Key Points
- Bitget has increased its estimated losses from the security breach to $388 million, up from an initial $352 million assessment.
- Additional compromised assets were discovered on TRON and Zcash blockchain networks during deeper analysis.
- The exchange plans a staged withdrawal reopening beginning September 28, concluding October 2.
- Tether and Circle have frozen approximately $318,000 in stablecoins associated with attacker wallets.
- CEO Gracy Chen has indicated possible involvement by North Korea’s Lazarus Group, though attribution remains unverified.
The cryptocurrency exchange Bitget has revised its assessment of a recent security incident, now estimating total compromised assets at approximately $388 million. This represents a significant increase from the preliminary $352 million figure announced just one day prior.
According to the exchange, this revised figure resulted from expanded blockchain forensics that uncovered additional stolen digital assets across the TRON and Zcash networks that weren’t identified during initial investigations.
The platform emphasized that this upward revision doesn’t indicate fresh unauthorized activity. Bitget stated the security incident has been completely isolated, with all vulnerabilities patched to prevent additional unauthorized asset movements.
Breakdown of Compromised Digital Assets
The security incident impacted multiple blockchain ecosystems, spanning Ethereum Virtual Machine-compatible chains, the XRP Ledger, Zcash, and TRON.
Compromised assets included XRP, Ether, Tether’s USDt, Zcash, USDC, USDT0, XAUt, BNB, AVAX, and TRX. XRP represented the single largest component of the theft, accounting for approximately $157.5 million in value.
Bitget confirmed that its cold storage infrastructure, which houses the majority of customer assets in offline environments, remained completely secure. The breach affected only portions of the platform’s hot and warm wallet systems.
As an immediate precautionary measure following the discovery of the breach, the exchange suspended all withdrawal functions. Bitget stressed this action was taken proactively rather than due to any shortage in user funds.
Phased Approach to Restoring Withdrawal Services
The exchange has announced a structured timeline for reinstating withdrawal capabilities across different asset classes. Bitcoin withdrawal functionality was scheduled to resume first, beginning September 28 at 08:00 UTC.
Ethereum network withdrawals were planned for September 29, with USDT withdrawals following on September 30.
Complete restoration of all remaining cryptocurrency withdrawals, alongside fiat currency and peer-to-peer transaction options, was targeted for October 2. The platform confirmed the security weakness exploited in the attack has been identified and remediated.
Bitget’s security infrastructure team is conducting comprehensive testing protocols for withdrawal systems ahead of each restoration phase. The exchange assured users that no manual action would be required from account holders when services resume.
Major stablecoin providers took action to minimize further damage. Both Circle and Tether implemented freezes on funds connected to a wallet address Bitget identified as “Bitget Exploiter 8.”
The frozen assets totaled 218,023 USDT and 99,990 USDC, representing roughly $318,000 in combined value. While this constitutes a fraction of overall losses, CEO Gracy Chen publicly acknowledged both organizations for their swift response.
The exchange has also established a recovery bounty initiative, providing incentives to individuals or organizations that assist in freezing or recovering the stolen digital assets.
Bitget disclosed it maintains a Protection Fund exceeding $464 million specifically designated to offset losses from security incidents. This reserve is designed to ensure customer account balances remain whole despite the breach.
Cybersecurity specialists Mandiant and blockchain analytics firm SlowMist are providing investigative support. Chen has suggested North Korea’s Lazarus Group as a potential perpetrator, an assessment echoed by certain blockchain security researchers.
However, Bitget has not issued definitive attribution. The identification of responsible parties remains ongoing as forensic analysis continues.
This incident represents one of the more significant security breaches in cryptocurrency exchange history, though it falls short of the $1.5 billion Ether theft from Bybit in February 2025. Bitget maintains that trading operations and deposit functions have remained fully operational throughout the event.





