Bitget Adds $35.9 Million to Its September 24 Breach Estimate
Bitget has raised the estimated value of assets transferred to attacker-controlled addresses during its September 24 security breach to approximately $387.5 million, up from the $351.6 million figure disclosed immediately after the attack.
The $35.9 million revision represents an increase of roughly 10.2% from the original estimate and reflects a broader accounting of the same incident rather than another round of unauthorized withdrawals.
Bitget said the updated figure incorporates affected assets on Zcash and TRON that were missing from its initial calculation. The exchange has now identified affected assets including XRP, ETH, USDT, ZEC, USDC, USDT0, XAUt, BNB, AVAX and TRX across Ethereum and other EVM networks, the XRP Ledger, Zcash and TRON.
The revision significantly expands the scope of the $351.6 million security breach Bitget initially disclosed on September 24, when unauthorized transfers were detected at approximately 18:31 UTC from portions of the exchange’s hot and warm wallet infrastructure.
Bitget continues to say its cold wallets were unaffected and that customer account balances remain intact.
The exchange has also reached an important technical milestone. Its security team says it has identified both the attack path and the methods used to bypass existing security controls, and that the underlying vulnerability has now been remediated.
“The incident remains contained and no further unauthorized transfers are possible,” Bitget said in its latest security update.
That claim marks a shift from emergency containment toward recovery, although Bitget has not yet released the detailed forensic report needed to independently assess exactly how the attackers penetrated its systems and why existing protections failed.
Security specialists Mandiant and SlowMist are assisting with the investigation, while Bitget says tracing of the stolen assets remains ongoing. The exchange cautioned that the $387.5 million figure could still change as additional transactions are classified.
The incident joins a growing series of large crypto security failures in which the immediate dollar estimate evolves as investigators reconstruct activity across multiple networks. Other incidents, including cross-chain payment exploits and custodial wallet breaches, have similarly highlighted the difficulty of determining the full exposure before tracing is complete.
A 5% Bounty Turns Recovery Into an Industry-Wide Effort
Bitget is now attempting to accelerate the recovery process by putting a direct financial incentive behind efforts to identify, freeze and return stolen funds.
Under its newly announced Recovery Bounty Program, an eligible person or organization whose voluntary actions directly cause affected assets to be frozen can receive a bounty equal to 5% of the amount successfully frozen.
Bitget is separately offering a 5% reward tied to funds successfully recovered through eligible voluntary efforts.
The program is not limited to actions taken after the announcement. Bitget says voluntary efforts that had already resulted in funds being frozen can also qualify.
There are important exclusions. Actions carried out because of court orders, law-enforcement requests or other compulsory legal processes are not eligible, and Bitget retains final authority over eligibility, contribution calculations and payments.
The exchange is also using Bybit’s LazarusBounty initiative as one of the core channels supporting the recovery effort and has published a live tracing dashboard, reporting portal and API intended for exchanges, stablecoin issuers, bridges, custodians, blockchain projects and security researchers monitoring the stolen assets.
This type of coordinated response matters because the recoverability of stolen crypto varies sharply by asset. Centralized stablecoin issuers can blacklist certain tokens, while native assets such as Bitcoin or Ether cannot simply be frozen at the protocol level. Recovery can therefore depend on attackers eventually interacting with exchanges, bridges or other identifiable infrastructure.
Similar questions have surfaced after protocols considered how to recover assets after cross-chain exploits, showing how technical control, governance and legal authority increasingly overlap during major crypto incidents.
Withdrawals Will Restart in Stages Beginning September 28
Bitget has also published a timetable for restoring withdrawals after suspending them during its emergency response.
Bitcoin withdrawals on the Bitcoin network are scheduled to resume at 08:00 UTC on September 28. Ether withdrawals will follow at 08:00 UTC on September 29 across Ethereum, BNB Smart Chain, Arbitrum, Base and Optimism.
USDT withdrawals are scheduled to return at 08:00 UTC on September 30 across Ethereum, BNB Smart Chain, Solana and TRON. Bitget plans to restore withdrawals for other tokens, along with fiat and peer-to-peer services, at 08:00 UTC on October 2.
Trading and deposits have remained operational during the withdrawal suspension.
