Three centralized exchange security incidents between 2024 and 2026 provide a public dataset for comparison. Bitget, Bybit, and WazirX suffered breaches with approximate losses of 387.5 million, 1.46 billion, and 230 to 235 million dollars respectively.
The order of magnitude does not correlate with the time each platform required to restore operations or with the percentage of funds users could withdraw.
The conclusion which follows points to a different factor: loss absorption capacity and custody architecture determine the result, not the size of the attack.
Bitget: Restoration in 85 Hours with Own Resources
The Bitget incident occurred in September 2026. Attackers exploited a vulnerability in a security product provided by a third party to forge withdrawal commands and drain approximately 387.5 million dollars from hot and warm wallets. Cold wallets remained intact, which limited the scope of the loss.
The operational response relied on the Bitget Protection Fund, with a balance exceeding 464 million dollars. The platform covered the full impact with own resources, so user balances registered no alterations. Bitcoin withdrawals reopened 85 hours and 29 minutes after detection.

Bitget complemented financial coverage with a recovery bounty program offering 5% of frozen funds and an additional 5% of recovered funds to any actor providing usable information. The platform also used LazarusBounty, a tool developed by Bybit, as a coordination channel between exchanges.
The Bitget decision consisted of prioritizing operational continuity and transferring cost to its own balance. The user did not participate in the loss. The exchange assumed the role of sole creditor of the incident before its clients, without activating socialization mechanisms or balance conversion.
Bybit: The Largest Recorded Loss and No Withdrawal Interruption
In February 2025 Bybit suffered the theft of approximately 1.46 billion dollars in ETH from a single cold wallet. The event ranks as the largest recorded theft in crypto infrastructure to date. The magnitude represented a relevant portion of assets under custody and exceeded the capacity of any known individual protection fund in the sector.
Despite the volume, Bybit did not suspend withdrawals at any point. CEO Ben Zhou used bridge loans to cover the shortfall and maintain 1:1 backing of client balances. The loss moved to the company balance sheet and to lenders participating in the operation, not to end users.
The first was the LazarusBounty program, with an initial reward of 10% on recovered funds. The second was a civil lawsuit against North Korea and the Lazarus Group filed in a United States court. The third was cooperation with other exchanges and custodians to freeze addresses associated with on-chain movements.
Results published in August 2026 indicate 48.4 million dollars recovered and 30.5 million frozen across more than 28 platforms and custodians. The aggregate figure represents approximately 5.3% of the total stolen. Bitget CEO Gracy Chen used the data as a comparative reference by noting the frozen percentage after roughly one year stood near 3.5%.
The Bybit case shows operational continuity can be sustained even against a loss of institutional scale, provided access to short-term liquidity and willingness to assume cost on the balance sheet. The effective recovery rate remains low, a data point the sector rarely incorporates into risk evaluations.
WazirX: 463 Days of Freezing and Clients Converted into Creditors
WazirX suffered in July 2024 the theft of 230 to 235 million dollars, equivalent to 40% or 45% of total platform assets. The attack vector was a multisignature wallet managed by a third-party custodian, a provider which concentrated the operational exposure surface.
Even with the lowest absolute loss of the three cases, WazirX applied the longest suspension: 463 days without access to crypto withdrawals. The platform lacked sufficient reserves to cover the shortfall and lacked access to bridge financing under viable conditions.
Reopening occurred in October 2025 under a court-approved restructuring scheme, in which clients became formal creditors of the entity. Recovery Tokens (RT) were issued to represent each creditor’s share in future profit distributions. The stated target aims to recover between 75% and 80% of locked funds over a horizon not precisely defined.
Approximately 85% of rebalanced assets were distributed. The remainder became linked to tokens without a secondary market and dependent on future business performance. WazirX migrated custody to BitGo and integrated Fireblocks as part of infrastructure reconstruction, and resumed operations with zero fees in October 2025.
The structural cause of the outcome was not the amount stolen. It was the combination of third-party custody dependency, absence of a protection fund, and a capital structure without margin to absorb a loss equivalent to nearly half of assets under management. The user assumed the cost because the platform had no other source of resources.
The Question the Sector Avoids Formulating
The three cases isolate one variable. Bitget and Bybit had balance sheet capacity to internalize the loss. WazirX did not. The exchange with the smallest absolute breach produced the longest wait because its financial architecture did not contemplate a scenario of partial asset loss.
The crypto sector has dedicated considerable effort to proof of reserves as a transparency mechanism. Proof of reserves answers a different question from the one which matters during an incident. Verifying assets exist at a given moment does not inform loss absorption capacity, nor custody structure, nor contingent financing arrangements available.
An exchange can publish a proof of reserves with correct balances and lack any mechanism to cover a gap. Transparency on contingent liabilities, committed credit lines, insurance coverage, and custody concentration remains outside the standard reports platforms publish voluntarily.
The opinion I hold is that disclosure of loss absorption capacity should become a mandatory component of public information for any platform custodying third-party assets. The relevant data point for a user is not only how many assets back balances, but who pays when a portion of assets disappears.
Bounty Programs: Underused and Fragmented
Bitget and Bybit implemented reward schemes with percentages of 5% and 10% on recovered funds. The logic consists of aligning incentives with external actors capable of tracing on-chain movements. The aggregate result in the Bybit case, with 5.3% recovery after more than a year, indicates the instrument has structural limits.
Fragmentation between platforms reduces effectiveness. Each exchange operates its own coordination channel, and information on frozen addresses does not circulate at the speed required for successful tracing. Adoption of LazarusBounty by Bitget represents an advance in interoperability, although limited to voluntary participation by counterparties.
A shared tracing and freezing infrastructure with common reward-sharing rules would produce superior results to bilateral schemes. The obstacle is not technical. It is coordination among commercially competing entities with incentives not to reveal breach magnitude or operational reserve composition.
Consequences for Risk Assessment
A capital allocator evaluating exposure to centralized exchanges should incorporate variables absent from standard analysis. Among them: percentage of assets in third-party custody, existence and size of protection funds, documented access to credit lines, insurance coverage, and historical time to restore withdrawals after previous incidents.
The comparison between the three cases suggests freezing time is a more informative indicator than the amount stolen. Bitget restored withdrawals in 85 hours. Bybit did not suspend withdrawals. WazirX maintained suspension for 463 days. The differential is not explained by attack sophistication or cooperation with authorities, but by the financial structure of each platform and by the design of its custody scheme.
The conclusion I defend is that loss absorption should be treated as a product feature and not as an unforeseen consequence of management. An exchange unable to cover a loss with own resources is transferring risk to the user, regardless of what its terms of service declare.
Third-party custody without information on provider controls shifts the attack surface beyond user reach. Judicial restructuring with recovery token issuance converts clients into subordinated creditors of a business with uncertain future viability.
The sector has sufficient data to establish disclosure standards on loss absorption capacity, custody architecture, and contingent financing. T






