The attacker behind Bitget’s $387.5 million security breach has moved more than half of the XRP stolen from the exchange, exposing a major limitation facing asset-recovery efforts: native XRP cannot be frozen at the protocol level.About 103 million XRP was taken during the September 24 attack and initially distributed across five holding accounts. Approximately 54 million XRP, worth around $83 million at Saturday’s prices, has since left those original wallets, leaving about 49 million XRP worth roughly $75 million.

The movements do not establish that the stolen XRP has been sold. They show that the attacker is dispersing the assets across additional addresses, making tracing and potential interception more complex as the distance from the original Bitget wallets increases.

Why Can’t Ripple Freeze the Stolen XRP?

The answer comes from the design of the XRP Ledger itself. XRP is the network’s native asset rather than a token issued by Ripple or another company.

The XRP Ledger includes freeze functionality for issued tokens, allowing an issuer to restrict assets it created under certain conditions. Its official documentation explicitly states that this functionality does not apply to XRP and that no entity can freeze native XRP held in an independent wallet.

That creates a sharp contrast with the stablecoins involved in the same breach. Circle and Tether have already frozen approximately $318,000 of USDC and USDT linked to the attacker by blacklisting an Ethereum address at the token-contract level. Those freezes demonstrated how issuer controls can stop stolen stablecoins while they remain in assets with centralized administrative controls.

XRP provides no equivalent mechanism. Ripple cannot remotely disable the attacker’s XRP or prevent transactions between self-custodied accounts.

Investor Takeaway

For stolen XRP, recovery depends less on the blockchain itself and more on whether the funds eventually reach a centralized intermediary that can restrict them.

Where Can the Stolen XRP Still Be Stopped?

Centralized exchanges remain one potential interception point. Although an exchange cannot freeze XRP sitting in an attacker-controlled external wallet, it can suspend an account that receives identified stolen funds and prevent the customer from withdrawing or converting them.

That makes real-time wallet tracking important. The faster stolen XRP is distributed across new addresses, however, the harder it becomes for exchanges, investigators and compliance providers to maintain an accurate map of the proceeds.

The original Bitget-linked XRP address received roughly 103 million XRP during the attack before distributing large blocks of the asset into separate accounts. Blockchain records subsequently showed 20 million XRP transfers into multiple wallets, followed by further movements from those holding addresses.

Movement should not be confused with market selling. An attacker can transfer XRP repeatedly between self-controlled wallets without interacting with an exchange or creating direct sell pressure.

Could the Stolen XRP Pressure the Market?

The original XRP haul was worth roughly $160 million when XRP traded near $1.54 on Saturday. That represented approximately 4% of the token’s reported $4.4 billion daily trading volume at the time.

That comparison does not mean selling the entire amount would automatically move XRP by 4%. Reported daily volume is not the same as available order-book liquidity, and the price effect of liquidation would depend on where, how quickly and in what size the assets were sold.

Distributing the XRP across more wallets could allow the attacker to liquidate smaller quantities over time, route funds through different venues or simply obscure the ultimate destination. On-chain transfers alone cannot distinguish among those possibilities.

Investor Takeaway

The $83 million movement creates potential XRP supply risk, but wallet transfers are not sales. Exchange deposits and identifiable conversions matter more for price pressure.

What Happens Next for Bitget?

Bitget has raised the confirmed value of assets transferred to attacker-controlled addresses to approximately $387.5 million from its initial $351.6 million estimate. The increase reflected additional Zcash and TRON assets identified during subsequent tracing rather than a second breach.

The exchange says the underlying vulnerability has been identified and remediated and that no further unauthorized transfers are possible. Mandiant and SlowMist are assisting with the investigation.

Bitget initially said its User Protection Fund would absorb the financial impact, with customer balances remaining unaffected. The fund was valued at more than $464 million when the incident was disclosed.

Withdrawals are scheduled to return in stages, beginning with Bitcoin at 08:00 UTC on September 28, followed by Ether on September 29 and USDT on September 30. Other tokens, fiat withdrawals and P2P services are scheduled for October 2.

Asset recovery is therefore only one part of the post-breach test. Bitget must also demonstrate that it can restore withdrawals on schedule while investigators track hundreds of millions of dollars across assets with very different technical possibilities for freezing, tracing and recovery.