User account balances, the company says, were not touched. That sentence is doing a lot of work. It is meant to calm the people who woke up checking whether their bitcoin was still there. It also draws a hard line between customer coins and the pot of money the platform keeps for exactly this kind of disaster. The protection fund took the hit. Then the company put its own capital back in. Whether that sequence feels reassuring or merely tidy depends on how closely you have followed earlier exchange failures. I lean toward cautious. History has a habit of being stingy with stolen crypto.
What Actually Left The Building
The headline figure is close to $388 million. Frozen assets, as of the latest public comments, sit near $1.1 million. Frozen is not the same as returned. Chen said as much in an email interview, and she did not disclose how much, if any, had actually come back. That distinction matters more than the press language usually admits. A freeze is a pause. A recovery is a deposit. Between those two words sits a long chain of exchanges, mixers, bridges, and counterparties who may or may not cooperate.
Speaking earlier in the week, Chen pointed to the thin recovery record from previous cryptocurrency exchange hacks. She is not inventing a mood. Anyone who has watched these episodes unfold knows the pattern. The first forty-eight hours produce wallet labels and hopeful tweets. The next week produces a forensic report. The months after that produce a quiet acceptance that most of the coins are gone, scattered, or sitting in places no court can reach. Perhaps the most interesting aspect this time is that the chief executive said the quiet part early, instead of promising a clawback that the trail cannot support.
Exchanges have a responsibility to demonstrate how they protect users, particularly when something goes wrong.
Gracy Chen, Bitget chief executive
That line is fair. It is also a standard the industry has failed often enough that it now sounds like a pledge rather than a description. Demonstration, in this case, has taken a specific shape: refill the protection fund from company reserves, publish a fresh proof of reserves, and keep withdrawals moving back online in stages. None of that retrieves the stolen coins. All of it tries to show that customers are not the ones holding the bag.
A Protection Fund That Had To Be Rebuilt
Before the theft, Bitget valued its protection fund at more than $464 million. After the hack, outside calculations based on the fund’s disclosed wallet addresses put it below $200 million. Chen says the company then restored it to more than $300 million using its own capital. The refilled fund, she added, remains publicly verifiable on-chain and sits apart from the reserves that back customer balances.
I have found that people hear “protection fund” and picture an insurance policy with a claims desk. It is closer to a company-owned reserve that can be spent when something breaks. Useful, yes. Contractual in the way a regulated bank deposit scheme is contractual, no. The refill is still the cleanest signal the firm has sent. “The financial impact is being absorbed by Bitget rather than passed on to our users,” Chen said. If that holds, customers avoid the worst version of this story, which is a socialized loss dressed up as a temporary pause.
There is a second reading, and it is less comforting. A fund that can drop by more than half in a single incident is a fund that was sized for a bad week, not for a structural failure of the tools around the wallets. Restoring it to $300 million is responsible. It is not the same as having $464 million again. The gap is real money. It is also a reminder that self-insurance has a ceiling, and that ceiling just got tested.
| Item | Reported figure | What it actually means |
| Stolen amount | Nearly $388 million | Assets taken from production wallet systems |
| Frozen so far | About $1.1 million | Paused somewhere, not confirmed returned |
| Fund before the hack | More than $464 million | Company protection reserve, not customer balances |
| Fund after the drawdown | Below $200 million | Outside estimate from disclosed wallets |
| Fund after refill | More than $300 million | Restored with Bitget’s own capital |
| Reserve ratio | 131 percent overall | Self-reported Sept. 29 snapshot, 19 assets |
Read that table slowly. The frozen line is the one that should bother you. Everything else is the company describing how it paid for the hole. Only the frozen line is about getting the money back, and it is tiny.
Proof Of Reserves, With The Usual Asterisk
Bitget’s latest proof of reserves, based on a Sept. 29 snapshot, showed a self-reported overall reserve ratio of 131 percent. All 19 covered assets were backed above 100 percent. On paper, that is the sentence customers wanted. In practice, a proof of reserves is a snapshot plus a method. It is not a live audit of every operational wallet, and it is not a promise about vendors sitting outside the snapshot.
Still, the timing is not nothing. Publishing a ratio above full backing days after a nine-figure loss is an attempt to separate two piles of money in the public mind: customer reserves on one side, the protection fund on the other. Chen was explicit that the refilled fund is separate from the reserves backing balances. If you only remember one structural claim from this episode, remember that one. The hack, as described, hit the systems around production wallets and was absorbed by the protection reserve, not by a silent haircut on user accounts.
