Bitget CEO Gracy Chen has signaled low expectations for recovering the $387.5 million lost in a September 24 security breach, drawing parallels to the February 2025 Bybit hack where recovery efforts yielded minimal results. The incident involved unauthorized transfers from hot and warm wallets via a vulnerability in a third-party security vendor’s backend system, though cold wallets remained secure. Investigators have linked suspicious activities to North Korean entities, while Bitget’s User Protection Fund absorbed the full loss, keeping customer balances intact and reserve ratios above 100%.
Following the breach, Bitget temporarily paused withdrawals before resuming them in phases and committed to replenishing its protection fund to over $300 million within a week. The exchange launched a bounty program offering 5% rewards for freezing or recovering assets and engaged forensic firms and law enforcement. Chen’s stance highlights the persistent industry challenge of supply chain vulnerabilities, as the attack exploited external dependencies rather than Bitget’s core infrastructure.
The explicit skepticism from Bitget’s leadership regarding fund recovery underscores a harsh reality in crypto security: once sophisticated attackers move assets through complex blockchain networks, retrieval becomes statistically improbable. This admission shifts the narrative from potential restitution to accepting permanent capital destruction, forcing exchanges to rely entirely on pre-existing insurance mechanisms like user protection funds rather than post-incident recovery operations. It also highlights the limitations of current investigative capabilities against state-linked actors who utilize advanced obfuscation techniques.
From an operational risk perspective, this incident serves as a critical warning about third-party dependencies. While Bitget’s robust reserves mitigated immediate customer impact, the breach originated outside its direct control, exposing a systemic blind spot in how exchanges vet and monitor external security vendors. As institutional adoption grows, regulators and partners will likely scrutinize these supply chain controls more intensely, demanding stricter accountability for outsourced infrastructure components that can compromise even well-capitalized platforms.


