TLDR
- Stablecoin issuers Circle and Tether blacklisted approximately $318,000 in USDC and USDT connected to the Bitget security breach.
- The exchange increased its loss assessment from $351.6 million to $387.5 million after including additional networks.
- A bounty initiative offers 5% rewards for freezing stolen assets and an additional 5% for successful recovery efforts.
- Bitget claims to have identified the exploit vector and patched the security flaw.
- A staged reopening of withdrawal services begins September 28, starting with Bitcoin transactions.
A significant security incident has impacted Bitget, one of the prominent cryptocurrency trading platforms, forcing the company to reassess the scale of its losses. Initially pegged at $351.6 million, the damage estimate has now climbed to $387.5 million as investigators uncovered additional affected assets.
The breach occurred on September 24 when Bitget’s monitoring systems flagged suspicious outbound transactions from multiple hot wallets at exactly 18:31 UTC. While the platform’s hot and warm wallet infrastructure was compromised, its cold storage facilities remained intact and secure.
According to Bitget CEO Gracy Chen, the perpetrators gained access through a backend infrastructure component connected to the wallet management system. The attackers manipulated transaction information to deceive the authorization mechanisms into approving fraudulent transfers. Chen specifically dismissed speculation that private keys were directly stolen.
Stablecoin Issuers Step In to Freeze Funds
In response to the incident, both Circle and Tether implemented freezing measures. Circle blacklisted a specific wallet address at 05:00 UTC on Friday containing approximately 170 ETH, 218,023 USDT, and 99,990 USDC.
Tether followed suit with its own blacklist action on the identical address, as confirmed by blockchain security company MistTrack. The combined effort resulted in approximately $318,000 worth of stablecoins being effectively frozen.
However, this represents only a fraction of the overall stolen funds. MistTrack’s analysis indicates that additional addresses associated with the attacker continue to hold over 63,000 ETH. Unlike stablecoins, Ethereum cannot be frozen since it operates without centralized control.
Security analyst Taylor Monahan monitored portions of the stolen USDC as they transferred between various wallet addresses. Her investigation revealed that some of the stablecoins were exchanged for ETH during these movements.
The revised loss figure of $387.5 million emerged after Bitget incorporated assets from two blockchain networks initially overlooked in the first assessment. The exchange confirmed the updated calculation now accounts for compromised funds on both Zcash and TRON networks.
Bitget emphasized that this revision represents a more comprehensive audit of the original security breach rather than evidence of additional unauthorized transactions.
The spectrum of compromised digital assets is extensive, spanning XRP, ETH, USDT, ZEC, USDC, USDT0, XAUt, BNB, AVAX, and TRX.
Forensic analysis has pinpointed four primary wallet addresses receiving the stolen cryptocurrency. These addresses are distributed across EVM-compatible chains, XRP Ledger, Zcash, and TRON networks.
Bitget Launches Bounty Program for Fund Recovery
Chen unveiled a reward initiative via X this week, soliciting assistance from cryptocurrency exchanges, cybersecurity experts, and blockchain analysts in tracing the misappropriated funds.
The incentive structure features dual compensation tiers. Contributors can receive 5% of any assets they assist in freezing, plus an additional 5% for funds successfully returned to Bitget.
The exchange clarified that actions completed prior to the bounty announcement remain eligible for rewards. Bitget retains discretion in determining qualification criteria and calculating individual contribution values.
Actions stemming from legal proceedings are excluded from bounty eligibility. This encompasses asset freezes mandated by judicial authorities or law enforcement agencies.
To promote transparency, Bitget established a publicly accessible tracking dashboard monitoring stolen fund movements in real time. The platform also implemented a submission portal enabling individuals to report intelligence on attacker-controlled addresses.
Cybersecurity firms Mandiant and SlowMist are collaborating on the investigation, according to the exchange. Bitget reports successfully identifying the attack methodology and implementing patches to address the exploited weakness.
The platform asserts that its current security posture prevents any additional unauthorized fund movements.
A systematic withdrawal restoration schedule has been established. Bitcoin withdrawal functionality returns September 28, followed by Ethereum-based withdrawals on September 29, USDT on September 30, and remaining cryptocurrencies plus fiat currencies by October 2.
Bitget maintains that user account balances have not been impacted by the incident. The company referenced its Protection Fund, previously valued above $464 million, as the financial safeguard covering losses. An updated fund valuation reflecting the $387.5 million shortfall has not yet been released.
Chen has scheduled a live interactive session for September 28 at 07:30 UTC to address community questions regarding the breach and outline the exchange’s recovery strategy.





