Mastodon Skip to content
LIVE - NYSE/-/- CRYPTO/OPEN/24/7
BTC$83,995▲ 1.11%ETH$2,681▲ 0.27%SOL$119.45▲ 1.41%TOTAL CRYPTO$2.88T▼ 1.78%S&P 5007,697.62▼ 0.18%NASDAQ27,007.20▲ 2.29%DOW51,209.05▼ 4.39%GOLD4,185.00▼ 6.62%WTI90.96▲ 6.06%BRENT98.29▲ 8.62%EUR/USD1.1342▼ 2.69%USD/JPY157.26▼ 1.30%DXY101.38▲ 1.97%
Crypto

Bitget Hacker Moves $83 Million in XRP Ripple Cannot Freeze

The attacker behind Bitget's $387.5 million breach moved about $83 million in XRP out of three wallets, and no issuer can freeze the native token.

Pexels – Moose Photos

The attacker behind the $387.5 million Bitget breach has moved roughly $83 million in stolen XRP out of three holding wallets, leaving about $75 million in accounts that the XRP Ledger’s rules cannot freeze. The transfers, tracked by CoinDesk through ledger records, show the bulk of the stolen XRP now on the move less than a week after the exchange disclosed what is shaping up as the largest crypto theft of 2026.

Nearly 103 million XRP was taken from Bitget on September 24 and split across five wallets. By 12:41 UTC on Saturday, two wallets that each started with 20 million XRP had been drained to about 23 and 55 tokens. A third wallet fell to roughly 5.8 million XRP. At 04:32 UTC Saturday, about 70 million tokens still sat in the original five accounts. Eight hours later, that balance had dropped to around 49 million.

The movements do not look like a single cash-out. One attempted transfer of about 521,000 XRP failed because the sending wallet lacked funds. Roughly an hour later, another wallet sent the same amount to the intended recipient. Investigators read the pattern as active redistribution across wallets rather than a one-time withdrawal, though wallet movements alone cannot show whether any tokens have been sold.

Why Ripple has no freeze button

The problem for recovery teams is structural. The XRP Ledger lets issuers freeze tokens they create on the network, such as stablecoins issued on the ledger, but that control does not extend to XRP itself, the chain’s native currency. Ripple has no mechanism to blacklist an address the way Circle blacklisted the attacker’s USDC holdings.

That leaves one realistic intervention point: a centralized exchange. If the attacker sends XRP to a platform, the exchange can restrict the receiving account and block withdrawals. It cannot touch the coins while they remain in a wallet the attacker controls. The same gap applies to Ether, which the attacker converted heavily in the first hours after the breach.

Circle and Tether have frozen roughly $320,000 in stablecoins tied to the breach, about 0.08 percent of the total loss. The two issuers locked the tokens at the contract level after a wallet labeled Bitget Exploiter 8 was flagged around 05:00 UTC on September 25. That address held 218,023 USDT, 99,990 USDC and 170.47 ETH. Both stablecoins were locked. The ETH in the same address stayed fully usable.

Chain analytics firm PublicAML counted about 68,465 ETH, worth roughly $183 million at the time, spread across attacker-controlled Ethereum wallets on September 25, including six wallets holding exactly 10,000 ETH each. Roughly $100 million in stolen tokens was converted to Ethereum early on to escape issuer freezes, and another $85 million was already held in ETH.

The loss grows to $387.5 million

Bitget raised its estimate of the September 24 theft to $387.5 million on Friday, up from an initial $351.6 million, after investigators counted Zcash and TRON assets missed in the first accounting. The exchange says the revision reflects a more complete tally of the original breach, not a second attack.

The breach did not involve stolen private keys. According to the exchange’s disclosure, the attacker exploited a vulnerability in a third-party security product used by Bitget’s backend wallet infrastructure, gained high-level credentials, and forged transactions that passed through Bitget’s own approval process without triggering alerts. Cold storage, which holds funds offline, was unaffected.

Bitget attributes the attack to North Korea’s Lazarus Group, citing the pattern of asset conversions, IP addresses and wallet links to past hacks. The group was behind the $1.5 billion Bybit theft in February 2025, the largest crypto hack on record, and has been linked to a string of exchange breaches over the past decade. Analysts note the group typically launders stolen funds slowly, converting through mixers and cross-chain bridges over months, which is why on-chain observers expect further movement in the coming weeks.

Withdrawals return, fund takes the hit

The exchange resumed withdrawals in phases starting September 28, with Bitcoin first, Ether on September 29, USDT on September 30 and remaining tokens on October 2. USDT withdrawals reopened at 08:00 UTC Wednesday and customers immediately pulled a record $463 million in a day, a measure of how much confidence the breach cost even as the exchange promised full coverage. Bitget’s reserve report still shows 131 percent coverage of customer holdings, but the protection fund has fallen below $200 million after covering the shortfall.

Bitget says its User Protection Fund, valued above $464 million before the incident, covers the loss. At $387.5 million, the hack equals about 83.5 percent of that fund, though recoveries and insurance could reduce the draw. The exchange has offered a 5 percent bounty for freezing attacker funds and another 5 percent for recovery.

Interception has been rare. NEAR Intents reported that its SHIELD system blocked more than $50 million in attempted transfers linked to the same attackers, one of the few documented stops so far. Everything else has depended on issuers with blacklist controls, and the attacker has systematically shifted value into assets nobody can freeze.

The incident has also revived a policy argument. Issuer-freezable stablecoins gave Circle and Tether a lever the native assets never had, and exchanges that list XRP now carry the practical burden of interception. The open question is where the remaining XRP goes. About 49 million tokens were still moving between the original wallets as of the weekend. If they reach a major exchange, recovery teams get another chance to restrict the receiving account. Until then, the tokens sit in wallets nobody but the attacker can touch, and the freeze debate shifts back to the exchanges waiting at the other end.

SourcesCoinDesk; AOL/TheStreet; Altcoin Buzz; CryptoNews; EthNews
Share: X