Newsroom
27 September, 2026 / News / AI / Tags: xrp, attacker, bitget, million, tokens

Nearly half the XRP taken in the exchange breach has left initial wallets as recovery options remain limited by network design
The attacker responsible for the Bitget exchange breach has transferred approximately $83 million worth of stolen XRP out of the original holding wallets, according to on-chain records reviewed as of Saturday. The movement leaves about $75 million still sitting in the five initial accounts while exposing a key limitation of the XRP Ledger.
Nearly 103 million XRP was removed from Bitget on Thursday, September 24, and split across five accounts controlled by the attacker. By 12:41 UTC on September 26, roughly 54 million XRP had left those original wallets. Two accounts that each started with 20 million XRP were reduced to balances of about 23 tokens and 55 tokens. A third account held approximately 5.8 million XRP after partial drainage. The remaining funds were distributed among additional wallets. The transferred portion was valued at around $1.54 per XRP. On-chain activity does not confirm whether any of the tokens have been sold.
One attempted transfer of about 521,000 XRP failed because the destination account lacked sufficient funds. A second wallet later sent an identical amount to the same recipient roughly an hour afterward.
XRP functions as the native asset of the XRP Ledger. The network permits issuers to freeze tokens they create and issue on the ledger, but that authority does not apply to XRP itself. As a result, there is no built-in mechanism available to block transfers or freeze balances held in wallets controlled by the attacker. This differs from issued assets such as certain stablecoins, where issuers retain blacklist capabilities.
Any recovery effort therefore depends on the destination of the tokens. If the XRP reaches a custodial exchange, that platform can restrict the receiving account and prevent further withdrawals. While the funds remain in attacker-controlled private wallets, no such intervention is possible at the network level.
Bitget revised its estimate of total assets transferred to attacker-controlled addresses to $387.5 million. The updated figure incorporates Zcash and TRON assets that were not included in an earlier assessment of $351.6 million. The exchange stated that the higher total represents assets taken in the original incident rather than additional unauthorized activity.
Customer balances remain covered by the exchange’s protection fund. Withdrawals are scheduled to resume in stages beginning September 28 for Bitcoin, followed by ether on September 29, USDT on September 30, and remaining tokens on October 2.
Separately, issuers of related stablecoins have restricted approximately $320,000 in tokens connected to the incident. Those freezes illustrate the contrast with native XRP, which lacks an equivalent control feature.
More than half of the stolen XRP has already been redistributed from the initial set of wallets. Because native XRP cannot be locked at the ledger level, investigators and the exchange must rely on monitoring subsequent transfers and cooperation from any platforms that receive the tokens. The remaining balances in the original accounts stay fully transferable under current network rules.









