By the early hours of Sept. 25, 2026, Bitget had become the latest exchange to report a major security breach. In a security notice, the company said its systems detected abnormal transfers from some hot and warm wallets at 02:31:11 Beijing time, with an initial estimated impact of about $351.6 million. Bitget said its cold wallets were not affected, the loss is covered by its user protection fund, and withdrawals were temporarily suspended until security checks are completed and services can resume in an orderly manner.

That headline figure is large enough on its own. Still, the harder question starts after the money leaves: who touches the funds next, and which of those parties still has the authority to do anything about it.
Bitget will have to deal with compensation first. Recovery is a separate track. Whether stolen assets can be slowed, identified, or contained depends on the exchanges, swap services, cross-chain protocols, aggregators, and operators that may sit somewhere along the route, and on which of them actually controls a meaningful part of the process.
After the incident, Bybit co-founder and CEO Ben Zhou said he was willing to help Bitget and that his team was updating the LazarusBounty platform to assist with tracking the stolen funds. In a crisis, support from a competitor stands out. It also reflects a practical reality: after a major theft, one platform rarely handles every part of the response on its own.
There is precedent for that kind of cooperation. After Bybit was hacked in 2025, Bitget CEO Gracy Chen publicly said Bitget would help with tracing and investigation. According to Bybit’s official incident timeline, Bitget also transferred 40,000 ETH to Bybit at the time to provide liquidity support. Liquidity support and asset recovery are not the same task, but both point to the same conclusion. Large-scale security incidents usually spill beyond a single company’s operational perimeter.
The difficult work begins after the public statements. Stolen assets may be swapped into other tokens, split across multiple addresses, or bridged to another chain in short order. The services they pass through do not all have the same powers. Some control custodial accounts. Some hold assets that have not yet settled. Some only manage a front end, routing logic, transaction forwarding, or part of the execution flow. For victims and investigators, the first urgent task is to identify which party can actually act.
In practice, post-theft cooperation turns on three questions: whether on-chain addresses can be matched to specific transactions, whether business authority can be translated into an operational step, and whether temporary restrictions can be connected to a formal legal process. Public support can signal intent. It does not answer who controls a given step, how far a transaction has progressed, what the available evidence supports, or how disclosure, preservation, and return might later be handled.
Step one: identify who actually has authority
Turning industry support into action starts with control, not branding. A service that receives assets, converts them, and pays out later may still control funds that have not settled. A custodial exchange may control the linked account and the deposit or withdrawal permissions attached to it. A cross-chain protocol or aggregator operator may control only the front end, routing, forwarding, or a limited execution layer.
That is why platform names and technical labels are only a starting point. The more useful test is the business flow and the control relationship inside it. Victims need that analysis to decide where to send requests. Operators that receive those requests need the same analysis to determine what they can pause, what they can verify, what they can preserve, and what sits outside their authority.
Legal duties also depend on the business model and the jurisdiction in play. Under Financial Action Task Force, or FATF, international standards, virtual asset service providers are generally expected to implement preventive measures such as customer due diligence, recordkeeping, and suspicious transaction reporting. The exact scope and method of compliance are set by local law. If a statutory duty to verify, preserve, or report has already been triggered, it should be handled under the applicable rules. Whether a firm can also restrict a transaction or disclose information to a specific party is a separate question.
The same framework can apply to businesses that use decentralized technology. In its July 2026 thematic report on DeFi, FATF focused on who has control over, or sufficient influence on, a given arrangement, listing factors such as administrative rights, upgrade control, concentration of governance tokens, and influence over infrastructure. The report offers an analytical framework under international standards. Actual obligations still depend on local law. For cross-chain protocols and aggregators, what the operator really provides and what parts of the stack it controls often says more than the label “decentralized.”
Step two: match on-chain addresses to specific transactions
Once a likely recipient of a request has been identified, the next step is to connect the on-chain path to the counterparty’s accounts, orders, and business records. Address labels can point investigators in a direction. They do not, by themselves, tell an operator whether the funds remain within its control or what room for action still exists.
When a victim platform or its authorized agent sends a cooperation request, the request can include the case background, the relevant blockchain, transaction hashes, token types, amounts, timestamps, related addresses, and the link between those clues and the recipient’s business. The service receiving the request can then verify the requester’s identity, the source of the materials, and the connection to its own transaction records. How far the transaction has progressed is a key part of the analysis.
For services that receive funds first and convert or pay out later, the control position changes depending on whether the assets are not yet converted, already converted but not yet paid out, or fully paid out. For cross-chain or aggregation services, operators can compare source-chain transactions, swap requests, destination-chain addresses, and execution status using records they lawfully hold. The exact checks will depend on the service architecture, the records available to the operator, and the applicable requirements.
