Bitget Hit by $350 Million Hack: How Can the Stolen Funds Be Traced?

Another exchange theft has happened—yet again. Only this time, the amount is roughly $350 million, and the victim is Bitget.
In the early hours of September 25, 2026, Bitget was hit by a sudden security incident. According to the security announcement published by the platform, at 02:31:11 Beijing time, the system detected abnormal transfers from some hot and warm wallets, with a preliminary assessment involving approximately $351.6 million; cold wallets were unaffected. Bitget stated that the relevant losses fall within the coverage of its user protection fund, and that it had temporarily suspended withdrawals, to be resumed in an orderly manner after the security review is completed.

Security announcement published by Bitget on September 25, 2026 (screenshot source: Bitget official website)
The more news like this I read, the harder it is to keep my attention fixed only on "how much money was lost again." The more practical question is: whose hands will the money pass through next, and which participants still have time to do something? How the losses are made up first tests Bitget; whether the funds can be intercepted also involves the exchanges, swap services, cross-chain protocols, and aggregation applications along the way, as well as the people who actually hold business authority over them.
After the incident, Bybit co-founder and CEO Ben Zhou expressed willingness to help Bitget, saying the team was updating the LazarusBounty platform to assist in tracing the flow of the stolen funds. At a critical moment, a competitor's willingness to lend a hand is a form of industry mutual assistance worth affirming.
Similar mutual assistance has appeared in previous thefts. After Bybit was hacked in 2025, Bitget CEO Gracy Chen publicly stated that she would assist in tracing and investigation. According to Bybit's official incident timeline, Bitget also transferred 40,000 ETH to Bybit at the time to provide liquidity support. Providing liquidity and recovering stolen assets are two different tasks, but together they illustrate one thing: after a major security incident, it is difficult for a single platform to handle all the responses alone.
After the expressions of support, the truly difficult work begins. Stolen assets may be quickly converted into other tokens, split across multiple addresses, or bridged to another chain. Of the services the funds pass through along the way, some can control custodial accounts, some hold transactions that have not yet been settled, and some can only manage front-end entry points, routing, or part of the execution process. Investigators and the victim must quickly identify the entities that actually have the ability to take action.
Asset-recovery collaboration really tests three things: whether on-chain addresses can be matched to specific transactions, whether business authority can be converted into disposal actions, and whether temporary measures can be smoothly connected to formal procedures.
These three things also determine the order of discussion in this article. Public statements can convey goodwill; whether the funds can be intercepted requires answering, layer by layer, who controls this link, how far the transaction has progressed, what measures the existing materials support, and how disclosure, preservation, and return are subsequently completed.
Step One: First Identify Who Truly Holds Disposal Authority
To turn industry support into action, the first step is to identify who holds actual authority over the relevant transactions. A service provider that receives assets and pays only after completing a swap may control assets that have not yet been settled; a custodial exchange may hold associated accounts and deposit/withdrawal authority; the operators of a cross-chain protocol or aggregation application may only control the front end, routing, transaction forwarding, or part of the execution process.
When determining whom to approach for assistance, platform names and technical labels can only provide a starting point; what really matters is the business process and control relationships. The victim can use this to find entities capable of accepting requests; the operator receiving a request can also use it to confirm exactly what it can suspend, verify, and preserve, and which matters exceed its own authority.
Legal obligations must also be assessed in light of the specific business and the applicable jurisdiction. Under the international standards of the Financial Action Task Force (FATF), virtual asset service providers should generally implement preventive measures such as customer due diligence, record-keeping, and suspicious transaction reporting, with the specific scope of application and manner of implementation determined by the laws of each jurisdiction. Statutory verification, preservation, or reporting obligations that have already been triggered should be performed in accordance with the applicable rules; whether transactions may also be restricted or information provided to specific parties requires separate assessment.
