Approximately $1.1 million of the approximately $388 million stolen from cryptocurrency exchange Bitget in last week’s cyberattack has been frozen, and the platform continues efforts to trace and recover assets.
CEO Gracie Chen told CNBC in an email interview that the frozen assets were not necessarily returned to the exchange. He did not say how much was recovered.
“We don’t expect to recover a significant amount of money,” Chen said on CNBC’s “Squawk Box Europe” on Wednesday, citing limited recoveries from hacks of cryptocurrency exchanges to date. However, “exchanges have a responsibility to demonstrate how they will protect their users, especially if something goes wrong,” she said.
Biggett said balances in user accounts will not be affected.
The exchange valued the conservation fund at more than $464 million before the theft. After the hack, the amount fell to less than $200 million, but has since recovered to more than $300 million, according to a Bloomberg calculation of the fund’s public wallet address. Chen said the replenished funds will remain publicly verifiable on-chain and separate from the reserves backing customer balances.
BitGet’s latest reserve attestation, based on a September 29 snapshot, showed that the self-reported overall reserve ratio was 131%, with all 19 underlying assets backed by more than 100%.
“We revived the fund using Bitget’s own funds,” Chen said. “The economic impact is being absorbed by Bitget rather than being passed on to users.”
An investigative report released on September 30 by Mandiant, part of Google Cloud, and blockchain security company SlowMist found that the attackers had compromised two third-party security products before gaining access to Bitget’s production wallet system.
SlowMist tracked the oldest malicious activity in available logs through August 31st. At this time, a previously unknown or zero-day vulnerability was exploited in one of the products.
Mandiant reported that the attackers were then able to gain privileged internal access without stealing the private keys and bypass the normal withdrawal process that customers deal with directly.
“I would say this method is quite sophisticated,” Chen said on Squawk Box Europe, adding that the attackers deleted their traces after the transfer to thwart investigations.
Neither report specifies which security products are affected. When asked, Chen declined to disclose further details about the vendor or product, citing the potential for additional security risks by releasing information beyond the published findings.
Reports indicated that the attack was not caused by North Korea. Chen previously said preliminary technical indicators were highly consistent with known North Korean hacker groups.
“We’ll have to wait further for further details on this,” she told CNBC.
Bitcoin, Ether, and USDT withdrawals have resumed. BitGet plans to resume withdrawals for the remaining cryptocurrencies on Friday, along with fiat currencies and peer-to-peer services.
