AMLBot Traces 4 BTC From Bitget Hack Into Wasabi CoinJoin
Key Takeaways
- •AMLBot says it traced approximately 4 BTC connected to the Bitget hack into Wasabi CoinJoin, a privacy protocol that mixes transactions to obscure their trail.
- •The Bitget hack was the security incident that prompted the exchange to temporarily withdrawals.
- •The traced amount represents only a fraction of the funds tied to the broader Bitget incident, and the finding is an analytics observation rather than a law enforcement or legal determination.
- •Once funds pass through a CoinJoin protocol, downstream tracing relies on indirect indicators and probabilistic inference, reducing confidence in attribution.
- •THORChain previously declined to block Bitcoin movements associated with the hackers, illustrating how decentralized infrastructure complicates coordination on stolen-fund recovery.

AMLBot, a cryptocurrency compliance and blockchain analytics platform, says it has traced approximately 4 BTC linked to the Bitget hack into Wasabi CoinJoin, a privacy-enhancing Bitcoin protocol that obscures the connection between transaction inputs and outputs.
According to AMLBot's analysis, the trail runs from funds associated with the exchange exploit through a CoinJoin transaction. The hack was the security incident that prompted the exchange to temporarily halt withdrawals. AMLBot characterized its work as on-chain tracing, identifying a path between wallets tied to the exploit and a subsequent transaction.
From Exploit to Mixing Protocol
The traced funds moved into Wasabi CoinJoin, according to AMLBot's reported analysis. Wasabi is a Bitcoin wallet built around the CoinJoin method, which batches multiple users' transactions together into a single collaborative spend. That structure makes it substantially harder to determine which input maps to which output on the public blockchain ledger, blurring the visibility that analysts and investigators normally rely on. CoinJoin has been part of the Bitcoin ecosystem for more than a decade, and wallet implementations such as Wasabi have packaged the technique for everyday use — while privacy tools of this kind have drawn heightened regulatory attention, making their appearance in a fund flow a notable marker for compliance teams.
Scope of the Finding
The reported trace covers approximately 4 BTC — a fraction of the total funds associated with the broader Bitget incident. AMLBot presented the work as an on-chain analytics observation. It does not constitute a law enforcement determination, a final legal ruling on responsibility for the exploit, or a confirmed attribution of the funds to any individual.
Why the CoinJoin Link Matters for Compliance
The reported movement into Wasabi CoinJoin highlights a persistent challenge for blockchain analytics: once funds pass through a privacy-enhancing protocol, the confidence level of any downstream trace typically drops. Post-mix tracing generally depends on indirect cues — such as transaction timing, amounts, or behavioral patterns — rather than a direct input-to-output match, which is why attribution claims in these cases are typically framed in probability terms. Compliance teams monitoring transaction flows must the statistical inference of post-mix attribution against the inherent ambiguity that CoinJoin introduces.
When a compliance platform such as AMLBot flags a potential link between hack-associated funds and a mixing service, the practical output is a risk signal, not a verdict. Virtual asset service providers use such signals to flag wallets for enhanced due diligence, freeze incoming deposits pending review, or file suspicious activity reports with regulators. Guidance from the U.S. Financial Crimes Enforcement Network (FinCEN) addresses how these obligations apply across different business models operating in the digital asset space.
The use of Wasabi CoinJoin does not in itself establish wrongdoing, however. The protocol serves privacy-conscious individuals for legitimate reasons, and a post-mix trace reflects probabilistic inference rather than certainty. That distinction matters in compliance assessments, where over-blocking legitimate users carries its own regulatory and reputational risk.
Continued On-Chain Scrutiny
The Bitget situation has drawn continued on-chain scrutiny. THORChain previously declined to block Bitcoin movements linked to the hackers, illustrating how decentralized infrastructure complicates industry-wide coordination on stolen-fund recovery. AMLBot's reported trace adds another data point to that ongoing picture. Whether additional hack-linked funds pass through privacy tools, and how exchanges and other virtual asset service providers respond to related risk signals, remain open questions as the full scope of fund movements stays under investigation.
Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.