This analysis also applies to businesses using decentralized technology. In its DeFi thematic report published in July 2026, the FATF focused on who has control or sufficient influence over the relevant arrangements, listing factors such as administrative authority, upgrade control, concentration of governance tokens, and infrastructure influence. The report provides an analytical framework under international standards, but specific obligations still return to local law. For cross-chain protocols and aggregation applications, what services the operator actually provides and which links it controls usually say more than the label "decentralized."
Step Two: Match On-Chain Addresses to Specific Transactions
After identifying the entities that may be able to accept requests, the next step is to match the on-chain fund path to the counterparty's accounts, orders, and business records. Address labels can only indicate the direction of tracing; only by landing on a specific transaction can the relevant operator more easily determine whether the funds are still within its control and what disposal options exist at this stage.
When the victim platform or its authorized agent makes an assistance request, it can, to the extent possible, explain the case, the blockchain involved, transaction hashes, token types, amounts, times, relevant addresses, and how these leads relate to the recipient's business. The service provider receiving the request can then, according to its own procedures, verify the requester's identity, the source of the materials, and its own connection to the transaction. How far the transaction has progressed is an important clue for assessing disposal options.
For services that collect payment first and pay after completing a swap, "not yet swapped," "swapped but not yet paid," and "already paid" correspond to different states of control. For cross-chain or aggregation services, the operator can use the materials it lawfully holds to check the source-chain transaction, the swap request, the destination-chain address, and the execution status. What specifically needs to be verified should be determined based on the business architecture, the materials lawfully held, and applicable requirements.
Once external leads are matched to actual accounts, a custodial exchange may be able to take measures where it has the authority and basis to do so. According to disclosures by Elliptic, in 2023 Binance and Huobi, acting on intelligence it provided, froze accounts containing approximately $1.4 million in crypto assets, with the funds originating from the earlier Harmony Horizon bridge attack. The key to this case succeeding was that external tracing results were matched to accounts controlled by the exchanges. Whether other platforms or protocols can take similar measures depends on their respective authority, evidence, and applicable procedures.

Elliptic discloses its collaboration with Binance and Huobi to freeze stolen funds linked to the Lazarus Group (screenshot source: Elliptic official website)
Step Three: Choose Appropriate Measures Based on the Transaction Stage
Once leads are matched to specific transactions, the question shifts from "what was found" to "what can still be done now." Restricting entry points, suspending swaps, deferring payments, and restricting transfers out of custodial accounts differ in their targets, sources of authority, and scope of impact. Operators need to make judgments balancing the urgency of continued fund movement, the credibility of the existing materials, and the rights of legitimate traders.
When assets that have not yet been settled remain under the service provider's control, the provider can assess the feasibility of suspending a swap or deferring payment in light of applicable law, contractual arrangements, technical capability, and the impact on the relevant users. The fact that a transaction has not yet been fully executed does not automatically create an obligation to freeze or return, but it may leave time for temporary verification. When a custodial exchange faces associated accounts, it also needs to review the specific basis, scope, and continuing conditions for restricting transfers out.
Operators of cross-chain protocols and aggregation applications should first sort out which links they control. Those that only manage the front-end interface can usually only act on that entry point; those that also hold transaction forwarding or execution authority may have additional room for intervention. When contract suspension or upgrade is involved, multi-signature arrangements, governance procedures, and the impact on other users will also affect whether the measures are feasible.
Entry-point restrictions can reduce the risk of a specific service being further exploited, but their actual effect depends on the service architecture and other access paths. If users can still access the service through other entry points or by directly calling the contract, restricting a single front end will have limited effect.
OKX's announcement on March 17, 2025, provides a real-world example. OKX stated that, after discovering Lazarus attempting to abuse its DeFi services, it proactively suspended its DEX aggregation service and upgraded its preventive measures after communicating with regulators; the announcement also noted that the aggregator connects liquidity across multiple protocols and does not itself custody customer assets. This case shows that non-custodial services can also adjust the products and entry points they control. Whether funds in the underlying protocols can be frozen still depends on the actual architecture and control authority.