Once external clues are tied to an actual account, a custodial exchange may be able to act if it has both authority and a sufficient basis. Elliptic disclosed that in 2023, Binance and Huobi froze accounts holding about $1.4 million in crypto assets based on intelligence it provided, with the funds linked to the earlier Harmony Horizon bridge attack. The key point in that case was not the public tracing alone. It was the match between external intelligence and accounts under exchange control. Whether another platform or protocol can do something similar depends on its own authority, evidence, and procedures.
Step three: choose measures based on transaction stage
Once a lead is tied to a specific transaction, the issue changes from “what was found” to “what can still be done now.” Restricting access points, pausing conversions, delaying payouts, and limiting withdrawals from custodial accounts are different measures with different legal bases, operational reach, and effects on users. Operators have to weigh the urgency of ongoing fund movement against the reliability of the materials in hand and the rights of ordinary users.
If unsettled assets remain under a service provider’s control, the provider can assess whether it is feasible to halt a conversion or delay a payout, taking into account applicable law, contractual arrangements, technical capability, and the impact on the user involved. The fact that a transaction is not yet complete does not automatically create a duty to freeze or return assets. It may, however, create time for temporary review. A custodial exchange dealing with a linked account also needs to examine the basis, scope, and duration of any outbound restriction.
Operators of cross-chain protocols and aggregators need to map their own control points first. If they manage only a front end, any measure may be limited to that entry point. If they also control forwarding or execution rights, there may be additional room to intervene. If contract pauses or upgrades are involved, multisig arrangements, governance procedures, and the effect on other users all matter.

Restricting one access point may reduce the risk that a service continues to be used, but the practical effect depends on the architecture and on whether other access paths remain open. If users can still reach the system through another interface or by calling the contract directly, a single front-end restriction may have limited value.
OKX offered a concrete example in a March 17, 2025 announcement. The company said that after detecting an attempt by Lazarus to abuse its DeFi service, and after communicating with regulators, it proactively suspended its DEX aggregation service and upgraded its protective measures. The same announcement said the aggregator connected liquidity from multiple protocols and did not itself custody customer assets. The example shows that a non-custodial service can still adjust the product and entry points it controls. Whether funds in the underlying protocols can be frozen is a different question and depends on the actual architecture and control rights.
When operators adopt temporary measures, they may also need to define scope, review checkpoints, release conditions, and record retention. If a binding law enforcement or court order applies to the operator, it should be handled according to its legal force and scope. If there are doubts about technical feasibility or the reach of the order, those issues may need to be raised through the relevant process. Even after funds have moved on, lawfully retained account, order, login, and communication records may still help later recovery efforts.
Step four: connect temporary restrictions to formal return procedures
Stopping funds for a moment only creates a window. Return is a separate question. It requires answers about ownership, what asset can actually be delivered, who should receive it, and under what procedure. After conversion and multiple transfers, a counterparty may assert its own basis for lawful acquisition. If the funds have entered an exchange pool, the claimant may need to show a further link between the controlled assets and the original stolen property.
Temporary transfer restrictions and final return often involve different thresholds and different proof requirements. A party that only manages a front end and does not control the assets may be able to help mainly by preserving records it lawfully holds. A party that controls customer information or order data must also consider the recipient of any disclosure, the scope of disclosure, confidentiality duties, and personal data protection requirements.
Judicial measures bring their own procedural demands. In the UK Piroozzadeh ruling in 2023, the victim obtained an interim proprietary injunction without notifying Binance, but the court later discharged the injunction because the applicant had not presented the case fully and fairly. The judgment discussed issues including a possible bona fide purchaser for value defense by the exchange and the difficulty of identifying and preserving assets once funds are mixed in a pool. The case dealt with an interim injunction application, not a final ruling on ownership. Even so, it is a reminder that on-chain tracing does not become a court remedy automatically. Evidence and procedure still matter.
Public rules from swap services show the same distinction. ChangeNOW’s public cooperation guidance asks requesters to provide case details, transaction information, address lists, and law enforcement process information. Its terms of service, in Clause 6.11, also state that depending on when a report is received, the platform may intercept a transaction only after the conversion has already been completed, in which case the asset available for return may be the post-conversion token. Under that clause, return also requires a clear request from law enforcement. That is ChangeNOW’s publicly disclosed mechanism. Other services may handle similar situations differently depending on applicable law, contract terms, asset status, and procedure.
What each participant can do first
In practice, one of the biggest problems is not a lack of willingness to help. It is that no one is sure who should send the next email, what should be attached, and who should make the call once it arrives. Funds do not wait while participants sort out process. Based on the authority held by different actors, several early steps stand out.
- Victim platforms or project teams: fix the incident timeline first, organize transaction hashes, implicated addresses, token types, amounts, and on-chain paths, and prepare ownership, police report, and authorization materials. External cooperation requests are easier to handle when they come through a single channel and clearly state what the recipient is being asked to verify, how far the current evidence goes, and how formal procedures are being advanced.
