Coindesk Bitget Hacker Moves $83 Million in Stolen XRP Amid Ongoing Investigation
Article Content
- •The Bitget exchange suffered a $387.5 million breach, with $83 million in XRP moved by the hacker.
- •Circle and Tether froze $320,000 in stablecoins, but most stolen funds in ether remain unfrozen.
- •Bitget's protection fund will cover customer losses, with withdrawals resuming soon.
The hacker responsible for the Bitget exchange breach, totaling $387.5 million, has transferred $83 million in stolen XRP from three wallets, leaving approximately $75 million still in accounts that cannot be frozen due to XRP Ledger rules. While exchanges can restrict accounts receiving the stolen XRP, Ripple cannot block transactions from the attacker's wallets. Circle and Tether have frozen $320,000 in related stablecoins, but most of the stolen funds, primarily in ether, remain unfrozen. The breach was executed through a backend system compromise, with Bitget's CEO confirming no private key compromise occurred. The exchange's protection fund will cover customer losses, and withdrawals are set to resume from September 28 to October 2. XRP's market price has slightly declined, but the stolen amount represents a significant portion of the token's trading volume.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Following this threat?
Track Bitget in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Exploits Target F5 and Check Point Products F5 Networks released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager on September 22, 2026, after confirming active exploitation. This flaw allows unauthenticated remote code execution (RCE) and has a CVSS score of 9.8. Concurrently, Check Point disclosed…
Critical Zero-Day Vulnerability in F5 BIG-IP APM Exploited for Remote Code Execution F5 Networks has reported a critical vulnerability in its BIG-IP Access Policy Manager (APM), tracked as CVE-2026-94127, which is being actively exploited in the wild. The flaw allows unauthenticated attackers to execute remote code on systems configured with both an APM access policy and an OAuth profile. This…