Bitget released an updated incident report on Friday regarding Thursday’s security breach, confirming that approximately $388 million in assets had been affected. This figure represents a revision upward from the $352 million initially reported, with onchain tracing indicating that $387.5 million was transferred to attacker-controlled addresses. The exchange attributed the discrepancy to a more complete accounting of transfers involving Zcash and TRON assets that were omitted from the initial estimate. Bitget stated that the incident remains contained, asserting that no further unauthorized transfers are possible.
The company announced it would continue to pause withdrawals while launching a bounty program designed to incentivize the freezing or recovery of the stolen assets. The breach involved addresses across Ethereum Virtual Machine networks, the XRP Ledger, Zcash, and TRON. Stolen assets included XRP, Ether, Tether’s USDt, Zcash, USDC, USDT0, XAUt, BNB, AVAX, and TRX. While CEO Gracy Chen previously speculated that a North Korean hacking group might be responsible, the follow-up report did not address these comments. Despite the revised total, this incident remains smaller than the February 2025 Bybit hack, where hackers stole about $1.5 billion worth of Ether.
The upward revision of stolen assets by roughly $35 million underscores the volatility of initial loss estimates during complex multi-chain security incidents. By explicitly linking the discrepancy to specific blockchain networks like Zcash and TRON, Bitget attempts to clarify the technical scope of the breach, yet the continued suspension of withdrawals signals lingering operational uncertainty. This approach highlights the tension between maintaining user confidence through transparency and managing the immediate liquidity risks associated with large-scale asset theft. The launch of a bounty program serves as a standard mitigation tactic, but its effectiveness depends heavily on the speed of response and cooperation from other exchanges and law enforcement agencies.
From a market structure perspective, this event reinforces the persistent vulnerability of centralized exchanges despite evolving security protocols. The involvement of diverse asset types, including stablecoins and privacy coins, complicates tracking efforts and increases the potential for fragmented recovery outcomes. Investors and institutional participants will likely scrutinize Bitget’s subsequent compliance actions and audit trails to assess whether their internal controls were sufficient to prevent such extensive unauthorized transfers. The comparison to the larger Bybit incident provides context, but each breach tests the resilience of the broader crypto infrastructure differently, particularly when cross-chain interactions are exploited.


