Key Points
Bitget hack update September 28: loss raised to $387.5M, attack method confirmed, BTC withdrawals live, THORChain dispute, $343M still in attacker wallets.
▶ Loss revised to $387.5 million and up from $351.6M and after investigators identified additional stolen assets on Zcash and TRON missed in the initial count.
▶ Attack method confirmed: the attacker exploited a vulnerability in a third-party security product, obtained high-level internal credentials, and used them to forge withdrawal commands. Private keys were not compromised. Cold wallets were not touched.
▶ BTC withdrawals resumed September 28 at 08:00 UTC. ETH follows September 29, USDT on September 30, other tokens and fiat from October 2. Each phase subject to security checks.
▶ Mandiant and SlowMist are assisting Bitget’s investigation alongside internal teams and law enforcement. A bounty program is live: 5% for qualifying freezes, 5% for successful recoveries.
▶ THORChain dispute: Bitget requested that THORChain block attacker addresses after stolen funds were routed through the protocol. THORChain declined, citing its permissionless design.
▶ AMLBot estimates approximately $343 million remains dormant across 13 attacker wallets: 68,300 ETH, 83M XRP, and 18,900 ZEC. Four BTC was traced through a Wasabi CoinJoin privacy mixer.
Four days after the Bitget Exchange hack CNB first reported on September 25, the picture looks materially different. The Bitget hack update on September 28 confirmed three things that were unknown at publication: the loss is larger than initially reported, the attack method has been identified, and Bitcoin withdrawals have restarted. The exchange has also become the centre of a public dispute with THORChain over whether decentralised protocols have any obligation to block funds linked to known hacks.
CEO Gracy Chen hosted a live AMA on September 28 at 07:30 UTC, thirty minutes before Bitcoin withdrawals reopened. In it she described how the attack actually worked, information that was not available when the hack was first confirmed. The Bitget hack update is not just a status report: the confirmed attack method changes how the industry should read the incident and what it means for exchange security practices more broadly.
This article covers all new information confirmed since September 25: the revised loss figure and why it changed, the attack method Bitget has now disclosed, the phased withdrawal schedule and what users need to do, the THORChain dispute and what it reveals, and where the $343 million in dormant stolen funds currently sits.
Why Did the Loss Figure Rise From $351.6M to $387.5M?
The initial $351.6 million figure came from Bitget’s first assessment of which wallets were drained and how much had left. As investigators including Mandiant and SlowMist traced fund movements across multiple blockchains in the days after the attack, they identified additional stolen assets on Zcash and TRON that were not captured in the initial count.
The mechanics: when an attacker drains a multi-chain exchange, the initial forensic picture is incomplete. Transfers happen across seven or more networks simultaneously and subsequent cross-chain bridging moves funds in ways that take time to follow. The $36 million gap between the initial estimate and the revised figure is not a correction of a mistake and it is the natural result of on-chain forensics catching up with a fast-moving attacker operating across multiple chains.
What does the Zcash addition to the loss figure tell us?
Zcash is a privacy coin. Transactions on Zcash can be fully shielded, meaning sender, receiver, and amount are all hidden from public blockchain analysis. The fact that attackers moved funds into Zcash is a deliberate obfuscation step and one that AMLBot, which tracked 18,900 ZEC still in an identified attacker wallet, was able to identify through on-chain patterns preceding the Zcash transfer rather than the Zcash transaction itself. It confirms the attackers were thinking systematically about obscuring their trail from the earliest stage of the hack.
What Was the Bitget Hack Attack Method? The Third-Party Security Product Explained
This is the most important new information in the September 28 update. The attack method that was unknown when CNB first reported the hack has now been confirmed by CEO Gracy Chen in her livestream.
According to Bitget’s account: the attacker exploited a vulnerability in a third-party security product that Bitget was using as part of its internal infrastructure. That exploitation gave the attacker high-level internal network credentials and effectively administrator-level access to Bitget’s backend wallet management systems. The attacker then used those credentials to create fraudulent withdrawal instructions that were fed into Bitget’s authorization-signing process and bypassed existing risk controls.
The Bitget Attack: Step by Step
Attacker identifies third-party security product vulnerability
The attacker found a flaw in a third-party security product integrated into Bitget’s infrastructure. The specific product has not been named publicly.
High-level internal credentials obtained
Exploiting the vulnerability gave the attacker high-level internal network access and administrator-level credentials that allowed interaction with Bitget’s backend wallet management systems.
Fraudulent withdrawal commands created
Using the credentials, the attacker generated withdrawal instructions that appeared internally legitimate but were directed to attacker-controlled addresses.
Authorization bypass
The fraudulent instructions were fed into Bitget’s authorization-signing process. The signing system processed them as legitimate because the credentials used to submit them were authentic.
Funds transferred to attacker addresses
Approximately $387.5M in XRP, ETH, and other assets transferred to attacker-controlled addresses across seven networks, beginning 18:31 UTC September 24.
Attacker begins cross-chain obfuscation
Stolen funds immediately began moving across chains: through THORChain, TRON, Zcash, and eventually through a Wasabi CoinJoin Bitcoin privacy mixer.
