Bitget Cyberattack: Update on Asset Recovery Efforts
In the wake of a recent cyberattack that resulted in the theft of approximately $388 million from cryptocurrency exchange Bitget, the company has managed to freeze around $1.1 million of the stolen assets. This information was communicated by CEO Gracy Chen during an email interview with CNBC.
Efforts to Recover Stolen Funds
While a portion of the assets has been frozen, Chen noted that this does not guarantee the return of these funds to the exchange. Specific details regarding the total amount recovered remain undisclosed. During an appearance on CNBC’s “Squawk Box Europe,” Chen expressed cautious optimism, stating she was “not expecting to recover a lot of funds,” referencing historical recovery rates from previous exchange breaches.
Impact on User Accounts
Bitget reassured users that their account balances have not been affected by the incident. Prior to the theft, the exchange reported a protection fund exceeding $464 million. Following the attack, this fund dropped to below $200 million but has since been revitalized to over $300 million. Chen emphasized that the replenished fund is verifiable on-chain and is distinct from the reserves that secure customer balances.
Proof of Reserves and Financial Responsibility
Bitget’s latest Proof of Reserves, calculated from a snapshot taken on September 29, indicated an overall reserve ratio of 131%, with all 19 covered assets backed by over 100%. Chen remarked, “We restored the Fund using Bitget’s own capital,” asserting that the financial repercussions of the breach will be absorbed by the company rather than passed onto users.
Investigation Findings
According to investigation reports released on September 30 by Mandiant, part of Google Cloud, along with blockchain security firm SlowMist, the attack was initiated through vulnerabilities in two third-party security products. The earliest sign of malicious activity was traced back to August 31, exploiting a previously unknown vulnerability. These breaches allowed the attackers unauthorized access to Bitget’s production wallet systems, circumventing standard withdrawal processes.
Chen characterized the attack as “quite sophisticated,” noting that the perpetrators deleted evidence after the illicit fund transfers to obstruct the investigation. Neither investigatory report identified the security products that were breached, and Chen declined to provide further details to prevent additional security risks.
Current Status of Withdrawals
As of now, withdrawals for major cryptocurrencies such as bitcoin, ether, and USDT have resumed. Bitget plans to reactivate withdrawals for its remaining crypto offerings and fiat services by Friday.
For more information, visit CNBC.
