BTCBTC$83,142-1.63%|
ETHETH$2,648.99-2.10%|
USDTUSDT$0.99973-0.00%|
BNB$763.5600-1.43%|
XRPXRP$1.4800-2.86%|
USDCUSDC$0.99983-0.00%|
SOLSOL$118.6900-2.19%|
TRXTRX$0.33365+0.12%|
ZECZEC$1,547.74-6.28%|
FIGR_HELOCFIGR_HELOC$1.0580-0.38%|
HYPEHYPE$89.0100-4.00%|
DOGEDOGE$0.09297-4.13%|
LINKLINK$13.7800-3.24%|
XMRXMR$533.7200-4.21%|
WBTWBT$82.9600-1.69%|
USDSUSDS$0.99972-0.00%|
ADAADA$0.24533-4.03%|
RAINRAIN$0.01254-1.33%|
LEOLEO$9.0700+0.24%|
XLM$0.20872-3.90%|
NEARNEAR$5.1500-5.56%|
BCHBCH$308.1700-9.81%|
UNIUNI$9.1400-9.35%|
LTCLTC$70.8500-1.46%|
CCCC$0.13724+2.35%|
USDEUSDE$0.99976+0.01%|
AVAXAVAX$10.5300-3.99%|
SUISUI$1.1900-0.36%|
DAIDAI$1.0000+0.01%|
GRAMGRAM$1.6000+0.83%|
BTCBTC$83,142-1.63%|
ETHETH$2,648.99-2.10%|
USDTUSDT$0.99973-0.00%|
BNBBNB$763.5600-1.43%|
XRPXRP$1.4800-2.86%|
USDCUSDC$0.99983-0.00%|
SOLSOL$118.6900-2.19%|
TRXTRX$0.33365+0.12%|
ZECZEC$1,547.74-6.28%|
FIGR_HELOCFIGR_HELOC$1.0580-0.38%|
HYPEHYPE$89.0100-4.00%|
DOGEDOGE$0.09297-4.13%|
LINKLINK$13.7800-3.24%|
XMRXMR$533.7200-4.21%|
WBTWBT$82.9600-1.69%|
USDSUSDS$0.99972-0.00%|
ADAADA$0.24533-4.03%|
RAINRAIN$0.01254-1.33%|
LEOLEO$9.0700+0.24%|
XLMXLM$0.20872-3.90%|
NEARNEAR$5.1500-5.56%|
BCHBCH$308.1700-9.81%|
UNIUNI$9.1400-9.35%|
LTCLTC$70.8500-1.46%|
CCCC$0.13724+2.35%|
USDEUSDE$0.99976+0.01%|
AVAXAVAX$10.5300-3.99%|
SUISUI$1.1900-0.36%|
DAIDAI$1.0000+0.01%|
GRAMGRAM$1.6000+0.83%|
News/Technology
Technology

Bitget Hacker Routes Stolen Funds Into Wasabi CoinJoin

Bitget hacker routing stolen Bitcoin funds into Wasabi CoinJoin.

Summary :

  • Approximately 4 BTC ($336,000) traced into Wasabi CoinJoin mixing rounds following multi-chain swaps.

  • Laundering trail crossed four networks: TRON, USDT0 omnichain bridge, Ethereum, and THORChain.

  • Confirmed total breach losses revised upward to $387.5 million across multiple asset classes.

  • Attacker holds $343 million dormant across 13 primary wallets, including 68,300 ETH and 83 million XRP.

  • Exchange scheduled phased withdrawal reopenings starting with Bitcoin on September 28.

Blockchain tracing connected roughly 4 BTC linked to the Bitget hacker to a Wasabi CoinJoin mixing round after the funds traversed four separate blockchains. Following the September exploit that compromised $387.5 million in exchange wallet assets, the attacker launched a multi-hop laundering pipeline to obscure transaction outputs. Initial movement began on the TRON network before bridging through cross-chain protocols into Bitcoin. While compliance firms successfully flagged the destination addresses, mixing protocols complicate long-term asset recovery by blending transaction histories with benign market participants.

Tracing the Bitget Hacker Across TRON, Ethereum, and THORChain

The movement of stolen assets highlights a highly structured multi-chain laundering strategy executed shortly after the breach occurred. The attacker initially held stolen TRX on the TRON network, converting the assets into USDT stablecoins. From TRON, the funds crossed over to Ethereum using USDT0, an omnichain Tether implementation built for cross-network transfers. Once on Ethereum, the attacker executed decentralized exchange swaps to convert the stablecoins into approximately 145 ETH. This sequence mirrored earlier stablecoin conversion routes where breach proceeds were converted into native tokens to bypass centralized freeze mechanisms.

