attempt to:
swap stablecoins
bridge assets
and
move funds between chains
before defenders coordinate.
That appears to have happened here.
ATTACKERS QUICKLY CONVERTED SOME STABLECOINS
Investigators reported that stolen stablecoins were rapidly exchanged into assets such as:
Ether.
This is a common laundering tactic.
Centralized stablecoins such as USDT and USDC may contain mechanisms allowing issuers to freeze specific addresses.
Native cryptocurrencies such as ETH can be harder to freeze at the protocol level.
Attackers therefore often convert assets quickly to reduce the effectiveness of emergency freezes.
That helps explain why only a tiny fraction of Bitget’s stolen funds has been stopped so far.
BITGET HAS FROZEN ONLY ABOUT $1.1 MILLION
As of October 2, Bitget said approximately:
$1.1 million
of the stolen funds had been frozen.
Compared with a total theft near:
$388 million,
that is a very small amount.
And again:
frozen does not mean recovered.
The assets may still sit in addresses controlled by other platforms or blockchain entities while legal and technical processes continue.
Bitget has not said how much has actually been returned.
BITGET IS OFFERING A 5% RECOVERY BOUNTY
The exchange launched an:
asset-recovery bounty program.
Individuals or institutions whose information directly leads to frozen or recovered funds can receive up to:
5%
of the affected amount.
Bitget is also using:
Bybit’s LazarusBounty platform
to help track stolen assets.
That collaboration is notable because Bitget previously assisted Bybit after its own massive hack.
BYBIT’S EXPERIENCE SHOWS WHY RECOVERY IS SO HARD
Bybit suffered an approximately:
$1.5 billion hack
in 2025.
U.S. authorities attributed that attack to hackers linked to North Korea.
A year later, only a relatively small percentage of the stolen assets had been recovered.
Chen cited that experience when explaining why Bitget is keeping expectations low.
The lesson is uncomfortable:
blockchains are transparent,
but transparency does not automatically mean assets can be seized.
Anyone can watch stolen money move.
Stopping it is another matter.
CRYPTO IS TRACEABLE — BUT NOT NECESSARILY REVERSIBLE
This is one of the biggest misconceptions about blockchain.
Transactions are often publicly visible.
Investigators can follow:
wallet addresses
token swaps
and
cross-chain transfers.
But blockchain transactions are generally irreversible.
There is no bank:
chargeback
or
cancel transaction button.
If funds reach decentralized protocols or wallets outside cooperating jurisdictions, recovery becomes difficult.
Tracing and recovering are two very different things.
NORTH KOREA IS SUSPECTED — BUT NOT YET CONFIRMED
Bitget CEO Gracy Chen previously said technical indicators were consistent with:
known North Korean hacking groups.
Investigators and blockchain analysts have pointed to:
IP infrastructure
and
money-laundering behavior
similar to activity previously associated with North Korean groups.
But as of the latest reports, there has been:
no final official government attribution.
That distinction matters.
North Korea remains a leading suspect.
It has not been conclusively established publicly as the attacker.
NORTH KOREA HAS BECOME A MAJOR CRYPTO SECURITY THREAT
If the attribution is eventually confirmed, the Bitget attack would fit a well-established pattern.
North Korean cyber groups have repeatedly targeted:
Crypto exchanges
Bridges
DeFi protocols
and
Blockchain companies.
Authorities in the U.S. and allied countries have accused the regime of stealing cryptocurrency to finance state operations and weapons programs.
North Korea denies allegations related to major crypto thefts.
Blockchain investigators estimate North Korea-linked hackers have stolen billions of dollars over multiple years.
2026 HAS ALREADY BEEN A BRUTAL YEAR FOR CRYPTO SECURITY
Bitget is not an isolated incident.
Reuters notes the crypto industry continues to experience large-scale attacks.
Major historical breaches include:
Bybit — approximately $1.5 billion
Poly Network — roughly $610 million
Ronin Network — around $540 million
Coincheck — about $530 million
and
Mt. Gox — roughly $500 million.
The Bitget breach now joins that list.
Last year alone, cybercriminals stole roughly:
$2.9 billion
in nearly:
150 crypto attacks.
BITGET SAYS USERS DID NOT LOSE THEIR BALANCES
The company has repeatedly emphasized that:
user account balances remain accurate.
Bitget says the financial loss is being absorbed by:
the exchange
and
its Protection Fund.
That distinction is important.
