Bitget CEO Gracy Chen stated she is not optimistic about freezing or recovering the $388 million in cryptocurrency stolen from the exchange during a breach late last week. In an interview published Tuesday, Chen referenced the February 2025 Bybit hack, where attackers stole approximately $1.5 billion in Ether; since then, Bybit has frozen and recovered only about $80 million, representing roughly 3.5% of the total stolen funds. Chen emphasized that freezing assets does not equate to full recovery.
The initial loss was reported at $352 million but was revised upward to $388 million following a more complete accounting of transfers. Bitget suspended withdrawals immediately after the Thursday attack and has resumed them in stages, starting with Bitcoin on Monday and Ether on Tuesday. To incentivize assistance, Chen announced a Recovery Bounty Program offering 5% of frozen attacker funds and 5% of recovered funds to exchanges, security researchers, and onchain investigators who contribute. Additionally, Tether and Circle blacklisted a wallet tied to the exploit, freezing $318,013 in USDT and USDC. The NEAR Intents team reported blocking over $50 million in assets linked to the attack, though blocked assets are distinct from frozen or returned funds.
This development highlights the persistent structural challenges in cryptocurrency asset recovery following large-scale exploits. The comparison to Bybit’s experience underscores that even with significant resources and cooperation from stablecoin issuers like Tether and Circle, the majority of stolen funds often remain inaccessible. The distinction between blocking transactions, freezing assets, and actual recovery remains critical for market participants assessing the true impact of such breaches.
From an institutional adoption perspective, the preliminary attribution to a DPRK-linked group based on IP address patterns introduces geopolitical complexity into what is otherwise a technical security failure. While Chen noted that an inside job was preliminarily ruled out, the uncertainty surrounding the perpetrator complicates legal recourse and insurance claims. The implementation of bounty programs and trace explorers represents a shift toward decentralized investigative efforts, yet the low historical recovery rates suggest that prevention and robust custody infrastructure remain more effective strategies than post-incident recovery.


