Crypto exchange Bitget has raised its estimate of the assets stolen in this week’s security breach to roughly 388 million USD — about 35 million USD more than first reported — after uncovering additional affected holdings on the Zcash and TRON networks.
By Keisha Williams | September 26, 2026
The exchange said the higher number reflects a more complete accounting of the original incident, not new unauthorized transfers. For customers and observers alike, the revision is a reminder of how messy large breach investigations are in their first days: the true scope of a hack is rarely visible while exchanges are still reconciling wallets. The revised figure ranks the incident among the largest security breaches in crypto industry history, though it remains well below the roughly 1.5 billion USD stolen from Bybit in February 2025.
The Hook: What the New Numbers Show
Bitget initially reported about 352 million USD in unauthorized transfers from its hot and warm wallet infrastructure on Thursday. The updated accounting puts the figure at about 388 million USD, after the exchange identified additional affected assets on the Zcash and TRON networks. Hot wallets are exchange-controlled addresses connected to the internet for everyday withdrawals; warm wallets sit one step further back. The breach involved addresses across Ethereum Virtual Machine networks, the XRP Ledger, Zcash, and TRON.
- 388 million USD — revised estimate of assets moved to attacker-controlled addresses, up from the initial 352 million USD.
- Affected assets include XRP, Ether, Tether’s USDT, Zcash’s ZEC, USDC, USDT0, Pax Gold’s XAUt, BNB, AVAX, and TRX.
- Withdrawals remain paused while the investigation continues.
- Bounty program launched to help freeze or recover stolen assets.
The Evidence: The North Korea Trail
Bitget CEO Gracy Chen said during a live question-and-answer session on X that preliminary findings point to possible North Korean involvement. Security investigators flagged similarities with previous attacks tied to the Democratic People’s Republic of Korea, and Chen said the exchange does not believe the breach was an inside job.
“We’ve identified some IP addresses that match the VPN choices by a certain DPRK group,” Chen said, referring to North Korea. She added that some stolen funds had already been recovered, without specifying the amount, and that the exchange is working with blockchain foundations and other partners on recovery efforts.
The attribution matters. North Korean hacking groups were linked to an estimated 2.02 billion USD in crypto theft in 2025, according to figures cited in the wake of the Bybit hack, which the FBI attributed to North Korea. State-backed thieves do not cash out through ordinary bank accounts — they move assets through mixing services and cross-chain transfers, which is why exchange bounty programs now target the intermediaries who help launder funds rather than just the hackers themselves.
The Core Conflict: Backend Compromise, Not Stolen Keys
The most important technical detail from Bitget’s early findings is what was not stolen: the private keys securing its cold storage. The breach points to a compromise of backend wallet services — the software layer that decides which transfers are legitimate — rather than attackers physically obtaining the keys to the vault. In plain terms, imagine a bank where the robbers did not steal the safe combination, but instead tricked the tellers’ computer system into printing legitimate withdrawal slips.
That distinction shapes the industry debate that follows every major hack. If keys are safe, the failure was in operational security — process, software, and people — which is fixable and insurable. If keys are compromised, customers have far more reason to fear for the underlying custody model. Bitget’s case currently looks like the first kind, and the exchange has repeated that customer assets remain covered by its protection fund.
Market Implications: What This Means for You
For Bitget users, the practical reality is patience: withdrawals are suspended until the investigation progresses further, and recovery of the moved assets will take weeks or months even in the best case. For everyone else, the incident is a nudge toward basic hygiene. Keep long-term holdings in a wallet you control, limit what sits on any single exchange, and treat any exchange — no matter how large — as a convenience, not a vault.
The market has absorbed the news without panic, consistent with the pattern after previous large breaches: the damage concentrates on the affected platform while major assets trade steadily. Bitcoin sits near 83,900 USD, Ethereum near 2,685 USD, and Solana near 121 USD, according to the site’s snapshot taken September 26.
The Verdict
A 35 million USD revision days after a 352 million USD hack is not a second disaster — it is the honest cost of counting everything. The real questions now are how much of the 388 million USD gets frozen or recovered, whether the North Korea attribution holds up, and how quickly Bitget can restore withdrawals without another incident. Until then, the episode stands as the year’s sharpest reminder that in crypto, the weakest link is rarely the blockchain. It is the plumbing built on top of it.
The cryptocurrency market remains highly volatile. This article is for informational purposes only and does not constitute financial advice.
Finding 35 million more on Zcash and TRON a day later shows how rough first-day hack numbers always are. 352 to 388 overnight.
makes you wonder how many other exchanges would even admit the number went up. at least they published the revision
The bounty on stolen funds is smart. Tainted Zcash is hard to move, whoever holds it needs an exit eventually.
bounties worked partially after bybit too. 1.5 billion vs 388, this is small change next to that one
35m discovered on zcash and tron a full day after the initial number. every day-one hack figure you read should carry a question mark
35 million extra was sitting in zcash and tron wallets the whole first day. day one hack numbers are always just estimates
388m and the comforting comparison is the 1.5b from bybit. grim era when that counts as good news
The Bybit comparison is doing a lot of work here. 388 million still ranks among the largest breaches ever, comfort is relative.
A 36 million gap between the day one and day two figures should make everyone discount initial hack numbers by default.
Offering a bounty to trace the stolen funds is smart. Stolen coins usually hit mixers fast, so early movement data matters most.
^ and tron transfers are basically public record, that part of the bounty might actually pay out
exactly, tron transfers are traceable forever. the zcash slice is the real question, shielded by default
Agreed on the bounty being smart, though bounties mostly recover crumbs. Bybit’s trail was mapped publicly and the funds still moved.
at least the revision is fuller accounting, not new transfers. small mercy
fuller accounting or not, finding 35m on two more chains a day later means the wallet inventory was incomplete. thats the scary part
thats the part that spooks me. if the wallet inventory was off by 35m, why would we trust 388 is final either
the zcash portion is probably gone for good, shielded pools dont care about bounties. the tron side might talk eventually