Bitget Says Most of $388 Million Crypto Hack May Never Be Recovered — But Users Were Made Whole Anyway

Business

Bitget Says Most of $388 Million Crypto Hack May Never Be Recovered — But Users Were Made Whole Anyway

SINGAPORE — Cryptocurrency exchange Bitget has admitted that most of the nearly $388 million stolen in one of the biggest crypto hacks of 2026 may never be recovered, even as the exchange restores withdrawals, replenishes its user-protection fund and says customers will not bear the financial loss.

Bitget CEO Gracy Chen said the exchange has managed to freeze only about:

$1.1 million

of the stolen assets.

That represents less than:

0.3%

of the total amount taken.

And frozen does not necessarily mean:

recovered.

The exchange has not disclosed how much money has actually been returned to its control.

Chen told CNBC she is:

“not expecting to recover a lot of funds.”

That admission makes the Bitget attack one of the clearest examples yet of a brutal reality in cryptocurrency security:

once digital assets move through enough wallets, blockchains and conversion services, recovering them can become extraordinarily difficult.

THE FINAL LOSS IS ABOUT $387.5 MILLION

Bitget initially estimated the theft at approximately:

$351.6 million.

Further reconciliation increased the figure to about:

$387.5 million.

Some reporting rounds that to:

$388 million.

The stolen assets were moved across:

11 blockchains

and included cryptocurrencies such as:

Ethereum

XRP

USDT

USDC

BNB

Avalanche

TRON

and

Zcash.

The breach affected:

hot wallets

and

warm wallets.

Bitget says its:

cold wallets

were not compromised.

THE ATTACK DID NOT BEGIN WITH A STOLEN PRIVATE KEY

This is one of the most important technical findings.

Many major crypto hacks involve the theft of:

private keys

or

seed phrases.

Those credentials effectively give the attacker control over blockchain assets.

But the Bitget attack appears to have taken a different route.

Independent investigations by:

Mandiant, part of Google Cloud,

and

SlowMist

found that attackers compromised third-party security products connected to Bitget’s infrastructure.

They then moved deeper into the exchange’s production wallet systems.

The attackers ultimately used Bitget’s own internal logic against it.

INVESTIGATORS FOUND A ZERO-DAY VULNERABILITY

The earliest known malicious activity dates to:

August 31, 2026.

SlowMist reported that attackers exploited a:

zero-day vulnerability

in a third-party security product.

A zero-day is a software flaw that is unknown to the vendor or has no available fix at the time it is exploited.

That makes these vulnerabilities especially dangerous.

Attackers can use them before defenders even know a weakness exists.

In Bitget’s case, the hackers may have maintained access for weeks before moving any money.

THE ATTACKERS HID INSIDE THE SYSTEM FOR ALMOST A MONTH

The main theft occurred on:

September 24.

But forensic logs indicate malicious activity began nearly:

four weeks earlier.

That means the attackers had time to:

study the environment

collect credentials

understand wallet workflows

and

prepare the withdrawal mechanism.

This kind of long dwell time is common in sophisticated cyberattacks.

The attacker does not immediately steal.

They first learn how the system works.

Then they strike.

TWO THIRD-PARTY SECURITY PRODUCTS WERE COMPROMISED

Investigators identified involvement from two unnamed external security products.

Reports refer to them only as:

Product A

and

Product B.

The vendors have not been publicly identified.

That is important because these were products designed to help protect infrastructure.

Instead, they became part of the attack path.

This turns the Bitget breach into more than a cryptocurrency-wallet problem.

It is also a:

software supply-chain security problem.

THE ATTACKERS MOVED LATERALLY INTO BITGET’S WALLET SYSTEM

After compromising the third-party security products, the attackers gained access to Bitget’s internal environment.

They then moved into a:

production wallet job server.

Malware was reportedly deployed.

Investigators also recovered a customized withdrawal tool.

That tool appears to have been built specifically around Bitget’s internal withdrawal logic.

Instead of simply stealing a key and signing transactions externally, the attackers made the exchange’s own systems generate unauthorized withdrawals.

THE FAKE WITHDRAWALS LOOKED LEGITIMATE TO THE SYSTEM

The attackers allegedly forged withdrawal requests that Bitget’s wallet infrastructure accepted as valid.

Those requests bypassed normal:

risk controls

and

verification systems.

That is a serious security lesson.

An exchange can protect private keys perfectly and still lose money if an attacker gains enough trusted access to make legitimate systems perform illegitimate actions.

The Bitget incident demonstrates why crypto security cannot rely only on key protection.

