Key Highlights
- Bitget confirms $387.5M hack after tracing more transactions involving Zcash and TRON.
- Recovery efforts are underway, with some funds frozen and a 5% bounty offered for eligible freezing and recovery efforts.
- Withdrawals remain suspended, with Bitget set to announce the withdrawal plan by September 26 at 4:00 AM UTC.
Bitget has confirmed that about $387.5 million in crypto was moved to attacker-controlled wallets during a security breach on September 24, 2026.
The Seychelles-based exchange said the updated figure came from further tracking of the stolen funds, while its teams continue to investigate the attack, recover assets and prepare to reopen withdrawals.
The new figure is higher than Bitget’s first estimate of $351.6 million. However, the exchange said the increase does not represent another $35.9 million in unauthorized transfers. Instead, the new amount comes from a fuller review of the transactions made during the attack.
The review added assets on Zcash and TRON that were not included in the first estimate.
Attack path identified and fixed
Bitget said the attack has been contained and that no more unauthorized transfers have taken place.
Its security team has also found the attack path and identified how the attacker was able to get around some of its security controls. The exchange said the weakness used in the attack has now been fixed.
The investigation is reportedly being carried out with cybersecurity firms Mandiant and SlowMist. Bitget said the work is still ongoing because the teams need more time to trace the funds and complete their checks. The exchange said more findings will be shared when they are confirmed.
Affected assets traced across networks
The affected assets span several networks and tokens. They include XRP, Ethereum, USDT, Zcash, USDC, USDT0, XAUt, BNB, Avalanche and TRX. Bitget said the incident affected Ethereum and other EVM networks, the XRP Ledger, Zcash and TRON.
Bitget has identified wallet addresses linked to the attacker on the affected networks. It has now shared those addresses with the wider crypto industry so exchanges, blockchain teams and security researchers can watch for movements of the funds.
Recovery efforts gain momentum
The recovery effort is already underway. Bitget said some of the affected assets have already been frozen through coordination with exchanges, blockchain projects, security firms and other members of the on-chain community.
To encourage more help, Bitget has launched a Recovery Bounty Program. Under the program, eligible participants can receive 5% of affected funds that are successfully frozen through their voluntary efforts.
Bitget offers bounty for recovered funds
Another 5% bounty is available when voluntary efforts directly lead to the recovery of affected funds.
Bitget said actions taken because of court orders, requests from law enforcement or other legal processes will not qualify for the bounty. The exchange will decide whether a submission qualifies and how much the participant receives.
The exchange has also opened tools that allow others to follow the stolen funds. These include a live tracking dashboard, a portal for submitting information about frozen or recovered funds and an API that tracks the attacker’s wallet holdings.
Withdrawals are still suspended as Bitget works to make sure its systems are safe before reopening them. The exchange said it is carrying out security checks and other technical work needed to restore the service.
Bitget said the withdrawal plan and timing will be announced by September 26 at 4:00 AM UTC. Until then, customers remain unable to withdraw funds from the exchange.
Bitget awaits next update
The breach was first detected at 18:31 UTC on September 24, according to Bitget’s earlier update covered by The Crypto Times. The exchange responded by suspending withdrawals while it investigated the unauthorized transfers. At that stage, the estimated loss stood at $351.6 million.
The latest update has now raised the confirmed amount to $387.5 million after more transactions were traced. Bitget said the figure may still change as investigators identify and classify more transactions.
The exchange has stressed that the incident remains contained and that no further unauthorized transfers are possible. Its investigation, fund tracing and recovery efforts are continuing, while users wait for the next update on when withdrawals will return.
Also Read: Jumper Announces JUMP Token Sale Starting September 29
