Bitget raised its estimate of the stolen funds to about $387.5 million. Circle and Tether froze only a small fraction of the loss. The attacker has started moving XRP that Ripple cannot freez
- Bitget raised its estimate of the stolen funds to about $387.5 million.
- Circle and Tether froze only a small fraction of the loss.
- The attacker has started moving XRP that Ripple cannot freeze.
- Bitget will restart withdrawals in phases from September 28.
Bitget now estimates that attackers took about $387.5 million from its wallets on September 24, up from an initial $351.6 million after investigators added Zcash and TRON assets to the count. Circle and Tether have frozen roughly $318,000 of that sum, or about 0.08%. By September 26, the attacker had moved around 54 million XRP worth close to $83 million, an asset no issuer can block. Every wallet involved is publicly visible, yet most of the money remains out of reach.
Why the ETH in a blacklisted wallet stayed movable
Circle blacklisted an address labeled “Bitget Exploiter 8” at around 05:00 UTC on September 25, and Tether followed several hours later. The wallet held 218,023 USDT, 99,990 USDC and 170.47 ETH. Both stablecoins were locked at the token-contract level. The ETH sitting in the same address remained fully usable.
Across the attacker’s wider holdings, the same gap runs into nine figures. PublicAML counted about 68,465 ETH, then worth roughly $183 million, spread across attacker-controlled Ethereum wallets on September 25, including six wallets holding exactly 10,000 ETH each. Ether has no central issuer, so the only realistic intervention point appears when coins land at a custodial platform.
Asset
Status after the hack
Who can freeze it
USDT
~$218K frozen
Tether
USDC
~$100K frozen
Circle
ETH
~68,465 ETH in attacker wallets
No issuer
XRP
~$83M moved on Sept 26
Not Ripple; exchanges only on arrival
Funds on CEXs
Potential choke point
The receiving exchange
XRP was the largest single asset in the original on-chain breakdown, with about 102.93 million tokens initially valued near $157.5 million. According to CoinDesk, roughly 54 million XRP left three of the original attacker wallets by September 26, while about $75 million remained in place at the time of its analysis.
The XRP Ledger does include freeze functionality, but it applies only to issued assets such as tokens and stablecoins created on the ledger. XRP itself is the network’s native currency, so Ripple has no mechanism to blacklist it the way Circle blacklists USDC. Exchanges can still lock stolen XRP once it reaches an account they control.
Swaps across five chains in 15 seconds
The attacker appears to have understood where the choke points sit. Decrypt reported that stolen stablecoins were swapped for ETH within minutes. Bitquery reconstructed 21 outgoing transfers across eight blockchains totaling about $357.36 million, including one burst at 19:01 UTC that hit five chains within 15 seconds and another at 19:16 UTC that did the same in nine. By 14:34 UTC on September 25, it had traced 126.71 BTC that originated from stolen BNB and TRX routed toward Bitcoin.
MistTrack, SlowMist’s tracking arm, reported that Bitget proceeds are now moving through THORChain for swaps and cross-chain bridging, the same route that carried nearly $1.2 billion from the Bybit hack. Gracy Chen has formally asked THORChain to reject transactions from the flagged attacker addresses, saying decentralization does not justify handling known stolen funds.
How falsified data got past Bitget’s authorization system
Bitget says the private keys were never exposed. CEO Gracy Chen said attackers compromised a backend component of the wallet infrastructure and fed falsified transaction information into the authorization system, which then approved the transfers. TRM Labs describes it as an infrastructure compromise in which the data shown to the approval process was manipulated. The breach reached parts of Bitget’s hot and warm wallet layers, while cold storage was not affected. Chen described 19 unauthorized transfers; Bitquery’s count of 21 reflects its own chain-by-chain reconstruction.
The weak point sat in the systems instructing those keys, and whether they can be trusted is now the central security question. CertiK’s H1 2026 data shows wallet compromises caused more than $444 million in losses across 33 incidents, the costliest category in a half-year total of more than $1.31 billion.
Elliptic says multiple indicators, including infrastructure overlap with ETH from an earlier DPRK-attributed attack, make a North Korean link “highly likely.” Chen also pointed to techniques consistent with DPRK-linked groups. Formal attribution remains under investigation.
Circle moved within hours this time
The speed of Circle’s response stands out against the April Drift Protocol exploit, where around $230 million in USDC tied to the roughly $280 million theft crossed from Solana to Ethereum through Circle’s own Cross-Chain Transfer Protocol. ZachXBT argued Circle had about six hours to act. Circle replied that freezes should follow legal process, and Drift investors have since filed a class action whose allegations remain unproven. Circle has not said whether Drift shaped its handling of Bitget.
Tether has a longer track record. It reported freezing about $4.2 billion in USDT linked to illicit activity by February, and its T3 Financial Crime Unit with TRON and TRM Labs froze nearly $9 million after the $1.5 billion Bybit hack in 2025.
Almost three hours between detection and the last traced transfer
Bitget says it detected the breach at 18:31 UTC on September 24. Bitquery places the last of the 21 transfers at 21:23 UTC, after Bitget had shifted hot-wallet assets to reserves at 20:40. The authorization state during that window may explain the gap, and the promised root-cause report will need to address it directly.
What changes for Bitget users from here
Withdrawals return in stages, while deposits and trading continue. Bitget says balances are unaffected and the pause reflects security checks rather than a liquidity problem.
Date (08:00 UTC)
Withdrawals reopened
September 28
BTC
September 29
ETH (Ethereum, BSC, Arbitrum, Base, Optimism)
September 30
USDT (Ethereum, BSC, Solana, Tron)
October 2
Other tokens, fiat and P2P
Bitget says its Protection Fund, valued above $464 million, covers the loss. At $387.5 million, the hack equals about 83.5% of that figure, although recoveries, insurance or other corporate resources could reduce the actual draw on the fund. The fund is held largely in bitcoin, so its dollar value moves with the BTC price until any payout is settled. Bitget has also said the $387.5 million figure may still change as investigators classify more transactions.
The exchange has also launched a Recovery Bounty Program offering 5% of funds frozen and 5% of funds recovered to parties whose actions directly produce those results. With Mandiant and SlowMist assisting the investigation, Chen is scheduled to take questions in an AMA at 07:30 UTC on September 28, half an hour before BTC withdrawals reopen.
The post Bitget Hack: Attacker Moves $83M in XRP That Ripple Cannot Freeze appeared first on ETHNews.