It also requires strong controls around:

Identity

Permissions

Third-party products

and

Withdrawal authorization.

THE MAIN THEFT LASTED LESS THAN THREE HOURS

SlowMist said the major unauthorized transfers ran for approximately:

2 hours and 52 minutes.

Once the attackers began moving funds, they operated rapidly across multiple blockchain networks.

Speed matters enormously in crypto theft.

Stablecoins can potentially be frozen if issuers or exchanges act quickly.

Attackers therefore often attempt to:

swap stablecoins

bridge assets

and

move funds between chains

before defenders coordinate.

That appears to have happened here.

ATTACKERS QUICKLY CONVERTED SOME STABLECOINS

Investigators reported that stolen stablecoins were rapidly exchanged into assets such as:

Ether.

This is a common laundering tactic.

Centralized stablecoins such as USDT and USDC may contain mechanisms allowing issuers to freeze specific addresses.

Native cryptocurrencies such as ETH can be harder to freeze at the protocol level.

Attackers therefore often convert assets quickly to reduce the effectiveness of emergency freezes.

That helps explain why only a tiny fraction of Bitget’s stolen funds has been stopped so far.

BITGET HAS FROZEN ONLY ABOUT $1.1 MILLION

As of October 2, Bitget said approximately:

$1.1 million

of the stolen funds had been frozen.

Compared with a total theft near:

$388 million,

that is a very small amount.

And again:

frozen does not mean recovered.

The assets may still sit in addresses controlled by other platforms or blockchain entities while legal and technical processes continue.

Bitget has not said how much has actually been returned.

BITGET IS OFFERING A 5% RECOVERY BOUNTY

The exchange launched an:

asset-recovery bounty program.

Individuals or institutions whose information directly leads to frozen or recovered funds can receive up to:

5%

of the affected amount.

Bitget is also using:

Bybit’s LazarusBounty platform

to help track stolen assets.

That collaboration is notable because Bitget previously assisted Bybit after its own massive hack.

BYBIT’S EXPERIENCE SHOWS WHY RECOVERY IS SO HARD

Bybit suffered an approximately:

$1.5 billion hack

in 2025.

U.S. authorities attributed that attack to hackers linked to North Korea.

A year later, only a relatively small percentage of the stolen assets had been recovered.

Chen cited that experience when explaining why Bitget is keeping expectations low.

The lesson is uncomfortable:

blockchains are transparent,

but transparency does not automatically mean assets can be seized.

Anyone can watch stolen money move.

Stopping it is another matter.

CRYPTO IS TRACEABLE — BUT NOT NECESSARILY REVERSIBLE

This is one of the biggest misconceptions about blockchain.

Transactions are often publicly visible.

Investigators can follow:

wallet addresses

token swaps

and

cross-chain transfers.

But blockchain transactions are generally irreversible.

There is no bank:

chargeback

or

cancel transaction button.

If funds reach decentralized protocols or wallets outside cooperating jurisdictions, recovery becomes difficult.

Tracing and recovering are two very different things.

NORTH KOREA IS SUSPECTED — BUT NOT YET CONFIRMED

Bitget CEO Gracy Chen previously said technical indicators were consistent with:

known North Korean hacking groups.

Investigators and blockchain analysts have pointed to:

IP infrastructure

and

money-laundering behavior

similar to activity previously associated with North Korean groups.

But as of the latest reports, there has been:

no final official government attribution.

That distinction matters.

North Korea remains a leading suspect.

It has not been conclusively established publicly as the attacker.

NORTH KOREA HAS BECOME A MAJOR CRYPTO SECURITY THREAT

If the attribution is eventually confirmed, the Bitget attack would fit a well-established pattern.

North Korean cyber groups have repeatedly targeted:

Crypto exchanges

Bridges

DeFi protocols

and

Blockchain companies.

Authorities in the U.S. and allied countries have accused the regime of stealing cryptocurrency to finance state operations and weapons programs.

North Korea denies allegations related to major crypto thefts.

Blockchain investigators estimate North Korea-linked hackers have stolen billions of dollars over multiple years.

2026 HAS ALREADY BEEN A BRUTAL YEAR FOR CRYPTO SECURITY

Bitget is not an isolated incident.

Reuters notes the crypto industry continues to experience large-scale attacks.

Major historical breaches include:

Bybit — approximately $1.5 billion

Poly Network — roughly $610 million

Ronin Network — around $540 million

Coincheck — about $530 million

and

Mt. Gox — roughly $500 million.

The Bitget breach now joins that list.

Last year alone, cybercriminals stole roughly:

$2.9 billion

in nearly:

150 crypto attacks.