When taking temporary measures, relevant operators can also consider the scope of application, review checkpoints, conditions for lifting, and record retention. For law enforcement or judicial orders that are legally binding and applicable to the party, they should be handled according to their effect and scope; where there are doubts about the scope of execution or technical feasibility, they can be explained and clarified through the appropriate procedures. Even if the funds have already been moved out, lawfully retained account, order, login, and communication records may continue to assist subsequent recovery efforts.
Step Four: Connect Temporary Restrictions to Formal Return Procedures
Temporarily stopping the funds only buys a window for handling the matter. Whether they can ultimately be returned still requires answering who the assets belong to, what can be delivered, to whom they should be delivered, and under what procedure. After swaps and multiple transfers, the counterparty may assert its own basis for a legitimate transaction and acquisition of the assets; once funds enter an exchange's pool, the claimant may also need to further prove the connection between the controlled assets and the original stolen funds.
Temporarily restricting transfers and final return often correspond to different conditions and evidentiary requirements. An entity that only manages the front end and does not control the relevant assets may mainly be able to provide lawfully held records; an entity holding customer information or order information must also consider the recipient, scope of disclosure, confidentiality obligations, and personal information protection requirements when disclosing externally.
Judicial measures also require the claimant to have its evidence and procedures in order. In the 2023 judgment in the UK Piroozzadeh case, the victim obtained a temporary proprietary injunction without notifying Binance, and the court later discharged the injunction because the applicant had failed to present the case fully and fairly. The judgment discussed the defense of bona fide purchase for value that an exchange might raise, as well as how to identify and enforce preservation once funds are mixed into a pool. That case concerned an application for a temporary injunction and did not finally adjudicate asset ownership, but it reminds claimants that turning on-chain tracing results into judicial measures still requires satisfying the corresponding evidentiary and procedural requirements.
The public rules of swap services can also reflect this distinction. ChangeNOW's public assistance instructions require the requester to provide case details, transactions, an address list, and law enforcement procedure information; clause 6.11 of its terms of service also states that, depending on when the report is received, the platform may intercept a transaction only after the swap is completed, in which case the assets that can be returned may be the post-swap token. Under that clause, return also requires an explicit request from law enforcement. This is the handling mechanism publicly disclosed by ChangeNOW; how other service providers handle such matters still depends on applicable law, contractual arrangements, asset status, and specific procedures.
What Different Participants Should Do First
When the above analysis is applied in practice, the biggest fear is that "everyone is willing to help, but no one knows who should send the next email, what to attach, and who should make the judgment after it is received." Fund movement will not wait for all parties to slowly familiarize themselves with the process. In light of the authority of different roles, the following items can serve as a reference when initiating disposal.
For the victim platform or project: It can prioritize fixing the incident timeline, organizing transaction hashes, involved addresses, token types, amounts, and on-chain paths, and preparing ownership, police report, and authorization materials. External assistance requests are best sent through a single window, clearly stating what the other party is expected to verify, to what extent the existing leads provide support, and how subsequent formal procedures are progressing.
For operators such as exchanges and swap services: After receiving leads, they can first check associated accounts, orders, and transaction stages, preserve KYC, login, device, communication, and operation records, and then have business, technical, compliance, and legal personnel assess the measures that can be taken in light of their own authority. Matters not yet confirmed can be noted as still under review; measures already taken and their limitations can also be fed back to the requester to the extent permitted by law.
For cross-chain protocols, aggregators, and related operators: They can promptly distinguish smart contracts, front ends, routing, APIs, upgrade authority, and governance mechanisms, and confirm which links are actually under their control. When planning to adjust entry points, suspend services, or initiate multi-signature or governance procedures, they should also assess other access paths, the impact on normal users, and conditions for restoration, and retain records of the facts and authority on which decisions were based.
For lawyers and on-chain investigation teams: The focus is to organize the on-chain path into a factual working document that can be understood by the platform internally, law enforcement, and the courts, and to match each request to a specific entity, authority, and procedure. When multiple jurisdictions or multiple service providers are involved, they should also design the sequence of material transmission and actions, avoiding leaving leads stranded in an address list, and avoiding a disconnect between temporary restrictions and subsequent preservation, disclosure, and return.
