About $1.1 million of the roughly $388 million taken from Bitget in last week’s cyber‑attack has been frozen, while the exchange continues its efforts to trace and recover the remaining funds.
Chen noted in an email interview with CNBC that frozen assets do not guarantee they have been returned to the exchange, and she declined to specify the exact amount recovered.
On CNBC’s “Squawk Box Europe” on Wednesday, Chen said she does not anticipate recovering a large portion of the stolen funds, pointing to the modest recoveries seen after other exchange hacks. She added that exchanges must show how they safeguard users, especially when incidents occur.
Bitget stated that user account balances remain unaffected.
Before the attack, Bitget’s protection fund exceeded $464 million; after the breach it fell below $200 million, per Bloomberg’s analysis of disclosed wallet addresses, and has since been rebuilt to over $300 million. Chen emphasized that the replenished fund is publicly verifiable on‑chain and is kept separate from the reserves that back customer balances.
Bitget’s most recent Proof of Reserves, using a September 29 snapshot, reports a self‑declared overall reserve ratio of 131 %, with each of the 19 covered assets backed by more than 100 %.
“We replenished the fund using Bitget’s own capital,” Chen said. “The financial impact is being absorbed by the exchange, not passed on to users.”
Investigation reports released on September 30 by Mandiant (a Google Cloud unit) and blockchain security firm SlowMist revealed that the attackers first compromised two third‑party security products before infiltrating Bitget’s production wallet systems.
SlowMist traced the earliest malicious activity in the available logs to August 31, when a previously unknown—or zero‑day—vulnerability was exploited in one of those products.
The attackers subsequently gained privileged internal access and were able to bypass the standard customer‑facing withdrawal process without stealing private keys, according to Mandiant.
“The method is quite sophisticated,” Chen remarked on “Squawk Box Europe,” noting that the attackers erased traces after transfers to obstruct the investigation.
Neither report named the compromised security products. When pressed, Chen declined to reveal additional vendor or product details, warning that disclosing such information could introduce further security risks beyond what has already been published.
The reports did not link the attacks to North Korea. Chen had earlier noted that preliminary technical indicators strongly resembled those associated with known North Korean hacking groups.
“We will need to wait for more details,” she told CNBC.
Withdrawals for bitcoin, ether and USDT have already resumed. Bitget plans to restore withdrawals for its remaining cryptocurrencies, as well as fiat and peer‑to‑peer services, on Friday.
Also Read
- Swiss Glaciers Lose 20% of Ice Volume Since 2021 Amid Record Heat, Minimal Snowfall
- World powers gather in Pacific to chart climate battle
- African Union Commission Calls for Restraint as Ethiopia, Eritrea, and Egypt Tensions Escalate
- Ethiopia and Eritrea Sever Diplomatic Ties Amid Escalating Northern Conflict

