Episode Summary
Executive Summary: Bitget CEO Gracie Chen described a major hack that stole about $388M across multiple chains, explaining how attackers used a third-party zero-day vulnerability and back-end fraud to bypass normal withdrawal controls. She detailed Bitget’s rapid containment, fund-tracing efforts, bounty offers, user protection fund, and broader concerns about social engineering, security practices, and industry cooperation to prevent laundering.
Main Topics: How the Bitget hack unfolded (Priority: 5/5): Chen explained the timeline: test transfers began around 6:31 UTC, large unauthorized withdrawals started at 6:58 UTC, and the incident lasted under three hours. The attackers used a third-party zero-day vulnerability to insert fraudulent withdrawal comments into internal systems rather than exploiting a normal user withdrawal flow. Incident response and containment (Priority: 5/5): Bitget’s reconciliation system detected discrepancies within minutes, automatically paused user withdrawals at 7:05 UTC, and the team moved funds from hot and warm wallets to cold storage. Chen emphasized that the attackers’ method meant the pause did not fully stop the bleed immediately. Cross-chain fund tracing and freezing (Priority: 5/5): The discussion covered affected chains, recovery efforts, and the role of issuers and protocols such as Circle, Tether, and Near Intents in freezing assets. Chen contrasted freezing with recovery and said legal procedures make recovery much harder. Security lessons and social engineering risk (Priority: 4/5): Chen said the exploit exposed weaknesses in third-party diligence and internal security architecture, and she stressed that social engineering remains a major threat. She also revealed that scammers were still targeting her immediately after the hack. Industry norms on decentralization vs. intervention (Priority: 4/5): The conversation explored whether protocols like Thorchain should block laundering flows and whether permissionless systems should still refuse stolen funds. Chen argued that neutrality should not mean helping hackers launder assets and praised solutions like Near Intents’ KYT-based policy layer. User protection fund and business continuity (Priority: 4/5): Chen described Bitget’s protection fund, created in 2022, as a backstop that helped keep users whole during the incident and supported ongoing withdrawals. She said the exchange remains committed to restoring the fund above its threshold and maintaining business continuity. Reputation, public scrutiny, and transparency (Priority: 3/5): The interview also addressed criticism from on-chain researcher ZachXBT, allegations about Bitget’s past token activity, and insinuations about Chen as a female Asian CEO. Chen focused on transparency, incident reporting, and proving operational resilience rather than engaging the personal attacks.
Key Arguments: The attackers used an internal-system compromise via a third-party zero-day, not a simple wallet key leak, which made detection and remediation harder. Bitget’s automated monitoring caught the discrepancy quickly, but the hackers’ back-end method allowed them to keep transferring funds until containment progressed. Freezing stolen assets is easier than recovering them; legal and procedural hurdles make actual return of funds much harder. Protocols and stablecoin issuers should not treat permissionlessness as a reason to facilitate laundering of stolen crypto. Social engineering is a major and ongoing attack vector, especially when public-facing executives are under pressure and communicating widely after an incident. A pre-built protection fund can materially reduce user harm and preserve confidence during a major exchange incident. Stronger third-party vetting, credential resets, server isolation, and multi-approval controls are essential post-incident security improvements. Industry collaboration among exchanges, security firms, researchers, and issuers is necessary to make laundering stolen funds difficult.
Data Points: Total stolen amount: $388 million - Approximate total value Bitget says was taken in the hack. First unauthorized withdrawal: 6:31 p.m. UTC on Sept. 24 - Initial small test transfers began before the larger theft. First large transfer: 6:58 UTC - Start time of the main wave of unauthorized withdrawals. Time to detection: ~7 minutes - Bitget’s reconciliation system detected a discrepancy and triggered a withdrawal pause shortly after the first large transfer. Withdrawal pause time: 7:05 UTC - User-initiated withdrawals were automatically blocked. Duration of main attack window: Less than 3 hours - From first large transfer at 6:58 to last transaction at 9:23 UTC. Second-round theft: ~$30 million - Additional losses occurred after Bitget moved funds back to cold storage and the attacker gained another opportunity. Frozen funds: $632K - Amount Bitget reported as frozen out of the total stolen funds at the time of the interview. User protection fund size: ~$556 million - Bitget’s protection fund value after moving some funds for withdrawal support. Protection fund threshold: $300 million - Bitget’s stated minimum target for the protection fund. Withdrawals on ETH reopen: 9,674 ETH inflow vs. 9,023 ETH outflow - Net inflow observed after Ethereum withdrawals reopened for one hour. Near Intents-related freeze: ~$500K - Chen said Near Intents helped freeze this amount via a near-intent/swap path. Bounty offer: 5% + 5% - Bitget offered 5% for voluntarily freezing attacker funds and 5% for voluntary recovery.
Pivotal Quotes: "This is not a hack. This is a social engineering towards me." — Gracie Chen: She described the post-incident attempts by scammers to impersonate major investment teams and target her personally. "Permissionlessness doesn’t mean neutral." — Gracie Chen: She argued that DeFi protocols should not facilitate laundering stolen assets simply because they are open or decentralized. "I just hope that this time we can do better than 3.5%. But I don’t have much hope. Honestly." — Gracie Chen: She compared current recovery prospects with the low frozen/recovered percentage from the Bybit hack.
Implications: The episode shows how quickly sophisticated exchange hacks now depend on internal compromise, social engineering, and cross-chain laundering. It also underscores rising pressure on protocols, issuers, and researchers to intervene, while exchanges must harden third-party security and crisis response.