Bitget hacker converts $6.3M in Ethereum to Bitcoin as the exchange tries to contain the movement of assets stolen in its September 24 security breach. Transaction records associated with the attacker-linked Ethereum address show 27 completed swaps through THORChain on September 28, exchanging approximately 2,390 ETH for 75.2 BTC. The completed Bitcoin payouts went to one receiving address.
The activity took place over roughly two and a half hours, from 03:55 to 06:23 UTC. Most swaps were submitted in batches of about 100 ETH. Four further orders involving a combined 400 ETH were pending in the transaction snapshot, so that amount should not be included in the completed $6.3 million conversion. Portions of two other orders failed to meet their minimum price requirements, resulting in around 114 ETH being returned to the sender.
The dollar value is an estimate based on the price of ETH when the transactions were assessed. The asset amounts and transaction statuses provide a clearer account of what had actually moved at that point; subsequent activity could change the address balances.

Why Bitget Asked for a Block
Bitget has published addresses it associates with the attacker and is working with blockchain projects, investigators and exchanges to trace or recover the stolen assets. As funds moved between networks, CEO Gracy Chen asked THORChain to refuse transactions from those identified addresses.
THORChain’s position is that a network halt is different from an address-specific freeze. Its documented controls can pause swaps across connected chains or restrict trading involving a particular chain. Such a step would interrupt transactions from other users as well. The controls do not provide a way to stop only one wallet’s swap while leaving the same route open to everyone else.
That leaves a difficult recovery problem. A centralized service may be able to restrict activity within systems it controls. THORChain enables swaps between blockchains without requiring users to deposit assets at a conventional exchange account. Its public transaction trail remains available to investigators, but visibility does not itself give them the power to reverse a completed Bitcoin payout.
What Happened in the September 24 Breach?
Bitget detected unauthorized transfers from part of its hot and warm wallet infrastructure on September 24. Its first public estimate put the affected assets at $351.6 million. After reviewing more transactions and assets, Bitget raised the figure to $387.5 million, and its updated incident account rounds the estimate to approximately $388 million.
The exchange says the higher figure comes from a more complete accounting of the original breach. It has not identified another wave of unauthorized withdrawals following containment. Bitget says its cold crypto wallets were unaffected and customer account balances remain unchanged.
Bitget’s preliminary investigation points to a possible vulnerability in a third-party security product that may have allowed the attacker to obtain high-level credentials and send fraudulent withdrawal commands. The company says the affected systems have been isolated and the vulnerability identified so far has been fixed. The full forensic investigation remains underway, with Mandiant and SlowMist assisting.
Those findings describe a possible attack path, not a final public account of every step the attacker took. Bitget says it will publish further details after they are verified.
A Separate Bitcoin Trail Was Already Under Scrutiny
The 75.2 BTC conversion is not the first route investigators have associated with the stolen funds. Earlier tracing connected a separate, smaller flow from TRON through Ethereum and THORChain to Bitcoin, with roughly 4 BTC later linked to a Wasabi CoinJoin transaction. Bitnxt’s report on that earlier CoinJoin activity explains how the route was traced.
These two figures should not be combined as though they describe a single swap. The approximately 4 BTC CoinJoin trail concerns earlier activity; the 75.2 BTC figure concerns the completed September 28 ETH-to-BTC swaps. Converting assets across chains can complicate recovery, but the transactions still leave records that investigators can follow.
What Happens Next?
Bitget has offered a bounty equal to 5% of eligible funds successfully frozen or recovered, subject to its program terms. It says some affected assets have already been frozen through cooperation with industry partners, although recovery totals should be treated cautiously until the exchange verifies them.
For users, the new swaps represent movement of funds attributed to the existing breach. They do not mean an additional $6.3 million was taken from Bitget on September 28. The questions now are whether the receiving Bitcoin remains traceable as it moves further, whether recovery partners can act on any subsequent deposits, and what Bitget’s completed investigation reveals about the original intrusion.
Official record | Purpose |
Inspect the public swap activity and current transaction statuses | |
Understand the scope of its trading and chain halt controls | |
Check the revised breach estimate, investigation and withdrawal status | |
Check attacker-address information and bounty conditions |
























