CEO Gracy Chen confirmed that core withdrawal services are operational, with the remaining fiat and P2P functions slated to return on October 2 at 08:00 UTC. The exchange maintains that customer account balances remain intact, asserting that the unauthorized transfers originated from vulnerabilities in its hot and warm wallet infrastructure rather than a compromise of cold storage or private keys.
As the exchange moves toward a full recovery, it has shifted focus to balance sheet transparency. A proof-of-reserves snapshot from September 29 indicates a 131% reserve ratio, with the company’s Protection Fund now exceeding its $300 million target. Despite these financial reassurances, the recovery of stolen assets remains complex. THORChain has rejected Bitget’s request to blacklist attacker addresses, citing its permissionless design—a stance that has drawn criticism from security firms like GoPlus, who argue the protocol’s validator-controlled architecture offers more intervention capability than THORChain admits.
Investigations into the September 24 breach continue alongside forensic partners Mandiant and SlowMist. While issuers like Circle and Tether have successfully frozen a small portion of the stolen funds, other assets have been funneled through privacy-focused services like Wasabi CoinJoin, complicating recovery efforts. Bitget currently maintains a 5% bounty for assistance in freezing or reclaiming the remaining stolen capital.

Comments (0)
No comments yet. Be the first!