The hacker behind the Bitget exchange breach has started moving stolen XRP, and there is little Ripple can do to stop it. About $83 million in XRP left three holding wallets by Saturday, leaving roughly $75 million still sitting in accounts the network’s rules do not allow anyone to freeze.
The theft dates to September 24, when attackers took about 103 million XRP from Bitget hot wallets and split it across five accounts. According to a CoinDesk review of XRP Ledger records, two wallets that each started with 20 million XRP were down to about 23 and 55 tokens by 12:41 UTC on Saturday. A third account held roughly 5.8 million XRP. Bitget has since raised its estimate of the total loss to about $387.5 million across all assets taken in the breach.
The freeze problem, explained
The XRP Ledger gives issuers the power to freeze tokens they create, a tool designed for stablecoins and other issued assets. That power stops at XRP itself, the ledger’s native currency. An exchange that receives stolen XRP can restrict the receiving account and block withdrawals, but nobody can freeze the coins while they sit in a wallet controlled by the attacker.
Circle and Tether, the companies behind USDC and USDT, face no such limit. Both issuers blacklisted addresses tied to the breach within a day, freezing about $320,000 in stablecoins. That figure is a rounding error next to the total loss, since most of the stolen funds sit in ether and XRP, neither of which carries issuer freeze controls.
Bitget promises full coverage
Bitget says its protection fund will cover the losses and that customer balances are unaffected. The exchange plans to restart withdrawals in phases starting September 28, a week after the breach was detected. CEO Gracy Chen has publicly linked the attackers to infrastructure connected to North Korea and rejected comparisons to FTX, arguing that a hot wallet compromise is a security event rather than a solvency problem.
The hack ranks among the largest exchange thefts in recent years. For comparison, the bulk of customer losses in past collapses came from misused deposits rather than stolen keys, which is why Bitget has pushed hard on the distinction. Whether the protection fund payout settles the matter may depend on how quickly withdrawals resume without disruption.
What happens to the money
Tracing suggests the attacker is working through the standard laundering playbook: splitting funds across many addresses, waiting for exchange inflows, and converting into assets that are harder to freeze. Exchanges that receive the stolen XRP can freeze the deposited balances once identified, which makes off-ramping harder but not impossible. Roughly $75 million in XRP remains in the original holding accounts and could still be intercepted if venues cooperate quickly.
The episode has renewed debate over freeze powers in general. Issuer control is what let Circle and Tether claw back funds within hours, but the same control is a censorship tool when applied to lawful holders. XRP’s design sits at the other end of the spectrum, with no central party able to block a transfer. The Bitget theft shows the cost of that trade-off in practice.
XRP’s price has held up better than the news might suggest, trading near $1.55 after the breach, supported by a streak of ETF inflows and whale accumulation. The market appears to be treating the theft as an exchange security failure rather than a problem with the token itself.
Watch two things this week: whether the phased withdrawal restart goes smoothly on September 28, and how much of the remaining $75 million gets moved before venues can lock it down.
Security researchers will be watching whether the attacker infrastructure matches prior North Korean operations such as Lazarus Group, which has accounted for billions of dollars in crypto thefts over the past decade. Attribution so far rests on Bitget own statement rather than independent forensic publication, so treat the North Korea link as provisional until blockchain analytics firms publish their findings.
For Bitget users, the practical question is counterparty trust. The exchange has published proof-of-reserves in the past and says the protection fund, funded from trading revenue, holds enough to absorb the loss. Past recoveries at hacked exchanges, from Binance 2019 hot wallet breach to Bybit much larger theft last year, show that full compensation is possible when reserves are genuine. The withdrawal restart on September 28 will be the real test of whether users believe it.
The wider damage
The breach hit more than XRP. Bitget disclosed losses across ether, USDT and other assets held in hot wallets, and the revised 387.5 million dollar estimate came after internal reconciliation of what was actually taken. The exchange paused all withdrawals within minutes of detecting the attack, which contained the damage but froze legitimate user funds for days. Customer service channels have been flooded, and the phased restart is designed to prevent a rush on remaining liquidity.
Past exchange hacks offer a rough playbook for what comes next. Stolen funds typically move through mixers, cross-chain bridges and small venues with weaker compliance before surfacing on major exchanges, a journey that takes days to weeks. Blockchain analytics firms are already labeling the attacker addresses, which will make any deposit to a KYC venue traceable and potentially recoverable. That is how hundreds of millions in previous thefts have been partially clawed back, though the process usually recovers a fraction of the total and takes years.