Bitget has increased its estimate of the funds stolen in a recent wallet attack to $387.5 million, up from a previous figure of $351.6 million, after identifying zcash (ZEC) and tron (TRX) among the affected cryptocurrencies. The exchange said the revised figure reflects a broader accounting of assets already compromised rather than any new unauthorised movement of funds.
The withdrawals from Bitget's hot and cold wallets were first detected on September 24, 2025. The exchange has said the security breach remains contained, and withdrawal processes remain suspended pending further technical reviews. A scheme to reactivate withdrawals was announced on September 26, though Bitget has not confirmed a resumption date.
Cause of the breach
Bitget chief executive Gracy Chen has disclosed the technical origin of the vulnerability. "The attacker compromised a critical server within our wallet infrastructure, manipulated transaction records and tricked the approval system into transferring the funds," Chen said.
The exchange is working with cybersecurity firms Mandiant and SlowMist on ongoing investigations into the incident.
Bounty programme
Bitget has launched a Recovery Bounty Programme aimed at enlisting external help to trace and freeze the stolen assets. "We have launched a Recovery Bounty Programme to mobilise exchanges, projects, security researchers, investigators and the wider onchain community to help freeze and recover the affected assets," the exchange said.
Under the scheme, participants who assist in freezing or recovering stolen funds will be entitled to 5% of frozen funds and 5% of liquidated funds. "The reward applies to voluntary actions that directly contribute to the freezing or recovery of affected funds," Bitget said, adding that "the final determination of eligibility, contribution, calculation methodology and reward amounts will be made by Bitget."
The bounty effort is being coordinated through lazarusbounty, a platform driven by rival exchange Bybit that has previously been used to track stolen funds linked to state-affiliated hacking groups.
For European users of the platform, the episode adds to a string of recent exchange security incidents that have kept pressure on operators to demonstrate robust custody practices, even as Bitget insists the breach has not spread beyond the assets already identified.




