Bitget Offers 5% Recovery Bounty After $387.5M Hack Hitting Ethereum (ETH)
Bitget launched a 5% bounty to freeze and recover funds from its $387.5M hack. Withdrawals resume in phases from Sept. 28; Circle and Tether froze $318K.
AI SummaryAI
- Bitget offers 5% rewards for freezing and 5% for recovering stolen funds.
- Bitget raised its hack-loss estimate to $387.5 million from $351.6 million.
- Circle froze 99,990 USDC and Tether froze 218,023 USDT tied to the attack.
- Bitcoin withdrawals resume at 08:00 UTC on Sept. 28, Ethereum on Sept. 29.
5% Bounty for Frozen Funds
Bitget has opened a two-tier recovery bounty that pays 5% of affected funds for helping freeze stolen assets and a further 5% for helping recover them, as the exchange's own tracing lifted the value moved to attacker-controlled addresses to roughly $387.5 million. Chief Executive Gracy Chen announced the program on X on Sept. 26, urging exchanges, security researchers and on-chain investigators to join the hunt for the outflows, and publicly thanked Circle and Tether for moving quickly on freezes. Under the exchange's published program terms, the two rewards cover distinct outcomes: an eligible participant earns 5% on funds they directly help freeze and another 5% on funds they directly help recover, and voluntary freezes already completed can qualify alongside future efforts. Bitget alone decides who qualifies, how each contribution is measured and what gets paid, while actions taken under court orders or law-enforcement requests are excluded.
The revised total, a sum larger than the market cap of dozens of mid-tier tokens, sits about $35.9 million above Bitget's initial $351.6 million estimate. The company attributes the increase to a fuller accounting that now includes affected assets on Zcash and TRON, which were absent from the first calculation — not to any fresh unauthorized transfers. Circle has frozen 99,990 USDC and Tether 218,023 USDT at addresses tied to the incident, a combined total near $318,000 that effectively removes those dollar-linked tokens from active circulating supply. Bitget says other affected assets have also been frozen through industry partnerships without disclosing an aggregate figure. The bounty push followed scrutiny of USDC flows during the attack, after security researcher Taylor Monahan described stolen USDC moving through intermediate wallets with portions converted into ETH. A live tracing dashboard lists four primary receiving addresses — one each for EVM networks, the XRP Ledger, Zcash and TRON — and the exchange says Bybit's LazarusBounty initiative will serve as an additional channel, with stablecoin issuers, bridges and custodians asked to monitor the listed addresses.
Withdrawals Resume Sept. 28
Bitget has set a phased timeline for restoring withdrawals after completing further checks on its systems, per its withdrawal schedule published Sept. 26: Bitcoin withdrawals resume at 08:00 UTC on Sept. 28, Ethereum withdrawals across the listed networks follow at the same time on Sept. 29, USDT returns on Sept. 30, and remaining tokens, fiat rails and peer-to-peer services come back online on Oct. 2. Deposits and trading never stopped. Bitget paused only withdrawals after detecting unauthorized transfers from portions of its hot and warm wallet systems at 18:31 UTC on Sept. 24; its initial security notice described both wallet tiers as partially affected while cold wallets stayed secure.
Investigators' working reconstruction points to an attacker who compromised a backend wallet service, fed falsified transfer information into Bitget's internal systems and triggered the exchange's own authorization process to move the assets. The preliminary probe ruled out a private-key leak, and Bitget says the attack path has since been identified, the underlying vulnerability fixed and no further unauthorized transfers are possible, with Mandiant and SlowMist assisting the review. The affected assets span XRP, ETH, USDT, ZEC, USDC, USDT0 — Tether's omnichain USDT variant built on LayerZero — tokenized gold XAUt, BNB, AVAX and TRX. Customer balances are unaffected, and Bitget's Protection Fund, valued at more than $464 million in the initial notice, covers the financial impact, though no updated fund valuation has been published alongside the revised loss figure. Chen is scheduled to host a live question-and-answer session at 07:30 UTC on Sept. 28 covering the incident and the restoration of withdrawals. Readers tracking the market in real time can follow live spot and futures prices on Gate.
On-Chain Trail Confirms Post-Mortem
Our read of the primary evidence is that this breach is unusually traceable for its size: four receiving addresses are published across EVM networks, the XRP Ledger, Zcash and TRON, and the on-chain USDC and USDT freezes are independently verifiable. The team's post-mortem is equally concrete: the root cause was a compromised backend wallet service used to feed falsified data into the authorization flow, remediation is complete and no private keys were leaked. The 5%-plus-5% bounty structure echoes Bybit's LazarusBounty and is hardening into an industry playbook for clawing back stolen funds. For depositors weighing exchange custody against self-managed options, from hardware devices to an AI crypto wallet, the lesson is that even major venues carry backend risk.
Related Tags

AI-generated, AI-reviewed, under COINOTAG editorial oversight.


