Bitget ‘not expecting to recover much’ from $388m hack: CEO

About $1.1 million of the nearly $388 million stolen from crypto exchange Bitget in a cyberattack last week has been frozen, as the platform continues its efforts to track and recover assets.

The frozen assets have yet to return to the exchange, CEO Gracy Chen told CNBC in an email interview. He did not say how many have recovered.

Speaking on CNBC’s “Squawk Box Europe” on Wednesday, Chen said he “doesn’t expect to get a lot of funding,” citing the limited recovery from previous cryptocurrency exchange hacks. However, “exchanges have a responsibility to demonstrate how to protect users, especially if something goes wrong,” he said.

Bitget said that user account balances were not affected.

The exchange was worth more than $464 million in protection funds before the theft. It was drawn down below $200 million after the hack, according to Bloomberg’s calculation of the fund’s wallet addresses, before being returned to more than $300 million. Chen said the replenished funds remain publicly verifiable and separate from the reserves that support customers’ balances.

Bitget’s latest Proof of Reserves, based on a September 29 snapshot, shows a self-reported overall reserve ratio of 131%, with all 19 guaranteed assets backed above 100%.

“We restored the Fund using Bitget’s own capital,” Chen said. “The financial impact is absorbed by Bitget rather than passed on to users.”

An investigative report released September 30 by Mandiant, part of Google Cloud, and blockchain security firm SlowMist found that attackers compromised two third-party security products before gaining access to Bitget’s production wallet system.

SlowMist tracks the earliest malicious activity in available logs up to August 31, when a previously unknown, or zero-day, vulnerability was exploited in one of its products.

An attacker can then gain privileged internal access and bypass the back-off process that a normal customer faces without stealing the private key, Mandiant reported.

“The method, I would say, is quite sophisticated,” Chen said on “Squawk Box Europe,” adding that the attackers removed traces after the transfer to hinder the investigation.

No reports have identified any affected security products. When asked, Chen declined to reveal details of other vendors or products, citing the potential to introduce additional security risks by releasing information beyond published findings.

The report did not attribute the attack to North Korea. Chen previously said early technical indicators were very consistent with a known North Korean hacker group.

“We’ll have to wait and see more about this,” he told CNBC.

Withdrawals for bitcoin, ether and USDT have resumed. Bitget has scheduled withdrawals for its remaining cryptocurrencies, along with fiat and peer-to-peer services, to resume on Friday.