Bitget disclosed a security breach on September 24 that the exchange initially put at $351.6 million in stolen assets. Following further investigation, the exchange revised the figure upward to $387.5 million. The unauthorised transfers involved XRP, ETH, USDT, ZEC, USDC, BNB, AVAX and TRX, moved across Ethereum and other EVM networks, the XRP Ledger, Zcash and TRON.
Bitget said the attacker compromised a critical backend system within its wallet infrastructure rather than obtaining private keys, and that cold wallets and the separate Bitget Wallet product were not affected. Bitcoin withdrawals resumed on September 28, ETH withdrawals on September 29 and USDT withdrawals on September 30, with other tokens, fiat services and peer-to-peer trading expected back by October 2. The exchange is working with Mandiant and SlowMist on tracing and recovery, and has launched a bounty offering a 5% reward for freezing stolen funds and a further 5% for assets recovered. Circle and Tether had already frozen roughly $318,000 in USDC and USDT linked to the incident by September 26.
On September 26, Bitget CEO Gracy Chen said attacker-linked addresses had been identified and tracked, and formally asked THORChain to deny service to those wallets. THORChain responded on September 28, refusing the request. The network said its halt mechanism exists to protect the protocol as a whole rather than to freeze specific funds or swaps, and compared its position to that of Bitcoin, Ethereum and BNB Chain. THORChain noted that roughly 4 BTC connected to the Bitget breach had been traced to a Wasabi CoinJoin round, after moving through TRON, USDT0 and Ethereum before reaching Bitcoin via the THORChain network.
A pattern going back to May
THORChain itself was exploited in May for about $10.7 million, when a malicious node operator took advantage of a weakness in the GG20 threshold signature scheme. The network did not blacklist the attacker's addresses on that occasion either. It instead rolled out version 3.19.0 as part of an eleven-step restart plan, with trading resuming on June 23.
The network's stance also echoes its handling of the 2025 Bybit hack, when Ether-to-Bitcoin conversions tied to that incident generated $2.91 billion in THORChain trading volume and about $3 million in fee revenue. A core THORChain developer left the project after a proposal to block Bybit-attacker transactions failed to win support from node operators.
GoPlus Security pushed back on THORChain's comparison to Bitcoin and Ethereum on September 27, pointing to THORChain's threshold-signature vault system, its validator set controlling those vaults, and its pause and halt mechanisms as structural differences. Michael Perklin argued that on Bitcoin, Ethereum and BNB Chain there is no active choice to sign a transaction, only an active choice to shut the network down.
Chen said decentralisation is a design principle, not a shield for facilitating known stolen funds, and added that the industry is watching.




