Home Latest Insights | News Bitget Recovers Little After $388 Million Crypto Hack as Attack Exposes Third-Party Security Risk

Bitget Recovers Little After $388 Million Crypto Hack as Attack Exposes Third-Party Security Risk

Bitget Recovers Little After $388 Million Crypto Hack as Attack Exposes Third-Party Security Risk

Bitget has frozen about $1.1 million of the nearly $388 million in cryptocurrency stolen during last week’s cyberattack, but the exchange’s chief executive said the amount ultimately recovered is likely to remain limited as investigators trace the funds across the crypto ecosystem.

Gracy Chen, Bitget’s CEO, told CNBC that frozen assets had not necessarily been returned to the exchange and declined to disclose how much of the stolen cryptocurrency had actually been recovered.

The limited recovery outlook highlights the difficulty of retrieving digital assets once they have moved through a network of wallets and exchanges. Speaking on CNBC’s “Squawk Box Europe” on Wednesday, Chen said she was “not expecting to recover a lot of funds,” pointing to the historically limited recovery rates following major cryptocurrency exchange hacks.

But she said the incident also placed a responsibility on exchanges to demonstrate that they can protect customers and respond effectively when security failures occur.

“Exchanges have a responsibility to demonstrate how they protect users, particularly when something goes wrong,” Chen said.

Bitget has maintained that customer account balances were not affected by the attack. The exchange has instead committed its own capital to rebuilding a protection fund that was sharply depleted during the incident.

The scale of the theft initially made the incident one of the more significant recent attacks on a cryptocurrency trading platform, but subsequent investigations have revealed a more complicated attack path than a conventional theft of private keys. Investigation reports published on September 30 by Mandiant, part of Google Cloud, and blockchain security firm SlowMist concluded that attackers compromised two third-party security products before obtaining access to Bitget’s production wallet systems.

SlowMist traced the earliest malicious activity identified in the available logs to August 31, when the attackers exploited a previously unknown, or zero-day, vulnerability in one of the products.

Mandiant said the attackers subsequently obtained privileged internal access and were able to bypass Bitget’s normal customer-facing withdrawal process without stealing private keys. The incident did not depend on obtaining customers’ private keys and then authorizing conventional withdrawals. Instead, the attackers reportedly used compromised infrastructure and privileged access to manipulate the exchange’s production wallet environment.

“The method, I would say, is quite sophisticated,” Chen said.

She added that the attackers deleted traces of their activity after transferring the funds, complicating the investigation and the effort to follow the stolen assets.

Neither Mandiant nor SlowMist identified the affected security products in their public reports. Chen also declined to identify the vendors or products, saying that releasing information beyond the published findings could create additional security risks.

However, the incident illustrates a broader problem facing cryptocurrency exchanges as their security architecture becomes increasingly dependent on external software and infrastructure. A vulnerability in a third-party component can potentially provide attackers with a route into systems that otherwise have controls designed to prevent unauthorized withdrawals.

That creates a security challenge for exchanges that extends beyond safeguarding private keys and customer accounts. Vendor access, privileged credentials, monitoring systems, and production infrastructure can all become potential attack surfaces.

Bitget Rebuilds Protection Fund With Its Own Capital

Bitget’s response has also focused on reassuring customers that the financial consequences of the theft will not be transferred to account holders. Before the attack, Bitget valued its protection fund at more than $464 million. The fund fell below $200 million following the theft, according to Bloomberg’s calculation based on the wallet addresses Bitget has disclosed publicly.

The exchange subsequently rebuilt the fund to more than $300 million.

“We restored the Fund using Bitget’s own capital,” Chen said. “The financial impact is being absorbed by Bitget rather than passed on to our users.”

Chen said the replenished fund remains publicly verifiable on-chain and is separate from the reserves supporting customer balances.

Bitget’s latest Proof of Reserves, based on a September 29 snapshot, reported an overall reserve ratio of 131%, with all 19 covered assets showing reserves above 100%. The figures are self-reported by the exchange, meaning they provide an indication of the assets Bitget says it holds rather than independently resolving every question surrounding its financial position.

The distinction between the protection fund and customer reserves is important for users assessing whether the exchange can withstand the financial impact of the hack. Bitget’s stated approach is to use corporate capital to absorb the loss rather than draw directly from customer balances.

The investigation has also left unresolved questions about who carried out the attack.

The Mandiant and SlowMist reports did not attribute the incident to North Korea. Chen had previously said that preliminary technical indicators were highly consistent with known North Korean hacking groups, which have been linked to numerous cryptocurrency thefts.

Asked about the attribution after the new reports were released, Chen said the company would wait for more evidence.

“We will have to wait further for further details on this,” she told CNBC.

The uncertainty over attribution reflects the difficulty of identifying sophisticated crypto attackers, particularly when they deliberately erase traces and move stolen assets through multiple addresses.

Meanwhile, Bitget has begun restoring normal operations. Withdrawals of bitcoin, ether, and USDT have resumed, while withdrawals for the remaining cryptocurrencies, as well as fiat and peer-to-peer services, are scheduled to resume on Friday.

The immediate priority is shifting from containing the breach to rebuilding confidence. Bitget has restored much of its protection fund and says customer balances remain intact, but the relatively small amount of frozen funds compared with the nearly $388 million stolen illustrates the fundamental challenge facing the exchange.

No posts to display

Post Comment

Please enter your comment!
Please enter your name here