Skip to content

Invest2 publishers2 min readPublished

Bitget's CEO doubts the $387.5 million lost through a vendor-linked backend will come back

Bitget CEO Gracy Chen doubts much of the $387.5 million stolen via a backend tied to a third-party security vendor will come back. So far about 0.2% of the loss has been frozen, so the exchange itself is paying for an outsourced security flaw.

The Investor · Invest desk

Illustration accompanying Bitget's CEO doubts the $387.5 million lost through a vendor-linked backend will come back

What happened

  • Attackers used spoofed transaction data to push 19 transfers past Bitget's authorization checks and drain its hot and warm wallets. Cold wallets and private keys were untouched.
  • Bitget first put the loss at $351.6 million, then raised it to $387.5 million after a fuller count of on-chain transfers.
  • Bitget's User Protection Fund, which held over $464 million before the breach, absorbed the whole loss, and customer balances stayed intact.
  • Chen compared the case to Bybit's February 2025 hack, where recovery efforts produced limited results.

Compiled by The InvestorSomething wrong?How this is made

Why it matters

  • cost To keep its pledge of refilling the fund past $300 million within a week, Bitget has to find about $223.5 million, and neither report says where that money will come from.
  • constraint Until the refill lands, the roughly $76.5 million left in the fund would cover less than a quarter of a loss the size of September's $320 million Liquid Network exploit.
  • exposure Crypto Briefing says exchanges routinely hand security, wallet and monitoring tools to outside vendors whose vetting varies widely, so any of them can lose hot-wallet funds even when keys and cold storage stay safe.

A fund holding a little over $464 million paid a $387.5 million bill [7][1], so one breach used about 83.5% of it [2]. Bitget has promised to take the fund back above $300 million within a week [8]. That target is about $164 million below the balance before the breach [10], so even if Bitget hits the deadline, its fund will be smaller than before the attack. Its reserve ratio stayed above 100% throughout, according to Crypto Briefing [9].

The recoveries so far are small next to those sums. Tether and Circle blacklisted a wallet linked to the exploit and froze $318,013 in USDT and USDC, Chen confirmed [11]. NEAR Intents froze about $500,000 [10]. Together that is $818,013, or about 0.21% of the loss [4][5]. NEAR Intents also reported blocking more than $50 million in assets tied to the attack [10], about 12.9% of the total [6], though the reports do not say how much of the blocked sum can be returned.

The bounty has two separate 5% rewards, one for freezing stolen assets and one for recovering them [12]. If every dollar came back through the program, the two rewards together would cost Bitget $38.75 million, a tenth of the loss [9]. Cointelegraph's headline quoted Chen as "not very optimistic" about recovery [6].

If recovery stays near today's fraction, Bitget absorbs close to the full $387.5 million [1][5]. Crypto Briefing wrote that the Bybit case "demonstrated how little exchanges can realistically claw back" once attackers have moved stolen assets on-chain [18]. If NEAR's blocked $50 million became frozen money, the loss would still be about $337.5 million [7].

A finding that an insider was involved would move the blame away from the vendor. Chen said North Korea may have been responsible, pointing to IP addresses that she said matched the VPN choices of a particular North Korean group [14], and Crypto Briefing reported that attribution is still under investigation [19]. Cointelegraph wrote that she had not "totally ruled out" an inside job [15]. She also told the outlet, "It's more based on our preliminary results of the investigation, we have ruled out that possibility." [16]

I'd expect most of the money to stay lost. The strongest evidence for that is that the chief executive is lowering expectations herself [2]. The case against is that the tracing is only days old: NEAR Intents reported its block on the Monday after the breach [10]. The view is wrong if frozen balances climb from under $1 million toward the $50 million NEAR has blocked, or if the fund is not back above $300 million within the week Bitget promised [10][8].

What to watch

  • Whether Bitget's User Protection Fund is back above $300 million by the one-week deadline, and whether the company says what paid for the top-up.
  • Whether any of the more than $50 million NEAR Intents says it blocked is frozen or returned to Bitget.
  • Whether investigators confirm the North Korea link or reopen the inside-job question, and whether the vendor is named.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories