Bitget released a follow-up on the security incident that unfolded earlier this week, stating that roughly $388 million in user assets were shifted to wallets controlled by the perpetrators. The new calculation reflects a more thorough accounting of transfers that occurred during the attack, increasing the previously announced $352 million figure by about $35 million.
Scope of the compromised assets
The breach touched several blockchain ecosystems, including Ethereum-compatible networks, the XRP Ledger, Zcash and TRON. Among the tokens taken were XRP, Ether, Tether’s USDT, Zcash, USDC, a token labelled USDT0, XAUt, Binance Coin, Avalanche and TRX. Bitget’s on-chain tracing identified $387.5 million that had already been moved to addresses linked to the attackers. The company emphasized that no additional unauthorized movements have been detected and that the situation is contained.
Response and recovery efforts
In the wake of the incident, Bitget has kept withdrawals on hold to prevent further losses. It also launched a bounty initiative, offering rewards to individuals who can help freeze or retrieve the stolen funds. While the exchange has not confirmed the identity of the threat actors, earlier comments from CEO Gracy Chen suggested a possible link to a North Korean hacking group, a claim that was not addressed in the latest report.
Comparison with prior crypto hacks
The incident ranks among the industry’s most sizable breaches. For perspective, a separate attack on Bybit in February 2025 resulted in the theft of approximately $1.5 billion worth of Ether. Bitget’s updated numbers underscore the growing scale of cross-chain exploits targeting major exchanges.
Why it matters
The revised loss figure highlights the challenges exchanges face in monitoring and securing assets across multiple blockchain networks. As attackers exploit interoperability, platforms may need to strengthen multi-chain surveillance and rapid response mechanisms. The ongoing withdrawal pause and the bounty program illustrate how exchanges are adapting their crisis management strategies, while the incident serves as a reminder to users of the inherent risks in custodial services.




