Bitget CEO Gracy Chen Affirms IPO Plans Despite $387.5 Million Security Breach
Key Takeaways
- •The breach, detected on September 24 at 18:31 UTC, resulted in approximately $387.5 million stolen from Bitget's hot and warm wallets through spoofed transaction data.
- •Stolen assets included roughly 103 million XRP valued at about $157 million, along with ETH and USDT, while cold wallets and private keys were not compromised.
- •Bitget's initial loss estimate of $351.6 million was revised upward to $387.5 million after some stolen funds were recovered on the Zcash and TRON networks.
- •CEO Gracy Chen said the attack's patterns resemble operations attributed to North Korean hacking groups, based on IP address analysis and transaction tracing.
- •Bitget's User Protection Fund of more than $464 million is expected to fully cover the losses, and withdrawals remain suspended while Mandiant and SlowMist investigate.

Bitget has suffered one of the largest cryptocurrency exchange hacks of 2026, losing $387.5 million to unauthorized withdrawals, but CEO Gracy Chen says the company remains committed to going public within three years.
The breach was detected on September 24 at 18:31 UTC. Attackers drained funds from both hot and warm wallets — the internet-connected tiers exchanges rely on to process day-to-day withdrawals — using spoofed transaction data. Stolen assets included approximately 103 million XRP, worth roughly $157 million, along with ETH and USDT. Cold wallets, which keep private keys offline, were not compromised, and no private keys were exposed.
Inside the Breach
The initial damage estimate came in at $351.6 million, but Bitget revised the figure upward to $387.5 million after recovering additional stolen assets on the Zcash and TRON networks — a sign of how stolen funds moving across multiple blockchains can complicate early damage assessments.
Chen disclosed that the attack's fingerprints resemble previous operations attributed to North Korean hacking groups, units that security researchers and government agencies have linked to a string of major cryptocurrency thefts in recent years. The assessment is based on IP address analysis and transaction pattern tracing, prompting Bitget to inform law enforcement and launch an on-chain tracing initiative, following the funds across public blockchains where every transfer is permanently recorded.
The exchange has brought in cybersecurity firm Mandiant and blockchain security firm SlowMist to investigate the breach and patch whatever gaps the attackers exploited. Withdrawals remain suspended while the platform works to shore up its defenses — a containment step that leaves customers unable to move funds out until the exchange reopens them.
The $464 Million Safety Net
Bitget maintains a User Protection Fund of more than $464 million, a reserve built specifically for scenarios such as this one. The fund will fully cover the $387.5 million in losses, meaning affected users should ultimately be made whole, with roughly $76 million to spare — an outcome that now depends on reimbursements arriving in full and on schedule.
IPO Ambitions in a Tough Market
Chen has described 2026 as a challenging year for cryptocurrency companies pursuing public listings. She attributed the difficulty to competition for investor attention from the AI and space technology sectors, which are commanding sky-high valuations and drawing capital away from digital asset firms.
The three-year IPO timeline Chen has outlined gives Bitget a runway to recover from the reputational damage and demonstrate that its security overhaul actually works. Any IPO prospectus will need to disclose the breach prominently, and how the company handled the aftermath — including the speed of user reimbursements and the effectiveness of its security upgrades — will matter as much as the breach itself. In the meantime, the markers to watch are when withdrawals resume, what the Mandiant and SlowMist investigation uncovers, and whether on-chain tracing recovers more of the stolen funds.