Bybit LazarusBounty Offer to Track Bitget Funds
Bybit co-founder and chief executive Ben Zhou said on 25 September 2026 that his team is ready to help Bitget after the hot-wallet incident, and that Bybit is updating the LazarusBounty platform to track the related funds. The offer is real as a public statement. It does not restore Bitget withdrawals, it does not publish a recovered dollar amount, and it does not mean U.S. law enforcement has attributed this theft.
The useful question is narrower than the headline. What can an exchange-built tracking board change in the hours after coins leave, and what did these two companies already do for each other in February 2025?
Key Takeaway: Zhou's 25 September statement is an offer to assist and to update LazarusBounty so flows from the Bitget incident can be followed. Bitget had lent Bybit 40,000 ETH from its own reserves after the 21 February 2025 theft, and that loan was repaid on 24 February 2025. Tracking can flag deposit addresses. It is not a freeze, not a withdrawal reopening, and not an FBI finding. The FBI attribution on the books is for the 2025 Bybit case, about $1.5 billion.
What Zhou said, and what Bitget answered
ChainCatcher, timestamped 25 September 2026 at 11:48, reported that Zhou said the Bybit team stands ready to help in various ways on the Bitget incident, that Bitget had supported Bybit when Bybit was attacked, and that Bybit is updating LazarusBounty to help track the flow of the relevant funds.
Bloomingbit's write-up of the same statement says Zhou wrote on X that Bybit is prepared to support Bitget, and that the LazarusBounty update is meant to detect and track movement of the stolen funds. It describes LazarusBounty as a platform Bybit built after its own hack, used to share suspicious addresses and trace flows. Xie Jiayin, identified there as Bitget's head of Greater China, thanked Bybit and Zhou and said they should reach out if anything was needed.
I do not have a bounty fee schedule, a reward cap, or a list of newly tagged addresses in those articles. Writing a payout number would be invented. The operational content of the offer, as published, is assistance plus a tracking update.
Bitget's own 24 September notice had already said abnormal transfer addresses were identified, flagged, and reported, and that law enforcement and on-chain firms were engaged. Zhou's post adds a named platform and a named counterparty. It sits on top of work Bitget said was already underway. It does not replace Bitget's incident report.
What LazarusBounty can change, and what it cannot
A public tracing board does one job well: it spreads address labels faster than each exchange repeating the same cluster work alone. If a deposit lands at a participating venue from an address on that list, the venue can delay or reject it under its own rules. That is how stolen-fund tracking sometimes turns into a freeze. The freeze is a decision by the receiving venue or by a legal order. The board itself does not sign a clawback transaction.
| What the 25 September offer includes | What it does not include |
|---|---|
| A public commitment from Bybit's chief executive to help | A date when Bitget withdrawals reopen |
| An update to LazarusBounty aimed at these flows | A published list of addresses inside the news articles cited here |
| Continuity with the February 2025 assistance | A dollar amount recovered |
| A channel Xie Jiayin publicly accepted | Proof the attacker is the same group as in 2025 |
Cointelegraph reported on 25 September that Chen said some stolen funds had already been recovered, without a figure. A bounty update and a partial recovery can both be true and still leave most of the $351.6 million in motion. Until an amount is tied to a publisher and a clock time, "some" stays qualitative.
The February 2025 case is the caution. The FBI said on 26 February 2025 that North Korea was responsible for the theft of approximately $1.5 billion from Bybit on or about 21 February 2025, and that TraderTraitor actors were converting and dispersing assets across thousands of addresses on multiple chains, with further laundering expected. A tracing platform existed because that dispersion was the problem. Dispersion is faster than a bounty board's first update.
Why the two exchanges are in each other's incident
The reciprocity is a dated loan, not a slogan.
On 21 February 2025 Bybit lost control of an Ether multisignature cold wallet. A preliminary investigation report put the haul above $1.4 billion, including 401,347 ETH plus other staked and wrapped ether balances. The FBI's public service announcement on 26 February 2025 put the theft at approximately $1.5 billion and named North Korea's TraderTraitor activity. Those two figures belong to the same event. The FBI number is the law-enforcement total. The report's 401,347 ETH is the coin-level breakdown available in the preliminary file. I do not blend them into a new total.
After that theft, Bitget lent 40,000 ETH. CryptoSlate and crypto.news, citing the companies and on-chain watches, place the repayment on 24 February 2025. CryptoSlate said Gracy Chen confirmed the return and described the loan as support with no interest and no collateral, drawn from Bitget's own reserves rather than user deposits. The dollar value depends on the ether print: about $99.98 million at the repayment transfer in those reports, with higher dollar marks when the loan was first extended and ether was priced differently. The stable fact is 40,000 ETH, interest-free on Chen's description, from company reserves, repaid in three days.
