The hacker behind Bitget’s $387.5 million breach has moved about $83 million in stolen XRP out of three holding wallets, leaving another $75 million in accounts that cannot be frozen under the XRP Ledger’s existing rules.
Nearly 103 million XRP was taken from Bitget on Thursday and split across five accounts. By 12:41 UTC Saturday, two accounts that initially held 20 million XRP each had been reduced to about 23 and 55 tokens, according to a CoinDesk review of XRP Ledger records. A third was down to roughly 5.8 million XRP. The drain rate means most of the haul could be off the original wallets within days.
Why the coins cannot be frozen
XRP is the native currency of the XRP Ledger, the blockchain built by payments company Ripple. The network lets companies freeze tokens they issue on it, but that power does not extend to XRP itself. Ripple has no built-in way to block the attacker from spending those coins, and neither does the XRP Ledger Foundation or any other entity.
That leaves recovery efforts dependent on where the money goes next. An exchange receiving stolen XRP can restrict the recipient’s account and block withdrawals. It cannot freeze coins while they sit in a wallet controlled by the attacker. The design treats XRP like bitcoin or ether: no issuer, no kill switch.
Circle and Tether, the companies behind USDC and USDT, have already frozen about $320,000 in stablecoins connected to the breach. Their tokens carry blacklist controls that XRP lacks. Roughly three quarters of what was stolen consists of native coins like XRP and ether that no issuer can claw back, which is why the stablecoin freezes captured only a small slice of the total.
The gap between what issuers can and cannot touch has become the defining feature of this heist. In hacks of ERC-20 tokens, issuers can sometimes blacklist addresses within hours. Here, the fastest-moving asset is also the one nobody can stop. It is an uncomfortable fact for an exchange that held most of its reserves in native coins.
Transfers accelerated overnight
The XRP movements sped up through Saturday. At 04:32 UTC, about 70 million tokens remained in the original five accounts. Eight hours later that balance had fallen to 49 million. About 54 million XRP has now left the holding wallets.
Some payments followed routes already used by the first wallet. After an attempted transfer of about 521,000 XRP failed because the sending account lacked funds, the second wallet sent an identical amount to the same recipient roughly an hour later. The pattern suggests the wallets were being driven by the same operator working through a prepared list of destinations.
The transfers show the attacker distributing stolen funds across more wallets. They do not reveal how much has been sold. XRP traded around $1.54 on Saturday, down about 4 percent over 24 hours while holding a weekly gain of roughly 9 percent, according to CoinGecko.
At that price the original XRP haul was worth about $160 million, or close to 4 percent of the token’s $4.4 billion in reported daily trading volume. How much a large sale would move the price depends on the buy orders available when it happens. Traders will be watching for unusual depth changes on major venues, since a $160 million position is large enough to notice but not large enough to be unabsorbable in a liquid market.
Bitget raises its loss estimate
Bitget lifted its estimate of the total theft to $387.5 million on Friday after including Zcash and TRON transfers missed in its first accounting. The exchange said the higher figure reflected assets taken during the original breach, not a second attack. The revision added roughly $36 million to the initial $351.6 million figure the company disclosed within hours of the incident.
Chief executive Gracy Chen said the hack happened through spoofed transaction data rather than stolen private keys, an unusual vector that has made the post-mortem harder for security teams to digest. If transaction data can be spoofed at the backend level, the usual advice about protecting keys misses the point entirely. The breach follows a string of large exchange incidents this year and puts fresh attention on hot wallet controls at mid-sized venues. Bitget confirmed its protection fund covers the loss and customer balances are unaffected.
Withdrawals are scheduled to resume in stages: bitcoin on September 28, ether on September 29, USDT on September 30 and other tokens on October 2. The exchange has also offered a 10 percent bounty for information leading to recovery of the funds.
What recovery looks like from here
On-chain tracing firms will follow the funds as they hop through wallets and, eventually, exchanges. Past cases show the pattern: stolen native coins get split, passed through mixers or cross-chain services, and deposited in batches small enough to slip past automated screening. Exchanges that receive flagged deposits can freeze the receiving accounts, which is how Circle and Tether managed their part of this case.
Law enforcement involvement is possible but rarely fast. Recoveries in comparable crypto thefts have taken months or years, and usually depend on the attacker slipping up at a regulated off-ramp. Bitget’s bounty program is designed to shorten that path by paying insiders or researchers who spot the funds early.
Tracking of the remaining XRP continues. What happens to the $75 million still in the original accounts will likely depend on whether the attacker tries to route it through venues willing to freeze it, or finds paths that avoid them. Either way, the case is already a reference point for a question exchanges rarely ask until it is too late: how much of what they hold can anyone actually get back.
