Ten days after hackers drained roughly $388 million from Bitget, the exchange has managed to freeze about $1.1 million of the stolen funds — close to 0.3 percent of the total — and CEO Gracy Chen says the exchange is "not expecting to recover a lot" of the rest.

"We will have to wait further for further details on this," Chen told CNBC in an interview published October 2, adding that approximately $1.1 million had been frozen with the help of issuers and protocols. Blockchain-analysis firm Chainalysis-linked figures put the frozen share at about 0.2 percent of the haul, as reported by Crypto Briefing.

The September 24 breach, the largest single crypto theft of 2026, saw attackers insert fraudulent withdrawal commands into backend systems governing the exchange's wallets, according to reporting on the incident. Bitget has since rebuilt its Protection Fund to about $309 million and opened a bounty program paying 5 percent of any funds white hats help freeze and another 5 percent of anything they help recover, as reported by 24/7 Wall St.

Attribution: one firm says North Korea, two stay silent

The attribution picture has split. Reports citing Chainalysis say the firm has linked most of the stolen XRP to actors tied to North Korea, a finding that would push DPRK-attributed crypto theft in 2026 past $1 billion, as reported by Crypto Briefing and others.

But the incident-response reports that examined the breach directly have not followed. According to CNBC, the Mandiant and SlowMist reports on the Bitget attack did not attribute it to any actor. Chen herself has pointed only to IP addresses and VPN infrastructure resembling known North Korean operational patterns, stopping short of a definitive call — language echoed in follow-up reporting that described attribution as still being firmed up.

The context explains the caution. Two of the year's other mega-thefts — $285 million from Drift Protocol on April 1 and $292 million from a KelpDAO bridge on April 18 — were tied by TRM Labs and LayerZero to TraderTraitor, a Lazarus-affiliated unit, together accounting for 76 percent of hack losses through April. If the Bitget attribution holds, it would place the year's three largest thefts in the same cluster. For now, North Korean involvement in Bitget remains suspected, not confirmed.

The laundering trail

The stolen XRP has been converted to Bitcoin without passing through centralized exchanges, according to analysis of the on-chain flows, with portions routed through cross-chain venues including THORChain — which processed tens of millions in stolen assets and declined Bitget's requests to block the addresses.

One screening layer did act. NEAR Intents said its SHIELD risk system rejected more than $50 million in wallet-linked swap attempts after the theft and froze roughly $503,000 mid-execution — before losing $3.8 million to an unrelated bug in its own infrastructure two days ago. That attacker returned the funds in full on October 2.

The gap between a 0.3 percent freeze rate and a 99.7 percent float is the practical lesson of the incident so far. Once stolen assets reach permissionless cross-chain liquidity, exchange bounty programs and issuer freezes recover crumbs; the deterrent that matters is upstream — key custody, withdrawal controls, and the speed of the first hours after detection.

TrustGrade tracks the security posture of platforms and protocols in digital assets. Verified trust data: trustgrade.ai.