The $387.5 million theft occurred from Bitget’s wallet infrastructure.
Customers were not told that their displayed balances had been reduced by the amount stolen.
Instead, Bitget is using its own resources to cover the shortfall.
THE PROTECTION FUND WAS WORTH MORE THAN $464 MILLION BEFORE THE ATTACK
Bitget created its Protection Fund in:
2022.
Before the hack, the fund was valued at more than:
$464 million.
That gave the exchange enough resources on paper to cover the entire security incident.
After the hack, the value of the fund reportedly fell below:
$200 million.
That raised obvious concerns.
Bitget then injected additional capital.
BITGET RESTORED THE FUND ABOVE $300 MILLION
By September 30, Bitget said it had replenished the fund to more than:
$300 million.
The company says it used:
its own capital
to restore the balance.
The Protection Fund’s wallets are publicly viewable on-chain.
That provides users with some transparency.
But the fund is distinct from the assets Bitget says back normal customer balances.
That distinction is important when assessing exchange solvency.
PROOF OF RESERVES IS ALSO PART OF BITGET’S RESPONSE
Bitget publishes:
Proof of Reserves.
These reports are intended to demonstrate that the exchange holds assets corresponding to customer balances.
The exchange says those reserves remained intact.
Proof-of-reserves systems can improve transparency.
But they have limitations.
They may show assets without fully revealing:
Liabilities
Off-chain obligations
or
Counterparty risks.
So they should not be treated as a complete financial audit.
WITHDRAWALS WERE TEMPORARILY SUSPENDED
After detecting the attack, Bitget suspended withdrawals across the platform.
The company said the action was:
a security measure
rather than:
a liquidity problem.
Deposits and trading continued.
The suspension gave Bitget time to:
isolate systems
patch vulnerabilities
and
review wallet infrastructure.
Services were restored gradually.
BITCOIN WITHDRAWALS RETURNED FIRST
Bitget restarted withdrawals in phases.
The schedule began with:
Bitcoin on September 28.
Then:
Ethereum withdrawals resumed September 29.
USDT followed on:
September 30.
Other cryptocurrencies, fiat withdrawals and peer-to-peer services were scheduled to fully return on:
October 2.
The staggered process allowed the exchange to test systems before reopening everything at once.
FULL WITHDRAWAL ACCESS IS NOW BEING RESTORED
By October 2, Bitget said it was completing the restoration of:
All supported crypto withdrawals
Fiat withdrawals
and
P2P services.
That is an important operational milestone.
But reopening the exchange does not mean the stolen funds have been recovered.
It means Bitget believes it has enough confidence in its security and financial position to resume normal customer activity.
THE HACK EXPOSED THIRD-PARTY RISK
Perhaps the biggest lesson is that a company can spend heavily on security and still be compromised through:
someone else’s software.
Modern financial platforms rely on:
Security appliances
Cloud services
Monitoring tools
Authentication systems
and
Outside vendors.
Every integration creates another possible attack surface.
The attacker only needs one trusted weak point.
That is why supply-chain attacks are so dangerous.
SECURITY SOFTWARE CAN BECOME THE ATTACK VECTOR
This is particularly unsettling because the compromised products were:
security tools.
Companies often grant security products broad access because they need visibility into:
Networks
Credentials
Applications
and
Servers.
If the security product itself is compromised, that privileged access becomes valuable to attackers.
The same phenomenon has appeared in major non-crypto cyberattacks as well.
The tools designed to protect a network can become the easiest route inside.
ZERO-DAYS ARE ALMOST IMPOSSIBLE TO DEFEND PERFECTLY
A zero-day vulnerability creates a particularly difficult problem.
If nobody knows the flaw exists, there may be:
no patch
and
no signature
for security systems to detect.
Companies therefore need multiple defensive layers.
Even if one system fails, another should prevent:
privilege escalation
or
unauthorized withdrawals.
The Bitget incident suggests attackers were able to move through enough layers to reach the wallet execution environment.
PRIVATE-KEY SECURITY IS NOT ENOUGH
Crypto exchanges have spent years improving cold-wallet security.
That remains essential.
But the Bitget attack shows a broader threat.
If an attacker can forge instructions inside a trusted system, they may not need the actual keys.
The wallet still signs the transaction.
From the blockchain’s perspective, the transaction looks legitimate.
The vulnerability exists:
before the transaction reaches the blockchain.
That means exchanges need controls at every step of the withdrawal process.