BITGET SAYS USERS DID NOT LOSE THEIR BALANCES

The company has repeatedly emphasized that:

user account balances remain accurate.

Bitget says the financial loss is being absorbed by:

the exchange

and

its Protection Fund.

That distinction is important.

The $387.5 million theft occurred from Bitget’s wallet infrastructure.

Customers were not told that their displayed balances had been reduced by the amount stolen.

Instead, Bitget is using its own resources to cover the shortfall.

THE PROTECTION FUND WAS WORTH MORE THAN $464 MILLION BEFORE THE ATTACK

Bitget created its Protection Fund in:

2022.

Before the hack, the fund was valued at more than:

$464 million.

That gave the exchange enough resources on paper to cover the entire security incident.

After the hack, the value of the fund reportedly fell below:

$200 million.

That raised obvious concerns.

Bitget then injected additional capital.

BITGET RESTORED THE FUND ABOVE $300 MILLION

By September 30, Bitget said it had replenished the fund to more than:

$300 million.

The company says it used:

its own capital

to restore the balance.

The Protection Fund’s wallets are publicly viewable on-chain.

That provides users with some transparency.

But the fund is distinct from the assets Bitget says back normal customer balances.

That distinction is important when assessing exchange solvency.

PROOF OF RESERVES IS ALSO PART OF BITGET’S RESPONSE

Bitget publishes:

Proof of Reserves.

These reports are intended to demonstrate that the exchange holds assets corresponding to customer balances.

The exchange says those reserves remained intact.

Proof-of-reserves systems can improve transparency.

But they have limitations.

They may show assets without fully revealing:

Liabilities

Off-chain obligations

or

Counterparty risks.

So they should not be treated as a complete financial audit.

WITHDRAWALS WERE TEMPORARILY SUSPENDED

After detecting the attack, Bitget suspended withdrawals across the platform.

The company said the action was:

a security measure

rather than:

a liquidity problem.

Deposits and trading continued.

The suspension gave Bitget time to:

isolate systems

patch vulnerabilities

and

review wallet infrastructure.

Services were restored gradually.

BITCOIN WITHDRAWALS RETURNED FIRST

Bitget restarted withdrawals in phases.

The schedule began with:

Bitcoin on September 28.

Then:

Ethereum withdrawals resumed September 29.

USDT followed on:

September 30.

Other cryptocurrencies, fiat withdrawals and peer-to-peer services were scheduled to fully return on:

October 2.

The staggered process allowed the exchange to test systems before reopening everything at once.

FULL WITHDRAWAL ACCESS IS NOW BEING RESTORED

By October 2, Bitget said it was completing the restoration of:

All supported crypto withdrawals

Fiat withdrawals

and

P2P services.

That is an important operational milestone.

But reopening the exchange does not mean the stolen funds have been recovered.

It means Bitget believes it has enough confidence in its security and financial position to resume normal customer activity.

THE HACK EXPOSED THIRD-PARTY RISK

Perhaps the biggest lesson is that a company can spend heavily on security and still be compromised through:

someone else’s software.

Modern financial platforms rely on:

Security appliances

Cloud services

Monitoring tools

Authentication systems

and

Outside vendors.

Every integration creates another possible attack surface.

The attacker only needs one trusted weak point.

That is why supply-chain attacks are so dangerous.

SECURITY SOFTWARE CAN BECOME THE ATTACK VECTOR

This is particularly unsettling because the compromised products were:

security tools.

Companies often grant security products broad access because they need visibility into:

Networks

Credentials

Applications

and

Servers.

If the security product itself is compromised, that privileged access becomes valuable to attackers.

The same phenomenon has appeared in major non-crypto cyberattacks as well.

The tools designed to protect a network can become the easiest route inside.

ZERO-DAYS ARE ALMOST IMPOSSIBLE TO DEFEND PERFECTLY

A zero-day vulnerability creates a particularly difficult problem.

If nobody knows the flaw exists, there may be:

no patch

and

no signature

for security systems to detect.

Companies therefore need multiple defensive layers.

Even if one system fails, another should prevent:

privilege escalation

or

unauthorized withdrawals.

The Bitget incident suggests attackers were able to move through enough layers to reach the wallet execution environment.

PRIVATE-KEY SECURITY IS NOT ENOUGH

Crypto exchanges have spent years improving cold-wallet security.

That remains essential.

But the Bitget attack shows a broader threat.

If an attacker can forge instructions inside a trusted system, they may not need the actual keys.

The wallet still signs the transaction.

From the blockchain’s perspective, the transaction looks legitimate.

