Bitget has frozen approximately $1.1 million of the nearly $388 million stolen in the September 24 cyberattack — about 0.3% of the total — and its chief executive says she does not expect the bulk of it back.
CEO Gracy Chen told CNBC the exchange is "not expecting to recover a lot of funds," citing the limited recoveries achieved in past exchange hacks. She also cautioned that the frozen assets had not necessarily been returned to the exchange — freezing locks funds at counterparties, but converting a freeze into a restitution depends on legal process and cooperation across jurisdictions.
The recovery gap in context
The $1.1 million figure lands against a revised loss estimate of roughly $387.5 million, after investigators widened the initial $351.6 million count by tracing attacker addresses across eleven blockchains including Ethereum, XRP Ledger, Zcash, TRON, Arbitrum, Optimism, Base, BNB Smart Chain, Avalanche, Algorand and Celestia, as The Hacker News reported.
The root cause, per Bitget's own analysis, was a zero-day vulnerability in third-party security software: attackers used it to obtain high-level internal credentials and issue forged withdrawal commands that bypassed existing risk controls. The vendor has been notified and the affected functionality disabled pending a fix.
The pattern mirrors other mega-hacks: once stolen funds fragment across chains and mixers, industry recovery rates typically fall to single-digit percentages. Bybit recovered a minority of its $1.5 billion February 2025 theft; most large exchange breaches resolve with the exchange absorbing the loss rather than retrieving the funds.
Operations restored, balance sheet hit taken
Bitget completed the final phase of its withdrawal restoration on October 2 at 08:00 UTC, reopening remaining token withdrawals, fiat channels and P2P services on its published schedule, as crypto.news documented. The exchange says user balances were unaffected by the breach and that it replenished its investor protection fund with its own capital to cover the loss.
Quartz noted that the frozen $1.1 million figure underscores how quickly sophisticated attackers convert stolen assets into forms that resist seizure — a forensics reality that turns incidents of this size into balance-sheet events for the platform rather than retrieval operations.
For users, the incident is a live case study in what "protection fund" means in practice: Bitget can make customers whole precisely because it can absorb the loss internally, not because the stolen assets are coming back.
TrustGrade tracks the security posture of platforms and protocols in digital assets. Verified trust data: trustgrade.ai.