Where did the stolen $387M go?

fiverr
Blockonomics


Bitget’s attacker has moved much of the exchange’s $387.5 million theft toward Bitcoin through cross-chain services, while only around $840,000 had been publicly frozen five days after the Sept. 24 breach.

Summary

  • Bitget says attackers moved $387.5 million from hot and warm wallets across blockchains in September.
  • BlockSec estimates attackers still controlled roughly $342 million five days after the Bitget theft began.
  • Tether, Circle and NEAR Intents froze roughly $840,000, equal to only 0.2% of stolen funds.
  • THORChain handled about $269 million in pass-through value, while Bitcoin became the main consolidation asset.
  • North Korea remains suspected, but BlockSec says current onchain evidence does not establish attacker identity.

BlockSec reported that the stolen funds followed three main paths: quickly converting assets that issuers could freeze, consolidating value from several chains into Bitcoin and gradually sending BTC into CoinJoin transactions.

Phemex

The security firm based its analysis on addresses published through Bitget’s tracking dashboard and a Sept. 29 snapshot, meaning the balances and laundering totals can continue changing as funds move.

How did the Bitget hacker move the stolen money?

Bitget said the breach began at 18:31 UTC on Sept. 24 with unauthorized transfers from portions of its hot and warm wallet infrastructure.

BlockSec found that the first transactions involved tiny test transfers of 0.84 ETH and 93 TRX. Larger withdrawals started at 18:58 UTC, while Bitget’s reconciliation system detected a discrepancy seven minutes later and blocked ordinary customer withdrawals.

The attackers were not relying on the normal customer withdrawal process, according to Bitget. The exchange said a vulnerability in a third-party security product gave the attackers high-level internal credentials, which were then used to submit forged withdrawal commands directly into its wallet system.

Private keys were not compromised, Bitget said, while its cold wallets remained unaffected. Independent investigations by Mandiant and SlowMist later confirmed that compromised third-party security software enabled unauthorized access to the exchange’s wallet environment.

The loss was initially estimated at $351.6 million before Bitget expanded the figure to roughly $387.5 million after accounting for Zcash and Tron transfers. BlockSec counted 13 stolen assets across 12 chains, with XRP representing the largest single-chain loss.

Assets that could be frozen were moved first. BlockSec found roughly $75.48 million in USDT, USDC and USDT0, plus 3,000 XAUt tokens, were converted into ETH or AVAX within 41 minutes of their theft.

Uniswap, UniswapX, 1inch and MetaMask’s built-in swap service appeared among the routes used. BlockSec said all those conversions were completed before Bitget CEO Gracy Chen publicly disclosed the breach.

Why has only $840K of Bitget’s $387M been frozen?

Once the assets had been converted, the attacker began moving value between chains and toward Bitcoin.

BlockSec estimated that around $269 million in pass-through value moved through THORChain across 7,804 transactions by its Sept. 29 snapshot. Chainflip handled roughly $37.27 million, while USDT0/LayerZero, Circle’s CCTP, Across and Stargate appeared in other routes.

Those figures cannot be added together as separate stolen amounts. BlockSec cautioned that the same funds can move through more than one protocol while traveling between chains.

Nearly five days into the laundering process, BlockSec estimated attacker-controlled wallets still held approximately $342 million, equal to 88.3% of the original stolen amount. Bitcoin accounted for around 83.7% of that balance, or roughly 3,386 BTC.

Publicly visible freezes were much smaller.

Tether and Circle had immobilized around $340,000 in stablecoins. Much of that money became vulnerable to freezing because it remained at addresses long enough for the issuers to respond.

NEAR Intents separately said its SHIELD risk system caught attempts to route more than $50 million through the service. BlockSec’s review of the disclosure found roughly $503,000 was stopped during execution, while around $166,000 passed through.

The NEAR Intents figures carry an estimated error margin of up to 10%, according to the service’s own disclosure.

Earlier coverage of NEAR Intents blocking Bitget-linked transfers found that some funds were left in pending transactions after being flagged during the swap process.

Combined, the Tether, Circle and NEAR Intents actions put publicly visible frozen funds near $840,000, just 0.2% of the amount stolen.

Why did so much Bitget crypto move through THORChain?

THORChain became the largest cross-chain route identified by BlockSec, drawing criticism from Bitget as stolen ETH continued to be converted into BTC.

Chen publicly asked THORChain to reject known attacker addresses, arguing that “decentralization is a design principle, not a shield” for stolen funds.

THORChain rejected the request and said its emergency halt functions are designed to protect the protocol as a whole, not selectively censor individual transactions.

The network said an emergency halt “is not a selective freeze” of a specific transaction or user.

A Bitget-linked wallet later swapped about $6.3 million of ETH into Bitcoin through THORChain, completing 27 swaps that produced approximately 75.2 BTC.

Other stolen funds reached Bitcoin mixers. BlockSec counted about $3.94 million entering CoinJoin transactions by Sept. 29.

One Sept. 27 CoinJoin transaction contained 356 inputs and 401 outputs. Four inputs, each containing 2.5 BTC, came from addresses Bitget’s tracker identified as belonging to the attacker.

Bitget hack: Where did the stolen $387M go? - 2

Separate tracking of Bitget funds entering Wasabi CoinJoin previously found a route starting on Tron, passing through Ethereum and THORChain, then reaching Bitcoin before mixing.

Did North Korea carry out the Bitget hack?

North Korean involvement remains an assessment, not a confirmed attribution by law enforcement.

Chen has said IP behavior and onchain patterns were “consistent with techniques used by DPRK-linked hacker groups.” Bitget said some IP addresses matched VPN infrastructure previously associated with a North Korean group, but the technical evidence behind that comparison has not been made public.

BlockSec found other possible links, including overlap with laundering methods used in attacks attributed to TraderTraitor and the use of THORChain to convert assets into Bitcoin.

Researcher ZachXBT identified several Chinese-speaking underground money launderers that he said were handling funds for the attacker. One had reportedly appeared in laundering activity connected with an earlier exploit.

Arkham separately pointed to the use of a peel-chain technique frequently associated with North Korean-linked operations.

BlockSec cautioned against treating those similarities as proof of attacker identity. Money-laundering services can work for different clients, while protocols such as THORChain and CoinJoin are available to unrelated users.

The security firm said the evidence points more directly to possible reuse of laundering groups than proof that the same hackers carried out earlier North Korean-linked attacks.

The comparison has centered partly on the 2025 Bybit theft. U.S. authorities formally attributed that $1.5 billion attack to North Korea’s TraderTraitor operation, while THORChain was heavily used to move the stolen Bybit funds.

No law-enforcement agency has publicly attributed the Bitget breach to North Korea as of the latest verified updates.

What happens next for Bitget and the stolen funds?

Bitget continues to trace wallets and is offering a bounty for recoveries. The exchange offers qualifying participants 5% of funds they directly help freeze and another 5% for funds successfully recovered.

The Bitget recovery bounty was launched while Mandiant, SlowMist, exchanges and blockchain investigators continued tracking attacker addresses.

Bitget has already restored Bitcoin, Ether and USDT withdrawals in phases. Its published schedule places other tokens, fiat withdrawals and P2P services at 08:00 UTC on Oct. 2, although the exchange’s official incident page had not yet posted a separate confirmation of that final reopening when checked.

Bitget says the exploited vulnerability has been fixed and user balances remain unaffected. Its forensic investigation, law-enforcement work, fund tracing and recovery effort remain open, while the exchange says further material findings will be published through its official security updates.



Source link

Changelly

Be the first to comment

Leave a Reply

Your email address will not be published.


*