How The Attackers Got In
Investigation reports released Sept. 30 by Mandiant, part of Google Cloud, and by the blockchain security firm SlowMist describe a path that did not start with a stolen seed phrase. The attackers compromised two third-party security products, then reached Bitget’s production wallet systems. SlowMist traced the earliest malicious activity in available logs to Aug. 31. A previously unknown flaw, a zero-day, was exploited in one of those products. From there the intruders obtained privileged internal access and bypassed the normal customer-facing withdrawal process. Mandiant reported that private keys were not stolen.
That last detail changes the mental picture. This was not someone walking off with a hardware wallet from an office drawer. It was someone already inside the tooling that is supposed to watch the door, then using that position to move funds without tripping the customer withdrawal rail. Chen called the method quite sophisticated. She also said the attackers deleted traces after the transfers, which is exactly what you do when you expect a forensic team to arrive on Monday.
Neither report named the affected security products. Asked to go further, Chen declined, citing the risk of creating new problems by publishing more than the findings already released. I get the instinct. Naming a vendor while the flaw may still be live elsewhere is how you turn one breach into a map for the next crew. It also leaves customers and rival platforms guessing which tool to distrust. That tension is not going away. Security disclosure and operational safety pull in opposite directions for a few uncomfortable weeks, sometimes longer.
- Two third-party security products were compromised before production wallet access.
- Earliest logged malicious activity dates to Aug. 31, via a zero-day in one product.
- Privileged internal access let attackers skip the normal withdrawal path.
- Private keys were not stolen, according to the Mandiant account.
- Traces were deleted after transfers, slowing the reconstruction.
- The vendors and product names remain unpublished.
If you work anywhere near operations, that list should feel familiar in a grim way. The expensive part of a modern stack is rarely the vault. It is the cluster of tools you rent so the vault can be monitored, approved, logged, and patched. Compromise those, and the vault’s marketing copy stops mattering.
The North Korea Question, Still Open
The reports did not attribute the attack to North Korea. Chen had previously said preliminary technical indicators were highly consistent with known North Korean hacking groups. Pressed later, she stepped back to a waiting posture. Further detail would have to come later. That is the honest version of attribution. Early indicators are clues. They are not a verdict.
State-linked crypto theft has a long rap sheet, and the methods rhyme often enough that analysts reach for the same names. Rhyming is not proof. In my experience, the platforms that rush a country label in week one spend month three quietly editing the sentence. Better to say the indicators point one way and the paperwork does not yet close the case. Users do not need a geopolitical headline to decide whether their withdrawal is live. They need the operational facts, which are already ugly enough.
Withdrawals Coming Back In Stages
Withdrawals for bitcoin, ether, and USDT have resumed. Bitget scheduled the remaining cryptocurrencies, along with fiat and peer-to-peer services, to come back on Friday. Staged reopening is the standard move after a wallet incident. You restore the deepest, most liquid rails first, watch them, then widen the gate. It is tedious. It is also how you avoid discovering a second hole while the first one is still being mapped.
A Friday restart for the long tail of assets is not a trophy. It is a calendar. If those rails open cleanly, the immediate customer crisis shrinks to a trust problem rather than a liquidity problem. If they do not, the protection-fund story has to carry even more weight. Either way, the stolen coins are a separate plot. Reopening the cashier does not restock what left through the back.
Why Recovery Usually Stays Small
Chen’s low expectations are not a shrug. They are a reading of the scoreboard. Large exchange thefts tend to split into a few buckets within hours. Some coins hit an address a compliant venue will freeze if law enforcement or the victim asks in time. Some coins cross a bridge into a chain with thinner cooperation. Some sit in mixers or are peeled into dozens of hops until the label “stolen” is a research note rather than a block on a withdrawal screen. The $1.1 million freeze fits the first bucket. The other $386 million-plus is, for now, everything else.
Could more get frozen next week? Yes. Blockchain trails do not expire just because a chief executive sounds pessimistic. Cooperation from other venues, stablecoin issuers, and bridge operators can still lock slices that look obvious in hindsight. The base rate, though, is harsh. Once funds leave the first hop and the operators start deleting logs, the recoverable share often collapses toward the single digits, then toward zero. Expecting “not a lot” is the adult forecast. Promising a full make-whole from the chain itself would be marketing.
A freeze is a traffic light. A recovery is the car actually coming back. Most of these stories end with the light stuck on red.
That is my line, not hers, but it matches what she described. The company can refill a fund. It cannot subpoena a wallet in a jurisdiction that does not answer. The gap between those two powers is where nine-figure hacks go to stay nine-figure hacks.
Vendor Risk Is The Real Plot
The part I cannot stop turning over is the vendor layer. Two outside security products. A zero-day in one of them. Privileged access after that. No stolen private keys. If you squint, this is a supply-chain story wearing a crypto costume. The same shape shows up in software breaches that have nothing to do with tokens: trust a tool, grant it deep rights, discover the tool was the door.