Source: Bitget CEO Gracy Chen September 28 livestream, crypto.news September 28 2026 (primary), airdropalert.com Bitget hack tracker | @cryptonewsbytes. Investigation ongoing and details may be updated.
The critical distinction from the initial reporting: this was not a private key compromise and not a customer-facing vulnerability. The attack bypassed Bitget’s security at the infrastructure layer by compromising a tool Bitget was using internally. No customer keys were accessed. No customer accounts were breached directly. The funds were stolen by forging internal withdrawal commands, not by draining individual user wallets.
In practice, this attack class is particularly dangerous because it sits above the blockchain security layer and below the customer security layer. Blockchain cryptography was not broken. Customer authentication was not bypassed. The vulnerability was in the operational infrastructure that sits between user accounts and the blockchain and exactly the attack surface that the Hacken Q2 2026 report CNB covered identified as responsible for 88% of crypto losses in Q2 2026.
When Do Bitget Withdrawals Resume? The Full Schedule
Bitget Withdrawal Resumption Schedule (September 28 and October 2, 2026)
| Date / Time (UTC) | Asset | Networks | Status |
|---|---|---|---|
| Sep 28, 08:00 UTC | BTC | Bitcoin network + BSC | LIVE |
| Sep 29, 08:00 UTC | ETH | Ethereum, BSC, Arbitrum, Base, Optimism | Scheduled |
| Sep 30, 08:00 UTC | USDT | Ethereum, BSC, Solana, Tron | Scheduled |
| Oct 2, 08:00 UTC | All other tokens | All networks | Scheduled |
| Oct 2, 08:00 UTC | Fiat + P2P | All services | Scheduled |
Note: Each phase is subject to additional security checks. Times and order may change. Trading and deposits continued throughout the withdrawal suspension. | Sources: Bitget official announcement, crypto.news September 28 2026 | @cryptonewsbytes
What Bitget users should do right now
BTC withdrawals are live. If you have been waiting to move Bitcoin off the exchange, you can do so now. ETH and USDT follow on a confirmed schedule. If you want to move funds before the scheduled dates for a specific asset, you need to wait for that asset’s date. Trading is fully operational and has been throughout. There is no indication that Bitget’s customer balances have been affected. The User Protection Fund covers the loss. If you see your balance correctly in the app, the funds are there and the withdrawal suspension was a security measure, not a sign that your specific assets were stolen.
What Is the THORChain Dispute and Why Does It Matter?
One of the most significant developments since the initial hack report is a public disagreement between Bitget and THORChain. On-chain investigators traced a portion of the stolen funds moving through THORChain, a decentralised cross-chain liquidity protocol that allows assets to be swapped across chains without a centralised intermediary. Bitget requested that THORChain take action to block addresses associated with the attacker.
THORChain’s response: no. The protocol declined, saying its permissionless design does not provide a mechanism for selectively blocking individual addresses. THORChain operates through smart contracts on its own network and there is no administrator who can flip a switch and block specific wallets. To do so would require either a protocol governance vote to add address-blocking functionality (which would take time and be contested) or a hard fork.
The dispute highlights a genuine tension that has no clean resolution. Bitget’s position is reasonable: stolen funds are identifiable on-chain and a protocol that facilitates their movement becomes a tool for laundering. THORChain’s position is also coherent: if a decentralised protocol can be pressured into blocking specific addresses on demand from an exchange that suffered a hack, it is no longer meaningfully decentralised. Every subsequent hack victim will make the same request. The pressure to add censorship capability accumulates until the protocol’s decentralisation is nominal.
What THORChain’s refusal actually means for the stolen funds
Approximately $343M in stolen funds has not moved through THORChain. AMLBot’s tracking shows the vast majority of stolen assets are still dormant in 13 identified attacker wallets. The funds that did move through THORChain and and led to the dispute and represent a small fraction of the total. The attacker’s primary strategy appears to be holding, not moving, most of the funds. This is consistent with Lazarus Group’s historical behaviour: the Bybit hack funds from February 2025 also remained largely unmoved for extended periods while investigators tracked them.
Bitget Hack Update: Where Is the $343M? AMLBot’s Wallet Tracking
AMLBot, a blockchain compliance firm, published a breakdown of attacker wallet holdings as of September 25, 2026. The estimate suggests approximately $343 million remains dormant across 13 identified attacker wallets, despite the smaller movements through THORChain and the Wasabi CoinJoin mixer.