The vulnerability exists:

before the transaction reaches the blockchain.

That means exchanges need controls at every step of the withdrawal process.

MULTI-PERSON APPROVALS MAY NOT SOLVE EVERYTHING

Many financial institutions use:

multi-signature

or

multi-party approval.

Those systems can reduce risk.

But if software is allowed to automatically approve trusted withdrawals based on compromised internal credentials, attackers may still bypass human verification.

Security therefore requires independent checks.

Large or unusual transfers may need verification across systems that cannot all be compromised through the same vendor.

This is known as avoiding:

common-mode failure.

THE HOT-WALLET TRADE-OFF REMAINS

Exchanges need hot wallets because customers expect:

fast withdrawals.

But wallets connected to online systems are inherently more exposed than offline storage.

Cold wallets reduce attack risk.

But they cannot process every customer request instantly.

The result is a trade-off.

Exchanges need enough crypto online to operate efficiently.

But every dollar kept in a hot environment creates potential risk.

Bitget says the majority of its assets remained in cold storage.

That prevented the incident from becoming even larger.

USERS SHOULD UNDERSTAND EXCHANGE CUSTODY RISK

The incident again raises an old crypto principle:

“Not your keys, not your coins.”

When cryptocurrency is stored on an exchange, the user relies on that exchange to:

Protect the assets

Remain solvent

and

Honor withdrawals.

Self-custody removes some exchange risk.

But it creates different dangers.

Users can:

Lose keys

Fall for phishing scams

or

Make irreversible transfer mistakes.

There is no risk-free custody method.

REGULATORS ARE PAYING MORE ATTENTION TO CRYPTO CUSTODY

The Bitget incident occurred as U.S. regulators were proposing new rules around cryptocurrency custody.

On October 1, the Securities and Exchange Commission proposed clearer requirements for investment advisers and funds holding crypto assets.

The proposal reflects a broader regulatory concern:

as institutional crypto adoption increases, custody standards need to become more formalized.

Large hacks make that debate more urgent.

EXCHANGE SECURITY IS BECOMING A SYSTEMIC ISSUE

Crypto is no longer a small niche market.

Large exchanges serve:

tens of millions

or

hundreds of millions of users.

Bitget says it serves more than:

120 million users worldwide.

When a platform of that size suffers a $388 million breach, the consequences extend beyond one company.

They affect:

Market confidence

Regulation

Institutional adoption

and

The reputation of the broader crypto industry.

BITGET’S RESPONSE MAY MATTER ALMOST AS MUCH AS THE HACK

Security incidents are sometimes unavoidable.

The real test becomes:

What happens afterward?

Bitget:

Suspended withdrawals

Investigated the breach

Published attacker addresses

Brought in Mandiant and SlowMist

Restored its Protection Fund

and

Restarted withdrawals.

Those actions may help preserve customer confidence.

But they do not erase the underlying security failure.

The exchange still needs to explain how trusted third-party software gained enough access to reach its wallet environment.

TRANSPARENCY WILL BE THE NEXT TEST

Bitget has disclosed more technical information than many hacked platforms historically did.

But important questions remain.

The third-party security vendors have not been named.

The exact vulnerabilities have not been fully disclosed.

Final attribution remains unresolved.

And Bitget has not revealed exactly how much stolen crypto has actually been recovered.

Users and regulators will likely want more information as investigations continue.

THE BIGGER STORY: BITGET SAVED ITS USERS — NOT THE STOLEN CRYPTO

The headline:

“Bitget recovery”

can easily create the wrong impression.

The exchange did not recover $388 million.

It has frozen only about:

$1.1 million.

CEO Gracy Chen openly says most of the stolen assets may never return.

What Bitget recovered was:

its ability to operate.

It restored withdrawals.

It rebuilt its Protection Fund above:

$300 million.

It says user balances remain fully backed.

And it absorbed the financial loss itself rather than passing it to customers.

That is an important distinction.

The exchange may survive the attack even if the money does not come back.

But the bigger lesson for the cryptocurrency industry is uncomfortable.

Attackers did not need to steal Bitget’s cold-wallet keys.

They compromised trusted security infrastructure, learned how the wallet system worked and convinced that system to send hundreds of millions of dollars away.

That exposes a new frontier in crypto security.

The industry has spent years protecting private keys.

Now it also has to protect every system that is allowed to tell those keys what to do.

Bitget may have rebuilt the financial wall around its users — but with more than $386 million still beyond its control, the hack shows that surviving a crypto theft and actually recovering the crypto are two very different victories.

Get our stories first on Google

More in Singapore

See all in Singapore