Key takeaways
- Bitget CEO Gracy Chen has said she is "not very optimistic" about recovering funds from the exchange's $388 million security breach, noting only a small percentage has been frozen or recovered and citing the 2025 Bybit hack as a reference point.
- Recovery depends almost entirely on the first minutes after an exploit. Once funds pass through protocols that no party controls, the freezing tools available to centralised issuers stop applying.
- This is the third time we have covered this incident, and the structural lesson has not changed: an exchange balance is a claim against a company, not an asset you control.
- Elsewhere: reporting indicates the CLARITY Act has failed, House Oversight has expanded a prediction-market probe to Hyperliquid, and a $7 billion ETF plumbing effort has run into IRS treatment questions.
Bitget's chief executive Gracy Chen has said publicly that she is "not very optimistic" about recovering funds from the exchange's security breach, which reporting now puts at roughly $388 million. She pointed to the 2025 Bybit hack as a reference point, and noted that only a small percentage of the funds had been frozen or recovered.
That is an unusually direct statement from an executive in this position, and it deserves credit for being direct. It also gives us a reason to explain something most people only learn after it affects them: what recovery actually involves, and why the odds are set within minutes rather than over months.
Recovery is decided in the first few minutes
When funds leave an exchange in an exploit, a clock starts. Almost everything that determines the outcome happens before most people know anything has occurred.
What can be frozen. Centralised stablecoin issuers can freeze tokens at specific addresses. That is a real power and it has recovered real money. We covered it directly when Circle and Tether froze part of this same attacker's holdings — and the number was instructive: of roughly $387 million, only about $318,000 was still freezable by the time the freeze landed.
Why so little. Because an attacker who has planned the exploit has also planned the exit. Funds are swapped out of freezable assets almost immediately — into assets no issuer controls, across chains, through protocols with no operator who could intervene even if asked.
So the freezing tools are real, narrow, and they expire. After that window, what remains is tracing rather than recovery.
Tracing is not the same as getting it back
This distinction gets blurred constantly in coverage, and it matters.
A public blockchain means stolen funds can be followed indefinitely. Analytics firms will map the movements, label the addresses, and publish the trail. That is genuinely valuable and it is frequently mistaken for progress toward recovery.
Watching money move is not the same as being able to take it back. Recovery requires a point where the funds touch something a legal authority can reach — a regulated exchange with identity records, a payment provider, a bank. Until then, the funds are visible and untouchable at the same time.
This is why sophisticated attackers are patient. They can sit on traced funds for years, because the trail does not degrade and neither does their position. Time works against the victim, not the attacker.
Why the Bybit comparison is the honest one
Citing the 2025 Bybit hack as a reference point is a realistic choice rather than a deflection.
That incident involved a comparable order of magnitude, a similarly rapid exit, and a similarly small recovered fraction. It established what a well-executed exploit of this size actually looks like afterwards, and the answer was not encouraging.
An executive drawing that comparison is telling users something true and unwelcome, which is more useful than an assurance that a process is ongoing. Worth noting for anyone assessing how a company handles an incident: the willingness to say the unwelcome thing is itself information.
What this means for you, and it is the same lesson
We have now covered this incident three times — the withdrawal suspension, the freezing attempt, and now the recovery assessment. The structural point has not changed at any stage, and repetition is the honest response to that.
A balance on a trading venue is a claim against a company. It is not crypto you control. In ordinary operation that distinction never surfaces. It surfaces exactly here: when the company has lost assets and the question of who bears that loss becomes a matter of its solvency, its insurance, and its choices.
Bitget has stated user funds are safe and has resumed withdrawals in stages, which we noted at the time. That is the company absorbing the loss, which is the outcome you want. It is also a decision a company makes rather than a right you hold, and those are different things.
The practical framing: distinguish what you are actively trading from what you intend to hold. A venue is a place to transact. Whether it is also a place to store is a question about that specific company's balance sheet, and you cannot read that balance sheet.
Elsewhere this week
The CLARITY Act has reportedly failed. We flagged in an earlier piece that it had fallen short in the Senate; reporting now describes it as dead. If that holds, the practical consequence is that US market-structure rules for crypto remain unsettled, and the rule-making stage we wrote about — where technical detail actually gets decided — continues without a legislative framework above it.
House Oversight has expanded a prediction-market probe to Hyperliquid. This follows the Kalshi appeal we covered. The unresolved question is the same one: when is a contract on an outcome a derivative, and when is it a wager. That question is now being asked of an onchain venue rather than a licensed one, which is the development worth watching.
A $7 billion ETF plumbing effort has run into IRS treatment questions. Reporting indicates a large staking-related ETF build-out has hit tax treatment uncertainty. This is the pattern we described about the GENIUS Act: the legislation is not the hard part, and the technical rules arrive late and decide everything.
The market
Bitcoin is around $84,000, having failed another attempt at $85,000 while US Treasury yields hold near multi-year highs — which pressured equities and precious metals at the same time. Total crypto market capitalisation is near $2.86 trillion, down about 3.4% on the day. Bitcoin dominance is around 58%, Ether about 11%. The Fear and Greed Index reads 73, in Greed.
Reporting also notes September is on track to be Bitcoin's strongest on record by monthly return. Worth treating carefully: "best September" is a statement about one calendar month across a short history, and monthly seasonality in an asset with roughly fifteen years of data is a very small sample. It is a fact about the past, not a signal.
What to take from this
Recovery after an exchange exploit is largely determined in the first few minutes, by whether funds can be frozen before they are swapped into assets nobody controls. After that, tracing continues indefinitely and recovers very little.
Which makes the pre-incident decision the only one you control: how much you leave on a venue, and for how long.
Frequently asked questions
Why can't stolen crypto just be reversed?
Because there is no authority above the private key. A valid transaction signed by whoever holds the key is final by design, and that finality is the same property that prevents anyone from reversing your legitimate transactions. The only interventions available are at the edges: issuers of centralised tokens can freeze specific addresses, and regulated exchanges can block deposits. Neither can undo a transfer that already happened.
How much is usually recovered after an exchange hack of this size?
Historically a small fraction. In this incident, reporting indicated that of roughly $387 million, only about $318,000 remained freezable by the time issuers acted. The CEO's reference to the 2025 Bybit hack points at a comparable outcome. The pattern is consistent because attackers who plan the exploit also plan the exit, converting out of freezable assets within minutes.
If the funds can be traced forever, why does that not lead to recovery?
Tracing tells you where funds are. Recovery requires a point where they touch something a legal authority can compel — a regulated exchange holding identity records, a bank, a payment provider. Until that happens, funds can be fully visible and completely unreachable. Attackers can wait years, and waiting costs them nothing.
Does "user funds are safe" mean my balance is guaranteed?
It means the company has stated it will absorb the loss, which is the outcome you want and is a decision rather than an entitlement. Your balance is a claim against that company. Whether the claim is honoured depends on its capital, insurance and choices — none of which you can inspect from outside. That is the distinction worth holding onto.
So should I never leave anything on an exchange?
That is not the conclusion, and we are not advising on your holdings. A venue is necessary to transact. The useful question is whether the amount sitting there reflects what you are actively trading, or has simply accumulated there because it was convenient. Self-custody moves risk from institutional failure to personal error, which is a genuine trade rather than a strict improvement — we covered that in detail separately.
Not financial advice. Crypto assets are volatile and unregulated in many jurisdictions. In India, gains are taxed at 30% with 1% TDS on transfers. Do your own research and never invest money you cannot afford to lose.
Editorial note: Crypto Shakti uses an AI-assisted research and drafting workflow. Every article is grounded in the linked primary sources and live market data captured at publication time.
