Thirteen days after the Bitget hack, most of the roughly $387.5 million taken has been pushed toward bitcoin, mainly through the cross-chain protocol THORChain. Publicly visible freezes cover about 0.2% of it. The trail is public. Can anyone still stop it?
The withdrawals were forged.
The swaps were real.
Bitget puts the loss from the 24 Sep attack on its hot and warm wallets at about $387.5 million. The exchange says customer balances are unaffected and its user protection fund covers the loss. Its private keys were not compromised and its cold wallets were untouched, according to the company. Attribution is unconfirmed.
Most of what is known about where the money went comes from Bitget’s own public tracing dashboard and from an analysis of it published by the security firm BlockSec on 30 Sep. The dollar figures below are theirs, from a dashboard snapshot taken at 12:30 UTC on 29 Sep, unless stated otherwise.

If the stolen funds are visible on every chain, why has so little been stopped?
The timeline
At 18:31 UTC on 24 Sep, Bitget’s Ethereum and Tron hot wallets sent two small test transfers, 0.84 ETH and 93 TRX. Bitget later said both were below its alert thresholds.
Related: The attacker’s test transfers
At 18:58 UTC, large outflows began. The first was 34.75 million USDT.
At 19:05 UTC, Bitget’s reconciliation system flagged the gap and blocked user withdrawals. The forged commands did not use that path. The outflows continued.
At about 19:09 UTC, ten minutes after it left Bitget, the stolen USDT started being swapped for ETH.
By about 19:42 UTC, the stablecoins and gold tokens taken on Ethereum and Arbitrum had all been swapped for ETH, BlockSec says. The slowest batch took 41 minutes from theft to last swap.
At 21:23 UTC, the last transfer left. At 21:30 UTC, Bitget’s chief executive posted about the incident. At 21:44 UTC, Bitget shut down its signing machines.
On 25 Sep, at 05:00 and 12:19 UTC, Circle and Tether froze stablecoins that had landed late on an attacker-linked address.
On 26 Sep, Bitget chief executive Gracy Chen asked THORChain to refuse service to the attacker’s addresses.
Post by @GracyBitget on X: https://x.com/GracyBitget/status/2103812967066439817
On 27 Sep at 11:03 UTC, four inputs worth 10 BTC from attacker-labelled addresses went into a Bitcoin CoinJoin transaction with 356 inputs and 401 outputs.
On 28 Sep, THORChain declined Bitget’s request. On the same day, NEAR Intents disclosed that it had blocked or frozen attempts to route funds through its service, and the researcher ZachXBT published accounts he alleges belong to people laundering the funds.
On 29 Sep, the dashboard showed the attacker still controlling about $342 million, 88.3% of the total.
Thirteen days in, the timeline has not ended. Where did the attacker go first?
How the Bitget hack happened
Bitget says the attacker exploited a zero-day flaw in a third-party security product, stole high-privilege internal credentials and wrote forged withdrawal commands into its wallet system. The attacker then deleted the related records, the company says.
Two firms hired by Bitget published early findings on 30 Sep. Mandiant said the attacker gained privileged access to two third-party security appliances. SlowMist dated the earliest malicious activity in the available logs to 31 Aug.
Related: Dalia’s first post-mortem update
On Bitget’s account, the signing system worked. The instructions it signed were false. Bitget says its keys were not compromised, and nothing published so far contradicts that.
Related: What a private key is
That matters for what came next. An attacker who never holds the keys has only one chance to move the money out. After that, the job is laundering.
So what did the attacker do with $387.5 million in a hurry?
Follow the funds
BlockSec describes three steps.
First, the attacker swapped anything an issuer could freeze. About $75.48 million in USDT, USDC and USDT0, plus 3,000 XAUt, became ETH or AVAX within 41 minutes of being taken.
| Stolen asset | Amount | Time to finish swapping | Swapped into |
|---|---|---|---|
| USDT on Ethereum | 34,751,168 | 18 minutes | 12,876.76 ETH |
| USDC on Ethereum | 12,852,046 | 18 minutes | 4,761.74 ETH |
| XAUt on Ethereum | 3,000.32 | 28 minutes | 4,689.14 ETH |
| USDT0 on Arbitrum | 19,668,852 | 41 minutes | 7,111.24 ETH |
| USDC on Avalanche | 8,204,679 | 33 minutes | 740,684 AVAX |
Source: BlockSec, from Bitget’s tracing dashboard.
The swaps used everyday routes: UniswapX, Uniswap, 1inch and the swap feature inside the MetaMask wallet. All were done before Bitget’s chief executive posted at 21:30 UTC.
