{"id":37514,"date":"2026-10-02T08:53:42","date_gmt":"2026-10-02T08:53:42","guid":{"rendered":"https:\/\/bitunikey.com\/news\/bitget-hack-where-did-the-stolen-387m-go\/"},"modified":"2026-10-02T08:54:17","modified_gmt":"2026-10-02T08:54:17","slug":"bitget-hack-where-did-the-stolen-387m-go","status":"publish","type":"post","link":"https:\/\/bitunikey.com\/news\/bitget-hack-where-did-the-stolen-387m-go\/","title":{"rendered":"Bitget hack: Where did the stolen $387M go?"},"content":{"rendered":"<div class=\"post-detail__content blocks\">\n<p class=\"is-style-lead\">Bitget\u2019s attacker has moved much of the exchange\u2019s $387.5 million theft toward Bitcoin through cross-chain services, while only around $840,000 had been publicly frozen five days after the Sept. 24 breach.<\/p>\n<div id=\"cn-block-summary-block_d9b39234f83441ef449470f530e4e176\" class=\"cn-block-summary\">\n<div class=\"cn-block-summary__nav tabs\">\n        <span class=\"tabs__item is-selected\">Summary<\/span>\n    <\/div>\n<div class=\"cn-block-summary__content\">\n<ul class=\"wp-block-list\">\n<li>Bitget says attackers moved $387.5 million from hot and warm wallets across blockchains in September.<\/li>\n<li>BlockSec estimates attackers still controlled roughly $342 million five days after the Bitget theft began.<\/li>\n<li>Tether, Circle and NEAR Intents froze roughly $840,000, equal to only 0.2% of stolen funds.<\/li>\n<li>THORChain handled about $269 million in pass-through value, while Bitcoin became the main consolidation asset.<\/li>\n<li>North Korea remains suspected, but BlockSec says current onchain evidence does not establish attacker identity.<\/li>\n<\/ul><\/div>\n<\/div>\n<p><!-- .cn-block-summary --><\/p>\n<p>BlockSec <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/blocksec.com\/blog\/bitget-hack-laundering-fund-tracing\" target=\"_blank\">reported<\/a> that the stolen funds followed three main paths: quickly converting assets that issuers could freeze, consolidating value from several chains into Bitcoin and gradually sending BTC into CoinJoin transactions.<\/p>\n<p>The security firm based its analysis on addresses published through Bitget\u2019s tracking dashboard and a Sept. 29 snapshot, meaning the balances and laundering totals can continue changing as funds move.<\/p>\n<p>    <!-- .cn-block-related-link --><\/p>\n<h2 class=\"wp-block-heading\"><strong>How did the Bitget hacker move the stolen money?<\/strong><\/h2>\n<p>Bitget <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.bitget.com\/campaigns\/bitget-security-incident-2026\" target=\"_blank\">said<\/a> the breach began at 18:31 UTC on Sept. 24 with unauthorized transfers from portions of its hot and warm wallet infrastructure.<\/p>\n<p>BlockSec found that the first transactions involved tiny test transfers of 0.84 ETH and 93 TRX. Larger withdrawals started at 18:58 UTC, while Bitget\u2019s reconciliation system detected a discrepancy seven minutes later and blocked ordinary customer withdrawals.<\/p>\n<p>The attackers were not relying on the normal customer withdrawal process, according to Bitget. The exchange said a vulnerability in a third-party security product gave the attackers high-level internal credentials, which were then used to submit forged withdrawal commands directly into its wallet system.<\/p>\n<p>Private keys were not compromised, Bitget said, while its cold wallets remained unaffected. Independent investigations by Mandiant and SlowMist later <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.bitget.com\/support\/articles\/12560603896305\" target=\"_blank\">confirmed<\/a> that compromised third-party security software enabled unauthorized access to the exchange\u2019s wallet environment.<\/p>\n<p>The loss was initially estimated at $351.6 million before Bitget expanded the figure to roughly $387.5 million after accounting for Zcash and Tron transfers. BlockSec counted 13 stolen assets across 12 chains, with XRP representing the largest single-chain loss.<\/p>\n<p>Assets that could be frozen were moved first. BlockSec found roughly $75.48 million in USDT, USDC and USDT0, plus 3,000 XAUt tokens, were converted into ETH or AVAX within 41 minutes of their theft.<\/p>\n<p>Uniswap, UniswapX, 1inch and MetaMask\u2019s built-in swap service appeared among the routes used. BlockSec said all those conversions were completed before Bitget CEO Gracy Chen publicly disclosed the breach.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Why has only $840K of Bitget\u2019s $387M been frozen?<\/strong><\/h2>\n<p>Once the assets had been converted, the attacker began moving value between chains and toward Bitcoin.<\/p>\n<p>BlockSec estimated that around $269 million in pass-through value moved through THORChain across 7,804 transactions by its Sept. 29 snapshot. Chainflip handled roughly $37.27 million, while USDT0\/LayerZero, Circle\u2019s CCTP, Across and Stargate appeared in other routes.<\/p>\n<p>Those figures cannot be added together as separate stolen amounts. BlockSec cautioned that the same funds can move through more than one protocol while traveling between chains.<\/p>\n<p>Nearly five days into the laundering process, BlockSec estimated attacker-controlled wallets still held approximately $342 million, equal to 88.3% of the original stolen amount. Bitcoin accounted for around 83.7% of that balance, or roughly 3,386 BTC.<\/p>\n<p>Publicly visible freezes were much smaller.<\/p>\n<p>Tether and Circle had immobilized around $340,000 in stablecoins. Much of that money became vulnerable to freezing because it remained at addresses long enough for the issuers to respond.<\/p>\n<p>NEAR Intents separately said its SHIELD risk system caught attempts to route more than $50 million through the service. BlockSec\u2019s review of the disclosure found roughly $503,000 was stopped during execution, while around $166,000 passed through.<\/p>\n<p>The NEAR Intents figures carry an estimated error margin of up to 10%, according to the service\u2019s own disclosure.<\/p>\n<p>Earlier coverage of NEAR Intents blocking Bitget-linked transfers found that some funds were left in pending transactions after being flagged during the swap process.