New on-chain activity has emerged in the Bitget hack case. According to a post from blockchain analytics account Lookonchain, a wallet starting with 0x4885 withdrew 257.6 ETH, worth about $692,000, and 545,000 USDT from Binance around 11 hours earlier. It then swapped the USDT for 200.2 ETH and, about an hour before the post, transferred a total of 457.9 ETH, or roughly $1.23 million, into a wallet associated with the Bitget hacker.
Lookonchain said the wallet "appears" to be linked to the attacker. No other confirmation has been provided so far to establish a direct connection between the 0x4885 wallet and the hacker.
An unusual funding route
The transfer pattern runs against the direction more commonly seen in hack cases. In many incidents, attackers move stolen assets out of the victim platform, swap them through decentralized exchanges, and scatter the proceeds across multiple chains. In this case, the 0x4885 wallet first withdrew funds from Binance, a centralized exchange with KYC requirements, and then sent the assets to the hacker wallet.
ABMedia said several explanations remain possible. The wallet could belong to the attacker or an accomplice and have been used to top up gas or consolidate funds. It could also be an attempt by a third party to create confusion. Relative to the total losses in the Bitget incident, the $1.23 million transfer is small. Still, if the wallet is eventually confirmed to be tied to the attacker, account information on Binance could become a useful lead for investigators. As of publication, Binance had not issued a public response.
Bitget loss estimate revised to $387.5 million
According to Crypto Briefing, Bitget detected unauthorized transfers from its hot and warm wallets at 18:31 UTC on Sept. 24, 2026, and then suspended all withdrawals. The initial estimated loss was $351.6 million. That figure was later revised upward to $387.5 million.
The revision included ZEC and TRX. Bitget said it had not found any other unauthorized outflows.
As for the attack method, the attacker did not steal private keys. Instead, the exploit abused a flaw in Bitget's backend wallet system to forge transaction authorization data and bypass standard verification checks. Cold wallets were not affected. Lookonchain had previously said the attacker had already converted most of the stolen assets on EVM chains into 67,982 ETH.
Investigation, attribution questions, and the protection fund
Bitget CEO Gracy Chen said the attack points to a North Korean hacking group based on IP behavior patterns and on-chain analysis. At the same time, the report said some analysts remain cautious about directly attributing the incident to Lazarus Group. Bitget and outside investigators, however, believe the attack characteristics match those of a North Korean state-backed operation.
Cybersecurity firms Mandiant and SlowMist have joined the investigation, and law enforcement agencies have been notified.
Bitget has pledged to absorb the losses in full through its user protection fund. The fund consists of 5,500 BTC and is valued at about $464 million. The current loss estimate equals about 83.5% of that amount. On that basis, the remaining buffer is about $76.5 million, before accounting for any assets that may later be recovered. Because the fund is denominated in bitcoin, that buffer will also move with the BTC price.
On the recovery side, Bitget has launched a bounty program. Parties that proactively freeze the attacker's funds can receive a 5% reward, and those that help recover assets can also receive 5%. The exchange has also published the attacker's addresses and a live tracking dashboard. Trading and deposits are operating normally, while withdrawals remain pending until system verification is completed.

