XRP, the native cryptocurrency to XRP Ledger by Ripple, accounts for the single largest slice of assets moved in Bitget’s September 24 hot-wallet incident.
On-chain monitor Lookonchain listed 102.93 million XRP, valued at about $157.48 million, ahead of 31,890 ETH and a mix of stablecoins, tokenized gold, BNB, AVAX and TRX.
Bitget’s own security notice put total funds affected at about $351.6 million and said the loss sits inside its User Protection Fund. The exchange has paused withdrawals while deposits and trading continue.
The XRP figure stands out because most of the stolen ledger balance has not followed the same conversion path as the Ethereum-family assets. Lookonchain said the attacker had already swapped most EVM-chain proceeds into 67,982 ETH, worth about $183 million.
The XRP position, by contrast, still sits largely on the XRP Ledger. That split matters for tracing: ether can be mixed and bridged quickly across many venues, while a concentrated XRPL balance is easier to watch but harder to freeze without coordinated issuer and exchange action.
Despite the scale of the hack and sheer size of the stolen amount in XRP, the cryptocurrency has not shown any sign of weakness. At the time of publishing (6:05 AM UTC, September 25) XRP was trading at $1.53, up 2.6% in the past 24 hours—as per CoinGecko data.
Read: Bitget Hacked for $351.6M: Withdrawals Frozen as CEO Points to North Korea
How the XRP Left Bitget Wallets
Bitget CEO Gracy Chen said systems flagged unauthorized transfers from some hot wallets at 18:31 UTC on September 24. In a later update she said the attacker compromised a backend wallet system, spoofed transaction data and triggered the firm’s own authorization process. Private-key theft, she said, has been ruled out. Cold wallets were not part of the drain.
The XRP transfers ran on a separate rail from the ETH, USDT and AVAX movements. Lookonchain’s itemized list treats the 102.93 million XRP as one of nine asset lines and the largest by dollar value. Independent dashboards that first tracked only EVM wallets understated the haul until the XRPL legs were added.
As of press time, Bitget has not published a per-asset official inventory; the XRP total therefore rests on Lookonchain’s original breakdown rather than on the exchange’s $351.6 million headline number, which is an aggregate estimate.
Chen said abnormal addresses have been flagged and reported to law enforcement and on-chain security firms. She has not given a withdrawal-reopening time, saying teams will announce a window only when they can keep it.
Bridged XRP and Unconfirmed Attribution
A smaller XRP flow is what investigators are using to argue a wider pattern. On-chain investigator SpecterAnalyst linked bridged XRP from the Bitget theft to funds from the July AFX incident, which that researcher attributed to TraderTraitor and, by extension, the Lazarus Group. The claim rests on a peel chain through NEAR Intents and related bridges into Ethereum addresses also tied, in that analysis, to the earlier AFX cluster.
That link is not an official finding. Chen has said some internet addresses seen in the intrusion resemble VPN patterns associated with a North Korea-linked group, while stressing identity is not confirmed. The Crypto Times has previously covered Lazarus-linked fund movement and the group’s longer theft record, but those files do not by themselves prove who ran the Bitget backend breach.
What is established on-chain is narrower: XRP was the biggest single asset taken, most of it has not been swapped into ETH, and only a thin bridged slice is being used to argue a connection to a prior theft.
Bitget says user balances remain intact and the protection fund covers the loss. Until the promised incident report is published, the XRP trail is a tracing problem, not a closed attribution.
Also read: Duelbits Hit by Suspected $4.3M Crypto Hack as Funds Shift to ETH
