Bitget, one of the world’s major cryptocurrency exchanges, is facing a major security incident after approximately $387.5 million worth of digital assets were transferred to attacker-controlled wallets.
The incident comes months after the exchange was drawn into controversy surrounding the dramatic price surge and subsequent collapse of RAVE, the native token of RaveDAO, following allegations of possible insider trading and market manipulation.
Bitget Confirms $387.5 Million Security Breach
Bitget said unauthorized transfers were detected on September 24 from wallets used to facilitate exchange operations.
The exchange initially estimated the value of the affected assets at approximately $351.6 million but later revised the figure to about $387.5 million after identifying additional affected assets across the Zcash and TRON networks.
The affected assets reportedly include XRP, ETH, USDT, ZEC, USDC, USDT0, XAUt, BNB, AVAX and TRX.
Bitget said it has identified the attack path and remediated the underlying vulnerability. The exchange also said the incident has been contained and that further unauthorized transfers are no longer possible.
Cybersecurity firms Mandiant and SlowMist are assisting with the investigation, while Bitget has launched a recovery bounty programme aimed at helping trace, freeze and recover the stolen assets.
RAVE Controversy Had Previously Put Bitget Under Scrutiny
The security incident follows an earlier controversy involving Bitget and the RAVE token.
In April 2026, RAVE experienced an extraordinary price rally, rising from approximately $0.25 to nearly $28 within about nine days, before subsequently losing more than 80% of its value.
The unusual price movement attracted the attention of blockchain investigator ZachXBT, who raised allegations concerning wallets associated with the RaveDAO ecosystem.
According to allegations published during the controversy, wallets linked to the RAVE ecosystem controlled a significant portion of the token’s supply, while substantial amounts of RAVE were reportedly transferred to centralized exchanges before the major price movement.
ZachXBT called on exchanges including Binance, Bitget and Gate to investigate the activity and offered a bounty for information from potential whistleblowers.
Bitget CEO Gracy Chen subsequently confirmed that the exchange had opened an investigation into the matter.
However, the allegations were not established as proof that Bitget or its employees engaged in insider trading. RaveDAO also denied responsibility for the unusual market activity.
Is the RAVE Controversy Connected to the Hack?
At present, there is no verified evidence linking the RAVE controversy to the latest Bitget security breach.
The two incidents involve fundamentally different allegations.
The RAVE controversy centred on unusual trading activity, token transfers and allegations of possible market manipulation, while the latest incident involves unauthorized transfers from Bitget-controlled wallets.
Bitget’s current investigation is focused on determining how the attackers gained access to the affected wallets, identifying the stolen assets and tracing their movement across different blockchain networks.
North Korean Hackers Suspected
Bitget CEO Gracy Chen has also said preliminary findings point toward a possible connection with North Korean state-linked hacking groups.
The preliminary attribution reportedly draws on similarities involving infrastructure, IP addresses, VPN activity and on-chain behaviour.
However, the attribution has not been independently established as a confirmed finding, and investigations remain ongoing.
What Happens Next?
The incident is likely to intensify scrutiny of cryptocurrency exchange security, wallet-management systems and the procedures exchanges use to monitor suspicious transactions.
Bitget says it is continuing to work with blockchain networks, cybersecurity firms, law-enforcement authorities and other cryptocurrency exchanges to trace the stolen funds and recover assets where possible.
The exchange has also encouraged industry participants to help identify and freeze suspicious addresses associated with the attack.
The RAVE controversy and the latest Bitget breach are currently separate incidents, and there is no established evidence that one caused or contributed to the other.
As investigations continue, the crypto industry will be watching closely for further details about the attack vector, the movement of the stolen funds and whether any additional parties were involved.
CoinNewsExtra will continue to monitor the investigation and provide updates as more information becomes available.