Bitget says the staggered restart is intended to allow additional validation of its withdrawal infrastructure rather than reflecting a shortage of customer assets. CEO Gracy Chen is scheduled to hold a live AMA on September 28 at 07:30 UTC to discuss the incident, the withdrawal process and next steps.
The gradual reopening is an important operational test. Crypto platforms can technically contain an exploit while still facing a second challenge in safely restoring services, something also seen when wallet infrastructure problems disrupted asset access or when broader security events forced platforms to restrict user activity.
The Revised Number Makes Bitget’s Protection Fund More Important
The difference between $351.6 million and $387.5 million is not cosmetic.
It changes the financial picture.
When Bitget first disclosed the incident, it said its User Protection Fund held more than $464 million and would cover the financial impact of the breach.
Using that September 24 valuation, a $387.5 million incident is equivalent to roughly 84% of the stated value of the fund.
That does not mean Bitget will necessarily need to liquidate 84% of the fund. Some stolen assets may be frozen or recovered, and the exact economic loss ultimately absorbed by the exchange could be lower. The value of the protection fund can also fluctuate with the market value of its underlying assets.
But the revised estimate substantially reduces the apparent buffer between the reported breach and the backstop Bitget pointed to when assuring customers their balances were protected.
That makes recovery more than a symbolic exercise.
Every dollar successfully frozen or returned reduces the amount the exchange potentially has to absorb itself.
The bounty economics make that obvious. Paying 5% to recover an asset leaves Bitget dramatically better off than losing 100% of it. Even relatively large bounty payments could therefore make financial sense if they materially increase recovery rates.
The Fix Matters, but the Root-Cause Report Matters More
There is a positive development in Bitget’s latest disclosure: this is no longer an active drain.
If the exchange’s technical assessment is correct, the vulnerability has been closed and the attacker can no longer use the same path to extract additional assets.
That is important.
But it answers only one of the major questions.
The next question is how an attacker was able to move nearly $400 million through infrastructure that was supposed to prevent unauthorized transfers in the first place.
Crypto security incidents are often judged by the final amount stolen, but investors should pay just as much attention to the control that failed. A vulnerability in a narrow application component creates a different long-term risk from compromised private keys, broken transaction-approval logic or a systemic failure in wallet architecture.
Recent cases such as the MultiversX response to a VM exploit demonstrate how much the recovery strategy depends on precisely where a security failure occurs.
Bitget says it has identified how existing controls were bypassed. Until the full forensic explanation is published, however, outside observers cannot properly judge whether the remediation fixes one exploitable bug or addresses a broader weakness in the exchange’s security model.
The Recovery Rate May Now Matter as Much as the Headline Loss
The $387.5 million figure is large, but it may not end up being the final economic cost.
The next phase is a race between the attacker and an unusually broad recovery network.
Exchanges can flag deposit addresses. Stablecoin issuers can freeze tokens. Blockchain analytics firms can trace movements. Bridges and custodians can monitor incoming assets. Investigators can attempt to connect wallets with identities. Bitget’s bounty now gives those participants a direct financial incentive to act voluntarily.
That structure is one of the more interesting consequences of the breach.
Crypto’s transparent ledgers make stolen assets unusually visible, but visibility is not the same thing as recoverability. An investigator may know exactly where hundreds of millions of dollars are sitting while having no technical mechanism to stop them from moving.
That gap becomes even more important when attackers move funds across several blockchains and asset types.
The industry has seen the same problem after security flaws in transaction authorization systems: the technical weakness may be repaired quickly, while the financial consequences continue long afterward.
For Bitget, three numbers now matter.
The first is $387.5 million — the current estimate of what reached attacker-controlled addresses.
The second is the amount eventually frozen or recovered.
And the third is what Bitget ultimately has to absorb after that recovery effort is finished.
The first number just became considerably worse.
The next few weeks will determine whether the other two move in Bitget’s favor.
Johan Shamshad is a financial markets writer at Dave Finances covering cryptocurrencies, trading platforms, brokers, fintech, financial regulation, and developments across global markets. He previously worked at Gulf News, adding newsroom experience to his coverage of fast-moving financial and digital-asset markets.
His work focuses on identifying market-moving events, company developments, regulatory changes, product launches, and shifts in trading and financial infrastructure.
Johan contributes news and analysis designed to help readers understand not only what happened, but why a development matters and how it may affect the wider financial landscape.