Exchanges love to talk about cold storage percentages and multi-party approval. Those controls are real, and they stop a certain class of theft. They do less when the monitoring and approval products themselves are the compromised surface. A policy that says three people must sign is weaker if the system collecting those signatures can be steered by someone who already owns the console. That is the uncomfortable lesson sitting inside the Sept. 30 reports.
Chen’s refusal to name the products is defensible and frustrating at the same time. Defensible, because a live flaw plus a brand name is an invitation. Frustrating, because every other platform using similar tooling is now doing quiet archaeology on its own vendor list. I would rather the industry circulate a confidential indicator list to peers within days than wait for a polished public post that names nothing. Public silence and private warning can coexist. Whether they did here is not something outsiders can check.
What Customers Should Actually Watch
If you hold funds on the platform, the useful checklist is narrower than the rumor mill. Balances were said to be unaffected. The protection fund was refilled from company capital and described as on-chain verifiable. Major withdrawals are back. The rest were due Friday. Attribution is unfinished. Recovery expectations are low. That is the whole operational picture, stripped of adjectives.
- Confirm your own balances against the last statement you trust, not against a screenshot in a chat.
- Treat the protection fund as a company reserve, not as a personal insurance contract.
- Watch whether Friday’s remaining rails actually open, and whether they stay open.
- Do not confuse a frozen wallet somewhere else with money already back in the fund.
- Assume vendor names will stay private until the flaw is no longer a live map.
None of those steps requires you to pick a side in the attribution debate. They require you to separate customer money, company insurance money, and stolen money. The firm is trying to keep the first pile intact by spending the second. The third pile is mostly gone, unless later freezes surprise everyone, including the chief executive.
A Note On Self-Reported Strength
The 131 percent reserve ratio is the number the company wants quoted. Fine. Quote it, and quote the method beside it. Self-reported. Snapshot dated Sept. 29. Nineteen assets, each above full backing on that snapshot. A ratio like that can be true and still fail to describe operational risk in the tools wrapped around the wallets. Reserves answer the question “are the liabilities covered right now?” They do not answer “can an outsider steer a security product and move coins before the snapshot notices?”
I have found that retail readers treat a reserve ratio like a credit score. Higher feels safer, full stop. It is closer to a bank’s capital ratio on a single afternoon. Useful. Incomplete. The hack did not falsify the Sept. 29 figure. It showed a failure mode that a reserve ratio is not designed to catch. Holding both ideas at once is the whole job.
Simple split after this incident: Customer balances — described as untouched Protection fund — drawn down, then refilled above $300 million Stolen coins — nearly $388 million, about $1.1 million frozen Recovery stance — not expecting a lot back
Pin that split somewhere. Most of the confused commentary this week mixed those four lines into one mood. They are four different claims. Only the last one is a forecast, and it is a gloomy one.
The Cost Of Looking Sophisticated
“The method, I would say, is quite sophisticated,” Chen said, and then noted the log deletion. Sophistication here is not a compliment. It is a way of saying the usual user-phishing story does not fit. No customer clicked a bad link and drained a personal wallet. The path ran through products the exchange itself relied on, then through internal privilege, then out. That is a higher bar, and it is also a worse headline for every platform that outsources a piece of wallet security.
There is a temptation, after a breach like this, to demand that every exchange build every tool in-house. That demand ignores why vendors exist. Specialist monitoring, signing workflows, and device attestation are hard to do well, and a mid-size platform will often buy them. The grown-up version of the lesson is narrower. Deep privileges need tighter vendor review, shorter token lifetimes, and a kill switch that does not live inside the same product you are trying to kill. Whether Bitget had those layers, and whether they failed or were never switched on, is inside the reports only in outline.
Deleting traces after the transfer is the detail that should end any remaining fantasy of a quick full recovery. Investigators can still follow coins on a public ledger. They cannot always follow the hands once the internal logs are gone. On-chain visibility and off-chain blindness are a miserable pair. You can see the money move and still not see who steered it.
How This Sits Next To Older Exchange Losses
Chen invoked the limited recovery from earlier exchange hacks without turning the interview into a history lecture. She did not need to. The pattern is public enough. Some incidents end with a partial freeze because a stablecoin issuer blacklists an address or a large venue catches a deposit. Some end with a law-enforcement seizure years later, long after users have moved on. Very few end with the original platform quietly receiving anything close to the stolen sum. “Not expecting to recover a lot” is what it sounds like when someone has read that record and decided not to narrate a miracle.
