How much did Bitget lose in the hack and what bounty is it offering for recovery?
Confirmed Published 2 min read
Short answer
Bitget said on September 25, 2026 that about $387.5 million in assets went to attacker-controlled addresses, up from its first estimate of $351.6 million. It attributed the rise to extra Zcash and TRON assets found while tracing.
The full answer
This is an update page. This page answers one question: how large the Bitget loss turned out to be, and what is known about a recovery bounty. The event itself is covered on the page about what happened in the September 2026 Bitget theft.
The bounty terms are not confirmed in the sources used here.
How much did Bitget lose?
Bitget said on September 25, 2026 that, based on onchain tracing and transaction classification, it had confirmed assets equivalent to approximately $387.5 million were transferred to attacker-controlled addresses [1]. That is a company figure, not an independent count.
The first estimate was lower. Analytics Insight reported that Bitget initially estimated about $351.6 million was stolen in the September 24 breach, a figure later raised to $387.5 million after additional Zcash and Tron assets were identified [6].
Why did the number go up?
Reporting on September 28, 2026 said Bitget raised the estimate after accounting for additional Zcash and TRON assets [2]. Analytics Insight reported on September 29, 2026 that the attack touched assets on several blockchains, including ETH, XRP, USDT and USDC [3]. Yahoo Finance reported that Bitget confirmed about $387.5 million in assets were transferred to attacker-controlled addresses, raising its initial estimate of $351.6 million after additional Zcash and TRON assets were accounted for [5].
Bitget’s incident page, last updated September 30, 2026, lists estimated affected funds of $388 million, which it calls final verified figures, involving 12 wallet addresses. The same page lists a Protection Fund of $464 million or more [4].
How did the attackers get in?
Bitget said in its security incident explainer, updated October 3, 2026, that its latest investigation found the attacker exploited a vulnerability in a third-party security product to obtain high-level internal credentials, then used them to send fraudulent withdrawal commands to the wallet system in the September 24, 2026 incident.
What bounty is Bitget offering?
The sources cited on this page do not confirm bounty terms, so none are stated here. Its incident page [4] is where any terms would appear.
Who did it, and can the funds be frozen?
Attribution is not settled.
On freezing, see can my XRP be frozen or taken back. For the supply side of XRP, which this theft did not change, see how many XRP exist.
What we know
- On September 25, 2026, Bitget said its onchain tracing confirmed assets equivalent to approximately $387.5 million were transferred to attacker-controlled addresses.
- Bitget’s first estimate was about $351.6 million, according to reporting on September 25, 2026.
- As reported on September 28, 2026, the higher figure came after additional Zcash and TRON assets were counted.
- Bitget’s incident page, last updated September 30, 2026, lists $388 million in affected funds across 12 wallet addresses and a Protection Fund of $464 million or more.
- On October 1, 2026, The Hacker News reported that Bitget confirmed the attackers used a zero-day flaw in third-party security products, citing SlowMist.
What we reason Analysis
- The jump from $351.6 million to $387.5 million, about $36 million, matches Bitget’s explanation of added Zcash and TRON transfers, as reported by CryptoTicker on September 27, 2026. Bitget’s own wording points to later tracing, not a second attack.
- Bitget calls the $388 million figure final on its incident page, and the Protection Fund figure it lists is larger. Bitget said on Sept. 26, 2026 that its protection fund will cover the losses and customer balances are unaffected, with withdrawals scheduled to resume in stages from Sept. 28 through Oct. 2.
What's still open
- As of October 6, 2026, the terms of a recovery bounty are not confirmed in the sources cited on this page. Bitget’s own incident page is the place to read them.
- Who carried out the attack is not established. TRM Labs, as cited by CTI Academy on September 28, 2026, said the 2026 total for North Korea-attributed hacks would pass $1 billion if Bitget were attributed too, which is a conditional statement.
In plain English
Bitget is a crypto exchange. It said hackers took about $387.5 million of assets, after first estimating $351.6 million. The higher number came from tracing more stolen coins on two other networks. Bitget says it has a large reserve fund set aside for such losses. Details of any reward for recovering the money were not confirmed in the sources used here.
Sources
- Bitget support article on the confirmed amount transferred to attacker addresses — Bitget, 2026-09-25 Primary
- Bitget hacker moved XRP — Yahoo Finance, 2026-09-28 Secondary
- Why XRP cannot be frozen after the Bitget hack — Analytics Insight, 2026-09-29 Secondary
- Bitget security incident 2026 — Bitget, 2026-09-30 Primary
- Stolen crypto and the limits of freezing — CryptoTicker, 2026-09-27 Secondary
- Bitget hack: XRP makes up largest slice in $351.6 million crypto theft — The Crypto Times, 2026-09-25 Secondary
- coindesk.com — coindesk.com, September 26, 2026 Secondary
Update log
- — Published.
I keep this site free, with no ads, paywall or affiliate links; gifts cover hosting and research time. Support the project, or report an error.
