Bitget Raises Hack Estimate From $228 Million To $387.5 Million
The Bitget hack ultimately affected about 387.5 million dollars in assets, compared to an initial on-chain estimate of 228 million dollars. The platform claims to have contained the attack but keeps withdrawals suspended during its security checks.

In Brief
- The Bitget hack ultimately reaches 387.5 million dollars.
- Withdrawals remain suspended during security checks.
- The attack reportedly exploited a critical backend system, without private key theft.
- Bitget’s protection fund is intended to cover losses.
- Part of the stolen assets has already been converted to ETH.
The Bitget hack exceeds initial estimates
Initial alerts published by Arkham and other analysts on this hack reported about 228 million dollars transferred in just 18 minutes. This data mainly concerned immediately identifiable movements across seven networks.
Bitget first announced a loss of 351.6 million dollars. On September 25, the platform revised this amount to 387.5 million dollars after including transfers carried out on Zcash and Tron. This revision does not correspond to new fraudulent withdrawals, according to the company.
The main confirmed elements show the scale of the incident :
- Unauthorized transfers began on September 24 ;
- The total amount now reaches about 387.5 million dollars ;
- Initial analyses had tracked seven blockchains, later adding Zcash and Tron ;
- The affected assets include XRP, ETH, USDT, ZEC, USDC, USDT0, XAUt, BNB, AVAX, and TRX ;
- The platform’s cold wallets are reportedly unaffected.
The new total may still evolve as transactions are classified. Bitget specifies, however, that no new unauthorized movements have been recorded since the incident was contained.
An internal system reportedly validated fake transfers
According to Gracy Chen, Bitget’s CEO, the hacker compromised a critical component of the system responsible for managing the exchange’s wallets. They then falsified transaction data to trigger the internal authorization process.
“The hacker compromised a critical backend system and triggered our authorization process to move funds,” declared Gracy Chen. The investigation is still seeking to determine how the initial intrusion was carried out.
Bitget claims private keys were not compromised. This detail suggests the attack did not result directly from stealing a key to freely sign transactions. Rather, it exploited the infrastructure responsible for preparing and approving transfers.
The platform had distributed funds between hot, warm, and cold wallets. This hack reportedly affected some of the first two categories, which are regularly connected to the exchange’s services. The separate Bitget Wallet product, which operates in self-custody on another infrastructure, was not affected.
The protection fund must cover losses
Bitget assures that the balances displayed on accounts remain accurate. Deposits and trading operations still function, but withdrawals remain suspended until the checks are completed.
The platform states its protection fund exceeds 464 million dollars. This reserve would exceed the currently identified amount by about 76.5 million dollars, or a margin close to 20%. Its value may vary, however, since a significant portion of the fund is held in bitcoin.
This coverage remains an assertion by Bitget. It means the company plans to absorb losses without passing them on to its customers, but actual reimbursement will depend on the final assessment and available liquidity.
The hacker has already converted part of the assets from Ethereum-compatible networks. Lookonchain estimates that 67,982 ETH, valued at around 183 million dollars, were obtained after several exchanges. These conversions complicate token freezing but do not make on-chain tracking impossible.
Bitget launches a bounty to recover assets
Bitget is working with Mandiant, SlowMist, authorities, and several ecosystem actors. Some assets have already been frozen with the help of platforms, stablecoin issuers, and blockchain projects.
The exchange offers a bounty equivalent to 5% of funds frozen or recovered through eligible voluntary intervention. It also provides a dashboard tracking addresses controlled by the hacker.
The company must announce the timeline for resuming withdrawals no later than September 26. The vulnerability is said to have been fixed, but teams continue to test before reopening the service.
Gracy Chen provisionally attributes the operation to North Korean hackers, based on observed IP addresses and methods. This attribution remains Bitget’s and has not yet been publicly confirmed by an independent authority.
Maximize your Cointribune experience with our "Read to Earn" program! For every article you read, earn points and access exclusive rewards. Sign up now and start earning benefits.
Diplômé de Sciences Po Toulouse et titulaire d'une certification consultant blockchain délivrée par Alyra, j'ai rejoint l'aventure Cointribune en 2019. Convaincu du potentiel de la blockchain pour transformer de nombreux secteurs de l'économie, j'ai pris l'engagement de sensibiliser et d'informer le grand public sur cet écosystème en constante évolution. Mon objectif est de permettre à chacun de mieux comprendre la blockchain et de saisir les opportunités qu'elle offre. Je m'efforce chaque jour de fournir une analyse objective de l'actualité, de décrypter les tendances du marché, de relayer les dernières innovations technologiques et de mettre en perspective les enjeux économiques et sociétaux de cette révolution en marche.
The views, thoughts, and opinions expressed in this article belong solely to the author, and should not be taken as investment advice. Do your own research before taking any investment decisions.