Bitgets September 24 security incident has entered two simultaneous phases:
- exchange recovery, with BTC withdrawals scheduled to restart on September 28 at 08:00 UTC;
- on-chain laundering, with attacker-linked assets increasingly converted and consolidated into Bitcoin.
- Sep. 28, 08:00 UTC: BTC / Bitcoin;
- Sep. 29, 08:00 UTC: ETH on Ethereum, BSC, Arbitrum, Base and Optimism;
- Sep. 30, 08:00 UTC: USDT on Ethereum, BSC, Solana and Tron;
- Oct. 2, 08:00 UTC: other tokens, fiat and P2P.
- the wallet-backend vulnerability has been identified;
- it has been remediated;
- the incident is contained;
- no further unauthorized transfers are possible through the identified path;
- customer account balances are unaffected;
- deposits and trading continue;
- Mandiant and SlowMist continue to assist.
- issuer freezes;
- exchange freezes;
- voluntary return;
- law-enforcement seizure;
- bounty-assisted recovery.
- 67,237.94 ETH;
- 18,669.98 ZEC;
- 10.11M ALGO;
- smaller stablecoin/XRP balances.
- USDT/USDC can be issuer-frozen;
- a centralized exchange can freeze an attacker account;
- native BTC cannot be frozen by an issuer.
- recovery losses for the exchange;
- operational costs;
- legal costs;
- future insurance/protection-fund depletion.
- DPRK attribution: Developing / high confidence by some investigators;
- government-confirmed attribution: not established in the sources reviewed.
- Incident detected Sep. 24 at 18:31 UTC.
- Current affected-value accounting ~ $387.5M.
- Backend transaction-data spoofing identified.
- Private-key compromise ruled out.
- Cold wallets unaffected.
- Vulnerability remediated.
- Incident contained.
- Phased withdrawal schedule.
- BTC scheduled Sep. 28 08:00 UTC.
- Large XRP balances moved through cross-chain routes.
- THORChain used heavily in conversion toward BTC.
- ~1,889.58 BTC attacker-linked holdings at one Sep. 27 snapshot.
- ETH movement toward BTC routes.
- Coinjoin/privacy-routing activity.
- Limited stablecoin freezes.
- Whether THORChain could or should censor flagged addresses.
- Final DPRK attribution.
- Final recovered percentage.
These two tracks must be evaluated separately. Bitget can fix the backend flaw and restore customer withdrawals while the attacker continues moving assets already stolen from the exchange.
BTC withdrawals are the first live recovery test
Bitgets official schedule says:
This report is published before the first 08:00 UTC milestone.
Therefore, WikiBit records the status as:
Scheduled â not yet verified operational.
The next evidence is an actual user withdrawal broadcast to Bitcoin and sustained processing without another emergency pause.
What Bitget says is fixed
Bitget says:
The exchange has ruled out a private-key compromise and describes the failure as a backend system spoofing transaction data into the authorization process.
The incident amount remains approximately $387.5M
Bitgets current accounting remains approximately:
$387.5 million
in assets transferred to attacker-controlled addresses.
That is not the same as final unrecoverable economic loss.
Recovery can come through:
The XRP position has materially changed
Earlier snapshots showed large attacker-controlled XRP balances sitting in a small number of XRP Ledger accounts.
By September 27, a detailed public reconstruction using Bitgets published attacker addresses found the original large XRP holding accounts had effectively been emptied, with most traceable XRP routed through cross-chain swap infrastructure toward Bitcoin.
One earlier dated snapshot found 27.63 million XRP had moved while approximately 75.35 million XRP remained. Later September 27 tracing showed the large accounts had continued to empty.
The moving numbers should not be mixed into one static âcurrent balanceâ because attacker wallets are changing continuously.
Attacker-linked Bitcoin holdings
At 14:28 UTC on September 27, one transaction-by-transaction reconstruction counted approximately:
1,889.58 BTC
in attacker-linked wallets, worth about $160 million at the prices used by that analysis.
The same snapshot counted approximately:
These are independent on-chain estimates, not Bitget-confirmed holdings.
THORChain becomes a central route
The attacker used THORChain repeatedly to convert stolen XRP/BNB/ETH-linked flows toward Bitcoin.
A public reconstruction counted thousands of XRP deposits into THORChain vault accounts and traced substantial net XRP flow out of the XRP side of the route.
The key risk is conversion away from assets that have stronger centralized intervention points.
For example:
Bitget asked THORChain to block attacker addresses
Bitget CEO Gracy Chen publicly called for THORChain to refuse service to addresses linked to the hack.
Reports of THORChains response say the protocol declined, citing its decentralized and permissionless design.
GoPlus Security challenged the simplicity of that answer, arguing that THORChains vault outflows rely on validator threshold signatures and therefore involve a different operational model from Bitcoin or Ethereum.
WikiBit treats this as a governance/policy dispute, not a settled technical fact about whether censorship is or is not possible.
What is established is that flagged stolen assets have continued to use THORChain.
CoinJoin and privacy routes
The attackers Bitcoin has also begun to fragment.
One public reconstruction traced approximately 19.23 BTC into coinjoin activity during the observed period and followed ZEC through privacy-pool and swap paths.
Again, these are on-chain research findings.
A coinjoin does not automatically prove that funds are unrecoverable, but it increases tracing complexity by intentionally breaking simple input-output heuristics.
Stablecoin freezes remain small
Tether and Circle have frozen only a small amount relative to the incident.
Current public tracing puts linked frozen USDT/USDC in the low hundreds of thousands of dollars.
That is useful recovery, but economically small next to the roughly $387.5M incident.
Why the attacker's asset conversion matters to Bitget users
Customer balances and stolen-fund recovery are separate.
If Bitgets Protection Fund and corporate balance sheet cover customers, the attacker can still create:
The percentage ultimately recovered determines how much of the incident Bitget must absorb economically.
Protection Fund
Bitget says its User Protection Fund exceeded $464 million around the incident and covers the financial impact.
WikiBit continues to treat this as a project statement until the incidents final accounting and any fund deployment are disclosed.
Attacker attribution
Bitget leadership has said DPRK involvement is highly likely.
TRM Labs reported multiple on-chain links consistent with North Korean laundering infrastructure but has not definitively attributed the theft.
Therefore:
Evidence Status
Confirmed / Official Bitget
On-chain / Security / Developing
Contested / Developing
Risk Assessment
Critical, with improving exchange operations but worsening recovery complexity.
The internal exploit path is reported fixed, yet stolen assets are moving into forms that are harder to freeze. The first BTC withdrawal reopening is the next customer-facing recovery test.
What to Watch Next
BTC withdrawal transactions after 08:00 UTC, service throughput, attacker BTC consolidation, THORChain/other swap routes, CEX deposit freezes, ETH-wallet movement, bounty recovery and final forensic disclosure.
FAQ
Are BTC withdrawals already openïŒ
At this reports cutoff, no. They are scheduled for 08:00 UTC on September 28.
How much did Bitget report as affectedïŒ
Approximately $387.5 million.
How much Bitcoin does the attacker holdïŒ
One independent on-chain snapshot at Sep. 27 14:28 UTC counted about 1,889.58 BTC linked to the attacker. It is a developing estimate.
Why is THORChain importantïŒ
Stolen assets have been converted across chains toward Bitcoin through THORChain, reducing the usefulness of issuer-level freezing.
Did THORChain block the attackerïŒ
Public reporting says it declined Bitgets request, citing permissionless operation.
Is North Korea confirmed as the attackerïŒ
No final government attribution is established in the sources reviewed.

