Cointelegraph iconCointelegraphSep 29, 2026 ~3 min source read

Bitget CEO: Recovery of $388M From Hack ‘Not Very Optimistic’

Bitget CEO Gracy Chen compared the exchange’s September breach to Bybit’s 2025 hack and warned that only a small share of stolen assets are likely to be frozen or recovered.

Bitget CEO ‘not very optimistic’ on recovering funds from $388M breach

Share this story

Send the public story page.

Useful takeaways from this story.

Chen cited Bybit’s Feb 2025 hack—where only roughly 3.5% of stolen funds were frozen—as a cautionary precedent.

Some mitigation has occurred: stablecoin issuers blacklisted related wallets and third parties reported freezing assets.

Bitget launched a bounty program tied to amounts frozen and recovered and began staged withdrawal restarts.

# What happened On Sept. 24 Bitget detected unauthorized transfers that resulted in about $388 million of assets being moved to attacker-controlled addresses. The company at first reported $352 million affected, then updated its accounting to the larger figure after further analysis.

# CEO's assessment

# What mitigation occurred

  • Bitget created a bounty program that offers 5% of funds that are frozen and another 5% for funds that are successfully recovered.
  • Stablecoin issuers Tether and Circle blacklisted a wallet tied to the exploit, which froze $318,013 in USDT and USDC tied to those addresses.
  • The NEAR Intents team reported blocking more than $50 million in assets linked to the attack and reported freezing about $500,000.

# Operational response Bitget suspended withdrawals immediately after the breach and later resumed withdrawals in stages, beginning with Bitcoin transactions and then Ether. The company also provided an updated accounting of transfers that raised the affected asset figure to about $388 million.

# Context within recent industry attacks The Bitget breach is among the largest crypto incidents of 2026, following other large exploits such as a $320 million exploit of the Liquid Network in September 2026. Chen and the reporting place Bitget's incident alongside past major hacks including Bybit (2025), Ronin Bridge (2022), and Poly Network (2021) to show the persistence and scale of exchange and bridge exploits in recent years.

# Responsibility and investigation Chen said initial investigative signals pointed toward a possible North Korea-linked actor based on IP addresses and VPN choices that matched a known DPRK group, but she also said Bitget had not completely ruled out other possibilities, including an inside job. She described the matter as complex and in need of thorough investigation.

# Immediate financial protection Separate updates around the incident noted that Bitget has a protection fund, established in 2022, which the company says helped absorb financial impact. That fund was later reported as reaching $309 million as part of recovery and resumption of operations.

# What to watch next The most important near-term indicators will be how much additional value can be frozen on-chain, whether any of those frozen sums can be traced to recoverable reserves, results of the internal and external investigation into attacker identity and attack vector, and how many user balances the protection fund ultimately covers.

# Bottom line Bitget has taken multiple technical and operational steps—accounting updates, staged withdrawal restarts, cooperation with stablecoin issuers, bounty offers, and use of a protection fund—but the CEO warned that precedent suggests most stolen assets may not be recoverable. Outcomes will depend on ongoing tracing and law enforcement or counterparty actions.

More context around this story.

Loading more related stories...

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app