Live Prices
Markets

Bitget CEO Addresses $387.5M Exploit as Protection Fund Restored Above $300M

TheCryptoDesk Editorial · 2m read
Bitget CEO Addresses $387.5M Exploit as Protection Fund Restored Above $300M

Bitget CEO Gracy Chen has defended the cryptocurrency exchange's financial position following a $387.5 million exploit on September 24, confirming that the platform replenished its protection fund above $300 million and maintains more than $1 billion in external capital.

Solvency Reserves and Hack Investigation Details

The attack, which Chainalysis attributed to North Korean actors, manipulated Bitget's internal withdrawal processes to siphon funds. As of October 6, investigators have frozen approximately $1.07 million, representing about 0.28% of the stolen assets, while Bitget completed its phased reopening of customer withdrawals on October 2.

Despite the total loss surpassing the protection fund's previous balance, Chen confirmed that Bitget used Bitcoin from the fund to meet immediate redemptions before restoring it past the $300 million threshold. She stated that the exchange holds additional capital exceeding $1 billion, asserting: "I can't tell you the exact number, but it's for sure more than one billion." Chen added that Bitget could absorb another major incident of several hundred million dollars if necessary.

Security Response and Withdrawal Dynamics

Addressing how attackers acquired internal system knowledge, Chen explained that a preliminary audit found no insider involvement. "The preliminary investigation so far is telling us there's no internal sort of involvement," she stated, though she noted the exact entry point involved an unidentified vulnerability in a third-party security product.

To mitigate ongoing risks, Bitget isolated affected systems, reset internal credentials, disabled the vulnerable third-party feature, and introduced extra approval layers for withdrawals. The incident reflects broader industry challenges where threat actors target centralized platforms, echoing recent investigations into how criminals establish laundering networks for stolen exchange funds. Furthermore, an analysis by security firm Certora estimated that roughly $238 million left Bitget after the exchange initially attempted to block withdrawals.

  • Stolen Capital: Attackers took $387.5 million on September 24 via internal withdrawal manipulation.
  • Frozen Recovery: Only $1.07 million (0.28%) has been frozen by investigators so far.
  • Financial Backing: The protection fund was restored above $300 million alongside over $1 billion in external reserves.
  • Post-Block Outflows: Certora estimates $238 million was moved after initial withdrawal halts.

Why It Matters

The Bitget breach underscores the persistent vulnerability of centralized exchange withdrawal pipelines to targeted exploits by sophisticated state-sponsored groups. While Bitget's ability to self-fund the $387.5 million deficit prevents immediate solvency issues, the delayed response noted by Certora highlights structural gaps in emergency withdrawal freezes. Institutional and retail trust will depend on whether Bitget can transparently audit its third-party security vendors and prove that modified internal permissions can withstand real-time intrusion attempts.

Read next