Major Crypto Exchange Hack Grows to $387.5 Million as Withdrawals Remain Frozen

Hackers

Crypto exchange Bitget has increased its estimate of assets transferred to attacker-controlled wallets from $351.6 million to approximately $387.5 million. Withdrawals remain suspended as investigators examine how attackers bypassed the exchange’s security controls.

Bitget Discovers More Missing Assets

Bitget detected unauthorized transfers from portions of its hot-wallet infrastructure at approximately 18:31 UTC on September 24. The company initially estimated that $351.6 million had been affected.

On Friday, September 25, Bitget increased that figure to approximately $387.5 million after identifying additional transactions involving Zcash and Tron. The revised total reflects a more complete accounting of the attack, according to the company, rather than additional transfers occurring after the incident was contained.

The stolen assets included XRP, Ether, Tether, USD Coin, Zcash, Tether Gold, BNB, Avalanche and Tron. The breach affected hot and warm wallets, which exchanges use to process transactions and maintain liquidity. Bitget says its offline cold wallets were not compromised. Bitget Support Center

Deposits and trading remain available, but customers still cannot withdraw assets. Bitget said it would announce the status and expected timing of withdrawals by September 26 at 4:00 a.m. UTC.

The company has hired Google-owned cybersecurity firm Mandiant and blockchain security company SlowMist to assist with the investigation.

How Attackers Moved the Money Without Stealing Private Keys

Bitget CEO Gracy Chen said the attackers compromised a backend system within the company’s wallet infrastructure. They allegedly used that access to create fraudulent transaction data that passed through Bitget’s authorization process.

The distinction is important.

A private key is the secret credential that directly controls cryptocurrency stored in a wallet. If an attacker obtains that key, the attacker can generally authorize transactions without going through the exchange’s normal systems.

Bitget says its private keys remained secure. In this case, attackers allegedly manipulated the operational system that prepared and approved transfers.

A useful comparison is a bank vault. The attackers did not need to steal the vault key if they could gain access to the office that prepares withdrawal orders and produce instructions that appeared legitimate.

That explanation comes from Bitget and has not yet been independently confirmed through a complete technical report. The company says it has identified and repaired the underlying vulnerability, but it has not publicly disclosed enough technical information for outsiders to evaluate how the controls failed.

The Withdrawal Freeze Is the Most Important Test

The size of the theft will attract attention, but the withdrawal freeze may ultimately matter more to customers and investors.

Cryptocurrency sitting on a centralized exchange depends on several layers of infrastructure. The blockchain can function correctly while a customer remains unable to access assets because the exchange has paused transfers.

This is counterparty risk in its clearest form. A customer may own Bitcoin, Ether or another cryptocurrency on an account statement, yet access still depends on the exchange’s technology, liquidity and willingness to process the withdrawal.

Bitget says customer balances remain accurate and that the incident has been contained. Those assurances remain company statements until withdrawals resume and customers can move their assets normally.

The speed and stability of that reopening will provide one of the strongest signals about the exchange’s financial and operational condition. A prompt restoration would support Bitget’s claim that the damage was limited to part of its wallet infrastructure. A prolonged or restricted reopening would raise deeper questions about liquidity and internal controls.

The Protection Fund Covers the Loss on Paper

Bitget says its User Protection Fund holds more than $464 million and can cover the full loss.

That claim sounds reassuring, but the updated $387.5 million figure would equal roughly 84% of the fund’s stated value. If the entire incident were charged against the fund at those values, approximately $76.5 million would remain before replenishment.

There is another complication. The protection fund holds about 5,500 Bitcoin, so its dollar value rises and falls with the price of Bitcoin. It does not operate like government-backed bank deposit insurance, and investors should avoid treating it as an equivalent guarantee.

Bitget also reported a 122% total reserve ratio in its August proof-of-reserves disclosure. That means the assets included in the report exceeded the corresponding customer balances at the time of the snapshot.

Proof of reserves can provide useful information about wallet balances. It does not provide a complete assessment of liabilities, operational security, corporate obligations or the quality of an exchange’s internal controls.

