NewsCryptoBitget Resumes Bitcoin Withdrawals as Hacker Routes ETH Through THORChain

Bitget Resumes Bitcoin Withdrawals as Hacker Routes ETH Through THORChain

Author: AI Crypto Core·

Key Takeaways

  • •Bitget has restored Bitcoin withdrawals after a security incident prompted a temporary halt, though the exchange has not confirmed whether its full security review is complete.
  • •On-chain investigators report that a wallet linked to the attacker moved Ethereum through THORChain, a decentralized cross-chain protocol that enables native swaps without KYC checkpoints.
  • •Separate analysis found that 4 BTC from the hack passed through the Wasabi CoinJoin mixing protocol, indicating the attacker layered obfuscation techniques across multiple chains simultaneously.
  • •THORChain declined requests to blacklist wallets tied to the breach, citing its neutrality principles, a position that drew comment from Ethereum co-founder Vitalik Buterin.
  • •No independently verified totals for stolen funds, attacker addresses, or transaction hashes had been confirmed by Bitget or credentialed forensics firms at publication.
Bitget Resumes Bitcoin Withdrawals as Hacker Routes ETH Through THORChain

Bitget has restored Bitcoin withdrawals after a security incident prompted a temporary halt, with on-chain investigators reporting that a wallet linked to the attacker moved Ethereum through THORChain, a decentralized cross-chain liquidity protocol, in a pattern they describe as typical of post-exploit fund transfers.

Withdrawals resume as tracing continues

The exchange said Bitcoin withdrawals were live again following a suspension put in place while its security teams examined the breach. Halting withdrawals during an active post-exploit review is standard exchange practice: it gives security teams time to audit wallet exposure and shut down any remaining unauthorized outflows. For depositors, that availability is the practical test during a breach response — funds held on an exchange can only be moved on demand while withdrawals are live. Bitget has not said publicly whether the resumption means the security review is fully complete or only that specific wallet segments have been cleared.

Tracing work spans several chains. In separate analysis, 4 BTC from the Bitget hack was found to have passed through Wasabi CoinJoin, a Bitcoin mixing protocol — evidence, researchers say, that the attacker layered obfuscation techniques across different chains at the same time instead of funneling everything through one venue. CoinJoin works by pooling many users' transactions into a single collaborative one, obscuring the direct on-chain link between a coin's origin and its destination — one reason tracing mixed coins depends on clustering rather than simple address-to-address following.

What users can verify themselves

At publication, no independently verified totals for stolen funds, specific wallet addresses, or transaction hashes had been confirmed by the exchange or by credentialed on-chain forensics firms. Because blockchain activity is public and pseudonymous, any address that is later disclosed can be followed in real time by anyone. Users who want to follow the funds themselves can check Mempool.space for Bitcoin transactions and Etherscan for Ethereum-side movements tied to any attacker addresses disclosed publicly.

Why THORChain features in the fund flows

THORChain allows native cross-chain swaps without wrapped tokens or centralized intermediaries, which has made it a frequent stop for post-exploit fund movement. An attacker holding Ethereum can convert directly into Bitcoin or other supported assets without a KYC checkpoint, making exchange-level blacklisting and chain-of-custody tracing harder.

The protocol's own response to the incident has proved contentious. THORChain declined requests to blacklist wallets tied to the Bitget hack, citing its neutrality principles — a position that drew comment from Ethereum co-founder Vitalik Buterin on the limits of censorship resistance when stolen funds are involved. The refusal highlights a structural tension in decentralized infrastructure: the permissionless design that lowers counterparty risk for ordinary users also weakens the effect of reactive freezes after a breach.

Swapping across chains through protocols like THORChain also turns a single-chain tracing problem into a multi-chain coordination problem. Freezing or recovering funds would require simultaneous action by multiple protocol teams, none of which has a contractual relationship with the affected exchange. That is why investigators generally watch destination wallets at centralized off-ramps rather than attempting to halt swaps mid-flight.

What remains unconfirmed

Several material details remain unverified at publication: the total volume of ETH swapped through THORChain, the specific transaction hashes or block heights involved, the identity or attribution of the attacker, and the full scope of assets affected beyond the Bitcoin withdrawal suspension. Figures appearing in secondary reports should be treated as unconfirmed until Bitget or a credentialed on-chain forensics firm publishes primary documentation. From here, the observable markers are concrete: an official word from Bitget on whether the review is complete, primary documentation quantifying the THORChain flows, and any public disclosure of attacker addresses — each of which would turn an unverified item above into something readers can check directly on-chain.

Taken together, the use of THORChain for ETH swaps alongside Wasabi CoinJoin for Bitcoin obfuscation points to a deliberate multi-protocol strategy — a pattern increasingly seen in exchange exploits, where attackers spread activity across chains to dilute investigator focus.

Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.