AMLBot Attacker Wallet Breakdown (as of September 25, 2026)
Source: AMLBot blockchain compliance firm | @cryptonewsbytes. Note: wallet balances change as funds move. This reflects the snapshot reported by AMLBot on September 25.
| Asset | Amount | Wallets | Notes |
|---|---|---|---|
| ETH | ~68,300 ETH | 8 Ethereum wallets | Largest single-asset holding. Not moved as of Sep 25. |
| XRP | ~83 million XRP | 4 XRP addresses | Originally ~103M XRP stolen. ~20M may have moved. |
| ZEC (Zcash) | ~18,900 ZEC | 1 wallet | Privacy coin. Shielded transactions obscure further movements. |
| BTC | ~4 BTC traced | Wasabi CoinJoin | Small amount moved through privacy mixer via TRON and THORChain. |
| Stablecoins frozen | ~$318K (USDC + USDT) | Frozen by Circle and Tether | Tiny fraction of total. Demonstrates stablecoin issuers can act quickly. |
| TOTAL DORMANT (est.) | ~$343M | 13 wallets | ~88% of revised $387.5M loss estimate still in identified wallets. |
The stablecoin freeze and approximately 99,990 USDC and 218,023 USDT and demonstrates both the power and the limit of stablecoin issuer intervention. Circle and Tether can and did freeze attacker-tagged wallets within days. The total frozen is approximately $318,000, or about 0.08% of the stolen funds. The vast majority is held in ETH, XRP, and ZEC, where no centralised issuer can freeze anything. This is exactly why sophisticated attackers target non-stablecoin assets for the bulk of their theft and use stablecoins only as brief transit layers.
Is Lazarus Group Confirmed? What Bitget Says Now and What “State-Backed” Actually Means
Bitget’s official position has shifted slightly from the September 25 statement. The exchange now describes the attacker as “sophisticated” and “state-backed” and language that clearly implies North Korea’s Lazarus Group without formally confirming it. Bitget said it will not confirm the identity of the attacker until the investigation reaches a firm conclusion.
The on-chain fund flow evidence, specifically AMLBot and Specter’s linking of stolen XRP to addresses associated with the July 2026 AFX exchange hack (attributed to TraderTraitor, a Lazarus subunit), remains the strongest public evidence for the Lazarus attribution. The third-party security product attack vector is also consistent with Lazarus Group’s tradecraft: the Bybit hack used a compromised Safe wallet UI to trick signers into authorising malicious transactions and a different technical approach but the same core concept of attacking the operational layer between user and blockchain rather than attacking cryptography directly.
Frequently Asked Questions
What is the latest Bitget hack update?
As of September 28, 2026: the total loss has been revised to $387.5 million from the initial $351.6M estimate. Bitcoin withdrawals resumed at 08:00 UTC on September 28. The attack method has been confirmed as a third-party security product vulnerability. Mandiant and SlowMist are investigating. A bounty program is live. Approximately $343M in stolen funds remains in 13 identified attacker wallets.
How did the Bitget hack actually happen?
Bitget CEO Gracy Chen confirmed on September 28 that the attacker exploited a vulnerability in a third-party security product Bitget was using internally. That gave the attacker high-level internal network credentials, which were used to forge withdrawal commands that bypassed Bitget’s risk controls. Private keys were not compromised. Cold wallets were not touched. The attack targeted Bitget’s operational infrastructure, not its cryptographic security or customer accounts.
When do Bitget withdrawals fully resume?
Bitcoin withdrawals resumed September 28 at 08:00 UTC. ETH follows September 29 (Ethereum, BSC, Arbitrum, Base, Optimism). USDT follows September 30 (Ethereum, BSC, Solana, Tron). Other tokens, fiat withdrawals, and P2P services resume October 2. Each phase is subject to security validation before opening.
Why did THORChain refuse to block the Bitget attacker?
THORChain operates as a permissionless decentralised protocol. Its architecture does not include a mechanism for selectively blocking individual addresses. Implementing such a mechanism would require either a governance vote to add censorship capability or a hard fork, either of which would take time and would fundamentally alter the protocol’s decentralised design. THORChain declined Bitget’s request on those grounds.
Where are the stolen Bitget funds now?
AMLBot estimates approximately $343M remains dormant across 13 identified attacker wallets as of September 25: approximately 68,300 ETH across 8 Ethereum wallets, 83 million XRP across 4 addresses, and 18,900 ZEC in one wallet. Small amounts have moved through THORChain and 4 BTC has been traced through a Wasabi CoinJoin mixer. Circle and Tether froze approximately $318,000 in stablecoins linked to attacker wallets.
Further Reading
CNB’s original September 25 report: the initial hack details, what Lazarus Group is, how the User Protection Fund works, and what users should do.
The Hacken Q2 2026 report that contextualises the Bitget attack: third-party security product vulnerabilities fall squarely in the operational failures category that drove 88% of Q2 losses.
The September 15 rsETH exploit and the contrast with Bitget. On-chain exploits can be front-run and partially recovered. Internal infrastructure breaches at this scale are harder to contain.
Sources: crypto.news September 28 2026 (primary: Gracy Chen livestream, attack method confirmed, withdrawal schedule, Mandiant and SlowMist, stablecoin freeze figures), The Block September 28 2026 (primary: phased withdrawal resumption, protection fund to be restored to $300M), BleepingComputer September 28 2026 (primary: third-party security product detail, credential forgery), airdropalert.com Bitget hack tracker September 28 2026 (primary: AMLBot $343M dormant estimate, wallet breakdown, Wasabi CoinJoin, THORChain dispute), The Market Periodical September 27 2026 (phased schedule), coingabbar.com September 28 2026 (THORChain dispute detail, AMLBot tracking) | Published September 28, 2026 | CryptoNewsBytes.com | Not financial advice.