Partial freezes still matter. $1.1 million is real money, even if it looks comic beside $388 million. It is also evidence that at least one counterparty listened. More listening could happen. It would be strange, though, to build a user communication plan around that hope. The plan they actually chose is the refill. Company capital in, fund back above $300 million, customer balances described as whole. That is a balance-sheet response to a blockchain problem. It can work. It does not scale forever if vendor breaches keep landing at this size.
What The Refill Does Not Prove
A company that can write a check to its own protection fund is a company with reserves beyond customer liabilities. Good. The refill does not prove the next incident will be smaller. It does not prove the unnamed products are patched everywhere they are installed. It does not prove attribution. It does not prove that Friday’s broader withdrawal restart will be boring, which is the only kind of restart anyone should want.
It does prove a choice. Bitget could have let the fund stay impaired and argued about coverage later. It moved its own capital instead, and it said so. I will take the explicit version. Ambiguity after a hack is how rumors start pricing in a haircut that may never come. Clarity about who eats the loss is worth more, this week, than another technical blog post about address clusters.
A Practical Reading For Anyone Still On The Platform
Stay concrete. If your balance matches what you expect, the company’s central claim is holding for you personally. If withdrawals in bitcoin, ether, or USDT are what you need, those rails were already back. If you need a smaller asset, fiat, or a peer-to-peer transfer, Friday was the scheduled day, and scheduled is not the same as completed. Check the status in the product, not in a recap article.
Then decide what the protection fund means for your own risk budget. A refilled reserve above $300 million is a cushion. It is not a reason to ignore concentration. One platform, one vendor stack, one bad August afternoon: that is the shape of this loss. Spreading assets is unglamorous. It is also the only control a customer fully owns once the keys sit with an exchange. I am not interested in scolding people who keep trading balances on a venue. I am interested in the difference between a trading balance and a life savings. This week argued for a wider gap between those two.
The Timeline, Compressed
Aug. 31 is the earliest malicious activity SlowMist could see in the logs it had. The public breach landed last week, with losses near $388 million. By the time Chen was speaking mid-week, about $1.1 million was frozen and the fund had been rebuilt past $300 million. Sept. 29 brought the proof-of-reserves snapshot. Sept. 30 brought the Mandiant and SlowMist write-ups. Withdrawals for the three major assets resumed, with the rest pointed at Friday. That is a fast public cycle for an incident this size. Fast is not the same as finished.
The deleted traces are why “finished” may never arrive in a satisfying way. Forensic teams can still publish indicators. They may never publish a name that sticks. Chen already walked from “highly consistent with” known North Korean groups to “we will have to wait.” Waiting is the correct posture when the logs are thin. It is also unsatisfying if you wanted a villain by the weekend.
Where I Land On The Whole Episode
The honest summary is short. A sophisticated path through two outside security products reached production wallet systems. Private keys stayed put. Coins did not. The protection fund absorbed the blow and was rebuilt with company money above $300 million, below its pre-hack level above $464 million. Customer balances were described as unaffected, with reserves self-reported at 131 percent on Sept. 29. Recovery hopes are deliberately low because about $1.1 million frozen is not a comeback story.
What I keep respecting, narrowly, is the refusal to pretend the chain will pay the firm back. Crypto platforms have spent years promising that transparency would make theft obsolete. Public ledgers help. They do not arrest anyone, and they do not reverse a well-run exit once the first hops are done. Saying you are not expecting much back is a kind of respect for the audience. The refill is the other half of that respect. If you cannot get the money, you can at least say whose capital replaces it.
The open questions are the ones that should keep risk teams elsewhere awake. Which products. Whether the zero-day is fully dead. Whether privileged access paths in similar stacks can be cut without waiting for a named advisory. Whether a protection fund north of $300 million is the new floor Bitget intends to hold, or a waypoint on the way back to the old figure. None of those answers were in the first round of statements. They are the answers that decide if this was a bad week or a template.
We restored the Fund using Bitget’s own capital. The financial impact is being absorbed by Bitget rather than passed on to our users.
Gracy Chen
Hold the company to that sentence. It is testable in a way most post-hack language is not. Either user balances stay whole and the fund remains the shock absorber, or the sentence ages badly. Given how little of the $388 million looks recoverable, that sentence is the actual product customers are buying this week. Not a miracle trace. A decision about who pays.
I do not expect the frozen figure to suddenly look proportional. I do expect more technical detail once naming the vendors is less like handing out a map. Until then, the story is already complete enough to use. Nearly $388 million left. About $1.1 million is stuck somewhere. The rest is a low-odds chase. The platform says it refilled the cushion and left customer balances alone. Believe the balances you can see. Treat the chase as a bonus, not a plan.
]]>