Bitget’s $387.5M Breach Bombshell: How Their Bold Recovery Bounty Could Change the Game Forever
Ever wonder what happens when a crypto exchange’s hot wallets turn into a hacker’s personal buffet? Well, Bitget just gave us a masterclass—in the unfortunate kind of way. Initially, they reported a breach affecting around $351.6 million, but as the forensic dust settled, that number ballooned to a staggering $387.5 million. Now, before you think it’s “new” theft, Bitget’s CEO Gracy Chen clarified it’s a more thorough tally of the assets already pilfered, including some stealthy Zcash and TRON tokens they missed at first glance. It’s like finding an extra stack of bills in the couch cushions after cleaning up a mess. The bright side? Their cold wallets stayed untouched, and the team, alongside top-notch security firms, is piecing together how the attackers slipped through the cracks—while also launching a bounty program to freeze and recover the stolen loot. If there’s one lesson here, it’s that even well-funded platforms need to keep their guards sharper than ever because in crypto—and business—complacency is a costly game. LEARN MORE

Bitget has raised the estimated value of assets affected by its September 24 security breach to approximately $387.5 million, up from an initial estimate of $351.6 million.
Within 24 hours of the September 24 (UTC) incident: here is our further update as promised. Our investigation with Mandiant and SlowMist is ongoing — thorough forensic analysis takes more than 24 hours, and further findings will be shared as they become available. Three key…
— Gracy Chen @Bitget (@GracyBitget) September 25, 2026
Bitget CEO Gracy Chen said in a post on X that the revised figure reflects a more complete accounting of transfers made during the incident, including Zcash and TRON assets that were not included in the original estimate. She stressed that the increase does not represent additional unauthorized transfers.
The incident was detected at 18:31 UTC on September 24, when Bitget identified unauthorized transfers from portions of its hot and warm wallet infrastructure. Cold wallets remained secure, and withdrawals were temporarily suspended while the exchange conducted security checks.
Bitget said the affected assets include XRP, ETH, USDT, ZEC, USDC, USDT0, XAUt, BNB, AVAX and TRX across Ethereum and other EVM networks, XRP Ledger, Zcash and TRON.
The exchange said its security team has now identified the attack path and the method used to bypass its existing security controls. The underlying vulnerability has been identified and remediated, according to Bitget, although the company has not yet publicly disclosed technical details of the exploit.
Bitget said no further unauthorized transfers have occurred since the incident was contained. Mandiant and SlowMist are assisting with the ongoing forensic investigation and tracing efforts.
The exchange has also launched a Recovery Bounty Program aimed at freezing and recovering stolen assets. Eligible participants can receive 5% of funds they help freeze and another 5% of funds they directly help recover.
Some affected assets have already been frozen through coordination with exchanges, blockchain projects and security firms. Bitget is also using Bybit’s LazarusBounty platform as part of the recovery effort.
Withdrawals remain temporarily paused while additional security checks and remediation work continue. Bitget said it will announce its withdrawal restoration plan by September 26 at 4:00 AM UTC. Deposits and regular trading remain available, although some onchain services have also experienced temporary disruptions during the security review.
Bitget previously said customer balances remain protected and that the initial $351.6 million estimate was fully covered by its User Protection Fund, which held more than $464 million at the time of the incident.
The investigation and asset tracing remain ongoing, and Bitget said the $387.5 million figure could be revised as additional transactions are classified.



Post Comment