Bitget clarifies $388M in assets affected by security breach

Crypto exchange Bitget updated its incident report after Thursday’s security breach, saying roughly $387.5 million in assets were transferred to attacker-controlled addresses — about $35 million more than its initial $352 million estimate. The company said the revised total includes assets on Zcash and TRON that were not counted previously, and it has paused withdrawals while offering a bounty to incentivize freezing or recovering the funds.

By AI Newsroom· Reviewed by Pranav, Founder & Editor-in-ChiefPublished 1 minute agoUpdated 1 minute ago0 views
Bitget clarifies $388M in assets affected by security breach

Why It Matters

The adjustment raises the confirmed scale of one of the largest exchange breaches in recent memory and highlights challenges in rapid on-chain accounting across multiple networks during an active security incident. The response steps — withdrawal suspension and a bounty program — reflect common industry measures to limit further loss and recover stolen assets.

Key Facts

  • Updated affected assets: $387.5 million transferred to attacker-controlled addresses
  • Initial estimate: $352 million
  • Increase from initial to updated: $35.5 million
  • Networks involved: EVM networks, XRP Ledger, Zcash, TRON
  • Noted stolen tokens: XRP, ETH, USDT, ZEC, USDC, USDT0, XAUt, BNB, AVAX, TRX

Bitget published a revised incident report after a security breach disclosed on Thursday, increasing the tally of assets shifted to attacker-controlled addresses to about $387.5 million. The exchange said this figure is roughly $35 million higher than the $352 million estimate provided in its initial update, attributing the change to a more complete accounting that added transfers on Zcash and TRON which had not been included earlier.

The company said the incident involved addresses on Ethereum Virtual Machine (EVM) networks as well as the XRP Ledger, Zcash and TRON, and listed a variety of tokens among the funds moved, including XRP, Ether (ETH), Tether’s USDt (USDT), Zcash (ZEC), USDC, USDT0, XAUt, BNB, AVAX and TRX. Bitget stated the revised total reflects the transfers observed through on-chain tracing and does not indicate additional unauthorized movements, adding that the breach is contained and no further unauthorized transfers are possible.

Bitget said it will continue to keep withdrawals paused and has launched a bounty program intended to encourage parties to freeze or recover the affected assets. The follow-up report did not revisit remarks CEO Gracy Chen made on Thursday speculating that a North Korean hacking group may have been responsible for the attack.

Even with the updated figure, the Bitget breach ranks among the larger exchange incidents in the sector; the report noted that hackers took about $1.5 billion worth of Ether from Bybit in February 2025. Bitget’s steps to halt withdrawals and offer rewards to recover funds mirror typical industry responses aimed at limiting damage and pursuing asset recovery during cross-chain theft investigations.

Keep Reading