Key Highlights
- The cryptocurrency exchange revised its security incident damages upward from $352 million to $388 million following expanded blockchain analysis.
- Additional compromised assets were identified on Zcash and TRON blockchain networks during the expanded investigation.
- A staged reopening of withdrawal services begins September 28, with complete functionality expected by October 2.
- Stablecoin providers Circle and Tether successfully froze approximately $318,000 connected to addresses associated with the breach.
- CEO Gracy Chen has indicated possible involvement by North Korea’s Lazarus Group, though official attribution remains pending.
In a revised incident assessment, Bitget disclosed that the security compromise impacted approximately $388 million in digital assets. The figure represents a significant increase from the exchange’s initial estimate of $352 million announced one day prior.
According to the platform’s statement, the revised calculation stems from an expanded examination of on-chain transactions. During this deeper analysis, investigators identified previously undetected stolen funds on both the Zcash and TRON blockchain ecosystems.
The exchange emphasized that the increased valuation reflects improved detection capabilities rather than additional unauthorized activity. Officials confirmed the security incident has been fully isolated and no further unauthorized asset movements are possible.
Breakdown of Compromised Digital Assets
The security incident impacted multiple blockchain infrastructures, spanning Ethereum Virtual Machine-compatible chains, the XRP Ledger, Zcash, and TRON protocols.
Compromised digital currencies encompassed XRP, Ether, Tether’s USDt, Zcash, USDC, USDT0, XAUt, BNB, AVAX, and TRX. XRP constituted the largest individual loss category, representing approximately $157.5 million of the total.
Platform representatives confirmed that offline cold storage systems, which house the majority of customer deposits, remained completely secure. The breach exclusively targeted portions of the exchange’s hot and warm wallet infrastructure.
Following the discovery of unauthorized access, Bitget immediately suspended withdrawal processing as a precautionary security measure. Officials stressed this action was implemented proactively rather than as a response to missing customer funds.
Phased Restoration of Withdrawal Services
The exchange has published a detailed timeline for gradually restoring withdrawal functionality over multiple days. Bitcoin withdrawal capabilities were designated for initial restoration on September 28 at 08:00 UTC.
Ethereum withdrawal services were scheduled to become available on September 29. USDT withdrawal processing was planned for September 30.
Complete restoration of all remaining cryptocurrency withdrawals, alongside fiat and peer-to-peer transfer options, was projected for October 2. Platform officials confirmed the security vulnerability exploited in the incident has been identified and remediated.
According to the exchange’s announcement, security specialists are conducting comprehensive testing of withdrawal infrastructure before activating each restoration phase. Bitget confirmed users will not be required to take any manual actions when withdrawal services resume.
Leading stablecoin issuers provided assistance in damage mitigation efforts. Circle and Tether implemented freezes on funds associated with a wallet address the exchange identified as “Bitget Exploiter 8.”
The immobilized assets comprised 218,023 USDT and 99,990 USDC, totaling approximately $318,000. While representing a modest fraction of overall losses, CEO Gracy Chen publicly acknowledged both organizations for their rapid response.
The platform has initiated a recovery incentive initiative, providing rewards to individuals or entities assisting in freezing or recovering the misappropriated funds.
Platform officials referenced their Protection Fund, valued at over $464 million, as the resource designated to compensate for incident-related losses. This reserve fund is specifically designed to ensure customer account balances remain fully protected.
Cybersecurity firms Mandiant and SlowMist have been engaged to support the ongoing investigation. Chen has publicly suggested North Korea’s Lazarus Group may be responsible, an assessment echoed by certain blockchain analysis specialists.
The exchange has not issued definitive attribution. Official responsibility determination remains pending as investigative efforts continue.
This security incident represents one of the more substantial breaches in cryptocurrency exchange history, though it falls short of the $1.5 billion Ether theft from Bybit in February 2025. Bitget maintains that trading operations and deposit functionality have remained fully operational throughout the incident response period.


