Perspectivas clave:
- Crypto scam news: Bitget CEO Gracy Chen expects limited recovery after attackers stole about $387.5 million.
- Roughly $1.1 million of stolen assets had been frozen, but Bitget did not disclose how much had been recovered.
- Bitget replenished its Protection Fund above $300 million and completed the restoration of withdrawals on Oct. 2.
Bitget CEO Gracy Chen expects the exchange to recover only a limited portion of the approximately $387.5 million stolen in September’s cyberattack.
About $1.1 million of the stolen assets had been frozen during recovery efforts. However, Chen said frozen funds had not necessarily been returned to the exchange.
Bitget has since replenished its Protection Fund above $300 million and restored all previously suspended withdrawal services.
Bitget Follows Funds After Nearly $388 Million Crypto Scam
Per a CNBC report, Bitget continues tracing the stolen assets while working with investigators on the cyberattack. Chen said the exchange does not expect to recover a large portion of the funds involved in the scam news.

However, she said exchanges must show how they protect users when security incidents occur. Bitget has maintained that user account balances remained unaffected throughout the incident.
Meanwhile, the exchange used its protection fund to address the financial effects of the theft. Bitget valued the fund above $464 million before the attack. It was calculated that the fund fell below $200 million after the hack. The calculation relied on the fund’s publicly disclosed wallet addresses.
The protection fund later rose above $300 million after Bitget restored part of its balance. Chen said Bitget used its own capital for the restoration. She also said the fund remains publicly verifiable on-chain. Furthermore, the protection fund remains separate from reserves supporting customer balances.
Bitget’s latest Proof of Reserves report also provided updated reserve figures. The Sept. 29 snapshot showed an overall self-reported reserve ratio of 131%. All 19 covered assets had reserve ratios above 100%, according to the report.
Mandiant and SlowMist Trace Attack Path
The recovery effort also followed findings from Mandiant and SlowMist, which published investigation reports on Sept. 30. The firms found that attackers first compromised two third-party security products. They then used that access to reach Bitget’s production wallet systems.
SlowMist traced the earliest malicious activity in available logs to Aug. 31. Its investigation found that attackers exploited a previously unknown zero-day vulnerability in one security product. The attackers subsequently gained privileged internal access.
Mandiant reported that the attackers bypassed Bitget’s standard customer-facing withdrawal process. They did so without stealing private keys from the exchange. Additionally, investigators found that the attackers deleted traces after transferring funds.
Neither Mandiant nor SlowMist identified the affected security products. Chen also declined to provide further vendor or product information. She cited potential security risks from releasing details beyond the published findings.
The investigations also did not attribute the attack to North Korea. However, Chen had previously said preliminary technical indicators matched known North Korean hacking groups. She said investigators would need additional details before making further determinations.
About €36M Remains Missing After Fideuram Scam
Fideuram and authorities moved quickly to stop and recover a large portion of the transferred funds. Italian reporting said international banking cooperation recovered or blocked more than half of the approximately €95 million originally transferred.

At least €36 million remained unaccounted for in late September.
Investigators believe a substantial portion of the missing money was converted into cryptocurrency after moving through overseas accounts.
Authorities are attempting to trace those assets through international judicial cooperation.
The conversion to crypto adds another layer of complexity because assets can move quickly between wallets, exchanges and jurisdictions.
Molesini has not been accused of participating in the fraud. Investigators have treated him as a victim of the impersonation scheme.
He stepped down as Fideuram chairman on March 12, citing personal reasons. The Bitget hack and Fideuram fraud involved different attack methods.
Bitget suffered a technical breach involving third-party security infrastructure, while Fideuram was targeted through social engineering and AI-assisted impersonation.
Both cases nevertheless demonstrate the increasingly complex ways attackers can move traditional and digital assets across financial systems.
This article is for informational purposes only and does not constitute financial, investment or cybersecurity advice.
El artículo Crypto Scam News: Bitget CEO Says Most Stolen Funds May Not Be Recovered apareció primero en The Coin Republic.

