A quick update on what Bitget has confirmed so far 👇
The Recovery Bounty Program is now live, offering a 5% bounty for voluntarily freezing attacker-controlled funds and another 5% for voluntarily recovering them. Anyone who wants to participate should check Gracy’s original update for the official requirements and submission channels.
The other important point is the withdrawal timeline. Bitget says teams are preparing to resume withdrawals and will announce the withdrawal plan by September 26 at 04:00 UTC.
Important: this is the time for the plan to be announced, not a confirmed time for withdrawals to reopen.
For anything account-specific, users should rely on official Bitget updates or support rather than unverified posts.
I think keeping these two points clear is important right now. No guessing, just confirmed information.
𝗜𝗠𝗣𝗢𝗥𝗧𝗔𝗡𝗧 𝗨𝗣𝗗𝗔𝗧𝗘𝗦: The withdrawal plan will be announced by September 26th, 4:00 AM UTC. We appreciate your patience on this matter.
Based on the latest onchain tracing and classification of transactions, assets equivalent to approximately $387.5 million were transferred to attacker-controlled addresses across multiple networks.
The revised figure reflects a more complete accounting of transfers that occurred during the incident, adding affected assets on Zcash and TRON that were not included in the initial estimate. It does not reflect further unauthorized transfers.
The incident remains contained and no further unauthorized transfers are possible.
The incident involved assets across Ethereum and several EVM networks, XRP Ledger, Zcash and TRON.
The primary attacker-controlled receiving addresses identified to date are:
→ EVM: 0x770b10b273fc44fe9197d6bf20f145c2e98463ee
→ XRP: rwNhefsz1UQEusxhCvHip3RANinWi4CTck
→ ZEC: t1WgMdtND8NF7NDUuYmq8MpMj1NTCXkMDVG
→ TRON: TBWNguTTgezw9dVorX441C6nDrZpRxYwKD
The confirmed affected assets include XRP, ETH, USDT, ZEC, USDC, USDT0, XAUt, BNB, AVAX and TRX.
Our investigation and tracing efforts remain ongoing.
The figures above reflect information confirmed at the time of publication and may be updated as additional transactions are classified and traced.
The incident remains contained, with no further unauthorized transfers since the incident was contained, and the investigation with Mandiant and SlowMist remains ongoing
Withdrawals remain temporarily paused while additional security checks and remediation are underway.
Bitget will continue to provide verified updates on the investigation, asset recovery, withdrawal restoration and the User Protection Fund through its official channels.
𝘍𝘰𝘳 𝘪𝘯𝘧𝘰𝘳𝘮𝘢𝘵𝘪𝘰𝘯𝘢𝘭 𝘱𝘶𝘳𝘱𝘰𝘴𝘦𝘴 𝘰𝘯𝘭𝘺.