CEO Puts a Grim Benchmark on Recovery Prospects

The head of crypto exchange Bitget has publicly signaled that the platform may never recoup the full $388 million in digital assets drained in a security breach that struck the exchange last Thursday. Speaking on Cointelegraph's Chain Reaction podcast, released Tuesday, CEO Gracy Chen drew a direct parallel to the February 2025 hack of rival exchange Bybit, describing it as a "good reference point" for understanding what Bitget's users can realistically expect.

In that earlier incident, attackers siphoned roughly $1.5 billion worth of Ether (ETH) from Bybit's hot wallets. Bybit, however, managed to freeze and recover a combined $80 million — a figure Chen used to underscore the slim odds of a full payout to affected customers.

"I'm actually not very optimistic because after a year or so of Bybit's hack, they've only [been able to freeze] about 3.5% of the total stolen funds," Chen said. "That's only the freezing. It's not about recovery yet."

For traders and depositors who held balances on Bitget at the time of the breach, Chen's remarks serve as a stark warning: even if stolen assets are eventually identified and frozen, the actual return of those funds to user accounts remains a separate and more uncertain process.

Bounty Program and Third-Party Efforts to Freeze Stolen Assets

In the immediate aftermath of the attack, Bitget activated a bounty scheme designed to incentivize blockchain analysts and law-enforcement partners to track the illicit flows. The program offers 5% of the value of frozen funds and an additional 5% for funds that are ultimately recovered.

Early results have been modest but noteworthy. The team behind NEAR Intents disclosed on Monday that it had blocked more than $50 million in assets linked to the exploit and frozen approximately $500,000. Separately, Chen confirmed that stablecoin issuers Tether and Circle had blacklisted a wallet associated with the attack, locking up $318,013 across USDT and USDC balances.

While these steps demonstrate that the stolen assets are not yet fully laundered, the overall picture — set against the Bybit precedent — suggests that the majority of the $388 million may remain beyond the exchange's reach for the foreseeable future.

Context: One of 2026's Largest Crypto Security Incidents

Bitget's breach ranks among the most significant attacks on the cryptocurrency industry in 2026, following a $320 million exploit of the Liquid Network back in September. It also joins a troubling roster of prior mega-hacks, including Bybit's 2025 incident, the $615 million Ronin Bridge breach in 2022, and the $611 million Poly Network attack in 2021.

The scale of the loss itself was revised upward after the initial disclosure. Bitget first reported that $352 million in digital assets had been drained during the Thursday attack and immediately suspended all withdrawals. Chen later issued an updated incident report reflecting what she called a "more complete accounting of transfers," raising the confirmed loss to approximately $388 million.

For users still holding funds on the platform, the staged resumption of withdrawals — Bitcoin (BTC) transactions reopened on Monday, followed by ETH on Tuesday — signals that the exchange is attempting to restore normal operations. However, the gap between the initial and revised loss figures underscores how quickly the full scope of a breach can expand, a point traders should keep in mind when assessing exposure on any single venue.

Suspected Perpetrators and the Inside-Job Question

Chen also addressed the identity of the attackers. In the hours following the breach, she indicated that North Korea could be responsible, citing "IP addresses that match the VPN choices by a certain [Democratic People's Republic of Korea] group." However, she stopped short of a definitive attribution and noted that Bitget had not "totally ruled out" the possibility that an insider facilitated the theft.

From a scam-alerts perspective, the ambiguity around the attacker's identity carries practical implications for affected users. If a state-sponsored group is confirmed, the likelihood of coordinated international law-enforcement action — and eventual fund recovery — improves somewhat. Conversely, if an inside job is confirmed, the breach may point to deeper structural weaknesses in the exchange's internal access controls, raising questions about whether a repeat incident could occur even after the immediate technical fixes are applied.

What Traders Should Watch Now

  • Bounty-program updates: Monitor Bitget's official channels for any announcements about additional frozen or recovered assets tied to the 5% bounty tiers.
  • Stablecoin issuer actions: Tether and Circle's wallet blacklisting is a starting point; further freezes could follow as the stolen USDT and USDC flow through de-mixing services.
  • Attribution developments: The North Korea hypothesis, if corroborated by other intelligence sources, could trigger sanctions-related asset freezes that benefit victims.
  • Exchange risk diversification: The Bybit comparison — 3.5% frozen after roughly a year — should temper expectations and reinforce the value of spreading holdings across multiple custodians rather than concentrating balances on a single exchange.

Chen's candid assessment, delivered on a public podcast, is rare in an industry where executives often project confidence. For Bitget's users, her words amount to a clear risk disclosure: the $388 million may be gone, and the window for meaningful recovery is already narrowing.