Bitget 'not expecting to recover a lot' from $388 million hack, CEO tells CNBC
- ID
- 31048
- Status
- summarized
- Published
- 02 Oct 2026, 2:03 PM
- Fetched
- 02 Oct 2026, 2:19 PM
- Provider
- CNBC Technology
- Category
- technology
- Original URL
- https://www.cnbc.com/2026/10/02/bitget-crypto-stolen-hack-recovery.html
- Source URL
- https://www.cnbc.com/id/19854910/device/rss/rss.html
Summary
- Score
- 3.0
- Created
- 02 Oct 2026, 2:19 PM
- Tags
- Audience
- developerssaas_founders
What happened
Bitget CEO Gracy Chen told CNBC that only about $1.1 million of the roughly $388 million stolen in a cyberattack last week has been frozen, and that she is 'not expecting to recover a lot of funds' based on recovery rates from previous exchange hacks. Bitget has refilled its Protection Fund to $300 million from its own reserves to cover losses, and Chen declined to name the third-party vendors that were breached, citing security risk.
Why it matters
The recovery number is the useful one: ~$1.1M frozen out of ~$388M, and frozen does not mean returned — so roughly 0.3% at best, with the shortfall absorbed by Bitget's own reserves rather than recovered. If you or your users keep funds on a centralised exchange, that ratio is the realistic planning assumption, not the $300M Protection Fund headline. The undisclosed third-party vendor breach is the second takeaway: you cannot check your own exposure against a named vendor, so any dependency on exchange or custody vendors has to be treated as unverified until Bitget says who was hit.
Discussion angle
If a breach comes through a third-party vendor and the vendor name stays undisclosed, what does that do to how you assess supply-chain risk in your own stack — and would you accept 'security risk' as a reason for non-disclosure from a vendor you depend on?