Key Takeaways
- Bitget has revised its security breach assessment, increasing total compromised assets from $352 million to $388 million.
- Additional stolen funds were discovered on Zcash and TRON blockchain networks during comprehensive forensic analysis.
- The exchange plans a staged withdrawal reopening beginning September 28, concluding October 2.
- Stablecoin issuers Circle and Tether have frozen approximately $318,000 connected to attacker wallets.
- CEO Gracy Chen has indicated potential involvement of North Korea’s Lazarus Group, pending verification.
The cryptocurrency exchange Bitget has issued a revised security incident report, confirming that approximately $388 million in digital assets were compromised during the recent attack. This represents a significant increase from the platform’s initial assessment of $352 million announced just one day prior.
According to the exchange, this revised figure emerged from comprehensive blockchain forensic analysis that uncovered additional compromised assets on both the Zcash and TRON networks, which had not been identified during preliminary investigations.
The platform emphasized that the increased valuation reflects more thorough discovery rather than additional security breaches. Bitget confirmed that the incident has been completely contained, with all vulnerabilities addressed to prevent any further unauthorized asset movements.
Breakdown of Compromised Digital Assets
The security incident affected multiple blockchain ecosystems, spanning Ethereum Virtual Machine-compatible networks, XRP Ledger, Zcash, and TRON infrastructures.
Compromised digital assets included XRP, Ether, Tether’s USDt, Zcash, USDC, USDT0, XAUt, BNB, AVAX, and TRX. XRP represented the largest individual loss category, accounting for approximately $157.5 million of the total.
The platform clarified that its cold storage infrastructure, which houses the majority of customer deposits in offline environments, remained completely secure. The breach exclusively impacted portions of the exchange’s hot and warm wallet systems.
Immediately following the security incident, Bitget implemented an emergency suspension of all withdrawal services as a precautionary measure. The company stressed that this decision was made to ensure platform security rather than due to insufficient customer funds.
Phased Withdrawal Restoration Timeline
The exchange has announced a systematic approach to restoring withdrawal functionality across multiple days. Bitcoin withdrawal services were prioritized for restoration, with operations resuming September 28 at 08:00 UTC.
Ethereum network withdrawals were slated for September 29, with USDT withdrawal capabilities scheduled for September 30.
Complete restoration of all remaining cryptocurrency withdrawals, alongside fiat currency and peer-to-peer transaction options, is projected for October 2. The platform confirmed that the security vulnerability exploited during the attack has been identified and remediated.
Bitget’s security infrastructure team is conducting extensive verification testing on withdrawal systems prior to each phase activation. The exchange assured users that no manual intervention will be required once withdrawal services resume normal operations.
Major stablecoin providers took immediate action to minimize damage. Both Circle and Tether implemented freezes on funds associated with a wallet address designated by Bitget as “Bitget Exploiter 8.”
The immobilized assets consisted of 218,023 USDT and 99,990 USDC, totaling approximately $318,000. While this represents a modest fraction of overall losses, CEO Gracy Chen publicly acknowledged both organizations for their rapid response.
The platform has initiated a recovery incentive program offering rewards to individuals or entities who assist in freezing or recovering the stolen digital assets.
Bitget disclosed that its Protection Fund, valued at over $464 million, will be utilized to compensate for incident-related losses. This reserve mechanism is designed to ensure complete protection of customer account balances.
Cybersecurity specialists Mandiant and blockchain forensics firm SlowMist have been engaged to support the ongoing investigation. Chen has suggested possible involvement by North Korea’s Lazarus Group, a theory echoed by certain blockchain security analysts.
The exchange has not issued definitive attribution for the attack. Official identification of responsible parties remains pending as investigative efforts continue.
This security breach represents one of the more substantial incidents in cryptocurrency exchange history, though it falls below the $1.5 billion Ether theft from Bybit that occurred in February 2025. Bitget reports that trading services and deposit functionality have maintained normal operations throughout the entire incident.



