NewsCryptoBitget Hack: $387.5 Million in Stolen Funds Traced Through Bitcoin, THORChain, and CoinJoin

Bitget Hack: $387.5 Million in Stolen Funds Traced Through Bitcoin, THORChain, and CoinJoin

Author: NFTENEX·

Key Takeaways

  • •Blockchain security firm BlockSec traced roughly $387.5 million in stolen funds linked to Bitget through Bitcoin, the THORChain protocol, and CoinJoin mixing services.
  • •THORChain refused to freeze the addresses involved in the fund movement, explaining that its permissionless design leaves no able to halt transactions mid-flight.
  • •In a separate analysis, AMLBot confirmed the mixing trail by following 4 BTC from the hack to the Wasabi CoinJoin wallet.
  • •Bitget has reopened BTC withdrawals and scheduled ETH withdrawals to resume on September 29 as part of a phased restoration of user access.
  • •The obfuscation route was set up in the hours and days after the breach, before Bitget completed its withdrawal restoration, indicating attackers prioritized speed over transaction efficiency.
Bitget Hack: $387.5 Million in Stolen Funds Traced Through Bitcoin, THORChain, and CoinJoin

Blockchain security firm BlockSec has traced funds from a reported $387.5 million theft linked to Bitget through Bitcoin, the THORChain cross-chain protocol, and CoinJoin mixing services, mapping an obfuscation route that spans multiple networks and privacy tools.

Key Points

  • BlockSec identified that stolen funds totaling approximately $387.5 million were routed through Bitcoin, THORChain, and CoinJoin after the reported Bitget exploit.
  • THORChain declined to block wallet addresses linked to the movement, citing its permissionless design.
  • Separate analysis by AMLBot corroborated the CoinJoin trail, tracing 4 BTC from the hack to Wasabi CoinJoin.

What BlockSec's Fund Trace Identified

The reported theft, totaling approximately $387.5 million, ranks among the largest exchange-linked exploits tracked this year. BlockSec's on-chain analysis found that stolen assets were converted and routed through Bitcoin before passing through additional layers designed to complicate recovery efforts.

THORChain, a decentralized cross-chain liquidity protocol, appeared in the traced path as a bridge between asset types. The protocol subsequently declined to block the wallet addresses associated with the $387.5 million in Bitcoin moves, citing its permissionless design, a decision that left the cross-chain channel open to further movement. The refusal contrasts with centralized exchanges, where flagged deposits can be frozen by the receiving platform once security researchers or law enforcement raise the alarm; permissionless protocols execute swaps through automated liquidity pools, leaving no operator able to halt a transaction mid-flight.

CoinJoin, the Bitcoin privacy technique that merges multiple transactions to obscure their origins, was identified as the final obfuscation layer in the traced route. In a separate analysis, AMLBot traced 4 BTC from the Bitget hack to Wasabi CoinJoin, a non-custodial Bitcoin wallet that implements CoinJoin mixing natively, corroborating the broader pattern BlockSec identified. Because CoinJoin merges a user's coins with those of other participants, attribution becomes substantially harder once funds clear a mixing round, placing the greatest tracing weight on the pre-mixing legs of the route that BlockSec and AML have already mapped.

Why Bitcoin, THORChain, and CoinJoin Matter

The three-stage route reflects a recognized playbook for laundering stolen crypto: convert to Bitcoin for its liquidity depth, use a cross-chain bridge to sever the asset trail, then apply a mixing service to fragment the transaction history on-chain. Each layer adds forensic complexity without requiring the cooperation of any single custodian.

THORChain's refusal to intervene highlights a structural tension in decentralized finance: permissionless infrastructure cannot distinguish between legitimate cross-chain swaps and post-exploit laundering without centralized controls that would conflict with its design principles. Investigators can observe the movement on-chain but cannot reverse or freeze it.

Tracing firms such as BlockSec and AMLBot can follow funds across these layers by clustering wallet addresses and mapping swap events, but confirming the attribution of wallets to specific individuals requires off-chain intelligence that blockchain data alone cannot provide. Where laundered funds resurface also shapes recovery odds: deposits reaching centralized venues can be flagged and frozen, while assets dispersed through mixers have historically proven far harder to claw back.

Bitget's Response and Withdrawal Status

Despite the scale of the reported exploit, Bitget moved to restore user access. The exchange resumed BTC withdrawals following the $388 million exploit and subsequently published a phased timeline for restoring further access, with BTC withdrawals reopened and ETH withdrawals scheduled for September 29. Withdrawal suspensions are a routine containment measure for exchanges after security incidents, with phased restorations allowing platforms to reopen outflows gradually.

The fund movements BlockSec traced were already in progress before Bitget completed its withdrawal restoration, meaning the obfuscation route was established rapidly in the hours and days following the initial breach — a pattern consistent with other large-scale exchange exploits in which attackers prioritize speed of obfuscation over transaction efficiency.

Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.