A revised assessment shows that the September 24 breach of the Bitget exchange resulted in the theft of approximately $387.5 million in digital assets.

Updated loss estimate

Bitget announced that the figure for stolen assets has climbed from the previously reported $351.6 million. The increase stems from on-chain analysis that uncovered additional holdings of Zcash and TRON that were not part of the initial count. The exchange’s chief executive confirmed that the new amount reflects transfers that occurred during the original intrusion and that no further unauthorized moves have been detected.

Ongoing investigation and remediation

Security teams spotted the illicit outflows from several hot wallets at 18:31 UTC on the day of the attack and immediately halted withdrawals while keeping deposits and trading open. The firm has engaged blockchain security firms Mandiant and SlowMist to conduct forensic work and to determine how the attackers penetrated its systems. According to the latest update, the vulnerability has been patched and the technical staff are validating the restored infrastructure before any withdrawal function can be re-enabled.

Industry-wide recovery effort

Bitget is coordinating with other exchanges and blockchain projects to immobilize the stolen tokens. Both Binance and Bybit have publicly pledged assistance, with Bybit planning to extend its LazarusBounty platform to monitor the illicit funds. The exchange has also released a live tracing dashboard, a reporting portal and an API that lists attacker addresses, enabling other platforms, stablecoin issuers and bridge operators to keep the assets under watch.

New bounty program

To accelerate the freezing and retrieval of the crypto, Bitget introduced a Recovery Bounty Program. Entities that voluntarily succeed in locking up stolen assets may earn a reward equal to 5% of the value they freeze. An additional 5% is offered for assets that are ultimately recovered through eligible voluntary actions. The program also applies retroactively to freezes that occurred before its launch, though any actions taken under court order or law-enforcement directives are excluded.

Withdrawal status and user protection

Customer withdrawals remain on hold, with Bitget promising an update on the restart schedule by 04:00 UTC on September 26. Deposits and trading continue to operate. The exchange’s User Protection Fund, which held more than $464 million at the time of the incident, is intended to cover user losses, though the ultimate burden will depend on how much of the $387.5 million can be reclaimed through the collaborative recovery campaign.

Why it matters

The enlarged loss figure makes the Bitget breach one of the largest crypto thefts of the year, underscoring the continuing vulnerability of centralized exchanges. The coordinated freezing effort and the introduction of a bounty scheme illustrate a growing industry willingness to pool resources and incentives to mitigate large-scale thefts. Successful recovery could restore confidence among users and set a precedent for collective response to future security incidents.