- Exchanges and swap services: once a lead is received, check linked accounts, orders, and transaction stage, preserve KYC, login, device, communication, and operational records, and then have business, technical, compliance, and legal staff assess what measures are available under the firm’s authority. If a point is not yet confirmed, the operator can say it is still under review. If a measure has already been taken, and the law allows communication, the requester can be told what was done and what the limits are.
- Cross-chain protocols, aggregators, and related operators: separate the smart contracts, front end, routing, APIs, upgrade rights, and governance mechanisms as quickly as possible, then identify which parts are actually under the operator’s control. If the operator is considering entry-point changes, service suspension, or a multisig or governance process, it also needs to assess alternative access paths, the effect on ordinary users, and the conditions for restoration, while preserving the factual and authority basis for the decision.
- Lawyers and on-chain investigation teams: the job is to turn the on-chain path into a factual record that internal platform teams, law enforcement, and courts can all understand, and to match each request to a specific party, authority, and procedure. Where multiple jurisdictions or service providers are involved, the order of action and document flow also matters. Otherwise, leads may remain stuck at the address-list stage, or temporary restrictions may fail to connect with later preservation, disclosure, and return.
The earlier all sides work from the same factual record, the easier it becomes to connect verification, restriction, disclosure, and return. Operators can also prepare in advance by setting up risk-reporting channels and internal decision paths that define who receives requests, who determines transaction links, who assesses legal basis, and when escalation to management or outside specialists is required.
Liability still depends on the evidence
Only after cooperation moves forward does it become easier to discuss responsibility with precision. A delayed response, a mistaken risk judgment, a continuing failure to meet statutory anti-money laundering duties, and knowingly helping criminal funds move are not the same thing in fact or in law. For protocols and applications, responsibility also has to be tied to a specific operator or controller. Labels such as developer or governance participant do not, by themselves, settle the issue.
At the regulatory level, the first question is whether the relevant party falls within the class of obligated entities under the applicable law. After that comes the question of what customer due diligence, recordkeeping, and reporting duties apply. FATF’s suspicious transaction reporting standard requires countries to impose legal rules under which financial institutions report promptly to financial intelligence units when they suspect, or have reasonable grounds to suspect, that funds are criminal proceeds. For virtual asset service providers subject to local law, the reporting entity, trigger, and method of compliance still depend on local rules.
Filing a suspicious transaction report with a statutory authority is not the same as disclosing customer information to a victim. The legal basis and limits are different, and reporting information may itself be subject to confidentiality restrictions. Whether an operator can say publicly that it has reported or is investigating depends on the applicable rules. More serious allegations, such as assisting money laundering, require proof of the conduct, the relevant state of mind, and any other elements required by local law.
Germany’s 2025 investigation into the crypto swap service eXch shows how authorities may look at both fund flows and business operations. Elliptic had traced some of the ETH stolen from Bybit as being converted into BTC through services including eXch. Germany’s Federal Criminal Police Office later said that on April 30, 2025, law enforcement seized eXch servers in Germany and crypto assets then worth about 34 million euros. The operator was suspected of commercial money laundering and operating an internet criminal trading platform. The notice also said the service had advertised on underground networks that it did not implement anti-money laundering measures and did not require users to verify their identity. Any criminal allegation still has to be proven under the relevant legal standards and evidence.
The lesson from that case is direct. Investigators do not only ask where the money went. They also look at how a service solicited business, how it organized conversions, and what it did when risk signals appeared. Keeping necessary verification and decision records can help an operator show when it identified a risk, what authority it had at the time, and why it did or did not take a particular step. The scope and retention period of those records still need to comply with applicable rules, and their evidentiary value must be assessed together with other evidence.
Recovery depends on linking authority, evidence, and procedure
After enough cases like this, one basic point becomes hard to ignore: recovery often depends on whether the relevant parties can connect authority, evidence, and procedure fast enough. Public support shows goodwill. It does not, on its own, stop assets, move records into an investigation, or create a lawful basis for return.
The hardest part is usually building an executable recovery chain out of on-chain paths, account and order information, business control rights, legal basis, and cross-border procedure. The earlier on-chain investigators, compliance teams, technical staff, and lawyers work from the same factual record, the easier it becomes to connect review, restriction, disclosure, preservation, and return. For institutions that have already seen abnormal asset flows, or may receive cooperation requests in the future, mapping authority, preserving evidence, and designing response paths early can reduce the risk of missing the window for action.
Users entrust platforms with assets, but also with trust. In the end, the industry looks more mature not when every incident produces another public statement, but when those statements can be turned into action that has a legal basis, can be executed, and leaves a record behind.

