Bitget raises breach loss estimate to $388m and keeps withdrawals paused
Bitget now says about $388 million in assets left the exchange in Thursday's security breach, $35 million more than its first estimate, and withdrawals remain frozen.

Key points
- Bitget said roughly $387.5 million was transferred to attacker-controlled addresses, up from the $352 million first reported.
- The revised total adds affected assets on Zcash and TRON that were missing from the initial estimate.
- Withdrawals stay paused and Bitget has launched a bounty to encourage freezing or recovery of the funds.
- Affected networks include EVM chains, the XRP Ledger, Zcash and TRON; stolen assets include XRP, ETH, USDT, ZEC, USDC, XAUt, BNB, AVAX and TRX.
- The update did not address CEO Gracy Chen's Thursday remarks speculating a North Korean hacking group may have been responsible.
Bitget has raised its estimate of the assets affected by Thursday's security breach to about $388 million, according to an updated incident report covered by CoinTelegraph. The exchange said roughly $387.5 million was transferred to attacker-controlled addresses, based on onchain tracing, which is about $35 million more than the $352 million it reported a day earlier.
In its Friday update, Bitget said the higher figure came from a fuller accounting of transfers made during the incident. The exchange said the revised number adds affected assets on Zcash and TRON that were left out of the first estimate, and that it does not reflect any further unauthorised transfers. Bitget added that the incident remains contained and that no additional unauthorised transfers are possible.
The exchange said the breach touched addresses on Ethereum Virtual Machine networks, the XRP Ledger, Zcash and TRON. Among the assets taken were XRP, Ether, Tether's USDt, Zcash, USDC, USDT0, XAUt, BNB, AVAX and TRX. Bitget also confirmed it would keep withdrawals paused while it deals with the aftermath of the breach.
Bitget lifts loss estimate
Alongside the pause, Bitget said it had launched a bounty programme aimed at encouraging the freezing or recovery of the assets. The exchange has not said when withdrawals might resume. The follow-up report did not address comments made on Thursday by chief executive Gracy Chen, who speculated that a North Korean hacking group may have been behind the attack.
The Bitget security breach remains one of the largest to hit the crypto industry, even after the revision. CoinTelegraph noted that hackers stole about $1.5 billion worth of Ether from Bybit in February 2025, a larger single incident. The scale of the Bitget loss places it among the most significant exchange breaches on record.
For customers, the immediate effect is that funds cannot be withdrawn while the exchange works through tracing and recovery. The bounty programme is intended to bring in outside help to freeze or claw back the transferred assets, though the report gives no detail on its size or terms. Bitget has stressed that the situation is contained and that the transfers already identified are the full extent of what left the platform.
Chains and assets affected
The case also highlights how exchange loss estimates can shift as tracing continues. Bitget's first figure covered only part of the affected chains, and the addition of Zcash and TRON assets pushed the total higher within a day. The company has not commented further on who might be responsible, leaving Chen's earlier speculation unaddressed in the official update.
