Bitget CEO Gracy Chen said the exchange probably will not get back much of the nearly $388 million stolen in last week’s hack, even with about $1.1 million frozen so far.
CNBC reported that Chen said on Wednesday on CNBC’s Squawk Box Europe that the frozen funds still have not been sent back to the exchange. She did not say how much has actually been recovered. But she made clear she does not expect the final figure to be big, because exchanges have historically recovered only small amounts after major hacks.
“An exchange has a responsibility to show how it protects users, especially when something goes wrong,” Chen said. Bitget said user account balances were not affected.
Bitget did not name the compromised third-party vendor
Chen refused to name the third-party provider tied to the breach. She said putting out more information than what is already in the investigation could open the door to extra cybersecurity risks.
Protection fund restored with Bitget capital
Bitget’s protection fund was worth more than $464 million before the hack. CNBC, citing Bloomberg calculations based on the fund’s public wallet addresses, said the fund briefly fell below $200 million after the incident. It has since been refilled to more than $300 million.
Chain News had earlier reported that Chen promised to bring the protection fund back to $300 million within one week. Chen said, “We used Bitget’s own capital to refill this fund, and Bitget took the financial hit instead of passing it on to users.”
She also said the replenished fund can still be publicly verified on-chain and is separate from the reserves backing customer balances.
Mandiant report details the intrusion path
A Mandiant investigation released by Bitget said the attackers gained unauthorized privileged access to two third-party security devices on Sept. 24. From there, they planted a web shell on one system, set up a remote control connection, moved laterally into a production wallet operations server, and deployed malicious packages.
The report said Bitget found no evidence that private keys were stolen, and cold wallets were not affected. Estimated losses were placed between $351.6 million and $387.5 million.
SlowMist traced earlier malicious activity to Aug. 31
CNBC said a separate cybersecurity firm, SlowMist, traced the earliest malicious activity to Aug. 31, when a zero-day vulnerability in one of the products was exploited.
Neither report blamed North Korea for the attack. Chen had previously said preliminary technical indicators were highly consistent with known North Korean hacking groups. This time, though, she said, “We still need to wait for more details.”
Some withdrawals have resumed
BTC, ETH, and USDT withdrawals have already resumed. Bitget said withdrawals for the remaining tokens, along with fiat and P2P services, were set to resume on Oct. 2 at 08:00 UTC.

