What to Know

  • The attacker behind Bitget’s $387.5 million breach has moved about $83 million in stolen XRP from three holding wallets.
  • Nearly 103 million XRP was taken from Bitget and divided among five accounts.
  • Two wallets that initially held 20 million XRP each were almost emptied by 12:41 UTC Saturday, falling to about 23 and 55 tokens.
  • A third wallet was reduced to about 5.8 million XRP as transfers accelerated overnight.
  • Roughly $75 million remains in accounts that cannot be frozen under existing XRP Ledger rules.
  • Ripple has no built-in mechanism to block the attacker from spending XRP held in wallets the attacker controls.
  • Exchanges can restrict recipient accounts if stolen XRP reaches their platforms, but they cannot freeze XRP while it remains in attacker-controlled wallets.
  • Circle and Tether have frozen about $320,000 in related USDC and USDT because those tokens include blacklist controls.
  • XRP traded around $1.54 on Saturday, down about 4% over 24 hours while still up about 9% for the week.
  • Bitget says its protection fund covers the loss, customer balances are unaffected, and withdrawals are scheduled to resume from Sept. 28 through Oct. 2.

Bitget Attacker Moves Stolen XRP Across Wallets

The hacker behind Bitget’s major crypto breach has shifted about $83 million in stolen XRP out of three holding wallets, intensifying attention on how stolen funds can be tracked, restricted, and potentially recovered once they begin moving through public blockchain rails. The transfers follow the theft of nearly 103 million XRP from Bitget, with the stolen tokens initially divided among five accounts.

By 12:41 UTC Saturday, two of those accounts had been almost completely drained. Each had initially held 20 million XRP, but one was reduced to about 23 tokens and the other to about 55 tokens. A third holding account had fallen to about 5.8 million XRP. The activity leaves roughly $75 million across the original holding accounts, based on the market value referenced in the latest tracking of the stolen funds.

The movement is significant because XRP itself cannot be frozen by Ripple under the XRP Ledger’s current rules. While the XRP Ledger supports issued assets that can include freeze controls, those controls do not apply to XRP, the network’s native currency. That distinction limits the options available to Ripple and shifts more of the recovery effort toward exchanges, analytics teams, and any venues that may receive the stolen funds.

Why Ripple Cannot Freeze the Stolen XRP

XRP is the built-in currency of the XRP Ledger, a blockchain associated with payments company Ripple. The ledger allows companies that issue tokens on the network to freeze their own issued assets under certain conditions. However, that authority does not extend to XRP itself. In practical terms, Ripple cannot simply lock the attacker’s XRP or prevent the wallet from signing transactions.

This architecture means the attacker can continue moving XRP as long as the wallets retain access to the private keys and can pay transaction costs. The network’s design places native XRP outside the issuer-style freeze model that applies to some tokens created on top of blockchains. For law enforcement, compliance teams, and exchanges, that makes downstream monitoring especially important.

An exchange that receives stolen XRP may be able to restrict a recipient account and prevent withdrawals. That can become a key control point if the attacker attempts to deposit funds on a centralized platform. But while the coins remain in wallets directly controlled by the attacker, exchanges do not have the ability to freeze them at the protocol level. This creates a window in which funds can be fragmented across more addresses, routed through additional wallets, or prepared for attempted liquidation.

Stablecoin Freezes Show a Different Control Model

Circle and Tether have already frozen about $320,000 in stablecoins connected to the Bitget breach. The action highlights a sharp contrast between native blockchain assets such as XRP and issuer-controlled tokens such as USDC and USDT. Those dollar-linked tokens include mechanisms that allow their issuers to blacklist addresses and prevent movement of the tokens in certain circumstances.

For investigators and affected platforms, the difference matters. Stablecoins with blacklist functions can be immobilized if issuers identify and act on connected addresses. Native assets without similar administrative controls rely more heavily on tracking, exchange cooperation, and legal processes. The Bitget case has therefore become a live example of how asset design can affect incident response after a major exchange breach.

That does not mean stolen XRP cannot be intercepted later. If the attacker sends XRP to a centralized exchange, compliance teams may restrict access, freeze the customer account, and stop withdrawals. However, the success of that effort depends on timely detection, wallet attribution, and the attacker’s choice of routing. Once funds are scattered into more wallets, tracing can become more complex, even though the underlying ledger remains transparent.

Transfers Accelerated Overnight

The pace of XRP transfers picked up sharply overnight. At 04:32 UTC Saturday, about 70 million XRP remained in the original five holding accounts. Roughly eight hours later, the balance had dropped to 49 million XRP. That rapid reduction suggests the attacker was actively distributing the funds rather than leaving them parked in the initial wallets.

Some of the payments followed routes that had already been used by the first wallet. In one case, an attempted transfer of about 521,000 XRP failed because the account lacked sufficient funds. Roughly an hour later, the second wallet sent an identical amount to the intended recipient. Market participants often view this type of pattern as an indication that a single operator or coordinated process is managing the movement of funds across multiple addresses.

