Quick Take
  • Attackers stole approximately $387.5 million from Bitget on September 24 by manipulating its internal withdrawal process.
  • According to Chainalysis, the attack was carried out by North Korean hackers.
  • And what security measures are the exchange taking?
  • BeInCrypto sat down with the exchange’s CEO, Gracy Chen, to answer these questions.

What Happened

Attackers stole approximately $387.5 million from Bitget on September 24 by manipulating its internal withdrawal process. According to Chainalysis, the attack was carried out by North Korean hackers.

So, is Bitget now safe to use? What if the next hack is bigger? And what security measures are the exchange taking? BeInCrypto sat down with the exchange’s CEO, Gracy Chen, to answer these questions.

Latest Updates on the Bitget Hack

As of October 6, the exchange has reopened withdrawals, while investigators continue tracing the stolen funds:

Investigation: The affected third-party security vendors remain unnamed publicly.

If another hack exceeded the protection fund, could Bitget cover it?

What has the hack cost Bitget in customers and business?

Chen said a preliminary internal investigation found no insider involvement. But she could not explain how the attackers acquired their knowledge of Bitget’s systems.

She said the investigation remained ongoing and could take longer than Bybit’s because the Bitget incident involved a more complicated set of systems.

Market Context

She said the company also held more than $1 billion in capital outside the fund.

Asked about another loss of several hundred million dollars, she said Bitget could absorb it. The interview did not establish how much of that capital was immediately available.

She provided no figures showing the scale of those deposits or how much withdrawn capital had returned.

Why It Matters

Chen described the impact on daily operations and profitability as limited.

Details

Withdrawals: Bitget says its phased reopening finished on October 2.

Frozen funds: Its tracker lists approximately $1.07 million frozen, about 0.28% of the loss. The amount actually returned remains undisclosed.

Attribution: Chainalysis now attributes the theft to North Korean actors.

In an exclusive BeInCrypto interview recorded before withdrawals fully resumed, CEO Gracy Chen defended Bitget’s financial position. She also acknowledged gaps in its understanding of the attack.

Chen said Bitget had replenished its protection fund above $300 million after using bitcoin from it to meet withdrawals. She considered that threshold sufficient for now, despite the latest theft exceeding it.

“I can’t tell you the exact number, but it’s for sure more than one billion.”

A couple of institutional clients withdrew large sums when Bitcoin withdrawals reopened, she said, but customers had since begun returning.

“Just within the last few days, many of them came back already.”

An hour after Ethereum withdrawals reopened, inflows exceeded outflows, according to Chen. She also described strong inflows when USDT withdrawals resumed.

How did attackers learn enough about Bitget to build a dedicated withdrawal tool?

“I actually don’t know. I wish I can ask them and get an answer there.”