Invest1 publisher2 min readPublished
Bitget will spend about 84% of its user protection fund covering a $387.5 million hack
Bitget will repay the $387.5 million drained from its hot and warm wallets out of a user protection fund of just over $464 million. Customers are made whole, and the reserve left behind would cover only about a fifth of another loss that size.
The Investor · Invest desk

What happened
- Bitget detected the breach on September 24 at 18:31 UTC, after attackers used spoofed transaction data to drain funds from its hot and warm wallets.
- Bitget's initial loss estimate of $351.6 million was later revised up to $387.5 million.
- CEO Gracy Chen said the attack resembles earlier operations attributed to North Korean hacking groups, based on IP address analysis and transaction pattern tracing.
- Bitget hired Mandiant and SlowMist to investigate and patch the breach, and withdrawals remain suspended in the meantime.
Compiled by The InvestorSomething wrong?How this is made
Why it matters
- cost The exchange carries the $387.5 million itself, paying users back from a reserve Bitget set aside for this kind of event.
- constraint Being made whole does not give customers access to their money; balances stay frozen until the investigators finish patching and Bitget reopens withdrawals.
- decision Crypto Briefing expects any Bitget prospectus to disclose the breach and how fast users were repaid, so the handling of the payout now becomes part of the listing case.
Against the loss, a fund of just over $464 million covers it about 1.2 times [5][2]. Repaying users will use about 84% of it [1].
About 103 million XRP, worth roughly $157 million, was among the stolen assets [4], or about 40% of the total [4]. The other $230 million or so included ETH and USDT [5].
The cold wallets held and no private keys were exposed [2]. The attacker still moved $387.5 million out of hot and warm wallets with spoofed transaction data [1][3]. Wallets that gave up that much held at least that much, so Bitget's online float at the time of the breach was no smaller than $387.5 million [7]. Crypto Briefing's account does not say what share of customer assets that was, or whether the fund will be refilled after the payout [1][5].
Crypto Briefing links the $35.9 million upward revision, about 10%, to Bitget recovering additional assets on the Zcash and TRON networks [3][6]. Recovered assets would normally shrink a loss. As reported, the figure runs the wrong way, and $387.5 million is best treated as a working number until Bitget reconciles it [3].
In my view Bitget's customers are thinly covered against a repeat. After the payout, the roughly $76 million left [5] would pay about a fifth of a second loss this size [3]. The gap can close one of two ways. Bitget refills the reserve, or it keeps less money in hot and warm wallets when withdrawals resume after Mandiant and SlowMist finish their work [7].
The counter-case is Chen's listing plan. She still intends to take Bitget public within three years [8]. She has also called 2026 a hard year for crypto listings, with AI and space companies drawing investor money away [9]. A company trying to list in that market has every reason to show a full reserve again, and quickly. The view is wrong if the fund is back near $464 million, or the online float sits well under $76 million, before withdrawals reopen [5][7].
What to watch
- Whether Bitget restores the User Protection Fund toward $464 million before it reopens withdrawals.
- What Mandiant and SlowMist find about how spoofed transaction data got past Bitget's hot and warm wallet controls.
- A reconciled loss figure from Bitget that explains how recoveries on Zcash and TRON raised the estimate.