Second, the attacker pulled the funds from every chain toward bitcoin, with Ethereum as the main transit point. THORChain carried the largest share.
According to the dashboard, about $269 million went into THORChain across 7,804 transactions. Chainflip, another cross-chain swap service, was second among swap services at about $37.27 million.
These are pass-through figures. The same funds can cross several services. They are not a laundered total.
Third, mixing. CoinJoin combines many users’ bitcoin in one transaction to break the link between inputs and outputs. By 29 Sep about $3.94 million had gone in. That is small next to the attacker’s bitcoin holdings.
On 29 Sep, BlockSec reported, the attacker still controlled roughly:
- 3,386 BTC, about 83.7% of the remaining value.
- ZEC worth about 8.5%.
- 9,357 ETH, about 7.3%.
- Stablecoins worth about 0.2%.
The evidence ledger, from BlockSec and public explorers:
Bitcoin CoinJoin with 10 BTC of attacker inputs: 2380584fe493b68403b1e1d5848118590c9b8c323efe630426e26b15523f125e (mempool.space)
Ethereum address with frozen USDT and USDC: 0xe07b…7d57 (shortened as BlockSec published it)
Ethereum address with frozen USDT (a THORChain refund): 0x9acc…b046
Then the frozen-versus-recovered line, which is where this story usually ends.
| Category | Amount | By whom | As of |
|---|---|---|---|
| Frozen by issuers | about $340,000 | Tether and Circle | 29 Sep |
| Frozen mid-swap | about $503,000 (its own figure, ±10%) | NEAR Intents | 28 Sep |
| Recovered and returned | none reported | — | 7 Oct |
Frozen is not recovered. Frozen funds still need a legal or voluntary process before anyone gets them back.
Why were these amounts caught when $75 million was not?
The response
The freezes share one feature, BlockSec found: the funds sat still for hours. Stablecoins bridged from BNB Chain arrived late on an address the attacker had already left, and stayed there until Tether and Circle acted. Another USDT batch stayed only 1 hour and 14 minutes before being swapped, and was not frozen.
NEAR Intents said the attacker tried to move more than $50 million through it. Its risk system declined quotes or halted execution, according to its disclosure. About $166,000 got through.
THORChain took the opposite position. “Decentralization is a design principle, not a shield for facilitating known stolen funds,” Chen wrote in her 26 Sep request. THORChain replied that the protocol “doesn’t censor by design”, and that “a halt is not a selective freeze of specific funds or an individual swap”.
Critics pointed out that THORChain paused its whole network in May after losing about $10.7 million to a flaw in its own signing scheme, BlockSec noted.
The swaps also paid fees. The independent researcher Andrey Sergeenkov counted at least $761,725 in protocol and service fees on swaps of the stolen funds through 2 Oct, crypto.news reported. THORChain liquidity providers received $573,226 of that. He traced a further $259,718 in THORChain affiliate fees to recipients he says have additional on-chain links to wallets that moved the stolen funds, The Crypto Times reported.
On attribution, nothing official yet. Elliptic counts the attack among suspected North Korean heists. TRM Labs calls it a likely North Korea attack. Bitget’s chief executive said the techniques were “consistent with” those of DPRK-linked groups, according to BlockSec.
ZachXBT alleges that five laundering intermediaries are moving the funds on the attackers’ behalf. His claims are allegations; we are not naming the accounts.
BlockSec urges caution: the laundering overlaps “point more directly to shared launderers”, not necessarily the same attackers. CryptoWatchDesk found no public attribution by the FBI or any other government agency as of publication.
Bitget has completed its withdrawal reopening and is offering 5% of any funds frozen or recovered through voluntary third-party action.
Related: Bitget’s final withdrawal stage
If the protocols that carried the money won’t stop it, who will?
Recap
The theft took under three hours, and the stablecoins were gone in 41 minutes.
About $342 million was still under the attacker’s control on 29 Sep, mostly as bitcoin.
THORChain carried the largest share and has refused to block addresses.
About $840,000 has been frozen. We found no report of funds recovered.
Nobody with official standing has named the attacker.
Protect yourself
- Spread large balances across exchanges and self-custody; an exchange’s protection fund is a promise, not a guarantee.
- Keep long-term holdings in self-custody, with keys you control and have backed up offline.
- After any exchange incident, use only the exchange’s official site and app for updates; phishing follows hacks.
- Never send funds to “recovery” services that contact you first.
When the money is public and the route is known, is permissionless still a defence?
Corrections and new evidence: [email protected]
Produced by the Crypto Watch Desk newsroom using AI tools. This article is for information only and is not investment advice.