The earlier all parties collaborate on the same factual working document, the easier it is to connect verification, restriction, disclosure, and return. Relevant operators can also establish risk-lead intake points and internal decision-making processes in normal times, clarifying who receives requests, who judges transaction relevance, who assesses the legal basis, and under what circumstances escalation to management or external professional teams is required.
Whether Liability Arises Ultimately Depends on Specific Evidence
Only after collaboration has progressed can the question of liability be discussed more accurately. A delayed reply, a single error in risk judgment, persistent violation of statutory anti-money laundering requirements, and knowingly helping to move criminal funds correspond to different facts and different legal assessments. For protocols or applications, liability must also be attributed to specific operators or controllers; identities such as developer or governance participant are not by themselves sufficient to determine liability.
At the regulatory level, the first step is to confirm whether the relevant entity is an obligated party under applicable law, and then to assess the specific customer due diligence, record-keeping, and reporting requirements. The FATF's suspicious transaction reporting standard requires countries to provide by law that financial institutions promptly report to the financial intelligence unit when they suspect or have reasonable grounds to suspect that funds are the proceeds of crime. For virtual asset service providers subject to local law, the reporting entity, trigger conditions, and manner of performance remain governed by local rules.
Submitting a suspicious transaction report to a statutory body and disclosing customer information to the victim are two different types of conduct, with different bases and boundaries. Reported information may also be subject to confidentiality restrictions. Whether a relevant operator can state externally that it has reported or is investigating must be assessed in light of applicable rules; more serious allegations such as assisting money laundering must be proven by evidence of specific conduct, subjective awareness, and other elements required by local law.
The 2025 investigation by German law enforcement into the crypto asset swap service eXch focused on both the flow of funds and the platform's manner of operation. Elliptic had traced and found that some of the ETH stolen from Bybit was converted into BTC through services such as eXch. Subsequently, Germany's Federal Criminal Police Office announced that, on April 30, 2025, law enforcement seized eXch's servers in Germany and crypto assets then worth approximately €34 million, with the operators suspected of commercial money laundering and operating an internet platform for criminal transactions. The announcement also mentioned that the service had advertised on underground networks that it did not implement anti-money laundering measures and did not require users to verify their identities. The relevant criminal allegations must still be proven according to the legal elements and evidence.
The lesson from this case is direct: investigators pay attention not only to where the funds passed through, but also to how a service solicits business, how it organizes swaps, and what actions it took when faced with risk leads. Operators retaining the necessary verification and decision-making records helps explain when a risk was discovered, what authority was held at the time, and why a particular measure was or was not taken. The scope and retention period of records should still comply with applicable rules, and their evidentiary value must be assessed together with other evidence.
Mankun Lawyer's Summary
Having seen quite a few similar incidents, I increasingly feel that the outcome of asset recovery often depends on something very simple: whether all parties can connect authority, evidence, and procedures in the shortest possible time. Public expressions of support let people see the warmth of the industry; truly stopping the assets, getting the materials into the investigation, and giving the return a legal basis still require item-by-item concrete work.
The hardest part of such matters is usually piecing together the on-chain path, account and order information, business control authority, legal basis, and cross-border procedures into an executable recovery chain. The earlier on-chain investigators, platform compliance, technical staff, and lawyers collaborate around the same factual working document, the easier it is to connect subsequent verification, restriction, disclosure, preservation, and return. For institutions that have experienced abnormal asset movement or may receive assistance requests, completing the sorting of authority, preservation of evidence, and design of response paths as early as possible can also reduce the risk of missing the disposal window.
What users entrust to a platform is not only assets, but also trust. The true mark of an industry's maturity is that, after every incident, publicly expressed goodwill can be translated into actions that are well-founded, executable, and traceable.
May we see fewer "another" and more evidence-backed "recovered."


