Bitget Breach Widens to $387.5 Million as Tracing Uncovers Zcash and TRON Haul
Cryptocurrency

Bitget Breach Widens to $387.5 Million as Tracing Uncovers Zcash and TRON Haul

Bitget revises breach losses to $387.5 million after cross-chain tracing

Bitget, the Seychelles-based cryptocurrency exchange, said on Sept. 25 that losses from a major security breach had risen to $387.5 million, up from an initial estimate of $351.6 million disclosed just a day earlier. The upward revision came after onchain tracing uncovered additional stolen assets held on Zcash and TRON that had been missed in the exchange’s first count.

The breach, detected at 6:31 p.m. UTC on Thursday, Sept. 24, saw unauthorized transfers drain funds from some of Bitget’s hot wallets. The stolen assets were moved to attacker-controlled addresses across Ethereum and other EVM-compatible networks, XRP Ledger, Zcash, and TRON. Bitget said the incident has been contained and that no further unauthorized transfers are possible.

The attack stands out for its mechanics. According to Bitget, the attacker did not obtain private keys. Instead, the exchange said a critical backend system within its wallet infrastructure was compromised, transaction data was spoofed, and the exchange’s own authorization process was manipulated into approving the outbound transfers. Bitget Wallet users were unaffected, the firm confirmed.

Reported stolen assets included XRP, ETH, USDT, USDC, XAUt, BNB, AVAX, TRX, and ZEC. The breadth of that list is notable. It points to a systemic drain across multiple custody chains rather than a single token pool being siphoned, and it explains why the initial loss figure proved understated.

The incident is among the largest exchange security failures recorded in the sector, and it lands at a moment when institutional confidence in centralized custody had been recovering. Readers following comparable incidents can find more in our exchange security coverage.

How the attack unfolded

By Bitget’s own account, the intrusion targeted the plumbing behind its hot wallets rather than the keys themselves. CEO Gracy Chen said the attacker compromised a critical backend system in the exchange’s wallet infrastructure, spoofed transaction data, and triggered Bitget’s authorization process to move funds out.

That distinction matters a great deal for how the industry should read this incident. Most historical exchange breaches have been traced to private-key compromise, whether through insider theft, key leakage, or compromised signing infrastructure. A spoofing attack that co-opts an exchange’s legitimate approval workflow is a different class of threat. It implies the attacker had sufficient access to Bitget’s internal systems to make malicious transfers look authentic to whatever checks were meant to catch them.

The technical response was swift in relative terms. The breach was detected at 6:31 p.m. UTC on Sept. 24. By the following day, Bitget had published a revised loss figure after additional onchain analysis. The gap between the two numbers, roughly $36 million, was attributable largely to assets on Zcash and TRON that the first estimate failed to capture.

Bitget has published partial addresses it attributes to the attacker, including an EVM address beginning 0x770b…63ee and a TRON address beginning TBWN…WKD, alongside further receiving addresses on XRP Ledger and Zcash networks. Flagging those addresses allows other exchanges, stablecoin issuers, and blockchain analytics firms to freeze or blacklist funds as they move.

The exchange has also launched a fund tracing and recovery bounty program, a step designed to enlist outside investigators in the effort to freeze and recover the stolen assets. Bounty programs of this kind have become a standard playbook element after large thefts, both to widen the surveillance net and to signal to the attacker that cash-out routes are being watched.

The choice of chains is itself instructive. Ethereum and EVM networks offer deep liquidity, which suits rapid disposal, but also robust tracing and freezing tools through major analytics providers and stablecoin issuers. XRP Ledger and TRON are common conduits for stablecoin movement. Zcash, a privacy coin, presents the sharpest tracing challenge of the group, and its presence in the attacker’s receiving mix suggests at least an intent to obscure fund flows. That the additional Zcash holdings were only found on the second pass of tracing underlines the difficulty.

