Bitget is offering 5% rewards for freezing and recovering stolen funds after revising its estimate of a recent hack to $387.5 million, up from an initial $351.6 million.
Bitget CEO Gracy Chen announced the initiative on X, calling on cryptocurrency exchanges, blockchain security experts and on-chain investigators to help track and recover the missing funds. She also acknowledged the assistance of stablecoin issuers Circle and Tether, which have already frozen some assets connected to the incident.
The recovery initiative comes as Bitget works to contain the breach, strengthen its security infrastructure and restore suspended withdrawal services. The exchange has also confirmed that independent cybersecurity firms Mandiant and SlowMist are assisting with its investigation.
Bitget hack triggers separate 5% recovery rewards
Under its newly introduced recovery program, Bitget will offer eligible participants 5% of the affected funds they directly help freeze and another 5% of funds they successfully recover.
The two rewards cover different outcomes, meaning participants could qualify for either or both, depending on their direct contributions. The exchange has also confirmed that voluntary actions taken before the program’s announcement may qualify if they have already resulted in assets being frozen.
However, the program does not guarantee payments to everyone involved. Bitget retains the authority to determine eligibility, assess individual contributions and calculate the final rewards. Actions performed under court orders, law enforcement requests or other compulsory legal processes are excluded.
To coordinate the operation, the exchange has established a live blockchain-tracing dashboard and a reporting portal where investigators can submit information about affected assets.
The tracking system identifies receiving addresses across Ethereum-compatible networks, XRP Ledger, Zcash and TRON. Bitget plans to update the dashboard as investigators discover additional wallets and trace subsequent transactions.
The exchange is also using Bybit’s LazarusBounty initiative as another channel for its recovery campaign. Cryptocurrency exchanges, stablecoin issuers, blockchain bridges and custodians have been encouraged to monitor the identified addresses and assist with freezing suspicious transactions.
Circle and Tether freeze assets as Bitget tracks stolen funds
The recovery operation has already produced some results, with Circle and Tether freezing a combined $318,000 in assets associated with the attack.
According to the reported figures, Circle froze 99,990 USDC, while Tether froze 218,023 USDT. Both stablecoins are pegged to the US dollar, and their issuers have mechanisms that allow them to restrict transactions involving certain blockchain addresses.
Chen thanked both companies for their assistance, highlighting the importance of cooperation between cryptocurrency platforms and blockchain infrastructure providers in responding to major security incidents.
The freezes represent only a small portion of the assets transferred during the breach. Bitget has also reported additional freezes involving industry partners but has not disclosed a comprehensive figure for all frozen or recovered funds.
Blockchain security researcher Taylor Monahan previously highlighted suspicious transactions involving the attacker’s wallets. Her observations included movements of stolen USDC and conversions into Ether, illustrating how attackers can use multiple transactions and blockchain networks to move compromised assets.
The Bitget hack has therefore become a coordinated recovery operation involving several parts of the cryptocurrency industry. However, freezing assets does not automatically mean they have been returned to their rightful owners. The exchange must still establish the status of the affected funds and complete the recovery process.
Bitget raises hack estimate to $387.5 million
Bitget’s latest investigation has increased the estimated value of assets transferred during the breach from $351.6 million to approximately $387.5 million.
The additional $35.9 million reflects a more comprehensive accounting of the original incident, including assets on Zcash and TRON that were not fully included in the initial estimate. Bitget clarified that the revised figure does not indicate another unauthorized transfer.
The exchange detected suspicious transactions at 18:31 UTC on September 24, affecting portions of its hot and warm wallet infrastructure. It immediately suspended withdrawals while keeping deposits and trading operational.
According to the preliminary investigation, attackers exploited a vulnerability in a backend wallet service. They allegedly manipulated transaction information to bypass existing security controls and trigger the system’s authorization process.
Chen said the initial investigation had ruled out a private-key leak. The exchange subsequently identified the attack route and confirmed that it had fixed the underlying vulnerability.
Bitget has also stated that its cold wallets remained secure and that the separate self-custodial Bitget Wallet product was unaffected.
Mandiant and SlowMist are assisting with the forensic investigation and additional security assessments. Bitget says the incident has been contained and that it has prevented further unauthorized transfers.
The affected cryptocurrencies include XRP, ETH, USDT, ZEC, USDC, USDT0, XAUt, BNB, AVAX and TRX.
Despite the scale of the breach, Bitget maintains that customer account balances remain unaffected. Its initial security announcement also stated that its User Protection Fund held more than $464 million, providing financial coverage for the incident. The exchange has not announced a revised valuation of the fund alongside its updated breach estimate.
Bitget schedules phased withdrawal restoration
Following additional security checks, Bitget has announced a phased plan to restore withdrawals, beginning September 28.
Bitcoin withdrawals are scheduled to resume at 08:00 UTC on September 28. Ethereum withdrawals across supported networks will follow on September 29, with USDT withdrawals scheduled for September 30.
Other cryptocurrency withdrawals, fiat services and peer-to-peer transactions are expected to return on October 2.
The gradual reopening is intended to give the exchange time to validate its systems before restoring access to additional services. Until then, users can continue trading and depositing assets, according to the company’s announcements.
The Bitget hack has placed renewed attention on the security of centralized cryptocurrency exchanges, particularly the backend systems responsible for authorizing transactions. Although the exchange says its vulnerability has been fixed, the ongoing investigation and recovery operation remain important parts of its response.
Chen is also scheduled to host a live question-and-answer session on September 28 at 07:30 UTC. The session is expected to address the incident, withdrawal restoration and the exchange’s next steps.
For now, Bitget’s recovery effort depends on continued cooperation across the cryptocurrency industry, while its phased withdrawal schedule marks the next stage in its response to the breach.