MULTI-PERSON APPROVALS MAY NOT SOLVE EVERYTHING
Many financial institutions use:
multi-signature
or
multi-party approval.
Those systems can reduce risk.
But if software is allowed to automatically approve trusted withdrawals based on compromised internal credentials, attackers may still bypass human verification.
Security therefore requires independent checks.
Large or unusual transfers may need verification across systems that cannot all be compromised through the same vendor.
This is known as avoiding:
common-mode failure.
THE HOT-WALLET TRADE-OFF REMAINS
Exchanges need hot wallets because customers expect:
fast withdrawals.
But wallets connected to online systems are inherently more exposed than offline storage.
Cold wallets reduce attack risk.
But they cannot process every customer request instantly.
The result is a trade-off.
Exchanges need enough crypto online to operate efficiently.
But every dollar kept in a hot environment creates potential risk.
Bitget says the majority of its assets remained in cold storage.
That prevented the incident from becoming even larger.
USERS SHOULD UNDERSTAND EXCHANGE CUSTODY RISK
The incident again raises an old crypto principle:
“Not your keys, not your coins.”
When cryptocurrency is stored on an exchange, the user relies on that exchange to:
Protect the assets
Remain solvent
and
Honor withdrawals.
Self-custody removes some exchange risk.
But it creates different dangers.
Users can:
Lose keys
Fall for phishing scams
or
Make irreversible transfer mistakes.
There is no risk-free custody method.
REGULATORS ARE PAYING MORE ATTENTION TO CRYPTO CUSTODY
The Bitget incident occurred as U.S. regulators were proposing new rules around cryptocurrency custody.
On October 1, the Securities and Exchange Commission proposed clearer requirements for investment advisers and funds holding crypto assets.
The proposal reflects a broader regulatory concern:
as institutional crypto adoption increases, custody standards need to become more formalized.
Large hacks make that debate more urgent.
EXCHANGE SECURITY IS BECOMING A SYSTEMIC ISSUE
Crypto is no longer a small niche market.
Large exchanges serve:
tens of millions
or
hundreds of millions of users.
Bitget says it serves more than:
120 million users worldwide.
When a platform of that size suffers a $388 million breach, the consequences extend beyond one company.
They affect:
Market confidence
Regulation
Institutional adoption
and
The reputation of the broader crypto industry.
BITGET’S RESPONSE MAY MATTER ALMOST AS MUCH AS THE HACK
Security incidents are sometimes unavoidable.
The real test becomes:
What happens afterward?
Bitget:
Suspended withdrawals
Investigated the breach
Published attacker addresses
Brought in Mandiant and SlowMist
Restored its Protection Fund
and
Restarted withdrawals.
Those actions may help preserve customer confidence.
But they do not erase the underlying security failure.
The exchange still needs to explain how trusted third-party software gained enough access to reach its wallet environment.
TRANSPARENCY WILL BE THE NEXT TEST
Bitget has disclosed more technical information than many hacked platforms historically did.
But important questions remain.
The third-party security vendors have not been named.
The exact vulnerabilities have not been fully disclosed.
Final attribution remains unresolved.
And Bitget has not revealed exactly how much stolen crypto has actually been recovered.
Users and regulators will likely want more information as investigations continue.
THE BIGGER STORY: BITGET SAVED ITS USERS — NOT THE STOLEN CRYPTO
The headline:
“Bitget recovery”
can easily create the wrong impression.
The exchange did not recover $388 million.
It has frozen only about:
$1.1 million.
CEO Gracy Chen openly says most of the stolen assets may never return.
What Bitget recovered was:
its ability to operate.
It restored withdrawals.
It rebuilt its Protection Fund above:
$300 million.
It says user balances remain fully backed.
And it absorbed the financial loss itself rather than passing it to customers.
That is an important distinction.
The exchange may survive the attack even if the money does not come back.
But the bigger lesson for the cryptocurrency industry is uncomfortable.
Attackers did not need to steal Bitget’s cold-wallet keys.
They compromised trusted security infrastructure, learned how the wallet system worked and convinced that system to send hundreds of millions of dollars away.
That exposes a new frontier in crypto security.
The industry has spent years protecting private keys.
Now it also has to protect every system that is allowed to tell those keys what to do.
Bitget may have rebuilt the financial wall around its users — but with more than $386 million still beyond its control, the hack shows that surviving a crypto theft and actually recovering the crypto are two very different victories.