Bitget has provided a clearer picture of the financial impact of its security breach after disclosing that roughly $388 million in assets were affected. The updated figure is about $35 million higher than the amount reported when the incident was first announced on Thursday, according to a subsequent analysis of assets on the Zcash and TRON networks. The clarification is significant, not only because of the size of the number, but also because it highlights how quickly the scope of a crypto security incident can evolve once investigators begin tracing assets across multiple blockchains.
What changed in the updated estimate
The initial report of the breach already represented a major security event, but the revised estimate suggests that the first accounting of affected assets was incomplete. An additional $35 million is not a trivial difference in an incident of this scale. It indicates that some assets were likely identified later, either because they were harder to trace, held in less commonly monitored accounts, or associated with chains that required deeper review.
In this case, the missing portion appears to be connected to assets on Zcash and TRON. That detail is important because different blockchains have different privacy features, wallet structures, transaction patterns, and indexing tools. As a result, a post-incident analysis may not produce a complete list of affected assets on the first pass.
Why the Zcash and TRON analysis mattered
Zcash and TRON are both established networks, but they do not behave in exactly the same way on-chain. Zcash includes shielded transactions, which can make asset movement less transparent than public chains. TRON, by contrast, is a high-throughput network widely used for token transfers and consumer-facing applications. Both networks can present unique challenges when an exchange is trying to determine exactly what was affected during a breach.
The fact that Bitget had to revise its estimate after reviewing assets on those networks suggests that the initial count may have relied on the most immediately visible data. As the investigation progressed, it became possible to identify additional balances, transfers, or asset positions that had not been fully captured at first. That is a common reality in crypto security incidents, where the first numbers are often estimates rather than final conclusions.
Why exchange breach estimates can change
In traditional finance, a security incident usually involves fixed account balances, internal ledgers, and regulated reporting channels. In crypto, the picture can be more complicated. Exchanges hold customer assets across multiple wallets, chains, custody systems, and internal accounting layers. If a breach affects access to those systems, the first task is to establish what was compromised, where the assets were located, and whether any were moved or exposed.
That process is rarely instantaneous. Teams may need to compare internal records with on-chain activity, review transaction histories, identify suspicious outbound transfers, and account for different token standards. They may also need to consider assets that are not immediately redeemable, assets that were in transit, or balances that were represented in a way that made them harder to count during the initial assessment.
Because of that, it is not unusual for an exchange to update its disclosure as the investigation continues. A revised figure does not necessarily mean the original report was careless. It may simply mean that the first estimate was made under urgency, while the later number benefits from a more complete dataset.
What the $388 million figure signals
A $388 million affected-asset figure places the incident among
Related read: Magic Eden Warns Legacy NFT Approvals Left $5.7M in Assets Exposed to Exploit
