Cryptelio

Bitget CEO Gracy Chen Doubts Recovery of $387.5 Million Stolen in Hack

Cryptelio Editorial Published 30 Sep 2026 · 10:30 UTC Updated 30 Sep 2026 · 11:03 UTC
Bitget CEO Gracy Chen Doubts Recovery of $387.5 Million Stolen in Hack

Gracy Chen, CEO of Bitget, has voiced doubts regarding the recovery of $387.5 million stolen during a security breach on September 24. The incident involved attackers exploiting a vulnerability in a third-party security vendor's system, leading to unauthorized transfers from Bitget's hot and warm wallets.

The breach was detected around 18:31 UTC, with attackers executing 19 transactions across various blockchain networks. Although cold wallets remained secure, the breach raised concerns about the effectiveness of recovery efforts, especially in light of the Bybit hack in February 2025, which yielded disappointing results.

Bitget's User Protection Fund, which had over $464 million prior to the incident, absorbed the loss, ensuring customer account balances remained intact. Withdrawals were temporarily paused but have since resumed in phases. The exchange has committed to replenishing its User Protection Fund to over $300 million within a week.

In response to the breach, Bitget launched a bounty program offering rewards for freezing and recovering stolen assets. The exchange is collaborating with forensic firms and law enforcement to investigate the incident, which may be linked to North Korean entities.

This incident underscores the vulnerabilities that exchanges face, particularly those stemming from third-party dependencies. Despite having a reserve ratio above 100%, Bitget's experience highlights the ongoing risks in the crypto exchange landscape.

Updated 11:03 UTC

New Developments in the Bitget Hack

  • Approximately $3.8 million worth of Zcash (ZEC) stolen from Bitget has entered a shielded transaction pool, rendering it untraceable.
  • The breach, which occurred on September 24, 2026, is now considered the largest single crypto theft of the year, totaling $387.5 million.
  • XRP accounted for the largest portion of the stolen assets, valued at around $157 million, with other assets including ETH, USDT, USDC, ZEC, BNB, AVAX, and TRX.
  • The breach was traced back to a zero-day exploit in a third-party security product used by Bitget, allowing attackers to manipulate transaction data without accessing cold storage or private keys.
  • Bitget CEO Gracy Chen has linked the attack to North Korean actors based on behavioral patterns and IP addresses.
  • As of September 30, attackers had moved approximately 18,900 ZEC from the exploit, with $3.8 million already laundered through Zcash’s Ironwood shielded pool.
  • Bitget has suspended withdrawals but is gradually reinstating them, citing a User Protection Fund of over $464 million to cover customer losses.

FAQ

What was the amount stolen in the Bitget hack?

$387.5 million was stolen during the security breach on September 24.

How did the hack occur?

The attackers exploited a vulnerability in a third-party security vendor's system, leading to unauthorized transfers from Bitget's hot and warm wallets.

What measures has Bitget taken to protect its users after the hack?

Bitget's User Protection Fund absorbed the loss, ensuring customer account balances remained intact, and they have launched a bounty program to recover stolen assets.

Are withdrawals still paused following the hack?

Withdrawals were temporarily paused but have since resumed in phases.

What is Bitget doing to investigate the hack?

Bitget is collaborating with forensic firms and law enforcement to investigate the incident, which may be linked to North Korean entities.

Related

Comments

Comments are moderated before publish.

No comments yet — be the first.

Comment as guest

Captcha