bitcoin cryptocurrency pexels

Bitget, one of the world’s largest cryptocurrency exchanges, has raised its estimate of the assets stolen in its recent hack to $387.5 million, after discovering that Zcash and TRON holdings were missed in the initial count. The company says the increase is not linked to any new transfers; the assets were already gone, and the counting has simply caught up with the crime (CoinCentral).

Nearly four hundred million dollars. Sit with that number for a second, because behind it are real people who woke up to find their savings, their trading accounts, their plans, drained into wallets controlled by strangers. This is the anatomy of one of the largest exchange hacks of the year, and it contains lessons that every person who holds crypto needs to understand, whether you keep $200 or $200,000 on an exchange.

The haul, as currently counted, reads like a tour of the crypto market: XRP, ETH, USDT, ZEC, USDC, XAUt, BNB, AVAX, and TRX. The attackers did not specialize. They took what they could reach, across chains, across asset types, a sweeping grab that tells you the breach was deep and the defenses, whatever they were on paper, did not hold where it mattered.

What happened next is where this story gets technically interesting and emotionally complicated. On Friday at 05:00 UTC, Circle, the company behind the USDC stablecoin, blacklisted a wallet tied to the attackers, a wallet holding 170 ETH, 218,023 USDT, and 99,990 USDC. Tether, the issuer of USDT, banned the same wallet shortly after. Together, the two companies froze about $318,000 in stablecoins. Three hundred and eighteen thousand dollars, against a theft of $387.5 million. The freeze was real, it was fast, and it was a drop in the bucket.

And here is the detail that should change how you think about crypto forever: the attackers’ addresses still hold more than 63,000 ETH, and that ether cannot be frozen. Not by Circle, not by Tether, not by anyone. This is the fork in the road that defines the entire crypto world. Stablecoins like USDC and USDT are issued by companies that keep a blacklist; when crime touches their tokens, they can reach in and stop the money from moving. Ether, the native asset of the Ethereum network, has no issuer, no customer service desk, no freeze button. Once it lands in an attacker’s wallet, it moves only when the attacker moves it. The same decentralization that crypto believers celebrate is, in a hack like this, the thief’s best friend.

Bitget’s response has followed the industry playbook. The exchange launched a Recovery Bounty Program, offering 5% of recovered value to anyone who helps freeze attacker funds and another 5% to anyone who helps recover them. Ten percent of $387.5 million is a serious incentive, and it is also a confession: the exchange cannot get this money back on its own, so it is crowdsourcing the chase. Bounty programs have worked before, sometimes. White-hat hackers, chain analysts, and even rival exchanges have helped trace and recover stolen funds in past incidents. But they are a long shot dressed as a plan, and customers waiting to be made whole should understand that.

Now zoom out, because this hack did not happen in a vacuum. On September 24, just days before the revised loss figure, the Federal Reserve proposed two new rules implementing the GENIUS Act for payment stablecoins. Under the proposal, issuers of payment stablecoins must fully back their tokens with short-term Treasury bills and other high-quality liquid assets, meet capital and risk-management standards, and go through a tailored application and appeals process. The rules are now in a 60-day public comment period, and the details here come from secondary reporting (CryptoNews).

The timing is worth noticing. Regulators are building a fence around stablecoins at the exact moment a hack is showing why the fence matters. The assets that could be frozen in the Bitget theft were the regulated-ish ones, the stablecoins with issuers who answer to someone. The GENIUS Act framework is, at its heart, an attempt to make sure those issuers are holding real, safe reserves behind every token, so that a dollar-pegged coin is actually worth a dollar when the storm comes. The 63,000 ETH that cannot be frozen sits outside that fence entirely, in the part of crypto that no regulator can reach.

So what are the hard lessons for anyone holding crypto on an exchange? Let me lay them out plainly, and mark the opinion as mine where it is mine.

First, an exchange is a company, not a vault. When you keep crypto on an exchange, you are trusting that company’s security, its honesty, and its solvency. The Bitget customers who lost funds did nothing wrong; they simply trusted a big name. Big names get breached. The history of crypto is a long list of big names that got breached.

Second, not all crypto is equally recoverable. This is the single most important technical lesson of the Bitget hack. If you hold stablecoins like USDC or USDT, there is at least a theoretical chance that stolen funds can be frozen, as Circle and Tether demonstrated. If you hold native assets like ETH, there is no freeze button, no matter how large the theft. Knowing which of your holdings can be stopped and which cannot should shape how much risk you take with each.

Third, bounties are hope, not a plan. A 5% bounty for freezing funds and 5% for recovery is better than silence, and Bitget deserves credit for offering it quickly. But if your financial safety depends on anonymous bounty hunters outracing professional thieves, your safety was never as solid as you thought.

Fourth, regulation is coming to the stable parts of crypto, and that is probably good for ordinary holders. The Fed’s GENIUS Act rules, with their requirements for T-bill backing and real capital standards, are aimed at making stablecoins boring. Boring is exactly what you want from something you treat like a dollar. The wild parts of crypto, the 63,000 unfrozen ETH and everything like it, will stay wild. Know which part you are standing in.

Here is my take, labeled as such: the Bitget hack will not be the event that makes people leave crypto, just as past hacks did not. But it should be the event that makes people stop treating exchanges like savings accounts. If you would not keep your emergency fund in a stranger’s backpack, do not keep your crypto on an exchange you have not stress-tested with the question, “What happens if they get hacked tomorrow?” The answer, as $387.5 million in missing assets now shows, is that you wait, you hope, and you learn the difference between the coins that can be frozen and the ones that cannot. Learn it now, while your money is still yours.