After acquiring ETH, the attacker routed the funds through THORChain liquidity pools to swap into 4.59 BTC. Non-custodial cross-chain swaps allow actors to jump between distinct Layer 1 blockchains without leaving centralized identity trails. Upon receiving Bitcoin, the attacker split the output into smaller tranches before broadcasting transactions into a Wasabi CoinJoin round. Analytics firms monitored each swap in real time, linking the 4 BTC output directly back to the original TRON deposit address. Despite the rapid chain hopping, public ledger records allowed researchers to reconstruct the entire conversion pathway.

The structured nature of these swaps points to automated execution scripts designed to bypass transaction monitoring algorithms. Moving funds through four distinct chains within days requires pre-funded gas accounts and automated slippage management. However, every cross-chain bridge and liquidity pool leaves permanent on-chain footprints. While decentralized protocol swaps prevent instant asset freezes, they do not erase the historical link between input deposits and output addresses when transaction sizes remain large.

Wasabi CoinJoin Mechanics and Tracing Obfuscation

CoinJoin mixing through Wasabi Wallet functions by combining Bitcoin inputs from multiple independent users into a single, complex transaction structure. By generating identical output values for all participants, the protocol breaks the deterministic link between senders and receivers. For the Bitget hacker, entering a CoinJoin round aims to anonymize the 4 BTC tranche, making it difficult for exchange compliance desks to identify the funds upon deposit. Once outputs leave a mixing round, standard heuristic tracking models struggle to assign definitive ownership probabilities to individual UTXOs.

Despite these mathematical obfuscation techniques, blockchain intelligence firms immediately blacklisted the output addresses associated with the round. Modern compliance software employs cluster analysis and statistical profiling to flag mixed UTXOs, prompting centralized exchanges to freeze deposits originating from privacy tools. Similar enforcement actions surrounding privacy software were analyzed during bitcoin mixing protocol enforcement actions against developer operations. Consequently, while CoinJoin obscures direct transaction links, it simultaneously taints the funds, severely restricting where the attacker can liquidate them.

The decision to mix only 4 BTC indicates the attacker is testing liquidation channels before moving larger capital tranches. Mixing large volumes through CoinJoin takes time because rounds require sufficient participant liquidity to achieve high anonymity sets. If an attacker dumps hundreds of Bitcoins into mixing pools at once, liquidity constraints and volume anomalies draw instant tracker attention. The 4 BTC test run demonstrates that the perpetrator understands the limitations of privacy tools when dealing with institutional-scale breach proceeds.

Dormant Attacker Wallets and Exchange Recovery Odds

The 4 BTC routed through Wasabi represents less than 0.1% of the total assets stolen during the September 24 breach. Approximately $343 million, representing 88% of the $387.5 million total loss, remains completely dormant across 13 attacker-controlled wallets. Analytics data shows eight Ethereum addresses holding roughly 68,300 ETH, four XRP addresses containing 83 million XRP, and a single Zcash wallet holding 18,900 ZEC. None of these primary vault addresses have initiated outgoing transactions since receiving the stolen assets, indicating that the bulk of the haul remains immobilized under global compliance surveillance.

Bitget's revised loss figure of $387.5 million updated the initial $351.6 million assessment after investigators identified additional TRON and Zcash transfers. The exchange clarified that backend wallet infrastructure was compromised rather than private key leaks, allowing security teams to patch the intrusion vector rapidly. Phased withdrawal reopenings are scheduled to begin September 28, backed by an internal Protection Fund holding over $464 million in reserves. Exchange operations continue under guidance from external forensic firms while strict exchange wallet security standards are implemented across all hot wallet endpoints.

Recovery odds for the dormant $343 million depend heavily on whether the attacker makes operational security errors during future conversion attempts. Because major stablecoin issuers can freeze assets on centralized chains and exchanges enforce strict KYC controls on high-value deposits, liquidating hundreds of millions in stolen crypto remains an extraordinary hurdle. Law enforcement agencies continue monitoring the 13 primary addresses alongside CoinJoin output streams. How long can the attacker keep $343 million immobilized before automated tracking tools flag their next liquidation attempt?

#Bitget#Bitget hacker#Wasabi Wallet#CoinJoin#THORChain#TRON#Bitcoin
Aaron Bailey

Author

Aaron Bailey

Blockchain Tech Analyst

Aaron Bailey has covered blockchain technology and decentralized systems for 2 years, focusing on protocol upgrades, Layer 2 developments, and emerging DeFi infrastructure. He breaks down complex technical shifts into clear, actionable insights for Bitnxt readers.

Share: