Bitget Raises Hack Loss Estimate to $387.5 Million as Withdrawals Stay Paused

Bitget said on Friday that its September 24 hot wallet breach was larger than first reported. The exchange now puts assets sent to attacker-controlled addresses at about $387.5 million. Its first estimate was $351.6 million. Withdrawals remain suspended while the investigation continues.
How the Number Grew
In its original security notice, Bitget said its systems detected unauthorized transfers from hot wallets at 18:31 UTC on September 24. The exchange described a three-tier wallet design. It said the breach touched only part of the hot and warm wallet layers, while cold wallets stayed secure. Bitget said it would not speculate on the attack vector until the investigation finished.
The revised total comes from Bitget's latest incident update. A fuller accounting added affected assets on Zcash and TRON that the first estimate missed. Bitget says the increase reflects better tracing, not new thefts. It also says no further unauthorized transfers are possible. The figure may change as more transactions are classified and traced.
The affected assets include XRP, ETH, USDT, ZEC, USDC, USDT0, XAUt, BNB, AVAX and TRX. Funds moved across Ethereum and other EVM networks, the XRP Ledger, Zcash and TRON. Bitget published one primary receiving address for each of those four network groups. The updates we reviewed do not name the attacker.

Bitget confirmed the $387.5 million figure in its September 25 incident update.
What Users Can Expect
Bitget says user balances remain intact. Its User Protection Fund held more than $464 million when the first notice went out, and Bitget says the fund covers the loss. Deposits and trading stayed open. Withdrawals are the part that is paused.
The exchange says it found the attack path, including how the attacker got past existing security controls. It also says the underlying vulnerability has been fixed. Technical teams are now validating security before withdrawals restart. Bitget will announce the withdrawal status or timing by 4:00 AM UTC on September 26.
Mandiant and SlowMist are running the forensic work alongside Bitget's own teams. CEO Gracy Chen clarified on X that the coming update will cover status and timing rather than a full plan.
The Recovery Bounty
Bitget says some stolen assets are already frozen, thanks to exchanges, blockchain projects and security firms. It has now launched a Recovery Bounty Program. Anyone whose voluntary action leads to frozen funds can receive 5% of the amount frozen. The same 5% applies to recovered funds.
Bitget named Bybit's LazarusBounty initiative as a core channel for the effort. Actions taken under court orders or law-enforcement requests do not qualify. Bitget also opened a live tracing dashboard and an API of attacker address holdings. It asked exchanges, stablecoin issuers, bridges and custodians to watch those addresses.
Outside support came quickly. Binance founder CZ wrote on X that it was a tough day for Bitget. He said he expects Binance and the BNB Chain community to do everything they can to help.
How the Token Reacted
Bitget's own token barely moved. CoinGecko showed BGB near $1.99, up 0.3% over 24 hours, inside a range of $1.89 to $2.03. Market cap sat around $1.4 billion. The page also carried a banner noting the exploit Bitget reported on September 24.

CoinGecko BGB page, with its September 24 exploit banner.
Prices can shift fast after an exchange incident. This article is not investment advice, so check current data before making any decision.
Related News

XRP and XLM Slip From Weekly Highs as ETF Inflows Continue
XRP and XLM pulled back about 5% to 7% from their September 23 highs alongside Bitcoin and Ethereum, while US spot XRP ETFs kept taking in money on both days.

Coinbase Enables Native INJ Support, Removing the Bridge Step
Coinbase turned on native Injective support this week, letting users deposit and withdraw INJ directly on the Injective chain with no bridge or wrapped-token step required.

Wyoming Migrates Its State Stablecoin To Chainlink CCIP
Wyoming's Stable Token Commission completed a full migration of its Frontier Stable Token off its prior bridging setup and onto Chainlink's Cross-Chain Interoperability Protocol, after a security review found it was the only infrastructure meeting the state's requirements.