Community Trust ScoreVerified
Bitget’s breach just got more expensive. The exchange revised its hack loss estimate up to $387.5 million after tracing efforts uncovered additional Zcash and TRON assets that weren’t part of the original tally. The breach hit on Sept. 24.
Security teams caught the unauthorized transfers from hot wallets at 18:31 UTC on Sept. 24. Withdrawals got suspended almost immediately. Deposits and trading kept running. Since then, no new unauthorized transactions have occurred — which is at least something. The vulnerability has been patched, and Bitget brought in blockchain security firms Mandiant and SlowMist to dig into how the attackers got in. More findings are expected as the investigation moves forward.
The number — $387.5 million — is big. Really big.
Bounty Program and Industry Allies
Bitget didn’t just sit on its hands. The exchange launched a Recovery Bounty Program, offering 5% of any successfully frozen funds to whoever pulls it off. Another 5% goes out for assets that come back through voluntary means. The incentives are retroactive too — actions taken before the program’s announcement still qualify. Compulsory legal actions, though, are excluded from bounty eligibility. No reward for court-ordered freezes.
Whether the program works depends heavily on where the stolen funds end up. Stablecoin issuers and centralized exchanges can freeze assets if they catch them in time. Self-custodied crypto is a different story. Once funds hit a private wallet, it’s basically a dead end for freezing efforts. That’s the hard reality of how blockchain asset recovery works.
Binance and Bybit are both involved in the recovery push. Bybit CEO Ben Zhou confirmed the exchange is helping and said they’ve updated the LazarusBounty platform as part of the effort. The name is a reference to the Lazarus Group, the North Korean hacking operation widely linked to some of the largest crypto thefts on record. Zhou’s involvement makes sense — Bybit suffered its own breach earlier, and Bitget had helped out then. So now the favor goes the other way.
Bitget is using LazarusBounty as a primary recovery channel, offering rewards through it for freezing or recovering stolen assets.
The $464 Million Protection Fund
Customer withdrawals are still suspended. Bitget said it planned to announce a withdrawal resumption plan by Sept. 26 at 04:00 UTC, but the exchange was clear: actual resumption isn’t guaranteed at that point. Technical teams are still validating systems to make sure everything’s secure before the doors reopen. Deposits and trading haven’t stopped.
Bitget says customer balances are accurate. And the exchange has a User Protection Fund holding over $464 million — that’s the backstop meant to cover losses if recovery efforts fall short. The math is uncomfortable but straightforward: $387.5 million in estimated losses against $464 million in the protection fund leaves a narrow margin, especially before accounting for whatever gets recovered. If the bounty program and partner freezes pull back a meaningful chunk, the fund holds. If not, things get tighter.
The exchange also set up a real-time tracing dashboard so industry participants can watch where the stolen funds are moving. There’s a reporting portal and an API loaded with attacker addresses. It’s a fairly aggressive transparency play — probably designed to keep partners engaged and make it harder for the funds to move quietly through exchanges.
What the Investigation Is Chasing
Mandiant and SlowMist are working through the forensics. The goal is to figure out exactly how the attackers got into Bitget’s hot wallets and whether the patched vulnerability was the only entry point. These investigations take time, and findings are still pending.
Bitget’s decision to keep trading and deposits running while suspending only withdrawals is a calculated move. It keeps the platform functional and prevents a full-blown market panic, but it’s also a bet that the internal systems are stable enough to handle continued activity. That’s not a trivial assumption given a $387.5 million breach.
The broader crypto industry has seen this playbook before. Large exchange hacks trigger coordinated responses, asset tracing goes into overdrive, and recovery rates vary wildly depending on how fast the stolen funds move and where they land. Self-custody and decentralized protocols make recovery harder. Centralized chokepoints — major exchanges, stablecoin issuers — are where freezes actually happen.
Binance and Bybit joining the effort matters because of their scale. If stolen funds hit either platform, there’s a real chance of interception. Smaller exchanges participating in the tracing dashboard adds more coverage. It’s not a guarantee, but it’s the best available option.
And the clock is running. The longer stolen assets sit in intermediate wallets, the more opportunities attackers have to move them through mixers, privacy coins, or cross-chain bridges that break the trail. Zcash assets are particularly tricky — privacy features built into the protocol complicate tracing in ways that standard blockchain analytics can’t fully solve.
Bitget’s updated loss figure of $387.5 million puts it among the larger single-exchange hacks in recent crypto history. The User Protection Fund at $464 million is the number customers are watching right now.
Frequently Asked Questions
What is Bitget’s total estimated loss from the September 24 hack?
Bitget raised its estimated hack loss to $387.5 million after tracing efforts uncovered additional Zcash and TRON assets not included in the original figure.
Will Bitget’s User Protection Fund cover customer losses?
Bitget’s User Protection Fund holds over $464 million and is intended to cover losses from the breach, though the actual amount needed depends on how much is recovered through ongoing bounty and freezing efforts.
When will Bitget resume withdrawals after the hack?
Bitget planned to announce a withdrawal resumption plan by Sept. 26 at 04:00 UTC, but said actual resumption of withdrawals is not guaranteed at that time, pending system validation by technical teams.
Why It Matters
The escalation of Bitget's hack losses to $387.5 million underscores the ongoing vulnerabilities in the cryptocurrency exchange ecosystem, particularly as assets like Zcash and TRON highlight the complexities involved in tracing stolen funds. This incident not only raises concerns about the security measures employed by exchanges but also potentially impacts market confidence, as users may reconsider the risks associated with trading on platforms that have experienced significant breaches. Additionally, the swift suspension of withdrawals and the continuity of deposits and trading could influence how other exchanges respond to similar security threats in the future.