That history explains Zhou's sentence that Bitget had helped when Bybit was hit. It does not mean Bybit now owes a 40,000 ETH loan in reverse. His 25 September words are about tracking help. A liquidity loan and a tracing update solve different failures. Bybit in 2025 needed ether in the withdrawal queue. Bitget in 2026, on its own notice, says the hole fits inside a protection fund above $464 million and that the open problem is the security review plus paused withdrawals. Sending a matching loan would be a different announcement. This one is not that announcement.
Why the 2025 FBI label does not travel automatically
Chen said on 25 September, in the Cointelegraph account, that some IP addresses matched VPN choices associated with a North Korean group, and that a North Korea link was highly likely on the evidence so far. She also said the identity was not fully confirmed in parallel coverage. Bybit's LazarusBounty name points at the group that hit Bybit. Using the name for a new board does not attribute the new theft.
Attribution would look like the 26 February 2025 PSA: an agency, a date, a victim, and a name for the activity. What exists for Bitget on 25 September 2026 is a chief-executive assessment plus a rival's offer to track. I would update the label if a later official notice names the same actors. I would not front-run it because the bounty product has Lazarus in the title.
What a user should do with the tracking news
- Keep using Bitget's official incident page for withdrawal status. A Bybit blog or an X post cannot reopen another company's withdrawals.
- If you run a venue, a market-making wallet, or a treasury that receives deposits, subscribe to the address labels those firms actually publish. A news recap will not list the clusters in time.
- Ignore direct messages that sell recovery, "bounty claim filing," or a fee to release your Bitget balance. Zhou's offer is exchange-to-exchange. It is not a retail claims desk.
- Separate three clocks: the tracing update, the incident report Bitget promised, and the moment withdrawals resume. They can land on different days. Only the third one returns an asset to a wallet you control.
- If you do not have a Bitget balance, this story does not change your bitcoin position. Stolen exchange float is a venue-loss and a law-enforcement problem. It is not a change in bitcoin's issued supply.
Key Takeaways
- On 25 September 2026 Zhou offered help and a LazarusBounty update to track Bitget-related flows. Bitget's Greater China head publicly accepted the contact. No reward table was in the reports used here.
- The 2025 precedent is specific: Bitget lent 40,000 ETH from its own reserves, and Bybit repaid it on 24 February 2025. That was liquidity. This week's offer is tracing.
- LazarusBounty can help label addresses. Freezes happen when a receiving venue or a legal process acts. The board does not pull $351.6 million back by being updated.
- The FBI has attributed the February 2025 Bybit theft to North Korean TraderTraitor actors. Bitget's September 2026 case, as of this writing, has a preliminary company assessment and no matching public FBI notice in the sources reviewed.
Frequently Asked Questions
Will Bybit's LazarusBounty get the Bitget money back?
It is built to share suspicious addresses and follow flows. That can help a venue stop a deposit. It does not sign a transaction that returns coins to Bitget users, and Zhou's statement did not claim a recovery percentage. Chen has said some funds were recovered, without a number.
Why is Bybit helping a competitor?
In February 2025 Bitget lent Bybit 40,000 ETH from company reserves after the cold-wallet theft. Bybit repaid that loan on 24 February 2025. Zhou cited that support when he offered tracking help on 25 September 2026. The new offer is not described as a new 40,000 ETH loan.
Does this prove the Lazarus group hacked Bitget?
No. LazarusBounty is the name of Bybit's tracking platform, created after the 2025 incident that the FBI attributed to North Korean actors. Chen has called a North Korea link highly likely based on IP and VPN patterns. A platform name plus a preliminary IP comment is not the FBI PSA that exists for Bybit.
Should Bitget users file a claim with Bybit?
Nothing in Zhou's reported statement opens a retail claims window at Bybit. Users should follow Bitget's own support article for balances and withdrawals. Messages that ask for a fee to "file the bounty" are outside this offer.
Related reading
Bitget Hot Wallet Incident and What User Balances Mean
Top 5 Crypto Liquidation Heatmap Tools: Features, Pros, and Cons
Top 5 Tools for Tracking Crypto Short Liquidations in Real-Time
Crypto Risk Management Tools: Comparing Strategies and Platforms
Top Solana Meme Coins Under Live Community Watch: Trader's Execution Breakdown
Crypto ETF Flows Offer a Window Into Market Sentiment, But They Are Not the Whole Picture
Top 5 Tools for Monitoring Your Crypto Liquidation Price
Cate (CATE) vs Similar Cryptocurrencies: Key Differences and Features
Story Protocol (IP) vs Other Blockchain Content Platforms: Key Differences and Features
How to Get Started with Sunrise DeFi: A Step-by-Step Guide
Risk disclosure
Cryptocurrency prices are highly volatile. This article is for educational purposes only and does not constitute financial, investment, legal, or tax advice. Always do your own research and consider your financial situation and risk tolerance before making any decision. Figures for the 2025 Bybit theft, the 40,000 ETH loan, and the 2026 Bitget loss reflect the cited sources and their dates. Dollar values on the ether loan moved with the ether price. Tracking tools and exchange withdrawal status can change without notice. Community reposts of executive statements are not the same as a law-enforcement attribution.


