More than 99% of the 102.97 million XRP taken from Bitget on 24 September remains untouched across five newly created wallets, with no mechanism on the XRP Ledger to freeze the funds.
The exchange said attackers had compromised “a critical backend system” within its wallet infrastructure, manipulated transaction data and transferred more than $350m from its hot and warm wallets. XRP accounted for the largest share, with on-chain trackers valuing 102.93 million XRP at $157.48m. The haul also included 31,890 ETH and about $75m in stablecoins.
Records on the XRP Ledger show the stolen XRP was divided between five addresses. Four contain 20 million XRP each, while the fifth holds 22,976,677 XRP, bringing the total to 102,976,680 XRP – the figure identified by one tracker on the night of the breach.
Each transfer was followed by a payment of 0.00001 XRP from unrelated addresses. The activity resembles address poisoning, a tactic in which scammers try to make victims copy an incorrect wallet address from their transaction history.
Bitget chief executive Gracy Chen said the exchange had contacted foundations responsible for each affected blockchain and that some had “already frozen the hacker’s wallet addresses”. Such intervention is possible with tokens controlled by an issuer, including USDT and USDC. Arbitrum also froze $71m linked to the KelpDAO exploit in April.
The XRP stolen in the Bitget attack cannot be frozen in the same way. The XRP Ledger’s freezing functions apply to issued tokens rather than its native asset. As a result, exchanges and bridges are the main points at which the attacker could potentially be blocked while attempting to convert the funds.
Chen said the hackers’ “IP behavioral patterns” and on-chain signatures were “consistent with techniques used by DPRK-linked hacker groups”, although she stressed that the identity of the attacker had not been confirmed.
On-chain analyst Specter published a flow graph linking ETH paid by the Bridgers swap service for stolen XRP to wallets associated with the Trader Traitor cluster. Specter also connected those funds to the AFX attack in July, in which about $24m was stolen.
That link remains limited because the graph passes through a single Ethereum wallet containing about $4,300. Small overlaps can also result from the use of the same laundering services. However, the activity is consistent with a wider pattern: security firm Blockaid attributed roughly $609m in losses during the first half of 2026 to the Trader Traitor cluster, which is linked to the Lazarus Group.
Only a small amount has so far moved from the five wallets. On-chain investigator Yfarmx reported that 33,500 XRP passed through Bridgers on 25 September, describing it as “a test run before a bigger cash-out”. The ledger now shows approximately 400,105 XRP removed from one wallet, while the other four remain inactive.
XRP was trading at $1.53, up 1.4% from the previous day. Bitget said its User Protection Fund, which currently holds 5,500 BTC, would cover the loss following an assessment.
