

Bitget has launched a recovery bounty offering 5% for freezing stolen assets and another 5% for recovering them after an attack it initially valued at $351.6 million.
Summary
- Bitget offers separate 5% rewards for eligible efforts that freeze or recover stolen funds.
- The exchange has raised its estimate of assets transferred to attacker addresses to $387.5 million.
- Circle and Tether have frozen about $318,000 in USDC and USDT linked to the attack.
- Bitget plans to restore withdrawals in phases starting Sep. 28.
Bitget CEO Gracy Chen announced the bounty on X and called on exchanges, security researchers, and on-chain investigators to help track the funds. She also thanked Circle and Tether for freezing assets linked to the attack.
The two rewards cover different results. Under Bitget’s program, an eligible participant can receive 5% of the affected funds they directly help freeze and 5% of funds they directly help recover. The exchange said voluntary actions that had already led to a freeze can qualify alongside future efforts.
Bitget bounty covers freezing and recovery separately
Bitget will decide who qualifies, how each contribution is measured, and how much to pay. Participation alone does not guarantee a reward, and the exchange excludes actions taken under court orders, law enforcement requests or other legal processes.
The company has opened a live tracing dashboard and a portal for submitting information about affected funds. Its published list of primary receiving addresses spans Ethereum and other compatible networks, XRP Ledger, Zcash and TRON. Bitget said the dashboard will be updated as investigators identify more addresses and follow further movements.
Bybit’s LazarusBounty initiative will also serve as a channel for the effort, according to Bitget. Exchanges, stablecoin issuers, bridges and custodians are among the groups the company has asked to monitor the listed addresses.
Circle and Tether have frozen 99,990 USDC and 218,023 USDT, respectively, at addresses tied to the attack, according to the earlier report shared on the incident. The amounts total roughly $318,000. Bitget’s update says other affected assets have also been frozen through work with industry partners, without giving a combined frozen or recovered total.
The freeze follows scrutiny of USDC movements during the attack. Security researcher Taylor Monahan flagged transfers and swaps involving the attacker, as crypto.news reported on Friday. Her account described stolen USDC moving through wallets while some assets were converted into ETH.
Bitget raises transferred-assets estimate to $387.5 million
Bitget’s latest tracing puts the value transferred to attacker-controlled addresses at approximately $387.5 million, up from its initial $351.6 million estimate. The company said the revised figure includes affected assets on Zcash and TRON that were absent from its first calculation. It attributed the increase to a fuller accounting of the original incident, rather than further unauthorized transfers.
The exchange detected unauthorized transfers from some hot wallets at 18:31 UTC on Sep. 24. Its initial security notice said portions of its hot and warm wallet systems were affected, while cold wallets remained secure. Bitget paused withdrawals after detecting the transfers but kept deposits and trading available.
Investigators believe an attacker compromised a backend wallet service, fed false transfer information into Bitget’s systems, and triggered its authorization process. Chen said the preliminary probe had ruled out a private-key leak. The account of the suspected entry route was covered by crypto.news on Sep. 25, before Bitget published its revised asset total.
In its later update, Bitget said its team had identified the attack path and fixed the underlying vulnerability. Mandiant and SlowMist are assisting with the investigation and security checks. The exchange said it had contained the incident and that no further unauthorized transfers were possible.
The affected assets include XRP, ETH, USDT, ZEC, USDC, USDT0, XAUt, BNB, AVAX and TRX, according to Bitget. Its tracing information identifies four primary receiving addresses so far, one each for EVM networks, XRP Ledger, Zcash and TRON.
Withdrawals are scheduled to return in phases
Bitget published a withdrawal schedule on Sep. 26 after conducting further checks on its systems. Bitcoin withdrawals are set to resume at 08:00 UTC on Sep. 28. Ethereum withdrawals on the listed networks are scheduled for the same time on Sep. 29, followed by USDT on Sep. 30 and other tokens, fiat and peer-to-peer services on Oct. 2.
The exchange said customer account balances remain unaffected and its Protection Fund covers the financial impact of the incident. Its first notice valued the fund at more than $464 million, before the company revised its estimate of the transferred assets. Bitget has not published a new fund valuation alongside the $387.5 million figure.
For U.S. readers, the issuer freezes concern dollar-linked tokens that can also be held outside Bitget. Circle’s USDC terms allow it to block transfers involving certain on-chain addresses. A recent U.S. Justice Department case separately involved Tether’s help in tracing and restraining crypto tied to an alleged illicit network; authorities have made no comparable public announcement about U.S. action in the Bitget investigation.
Chen is scheduled to host a live question-and-answer session at 07:30 UTC on Sep. 28 to discuss the incident, the restoration of withdrawals, and Bitget’s next steps.