NewsCryptoAMLBot Traces 4 BTC From Bitget Hack Into Wasabi CoinJoin

AMLBot Traces 4 BTC From Bitget Hack Into Wasabi CoinJoin

Author: DefiLiban·

Key Takeaways

  • •AMLBot traced approximately 4 BTC from wallets tied to the Bitget exploit into Wasabi CoinJoin, marking a partial trace rather than a recovery or seizure of funds.
  • •Under standard AML risk-scoring, tainted funds entering a CoinJoin round contaminate the entire output set, exposing exchanges and custodians to sourcing risk even for depositors uninvolved in the hack.
  • •THORChain previously declined to block roughly $387.5 million in Bitget hack funds from moving into Bitcoin, illustrating how permissionless bridging infrastructure complicates post-exploit tracing.
  • •Bitget has reopened BTC withdrawals with ETH withdrawal resumption scheduled for September 29 as part of its phased recovery process.
  • •Under frameworks informed by FinCEN's proposed rules on crypto mixing, receiving outputs from a mixing round tied to a known hack warrants enhanced due diligence, source-of-funds review, and potential SAR filing.
AMLBot Traces 4 BTC From Bitget Hack Into Wasabi CoinJoin

Blockchain analytics platform AMLBot has traced approximately 4 BTC linked to the Bitget hack into Wasabi CoinJoin, identifying a privacy-layer laundering path that complicates on-chain attribution and creates direct exposure risk for any exchange or custodian receiving downstream outputs from the affected mixing round.

What AMLBot's Trace Establishes

AMLBot, which operates as a crypto compliance and blockchain analytics platform, identified the movement of roughly 4 BTC originating from wallets associated with the Bitget exploit and routed into Wasabi CoinJoin. The finding is a partial accounting of fund movement — not a full recovery or seizure — and the company attributed the trace to on-chain monitoring of post-hack wallet activity.

The 4 BTC figure is significant, less for its absolute size than for what it confirms: proceeds from the Bitget breach are actively being processed through privacy-layer infrastructure. Compliance teams at exchanges and custodians should treat any CoinJoin output from this period as a potential exposure vector pending further taint analysis.

Cross-Chain Context

The Bitget incident has already drawn significant cross-chain attention. As previously reported, THORChain declined to block Bitget hack funds as they moved $387.5M into Bitcoin, illustrating how permissionless bridging infrastructure compounds the post-exploit tracing challenge. By the time funds reach a CoinJoin, investigators are already working several hops downstream from the original exploit address.

Why the Wasabi CoinJoin Route Raises Compliance Risk

Wasabi Wallet implements CoinJoin as a coordinator-assisted transaction protocol: multiple participants combine inputs and receive equal-denomination outputs, breaking the direct on-chain link between sender and receiver. That equal-output structure is designed to frustrate cluster analysis, which is the primary tool blockchain analytics platforms use to trace funds across addresses.

Under standard AML risk-scoring frameworks, when known-tainted funds enter a CoinJoin round they contaminate the entire output set from that round. Exchanges receiving any output from a mixing round that included Bitget hack proceeds therefore face a sourcing risk even if their specific depositor had no direct involvement in the exploit. This is the core compliance exposure: CoinJoin distributes taint probabilistically across all participants. For ordinary users, the practical effect is that deposits with no connection to the hack can still draw enhanced due diligence, source-of-funds requests, or processing delays if they touch an affected output.

A distinction remains between risk indicators and proof of laundering intent. CoinJoin is a legitimate privacy mechanism, and most participants in any given round are not associated with illicit funds. However, under frameworks informed by FinCEN's proposed rules on convertible virtual currency mixing, receiving outputs from a mixing service used to process proceeds of a known hack constitutes a material risk indicator that warrants enhanced due diligence, source-of-funds review, and potential Suspicious Activity Report (SAR) filing.

Operational Implications for Exchanges and Compliance Teams

The immediate action item for exchanges and custodians is to run CoinJoin-output screening against the known Bitget hack address cluster. Analytics platforms that support taint tracing through mixing rounds, including AMLBot, can assign probabilistic exposure scores to outputs from the relevant mixing rounds. Deposits flagging above threshold require case documentation and manual review before processing.

As Bitget works through its recovery process — with BTC withdrawals reopened and ETH resumption scheduled for September 29 — the practical risk window for compliance teams extends beyond the exchange itself. Any platform in the downstream flow, including OTC desks, DEX aggregators, and bridges, should treat CoinJoin outputs linked to this time window with elevated caution until AMLBot or other analytics providers publish a more complete address cluster. The markers to monitor from here include whether expanded cluster data covering additional mixing rounds is published, how rulemaking informed by FinCEN's mixing proposal develops, and whether Bitget's phased withdrawal resumption holds to its stated schedule.

The broader protocol-layer lesson is that the combination of permissionless cross-chain routing and CoinJoin privacy layers creates a layering path that significantly extends the trace horizon. Compliance programs that rely solely on direct-deposit screening without hop analysis are structurally underprepared for this threat pattern. Calibrated risk scoring, multi-hop taint propagation, and prompt alert escalation to senior compliance staff are the minimum controls warranted when a major exchange hack intersects with active CoinJoin usage.