A hacker linked to a breach of the crypto exchange Bitget has begun shifting roughly $83 million worth of stolen XRP, moving the funds in a way that appears designed to sidestep any intervention from Ripple, the company behind the token.
The Movement of Stolen Funds
Blockchain observers have flagged unusual activity across a cluster of wallets tied to the theft. Two of the accounts holding the pilfered XRP have been nearly emptied, while a third is actively being drained. Roughly $75 million is still believed to remain spread across the five wallets that originally held the stolen tokens.
The staggered, methodical draining of the accounts suggests the perpetrator is attempting to launder or disperse the assets before they can be traced and recovered. Such tactics are common in large-scale crypto thefts, where speed and fragmentation are used to complicate any efforts to claw back funds.
The stolen XRP is being moved in a way that Ripple has no power to freeze.
Why Ripple Cannot Intervene
A key wrinkle in this case is that Ripple, despite being closely associated with XRP, lacks the ability to freeze the stolen tokens. Unlike some stablecoin issuers who can blacklist addresses and halt transfers, XRP on the open ledger does not give Ripple that kind of centralized control once tokens are in circulation.
This distinction highlights an ongoing tension in the crypto industry between decentralization and consumer protection. While immutability and censorship resistance are often celebrated as core features, they also mean that victims of theft have limited recourse when funds are on the move.
For Bitget and any affected users, the situation underscores the persistent security challenges facing centralized exchanges, which remain prime targets for sophisticated attackers.
- Two wallets have been almost fully emptied
- A third wallet is currently being drained
- About $75 million remains across the original five accounts
- Ripple has no mechanism to freeze the stolen XRP
Recovery of the funds, if it happens at all, would likely depend on cooperation from exchanges or other on-ramps where the hacker might eventually attempt to cash out.
