The cryptocurrency exchange Bitget has revised its estimate of losses following a significant security breach, now confirming that approximately $388 million in digital assets were compromised. This adjustment represents a notable increase from the initial assessment of $352 million released just one day prior. As the exchange maintains a halt on platform withdrawals to facilitate recovery efforts, the updated figures highlight the operational challenges involved in quantifying losses across multi-chain environments, with broader implications for liquidity and user trust in centralized exchange infrastructure.
Quantifying the Scope of Asset Exfiltration
The updated figure of $387.5 million stems from refined onchain tracing, which identified additional affected assets on the Zcash and TRON networks that were omitted from the preliminary tally. The exchange asserts that this adjustment is the result of a more comprehensive accounting rather than further unauthorized activity, emphasizing that the breach is now contained and no subsequent transfers have occurred. The breadth of the impact spans several major chains, including Ethereum Virtual Machine (EVM) networks and the XRP Ledger. Assets involved in the theft include major market participants such as Ether (ETH), Tether (USDT), XRP, USD Coin (USDC), Binance Coin (BNB), Avalanche (AVAX), Tron (TRX), and Zcash (ZEC), alongside Tether Gold (XAUt).
For market participants, the scale of this event is substantial, though it remains secondary to the record-breaking $1.5 billion theft from Bybit that occurred in February 2025. The current situation demands attention due to the high liquidity profile of the stolen tokens, which can create significant sell-side pressure if the attackers attempt to liquidate holdings through decentralized exchanges or mixers. The operational paralysis caused by the ongoing withdrawal pause restricts the flow of these assets, leaving investors to monitor whether the firm’s bounty program can successfully incentivize the freezing or recovery of these funds before they are obfuscated through privacy-centric protocols.
Systemic Implications and Security Vulnerabilities
While investigations into the origin of the attack continue, the management team has previously pointed toward potential involvement by North Korean hacking groups, citing IP address analysis. Such attribution, if substantiated, places this breach within a broader trend of state-sponsored actors targeting high-liquidity crypto exchanges to bypass financial sanctions. For traders and institutional liquidity providers, this event serves as a sharp reminder of the counterparty risks associated with centralized holding structures.
When large quantities of major assets like ETH and USDT are siphoned, the ripple effects are felt across the broader digital asset space. The forced lockup of funds on Bitget reduces active circulating supply on the platform, which can lead to localized liquidity constraints. Investors must now assess the collateral damage to their own risk exposure and evaluate the security architecture of the platforms they utilize. The reliance on multi-chain wallets introduces distinct vectors for exploitation, as evidenced by the successful targeting of assets across disparate networks like Zcash and TRON in this single incident.
Risk Mitigation and Future Monitoring
For active participants, the immediate priority is to observe how the exchange restores its operational capacity and whether it can provide a transparent recovery roadmap. The continued freeze on withdrawals suggests that technical or security remediation is ongoing, and traders should remain cautious regarding their exposure to the platform until regular service is fully restored. The effectiveness of the newly launched bounty program will be a primary indicator of whether the exchange can reclaim significant portions of the lost assets or if the funds will become permanently disconnected from the platform’s reserves.
- Monitor Withdrawal Status: The ongoing freeze on withdrawals limits liquidity and prevents users from moving assets; watch for specific timelines regarding the restoration of account functions.
- Track Asset Movement: Onchain analysts are actively monitoring the wallets identified as attacker-controlled. Any movement of these funds to centralized exchanges or bridges may indicate attempts to liquidate, which could impact the pricing of the stolen tokens.
- Evaluate Platform Risk: Users should re-assess their reliance on single-exchange liquidity during periods of heightened volatility, particularly when large-scale security incidents trigger platform-wide withdrawal halts.
- Account for Contagion: Watch for any spillover effect where market participants move assets off other exchanges due to increased sensitivity regarding custodial safety, which could drive short-term volatility in the broader market.
Editorial note: This article is market intelligence for educational purposes and is not investment advice.
Source: Cointelegraph.com News (2026-09-25 17:17:00). Independently rewritten and reviewed by the Next Move Markets editorial desk.

