Summary

  • Bitget has issued an updated report on its recent security breach, revising the total value of affected assets upward to approximately $387.5 million from an initial estimate of $351.6 million.
  • The exchange clarified that the increased figure is the result of exhaustive on-chain transaction tracing rather than a ongoing attack or secondary security incident.
  • Forensics teams have identified and patched the underlying exploit vector, confirming that unauthorized access pathways have been completely closed.
  • Independent cybersecurity and blockchain analytics firms Mandiant and SlowMist have been brought in to assist with the investigation, asset recovery, and infrastructure auditing.
  • Affected assets span multiple blockchain networks, including Ethereum, EVM-compatible chains, XRP Ledger, Zcash, and TRON.
  • A recovery bounty program has been established to reward individuals or entities whose actions directly lead to the freezing or retrieval of stolen funds.
  • Bitget has outlined a multi-day timeline for restoring user withdrawals, starting with Bitcoin on September 28, followed by Ether on September 29, USDT on September 30, and all remaining assets, fiat services, and peer-to-peer trading by October 2.
  • The platform reiterates that customer account balances remain intact and fully covered by its internal protection reserves and financial arrangements.

Cryptocurrency exchange Bitget has released a detailed progress update regarding the major security breach discovered earlier this week, revising the financial scope of the incident and laying out a clear, step-by-step timeline for resuming standard operations. According to the platform’s latest findings, the total value of digital assets transferred to attacker-controlled wallets is now estimated at approximately $387.5 million. This represents a notable increase from the exchange’s initial estimate of $351.6 million reported shortly after the attack was detected.

Bitget emphasized that the $35.9 million upward adjustment does not indicate an ongoing security compromise or a second wave of unauthorized transfers. Instead, the revised total reflects the detailed findings of ongoing forensic transaction tracing across complex multi-chain protocols. As technical teams and external security analysts continue to map out every movement of the compromised funds, previously untracked token movements across various smart contracts and bridge protocols have been formally cataloged into the total loss tally.

The disclosure marks a critical pivot in the exchange’s response strategy, shifting the operational focus from immediate crisis containment to forensic asset recovery, platform hardening, and the methodical restoration of normal user services. While the scale of the theft places the breach among the larger exchange exploits recorded in recent years, Bitget continues to maintain that its balance sheet and dedicated protection mechanisms are fully capable of absorbing the financial impact without compromising user funds.

Forensic Investigation and Exploit Remediation

In its official assessment, Bitget reported that its internal security team, working alongside specialized external cyber forensic researchers, has successfully identified the attack path used by the perpetrators. The unauthorized transfers relied on a specific flaw that allowed the attacker to bypass existing security checks and authorization protocols governing the exchange’s hot wallet infrastructure.

Bitget stated that the underlying vulnerability has been completely remediated. Security controls across all hot wallet management systems and API gateways have been re-engineered, patched, and subjected to rigorous stress testing to guarantee that no further unauthorized withdrawals can occur.

To ensure the integrity of its remediation efforts and conduct a thorough post-mortem analysis, Bitget has engaged two prominent third-party security firms: cybersecurity titan Mandiant and specialized blockchain forensic firm SlowMist. The two independent entities are assisting Bitget’s internal teams in dissecting the exploit vector, auditing the updated codebase, and tracing the stolen funds across public ledgers.

The scope of the breach covers a diverse range of digital assets across multiple underlying blockchain architectures. Rather than targeting a single asset or single network, the attacker managed to siphon assets across several distinct infrastructure ecosystems, including:

  • Ethereum and various Ethereum Virtual Machine (EVM)-compatible networks
  • The XRP Ledger (XRPL)
  • Zcash (ZEC)
  • TRON (TRX)

The multi-chain nature of the attack added significant complexity to the initial loss calculations, as forensic teams were required to monitor parallel liquidity pools, cross-chain bridges, and decentralized exchanges operating across different consensus models.

To aid in the reclamation of lost funds, Bitget has officially launched a recovery bounty program. Under the terms of the program, security researchers, white-hat hackers, and blockchain analytics professionals who provide actionable intelligence or direct assistance that results in the freezing or recovery of stolen funds will be eligible for financial rewards. The bounty payouts are calculated as a percentage of the total asset value successfully secured or returned to the exchange.

Bitget revealed that some progress on asset recovery has already been made. Through real-time monitoring and swift coordination with stablecoin issuers, centralized exchange partners, and decentralized finance protocols, a portion of the stolen assets has already been identified and frozen on-chain. Efforts to trace and immobilize the remaining funds continue around the clock in collaboration with law enforcement agencies and global cybersecurity networks.

The Staged Withdrawal Roadmap and Operational Testing

With the security flaw addressed and platform infrastructure undergoing continuous audit, Bitget has unveiled its schedule for reopening user withdrawals. Rather than enabling full withdrawal functionality across all supported assets simultaneously—a approach that can strain security monitoring systems and create system-wide operational bottlenecks—the platform will execute a phased rollout over several days.

The staged resumption schedule is structured as follows:

  • September 28: Bitcoin (BTC) withdrawals are scheduled to reopen first, providing a testbed for the platform’s core accounting and hot-wallet withdrawal pipelines under controlled conditions.
  • September 29: Ether (ETH) withdrawals across all supported Layer-1 and Layer-2 networks are slated to follow.
  • September 30: Tether (USDT) withdrawals across all supported blockchain networks will be reinstated, restoring access to the market’s primary liquidity reserve.
  • October 2: Withdrawals for all remaining altcoins, along with fiat deposit/withdrawal channels and peer-to-peer (P2P) trading services, are expected to return to standard operation.

This gradual timeline represents one of the most vital operational tests for Bitget following the exploit. Implementing a multi-stage rollout allows the exchange’s security monitoring systems to analyze transactional traffic patterns in real time, verifying that the patched wallet infrastructure handles live user requests without unexpected performance degradation or security anomalies.

Throughout the incident, Bitget has repeatedly reassured its global user base that individual account balances remain entirely intact. The exchange relies on dedicated asset protection reserves, designed specifically to serve as a backstop during black swan operational events or security breaches of this nature. The coming days will provide users with their first opportunity to test these assurances in practice as processing queues open and capital flows out of the platform.

Moving from Containment to Long-Term Recovery

The adjustment of the official loss figure to $387.5 million elevates the severity of the exploit, making it one of the most prominent security events in the digital asset sector this year. However, the exchange’s rapid publication of a technical diagnosis, engagement of third-party security auditors like Mandiant and SlowMist, and clear public timetable reflect a calculated effort to preserve market confidence and operational transparency.

In the immediate aftermath of a major exchange exploit, the primary risk for trading venues is not merely the direct financial loss, but the potential erosion of user trust and the operational panic that can follow prolonged service suspensions. By maintaining clear lines of communication and providing actionable dates for service restoration, Bitget aims to mitigate systemic uncertainty among its institutional and retail clientele.

The execution of the recovery bounty and cross-industry freezing initiatives highlights the evolving nature of post-breach response in the cryptocurrency industry. While modern privacy tools and cross-chain swapping protocols complicate recovery efforts, the inherent transparency of public blockchains—combined with active cooperation among major exchanges and analytics firms—frequently allows victimized platforms to freeze substantial portions of illicitly acquired assets before they can be fully liquidated.

For Bitget, resolving the immediate technical breach was the essential first phase of its crisis response. The true operational test now lies in executing its staged withdrawal roadmap on schedule, ensuring that user transactions are processed without friction, and continuing the multi-jurisdictional chase to recover the remaining stolen funds.

Leave a Reply

Your email address will not be published. Required fields are marked *