About 54 million XRP has now left the original holding accounts. The transfers show that the attacker is spreading the stolen tokens across more wallets, although the public movement of funds does not show how much, if any, has been sold. On-chain transfers can indicate redistribution, preparation for liquidation, or attempts to complicate tracing, but they do not necessarily confirm market sales unless the funds reach identifiable trading venues or other liquidity channels.

XRP Price Holds Weekly Gain Despite Pressure

XRP traded around $1.54 on Saturday, down about 4% over 24 hours while retaining a weekly gain of about 9%. At that price, the original XRP haul was worth roughly $160 million. That amount was equivalent to about 4% of XRP’s $4.4 billion in reported daily trading volume.

The market impact of any sale would depend on liquidity conditions at the moment of execution. A large token balance can appear manageable compared with daily reported volume, but price movement is ultimately shaped by the depth of buy orders available when selling occurs. If an attacker attempts to liquidate quickly into thin order books, slippage can be more severe. If funds are dispersed and sold gradually, the immediate visible impact could be smaller.

Technical traders are also watching whether the stolen XRP becomes a psychological overhang for the market. Even without confirmed sales, the knowledge that a large balance is moving can influence short-term sentiment. Some traders may reduce exposure while they wait for more clarity, while others may focus on the token’s broader weekly performance and liquidity profile.

Bitget Says Protection Fund Covers the Loss

Bitget has raised its estimate of the overall theft to $387.5 million after including Zcash and TRON transfers that were missed in its initial accounting. The exchange said the higher figure reflected assets taken during the original breach rather than a separate attack.

The company has also said its protection fund covers the loss and that customer balances remain unaffected. That statement is central for users watching the exchange’s response, because the main operational risk after a breach is whether customers can access their funds and whether the platform can restore normal service without imposing losses on account holders.

Withdrawals are scheduled to resume in stages. Bitcoin withdrawals are set to resume Sept. 28, followed by ether on Sept. 29, USDT on Sept. 30, and other tokens on Oct. 2. A phased reopening is common after major security incidents because exchanges typically need to review wallet infrastructure, verify balances, monitor suspicious flows, and rebuild confidence before returning all asset withdrawals at once.

What Comes Next for the Recovery Effort

The immediate focus is on the remaining balances in the original XRP holding accounts and any new wallets that receive funds. Because the XRP Ledger is public, analysts can continue monitoring flows, but the absence of a protocol-level freeze for XRP means stopping the attacker depends heavily on where the funds move next.

If the stolen XRP reaches a centralized exchange, the receiving platform may restrict the recipient account and prevent withdrawals. If the funds remain in self-custodied wallets or move through routes that do not involve compliant intermediaries, recovery becomes more difficult. The frozen USDC and USDT linked to the breach show that some connected assets can be immobilized, but the larger XRP component remains subject to a different set of constraints.

For the broader crypto market, the Bitget incident underscores a familiar tension. Public blockchains provide transparent transaction records, but that transparency does not automatically equal control. Native assets can be traceable yet still movable, while issuer-controlled assets can be frozen but introduce central points of intervention. The outcome of the Bitget recovery effort will likely depend on how quickly exchanges, stablecoin issuers, investigators, and analytics teams coordinate around the attacker’s next moves.

Frequently Asked Questions (FAQs)

How much XRP was stolen from Bitget?

Nearly 103 million XRP was taken from Bitget and divided among five accounts after the breach.

How much stolen XRP has the hacker moved?

The attacker has moved about $83 million in stolen XRP out of three holding wallets, with about 54 million XRP leaving the original holding accounts.

How much remains in the original holding accounts?

Roughly $75 million remains across the original accounts, based on the latest movement and market value described for the stolen XRP.

Why can’t Ripple freeze the stolen XRP?

Ripple cannot freeze XRP held by attacker-controlled wallets because XRP is the native currency of the XRP Ledger, and the network’s freeze controls apply to certain issued tokens rather than XRP itself.

Can exchanges stop the stolen XRP?

Exchanges can restrict accounts that receive stolen XRP and prevent withdrawals, but they cannot freeze XRP while it remains in wallets controlled by the attacker.

What did Circle and Tether freeze?

Circle and Tether froze about $320,000 in related USDC and USDT because those stablecoins include address-blacklisting controls.

What was XRP’s market reaction?

XRP traded around $1.54 on Saturday, down about 4% over 24 hours while still holding a weekly gain of about 9%.

Will Bitget customers take losses from the breach?

Bitget says its protection fund covers the loss and that customer balances remain unaffected.

When are Bitget withdrawals scheduled to resume?

Bitcoin withdrawals are scheduled to resume Sept. 28, followed by ether on Sept. 29, USDT on Sept. 30, and other tokens on Oct. 2.