The meaningful test now is whether Bitget can cover the loss, reopen withdrawals and publish enough evidence for customers to verify that the company remains adequately funded.

Recovery Efforts Have Started

Bitget has launched a recovery program offering a 5% bounty to eligible parties that help freeze or recover stolen assets. The exchange has also published wallet addresses connected to the incident so exchanges, stablecoin issuers and blockchain companies can monitor the funds.

Circle and Tether have already frozen approximately $318,000 in USDC and USDT connected to an attacker wallet. That is a very small portion of the total amount. Other identified addresses held more than 63,000 Ether, according to CoinDesk.

This illustrates an important difference among digital assets.

Companies such as Circle and Tether can blacklist addresses holding their issued stablecoins. Native cryptocurrencies such as Bitcoin and Ether generally cannot be frozen by an issuer. Investigators may track those coins publicly, but stopping or recovering them usually requires cooperation from an exchange, bridge or other service where the attacker eventually tries to move or convert the assets.

Bitget’s recovery rate will depend partly on how quickly the attackers move funds and whether they pass through services willing or legally required to intervene.

What the Breach Means for Crypto Investors

Centralized Exchanges Remain a Point of Failure

Blockchain networks use decentralized systems, but most investors interact with them through centralized companies.

An exchange can offer convenient trading, tax records and account recovery while also becoming a concentrated security target. The Bitget incident appears to have exploited that centralized operational layer rather than a flaw in XRP, Ethereum or the other affected networks.

Investors therefore face two different risks: the price risk of the cryptocurrency and the custody risk of the company holding it.

“Cold Wallets Are Safe” Does Not Resolve Every Concern

Cold storage is designed to isolate assets and signing credentials from internet-connected systems. Keeping most customer assets offline can reduce the amount exposed during a breach.

Bitget says its cold wallets were untouched. Even so, attackers reportedly moved hundreds of millions of dollars from the exchange’s operational wallets. That raises questions about transfer limits, automated approvals, monitoring systems and the amount of capital accessible through connected infrastructure.

Investors should watch for the technical report to explain why unusual transactions were authorized and why transfers reportedly continued after the exchange’s detection timestamp.

Forbes identified blockchain transactions that continued for nearly three hours after Bitget says its systems detected the activity. The report acknowledged that disabling wallets across several networks is more complicated than flipping a single switch, but the gap remains an important issue for the investigation.

U.S.-Listed Crypto Companies Could Gain a Trust Advantage

Bitget is privately held, so investors cannot buy or sell its shares on a U.S. exchange. The incident could still affect publicly traded cryptocurrency businesses.

Coinbase, Robinhood, Bullish and other regulated platforms compete partly on trust, custody and compliance. A large breach at a rival can strengthen their marketing position if customers begin moving toward exchanges perceived as having stronger controls.

Circle’s ability to freeze stolen USDC also demonstrates one reason regulated stablecoin issuers may become more deeply integrated into institutional cryptocurrency markets. That power can help recover stolen funds, although it also reminds investors that centralized stablecoins depend on the issuer’s policies and legal obligations.

Cybersecurity spending across the crypto industry could rise as exchanges review wallet backends, approval systems and employee access. Mandiant’s involvement shows that large crypto platforms increasingly require the same incident-response capabilities used by banks, governments and major corporations.

The Market May Be Underestimating the Bigger Risk

The immediate reaction may remain contained because Bitget says customer balances are intact and the wider cryptocurrency market continues operating normally.

That interpretation could prove correct. It could also overlook a broader issue.

The attack reportedly targeted the systems that an exchange uses to decide whether transactions are legitimate. Those operational controls exist across the industry. If Bitget’s final report identifies a software weakness, vendor problem or widely used infrastructure component, other exchanges may need urgent security changes.

The incident could therefore become more significant even if Bitget absorbs the entire financial loss. The central question is whether the vulnerability was unique to Bitget or reflects a more common weakness in exchange wallet infrastructure.

About Author

Leave a Reply