Bitget successfully rebuilt its Protection Fund to $309 million following a September 24, 2026, security breach that resulted in the theft of approximately $388 million in customer funds. The stolen assets included Bitcoin, Ethereum, USDT, and other cryptocurrencies. CEO Gracy Chen confirmed that attackers exploited vulnerabilities in acquired third-party software and internal login credentials to drain hot and warm wallets, while cold storage remained secure. Bitget utilized the fund to compensate users without passing losses to customers.
Withdrawals were temporarily frozen but resumed sequentially: Bitcoin on September 28, Ethereum on September 29, USDT on September 30, and remaining assets on October 2. Proof of reserves released on September 29 indicated 131% overall coverage, with 142% for Bitcoin and 110% for Ethereum. Although the fund was restored to $309 million by September 30, it remains significantly lower than its pre-hack level of approximately $464 million. The incident occurred just 18 days after a separate $320 million exploit on the Liquid Network.
The restoration of Bitget’s Protection Fund demonstrates the critical role of discretionary capital buffers in maintaining user confidence during high-value exchange breaches. By absorbing the loss internally rather than socializing it among customers, Bitget preserved operational continuity and trust. However, the fact that the fund is governed by internal policy rather than regulatory mandate highlights the inherent fragility of centralized custody models. Users are protected only as long as the exchange chooses to maintain sufficient reserves, creating a dependency on corporate solvency and transparency that extends beyond technical security measures.
From an institutional adoption perspective, this event underscores the limitations of current recovery mechanisms in decentralized finance infrastructure. While NEAR Intents and stablecoin issuers froze small fractions of the stolen assets, privacy tools like Zcash’s Ironwood shielded pool effectively obscured the majority of the illicit flows. This asymmetry between attack sophistication and defensive capability suggests that exchanges must prioritize robust proof-of-reserves audits and transparent communication protocols. Future risk mitigation will likely depend less on reactive fund rebuilding and more on proactive verification of asset backing and clearer delineation of liability in custody agreements.


