NewsCryptoBitget Hack: BlockSec Traces $387.5M in Stolen Funds Through Bitcoin, THORChain and CoinJoi

Bitget Hack: BlockSec Traces $387.5M in Stolen Funds Through Bitcoin, THORChain and CoinJoi

Author: AI Crypto Core·

Key Takeaways

  • •BlockSec traced roughly $387.5 million in stolen Bitget funds through Bitcoin, the THORChain cross-chain protocol, and a service identified as CoinJoi.
  • •THORChain governance rejected a proposal to blacklist the hacker's addresses, drawing commentary from Vitalik Buterin and fueling debate over decentralized protocols' responsibility for filtering stolen funds.
  • •NEAR Intents reported blocking approximately $50 million in Bitget hack flows, representing the largest single interdiction in the reported fund trail.
  • •Bitget resumed Bitcoin withdrawals after the hacker swapped ETH through THORChain, with Ether withdrawals scheduled to follow.
  • •AMLBot separately traced 4 BTC from the hack to Wasabi CoinJoin, though the research does not confirm whether CoinJoi and Wasabi CoinJoin refer to the same service.
Bitget Hack: BlockSec Traces $387.5M in Stolen Funds Through Bitcoin, THORChain and CoinJoi

Blockchain security firm BlockSec has traced the movement of funds stolen in the Bitget hack, reporting that roughly $387.5 million was routed through Bitcoin, the THORChain cross-chain protocol, and a service identified as CoinJoi. The trace maps an obfuscation pattern that has become common in large-scale exchange hacks: convert on-chain assets, swap across chains, then fragment the trail.

What BlockSec's Trace Revealed

According to BlockSec's reported analysis, the stolen Bitget funds did not sit idle. The attacker moved assets into Bitcoin, used THORChain as a cross-chain routing layer, and passed funds through CoinJoi. Each step serves a distinct purpose in severing the on-chain link between the original theft and any eventual cash-out attempt.
THORChain enables native cross-chain swaps without wrapped tokens or centralized bridges, making it a technically effective tool for moving value between chains. After the hack, THORChain's governance rejected a proposal to blacklist the Bitget hacker's addresses, a decision that drew commentary from Ethereum co-founder Vitalik Buterin and sharpened debate over whether decentralized protocols bear responsibility for filtering stolen funds. That debate sits within a longer regulatory arc: in 2022, the U.S. Treasury's Office of Foreign Assets Control sanctioned the Bitcoin mixer Blender.io and the Ethereum-based mixing protocol Tornado Cash over their use in laundering hack proceeds, actions that fueled lasting legal debate over how far sanctions can reach into open-source, permissionless protocols.

Separately, blockchain analytics firm AMLBot identified a smaller slice of the movement: 4 BTC from the Bitget hack was traced to Wasabi CoinJoin, a Bitcoin privacy tool that mixes transactions to obscure input-output links. The CoinJoi reference in BlockSec's trace may relate to this same mixing activity, though the research brief does not confirm whether CoinJoi and Wasabi CoinJoin refer to the same service or separate steps in the chain.

The Limits of What Tracing Establishes

Tracing confirms observed asset movements; it does not establish final disposition. BlockSec's reported analysis shows where funds traveled, not whether they were recovered, frozen by exchanges, or converted to fiat. Those are separate questions that depend on whether any centralized service in the path cooperated with investigators. That is also what makes tracing actionable: its practical value lies in identifying chokepoints where funds can still be intercepted, while permissionless segments of the route largely sit outside any single party's control.

Not all of the stolen funds reached anonymous protocols unchecked. NEAR Intents reported blocking approximately $50 million in Bitget hack flows, representing the largest single interdiction in the reported fund trail. That left the remaining majority of the $387.5 million moving through channels where intervention was either unavailable or declined.

Bitget itself began restoring user access to funds in the aftermath. Bitcoin withdrawals resumed after the hacker swapped ETH through THORChain, with Ether withdrawals scheduled to follow. The sequencing suggests Bitget prioritized restoring BTC liquidity once the attacker had already moved the ETH-denominated portion of the theft off-platform.

What the Route Signals for On-Chain Forensics

The Bitcoin–THORChain–CoinJoi path mirrors a pattern seen in other major exchange hacks: use a permissionless cross-chain protocol to break the asset trail at the chain boundary, then apply a coin-mixing step to fragment Bitcoin UTXOs. For on-chain forensic teams, this combination requires analysis across at least two chains and probabilistic UTXO clustering, rather than simple address-following.

The $387.5 million figure, if accurate, would place the incident among the larger single-exchange thefts in recent memory. BlockSec's trace is the earliest public accounting of where the funds moved, but the full picture of how much was ultimately recoverable, frozen, or laundered will depend on reporting from exchanges and analytics firms in the weeks and months ahead. Among the open questions: whether additional services along the route act to freeze funds, and whether the governance decision not to blacklist draws renewed regulatory attention to permissionless cross-chain infrastructure.

Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.