<\/p>\n<p>Combined, the Tether, Circle and NEAR Intents actions put publicly visible frozen funds near $840,000, just 0.2% of the amount stolen.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Why did so much Bitget crypto move through THORChain?<\/strong><\/h2>\n<p>THORChain became the largest cross-chain route identified by BlockSec, drawing criticism from Bitget as stolen ETH continued to be converted into BTC.<\/p>\n<p>Chen publicly asked THORChain to reject known attacker addresses, arguing that \u201cdecentralization is a design principle, not a shield\u201d for stolen funds.<\/p>\n<p>THORChain rejected the request and <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/x.com\/THORChain\/status\/2104460133132562449\" target=\"_blank\">said<\/a> its emergency halt functions are designed to protect the protocol as a whole, not selectively censor individual transactions.<\/p>\n<p>The network said an emergency halt \u201cis not a selective freeze\u201d of a specific transaction or user.<\/p>\n<p>A Bitget-linked wallet later swapped about $6.3 million of ETH into Bitcoin through THORChain, completing 27 swaps that produced approximately 75.2 BTC.<\/p>\n<p>Other stolen funds reached Bitcoin mixers. BlockSec counted about $3.94 million entering CoinJoin transactions by Sept. 29.<\/p>\n<p>One Sept. 27 CoinJoin transaction contained 356 inputs and 401 outputs. Four inputs, each containing 2.5 BTC, came from addresses Bitget\u2019s tracker identified as belonging to the attacker.<\/p>\n<figure class=\"wp-block-image size-large\"><\/figure>\n<p>Separate tracking of Bitget funds entering Wasabi CoinJoin previously found a route starting on Tron, passing through Ethereum and THORChain, then reaching Bitcoin before mixing.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Did North Korea carry out the Bitget hack?<\/strong><\/h2>\n<p>North Korean involvement remains an assessment, not a confirmed attribution by law enforcement.<\/p>\n<p>Chen has said IP behavior and onchain patterns were \u201cconsistent with techniques used by DPRK-linked hacker groups.\u201d Bitget said some IP addresses matched VPN infrastructure previously associated with a North Korean group, but the technical evidence behind that comparison has not been made public.<\/p>\n<p>BlockSec found other possible links, including overlap with laundering methods used in attacks attributed to TraderTraitor and the use of THORChain to convert assets into Bitcoin.<\/p>\n<p>Researcher ZachXBT identified several Chinese-speaking underground money launderers that he said were handling funds for the attacker. One had reportedly appeared in laundering activity connected with an earlier exploit.<\/p>\n<p>Arkham separately pointed to the use of a peel-chain technique frequently associated with North Korean-linked operations.<\/p>\n<p>BlockSec cautioned against treating those similarities as proof of attacker identity. Money-laundering services can work for different clients, while protocols such as THORChain and CoinJoin are available to unrelated users.<\/p>\n<p>The security firm said the evidence points more directly to possible reuse of laundering groups than proof that the same hackers carried out earlier North Korean-linked attacks.<\/p>\n<p>The comparison has centered partly on the 2025 Bybit theft. U.S. authorities formally attributed that $1.5 billion attack to North Korea\u2019s TraderTraitor operation, while THORChain was heavily used to move the stolen Bybit funds.<\/p>\n<p>No law-enforcement agency has publicly attributed the Bitget breach to North Korea as of the latest verified updates.<\/p>\n<h2 class=\"wp-block-heading\"><strong>What happens next for Bitget and the stolen funds?<\/strong><\/h2>\n<p>Bitget continues to trace wallets and is offering a bounty for recoveries. The exchange <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.bitget.com\/support\/articles\/12560603896108\/\" target=\"_blank\">offers<\/a> qualifying participants 5% of funds they directly help freeze and another 5% for funds successfully recovered.<\/p>\n<p>The Bitget recovery bounty was launched while Mandiant, SlowMist, exchanges and blockchain investigators continued tracking attacker addresses.<\/p>\n<p>Bitget has already restored Bitcoin, Ether and USDT withdrawals in phases. Its published schedule places other tokens, fiat withdrawals and P2P services at 08:00 UTC on Oct. 2, although the exchange\u2019s official incident page had not yet posted a separate confirmation of that final reopening when checked.<\/p>\n<p>Bitget says the exploited vulnerability has been fixed and user balances remain unaffected. Its forensic investigation, law-enforcement work, fund tracing and recovery effort remain open, while the exchange says further material findings will be published through its official security updates.<\/p>\n<p>    <!-- .cn-block-related-link --><\/p><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Bitget\u2019s attacker has moved much of the exchange\u2019s $387.5 million theft toward Bitcoin through cross-chain services, while only around $840,000 had been publicly frozen five days after the Sept. 24&hellip;<\/p>\n","protected":false},"author":1,"featured_media":37515,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-37514","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cryptocurrency"],"_links":{"self":[{"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/posts\/37514","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/comments?post=37514"}],"version-history":[{"count":1,"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/posts\/37514\/revisions"}],"predecessor-version":[{"id":37516,"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/posts\/37514\/revisions\/37516"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/media\/37515"}],"wp:attachment":[{"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/media?parent=37514"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/categories?post=37514"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/tags?post=37514"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}