Bitget freezes $1.1M of $388M stolen, CEO doubts recovery
Bitget has frozen about $1.1 million of the $388 million stolen in a September 24 hack, as its CEO says she does not expect to recover much of the funds.
· 4 min read

Roughly $1.1 million of the nearly $388 million taken from crypto exchange Bitget in a cyberattack last week has been frozen, according to CNBC, as the platform keeps trying to trace and retrieve the assets. Bitget CEO Gracy Chen told the outlet in an email interview that frozen assets are not necessarily back in the exchange’s hands, and she did not disclose the amount recovered so far.
Speaking on CNBC’s “Squawk Box Europe” on Wednesday, Chen said she was not expecting to recover a lot of funds, pointing to the limited recoveries seen after earlier cryptocurrency exchange hacks.
Also read: Bitget Raises Hack Estimate to $387.5M, 83.5% of Protection Fund
Key facts
- About $1.1 million of the nearly $388 million stolen from Bitget has been frozen, CNBC reported.
- Bitget’s protection fund, valued at more than $464 million before the theft, fell below $200 million after the hack before being restored to more than $300 million, a figure CNBC attributed to Bloomberg’s calculation of the fund’s disclosed wallet addresses.
- Bitget’s latest Proof of Reserves, based on a Sept. 29 snapshot, showed a self-reported overall reserve ratio of 131%, with all 19 covered assets backed above 100%.
- Investigation reports released Sept. 30 by Mandiant, part of Google Cloud, and SlowMist found the attackers compromised two third-party security products before reaching Bitget’s production wallet systems.
- Chainalysis traced the funds across four blockchains using in-house AI and custom automation, compressing more than 20 hours of manual bridge reconciliation into under 10 minutes, Coinpedia reported.
How the attackers got in
The Sept. 30 reports found that two third-party security products were compromised first, giving the attackers a path into Bitget’s production wallet systems. SlowMist traced the earliest malicious activity in the available logs to Aug. 31, when a zero-day vulnerability was exploited in one of the products.
Mandiant reported that the attackers used privileged internal access to bypass the normal customer-facing withdrawal process without taking private keys. Chen described the method as quite sophisticated and said the attackers deleted traces after transfers to slow the investigation. Neither report named the affected security products, and Chen declined to give vendor or product details, citing the risk of adding security exposure beyond what had already been published.
Also read: Crude Oil Settles Higher as Diplomacy Doubts Cloud US-Iran Conflict
CNBC reported that the reports did not attribute the attack to North Korea, though Chen had earlier said preliminary technical indicators were highly consistent with known North Korean hacking groups. Asked about attribution, she told CNBC, “We will have to wait further for further details on this.”
AI and a four-chain trail
Coinpedia reported that Chainalysis put in-house AI and custom automation to work on the funds, reducing more than 20 hours of manual bridge reconciliation to under 10 minutes and placing labels on its data platform for compliance teams and law enforcement partners within minutes of identifying the stolen funds.
According to that report, the funds left Bitget across 23 transfers in the first three hours and reached four chains: Ethereum accounted for 49.7%, XRP 40.8%, Zcash 7.6% and Tron 1.8%. Investigators identified cross-chain liquidity protocols, messaging protocols, instant swaps and laundering services among the methods used, and Coinpedia reported that the stolen XRP was routed through a cross-chain liquidity protocol in exchange for Bitcoin on another network, with tens of millions of dollars moving that way over roughly a day and a half before reaching attacker-controlled addresses. Chainalysis said its AI work did not replace human investigators, who set the logic and reviewed the output.
The reports differ on attribution: Coinpedia said Chainalysis tied the attack to North Korean actors and that crypto stolen by such actors in 2026 passed $1 billion, while CNBC said the Mandiant and SlowMist reports did not attribute the attack to North Korea. Coinpedia cited a $387 million figure for the theft, while CNBC and Bitget put the total at nearly $388 million.
Bitget said user account balances were not affected. Chen told CNBC the protection fund was rebuilt with Bitget’s own capital, that the financial impact is being absorbed by the exchange rather than passed to users, and that the replenished fund remains publicly verifiable on-chain and separate from the reserves backing customer balances.
Why it matters
Bitget’s users are the immediate audience: the exchange says their account balances were untouched, and its Proof of Reserves snapshot shows all 19 covered assets backed above 100%. For the wider market, the case turns on how much of a hacked exchange’s losses can realistically be clawed back, and Chen’s own answer suggests very little. Exchange protection funds are a public-facing safety net, and Bitget’s drawdown and partial rebuild will be read as a test of how durable those funds are in practice, while the attribution fight touches on the sanctions and law enforcement pressure that has followed North Korean-linked crypto theft in recent years.
What to watch
Bitget has scheduled withdrawals for its remaining cryptocurrencies, along with fiat and peer-to-peer services, to resume on Friday, after bitcoin, ether and USDT withdrawals already restarted. The frozen $1.1 million also remains one to track, since it has not necessarily been returned to the exchange. Attribution remains an open question, with Chen saying further details are still to come.
Sources: CNBC, Coinpedia

Emily Torres covers cryptocurrency and decentralized finance for StockPil, tracking blockchain markets and regulatory developments.
More from Emily →