Bitget’s $157M XRP Problem: The Biggest Stolen Slice May Be the One No Foundation Can Freeze
More than $157 million worth of XRP stolen in the Bitget breach is now sitting in wallets that cannot be frozen by any issuer or foundation, according to the source’s review of XRP Ledger activity and public comments from Bitget.
The exchange said attackers compromised “a critical backend system” in its wallet infrastructure, spoofed transaction data, and drained more than $350 million from hot and warm wallets. The largest reported single portion was XRP: roughly 102.93 million tokens, valued by the source at about $157.48 million.
Three transfers created the XRP pile
According to the source, two Bitget wallets sent 102,926,478 XRP to a new address in three payments on Sept. 24. A watcher cited in the source calculated a slightly higher total of 102,976,680 XRP when adding related ledger activity.
The attacker later split the XRP across five wallets, the source said: four holding 20 million XRP each and a fifth holding 22,976,677 XRP.
Each transfer was followed by a tiny 0.00001 XRP payment from unrelated addresses, a pattern the source described as typical of address poisoning scams, where bad actors try to trick users into copying a lookalike wallet address.
Why this part of the theft is harder to stop
Bitget CEO Gracy Chen said the exchange contacted foundations on affected chains and that some had “already frozen the hacker’s wallet addresses,” according to the source.
That tool can work for issued assets such as USDT or USDC, where an issuer can intervene. But native XRP is different. The XRP Ledger’s freeze functions apply to issued tokens, not XRP itself.
That leaves exchanges, bridges, and other off-ramps as the practical chokepoints if the attacker tries to convert or cash out the funds.
Possible Lazarus ties remain unconfirmed
Chen said IP behavior and on-chain signatures were “consistent with techniques used by DPRK-linked hacker groups,” while also stressing that the attacker’s identity had not been confirmed.
On-chain analyst Specter went further, posting a flow graph that tied ETH paid out by the Bridgers swap service for stolen XRP to wallets tagged with the Trader Traitor cluster. The source says Specter connected those funds to July’s roughly $24 million AFX attack.
That link remains tentative. The source notes the connection runs through a single Ethereum wallet holding about $4,300, and that small overlaps can also reflect shared laundering routes rather than direct attribution.
Security firm Blockaid attributed roughly $609 million of first-half 2026 losses to the Trader Traitor cluster, which is associated with the Lazarus Group, according to the source.
Only a small amount has moved so far
For now, the attacker appears to have moved only a small fraction of the XRP. The source says about 400,105 XRP had left one of the five wallets by Sept. 25, while the other four wallets had not moved any coins.
On-chain sleuth Yfarmx reportedly spotted 33,500 XRP moving through Bridgers on Sept. 25 and described it as “a test run before a bigger cash-out.”
XRP was trading at $1.53, up 1.4% on the day, according to the source. But the risk remains that a larger wave of stolen XRP could move through swap venues or exchanges.
Bitget said its User Protection Fund will cover losses after assessment. The source says the fund currently holds 5,500 BTC.