Hacker sending crypto funds into a Wasabi CoinJoin mixer

Bitget Hack Funds Worth $4M Enter Wasabi CoinJoin

Key Insights

  • AMLBot traced approximately 4 BTC into Wasabi CoinJoin after the attacker moved funds through TRON, Ethereum and THORChain.
  • Bitget’s estimated losses increased to $387.5 million after investigators identified additional Zcash and TRON assets.
  • Approximately $343 million remained dormant across 13 attacker-controlled wallets, while Bitget prepared its phased withdrawal reopening.

On September 27, the Bitget hack investigation entered a new phase, with AMLBot tracing around 4-bitcoins to a Wasabi CoinJoin transaction. The discovery is another effort to cover up the stolen cryptocurrency following the Bitget hack on September 24, during which it claimed to have lost about $387.5 million.

The path would be TRON, Ethereum, Bitcoin, and last but not least, THORChain.The journey would be from TRON, to Ethereum and Bitcoin and finally, THORChain. In the interim, majority of the stolen assets have remained dormant, and Bitget is ready to resume withdrawals.

The stolen funds have been spread across blockchains

By looking at the transaction history AMLBot could follow the change of TRON (TRX) from a wallet, to a Tether (USDT) wallet, which let AMLBot see the attacker’s moves. The money then trickled over to Ethereum via USDT0, an omnichain Tether that enables cross-chain transfers.

The assets transferred to Ethereum were then converted to around 145 Ether (ETH). The money then went through THORChain and finally to Bitcoin, where it was converted to approximately 4.59 BTC.

The next transactions split up the Bitcoin into smaller amounts before sending them to Wasabi CoinJoin. According to AMLBot, its analysis connected around 4 BTC in one CoinJoin round to the original TRON wallet that is linked to Bitget.

The transaction sequence explains how hackers can be able to transfer the stolen assets to various different blockchain ecosystems. Every conversion causes investigators and compliance providers new challenges in the tracing process.

Wasabi CoinJoin makes fund recovery harder.

Wasabi takes advantage of CoinJoin to bundle together Bitcoin in/out of many people in a single transaction. That makes it more difficult to connect individual inputs with individual outputs for blockchain observers.

AMLBot described the transaction as an apparent attempt to obscure the stolen funds. However, blockchain records establish transaction movements rather than independently proving the attacker’s intentions.

The firm has restricted addresses associated with the traced flow and continues monitoring the attacker’s Bitcoin activity for further CoinJoin transactions. Some addresses connected to the breach have also been frozen, although the available information does not establish the total value recovered through those actions.

The latest development follows Bitget’s request for THORChain to block funds connected to the incident. AMLBot’s findings also demonstrate how compliance firms can trace transactions across different networks, even after attackers convert assets repeatedly.

Bitget losses reach $387.5 million

Bitget first estimated that the breach on September 24 cost $351.6 million because some unauthorized transfers hit parts of its warm wallet infrastructure.

It also detected the breach at 18:31 UTC, suspended withdrawals, and maintained deposits and trading. The exchange confirmed that its cold wallets remained secure.

By September 25 investigators had found Zcash and TRON assets so the estimate went up to, about $387.5 million.

Bitget clarified that this new amount was a more thorough count of the original loss, not an extra theft.

Meanwhile, Bitget CEO Gracy Chen said investigators identified a backend wallet infrastructure compromise. She also stated that the investigation had ruled out private key compromise.

The exchange subsequently reported that its security team had identified and fixed the vulnerability. However, Bitget has not released a complete technical report explaining the exploit.

Dormant funds and withdrawal restoration

AMLBot estimated that approximately $343 million remained dormant across 13 attacker-controlled wallets as of September 25. That amount was 88% of the around 389 million dollars that the company kept track of.

The wallets were said to have about 68,300 ETH, 83 million XRP and 18,900 ZEC. AMLBot said none of the 13 addresses had sent outgoing transactions at the time of its update. The contrast between dormant balances and active laundering routes leaves investigators monitoring whether additional funds will move.

Bitget is going to start allowing withdrawals, in parts starting on September 28.

  • Bitcoin withdrawals will begin again at 08:00 UTC on September 28.
  • ETH withdrawals across supported networks are scheduled for September 29.
  • USDT withdrawals are scheduled for September 30.
  • Other token withdrawals, fiat services and peer-to-peer withdrawals are expected on October 2.

Bitget said Mandiant and SlowMist continue assisting with the investigation. The exchange also stated that its Protection Fund, valued above $464 million during the withdrawal suspension, would cover the losses.

Conclusion

The Bitget hack investigation now extends beyond the initial breach, with AMLBot tracing Bitcoin through multiple networks into privacy-focused transaction infrastructure. Although investigators have identified several laundering routes, most tracked assets remained dormant as of September 25.

The coming withdrawal restoration and continued blockchain monitoring will provide further information about Bitget’s recovery efforts and the movement of remaining stolen funds.

Scroll to Top