Why the revised number matters

The jump from $351.6 million to $387.5 million in roughly 24 hours is not a rounding error. It is roughly a ten percent increase in stated losses, and it illustrates a structural problem in how the market prices and reacts to exchange breaches.

Initial loss estimates after any large hack are almost always provisional. Exchange security teams typically see the first wave of outbound transfers on the chains they monitor most closely, which in practice means Ethereum and other EVM networks where analytics coverage is deepest. Assets that move on less-tracked chains, or on privacy-oriented networks, can take days to surface. In Bitget’s case, the missed holdings sat on Zcash and TRON.

For counterparties, insurers, and users trying to gauge solvency risk in the hours after an incident, that lag is dangerous. A $351.6 million loss and a $387.5 million loss may lead to similar conclusions about the exchange’s health, but the trajectory of the number matters. If further tracing surfaces more assets, confidence erodes further; if the figure stabilises, containment claims become credible. Bitget’s statement that the incident is contained, with no further unauthorized transfers possible, is intended to close exactly that loop.

There is also a market-mechanics dimension. Large thefts involving ETH, USDT, USDC and BNB can prompt issuers and validators to freeze portions of the haul, which in Tether’s case has happened repeatedly after prior incidents. XAUt, a gold-backed token, adds another layer, since its issuer can likewise blacklist compromised holdings. The privacy properties of ZEC are the wild card, and recovery prospects there are likely to be the weakest.

For a sector that has spent the past year arguing that centralized exchanges with professional custody stacks are safer than decentralized alternatives, the incident is an uncomfortable data point. The attack did not defeat Bitget’s key management. It defeated the systems around it. That is a reminder that exchange risk is not solely a question of where private keys sit, but of the integrity of the entire authorization pipeline, from backend services to transaction validation to transfer approval.

What comes next

The immediate priorities are tracing, freezing, and recovery. Bitget’s bounty program signals that it expects the recovery effort to be lengthy and partly outsourced. Attacker addresses on EVM networks and TRON are now public, which should accelerate blacklisting by exchanges and stablecoin issuers. The Zcash trail is the harder problem.

For regulators, the incident adds fuel to an ongoing debate over exchange operational resilience. A breach that worked by spoofing transaction data and manipulating an authorization process sits squarely in the domain of systems and controls, the same supervisory territory that banking regulators have policed for decades. Jurisdictions drafting or refining crypto custody rules will likely study the Bitget case closely, particularly the question of whether the exchange’s monitoring should have caught spoofed transactions before funds left.

For users, the episode repeats an old lesson with a new mechanism. Withdrawals, diversification across venues, and self-custody of large holdings remain the standard defences, whatever the technical route an attacker takes.

Closing analysis

The Bitget breach is significant less for its headline number than for what it reveals about how such numbers are produced. A nine-figure theft was undercounted by tens of millions of dollars for a full day because the assets sat on chains the first tracing pass did not fully cover. As cross-chain activity grows, initial hack estimates will become less reliable, not more, and the market should treat early figures from any breach as floors rather than totals.

The deeper concern is architectural. Bitget says its private keys were never compromised, and that may well be true. But an attacker who can spoof transaction data and drive an exchange’s own authorization process to release nearly $400 million has found something equally valuable. Key security is necessary but not sufficient. The industry’s next wave of hardening will have to focus on backend integrity, transaction authenticity checks, and multi-layered validation that assumes sophisticated internal access, because that is precisely what this attacker had.

Recovery will now be a grinding, chain-by-chain effort. The transparent chains offer reasonable odds of partial freezes. Zcash offers few. How much Bitget ultimately recovers, and how quickly it makes affected users whole, will determine whether this incident is remembered as a catastrophic failure or as a costly but survivable stress test of a large exchange’s defences.

CN

CryptoGazette Newsroom

Crypto Reporter

CryptoGazette Newsroom is the lead news desk covering price action, on-chain analytics, regulation, DeFi protocols, NFTs, and institutional adoption across the cryptocurrency ecosystem. The Newsroom focuses on time-sensitive market-moving stories.