Bitget CEO Chen: Fund Will Compensate Approximately $388 Million
Gracy Chen stated in a live broadcast that attackers exploited vulnerabilities in third-party security products to steal internal network credentials, forge withdrawal instructions to the wallet system, and bypass risk controls; private keys were not leaked, cold wallets were unaffected, the vulnerability has been patched, and the incident is under control.
She confirmed that approximately $388 million in assets were transferred out, and the attacker's address along with on-chain tracking data has been disclosed. All losses will be covered by the user protection fund, which will be replenished to at least $300 million within a week after being utilized, and recovery efforts will be initiated, while confirmed vulnerabilities and attack information will be shared with the industry.
The timeline anchors on unauthorized transfers from the multi-chain hot wallet and warm wallet on September 24. The company previously revised the amount from approximately $351.6 million to about $387.5 million, which is close to the current figure of $388 million. Mandiant and SlowMist continue to participate in the investigation.
Bitcoin withdrawals have reopened as of September 28 at 8:00 UTC, while ETH, USDT, and other assets will be restored in phases on September 29, 30, and October 2. Trading and deposits have not stopped, and self-custody wallets are stated to be independent of the exchange's custody.
The names of the third-party products have not been disclosed in the live broadcast summary to a referable vendor trademark level. The attack is described as credential impersonation combined with instruction forgery, rather than traditional malware residency. Some hacker addresses are reportedly frozen.
From a market mechanism perspective, what is sold is the immediate payout of the protection fund for the hot wallet gap, and what is bought is the avoidance of user runs. Funds are allocated from the fund to the liability side, and then replenished by operating cash flow within a week to cover the $300 million baseline; the beneficiaries are users whose account balances remain unchanged, while the burden falls on the fund's scale and the identified security supply chain. The incident is driven by forged signature instructions rather than the cold storage being accessed.
Source: Public Information
ABAB AI Insight
Chen emphasized three key points: the keys are still there, the vault is intact, and the instructions were deceived. Compensation will not be shared by users but will come from the pre-collected protection fund, which will be replenished to the $300 million threshold within a week, effectively turning a one-time hole into a demonstrable reserve ratio. Disclosing the attack address outsources the recovery efforts to the entire network of observers.
The capital path is that transaction fees are accumulated as potential liability reserves. The $388 million test is whether the fund can cover this amount upfront without drawing from user balances, and then rely on subsequent revenue to replenish it. Synchronizing vulnerabilities with the industry turns vendor incidents into a market-wide patch event, reducing the public scrutiny focused solely on one exchange.
A comparable case is Binance's use of SAFU to cover 7,000 bitcoins in 2019, and banks using deposit insurance instead of adjusting their books. The difference this time is that the gap is an order of magnitude larger, and the entry point is in third-party security software. The industry phase is that after the widespread adoption of multi-layer verification for hot wallets, the vendors relied upon for verification have become a new systemic risk.
Structural judgment belongs to the reconstruction of the industrial chain. The mechanism is that whoever issues the "risk-controlled" instruction to the wallet temporarily holds the right to dispose of user assets; the fund decides whether users will run, and the patch cycle determines who will be the next victim.