An address linked to the attacker behind Bitget’s $387.5 million September 24 security breach attempted to move stolen funds through cross-chain protocol Chainflip, only for the deposit to be rejected by the broker handling the transaction and returned to the originating address.
The September 29 development was disclosed by blockchain security platform MistTrack, which has been tracking addresses associated with the Bitget theft alongside SlowMist and other investigators.
According to MistTrack’s latest tracing update, the assets were not frozen by Chainflip itself. Instead, the broker used for the attempted transaction refused the deposit, causing the funds to be sent back rather than completing the intended cross-chain route.
The amount involved in the rejected transaction was not specified in MistTrack’s public update. The episode nevertheless provides a fresh look at how the Bitget attacker is trying to move funds across an increasingly complicated network of bridges, brokers, swap protocols and Bitcoin addresses.
The Failed Chainflip Route Comes Five Days After the Bitget Hack
The laundering attempt is a follow-up to the September 24 attack on Bitget rather than a new security incident.
Bitget detected unauthorized transfers from portions of its hot and warm wallet infrastructure at 18:31 UTC that day. The exchange initially estimated that approximately $351.6 million had been affected before revising the figure upward to $387.5 million after accounting for additional Zcash and TRON assets.
Bitget has said private keys and cold wallets were not compromised. Its investigation instead found that the attacker exploited a vulnerability in a third-party security product, obtained high-level internal credentials and inserted fraudulent withdrawal instructions into the exchange’s wallet backend.
That finding expanded on Dave Finances’ earlier reporting that Bitget’s backend wallet system was compromised even though the cryptographic keys controlling the affected wallets remained secure.
The attacker moved assets across Ethereum and other EVM networks, XRP Ledger, Zcash and TRON. Affected assets included XRP, ETH, USDT, USDC, ZEC, BNB, AVAX, TRX and Tether Gold.
Bitget has since published attacker-controlled addresses and launched a recovery bounty program while Mandiant and SlowMist assist with forensic analysis and fund tracing. The exchange has also begun restoring withdrawals in phases, starting with Bitcoin on September 28.
Chainflip Had Already Appeared in Earlier Laundering Routes
The September 29 rejection does not mean the attacker had previously been unable to use Chainflip.
Earlier blockchain tracing had already identified Chainflip among several cross-chain services touched by Bitget-linked funds. TRM Labs reported that stolen assets were being broken into smaller portions and routed through services including THORChain, Chainflip, Across and other bridging or swap infrastructure.
Separate transaction reconstruction found Bitget-linked assets being converted into Bitcoin through Chainflip during the first days after the theft.
That makes the latest failed deposit notable because it shows the same route becoming less reliable as addresses are identified and compliance information spreads across the industry.
The attacker has faced similar problems with stablecoins. Centralized issuers can blacklist specific addresses and prevent balances from being transferred, a mechanism Dave Finances recently examined after a USDC blacklist action highlighted the importance of real-time address screening.
Assets such as ETH and BTC do not have an issuer with an equivalent freeze function. That gives attackers a strong incentive to move stolen stablecoins and other tokens into more censorship-resistant assets before investigators, issuers or exchanges can intervene.
The Broker Rejected the Deposit — Chainflip Did Not Freeze It
The distinction between Chainflip and the broker involved in the transaction is important.
Chainflip provides decentralized cross-chain swapping infrastructure, but users can access it through brokers that request deposit channels on their behalf. A broker can operate the interface or API through which a swap is initiated, while the underlying protocol handles the cross-chain execution and liquidity.
In this case, MistTrack specifically said the broker refused the deposit. It did not report that Chainflip validators froze the assets, changed protocol rules or seized the attacker’s balance.
The funds were instead returned to the source address.
That creates a very different security and compliance model from an issuer freezing USDC or USDT. It also differs from a bridge shutting down entirely following an exploit, as happened when Payy suspended its payment infrastructure after a $1.83 million USDC bridge attack.
The Chainflip episode shows that even when a base protocol remains permissionless, businesses and interfaces around that protocol can still create practical checkpoints.
Attackers Can Simply Move to the Next Bridge
That is also the limitation.
Blocking one route does not stop an attacker who controls hundreds of millions of dollars and can try another route minutes later.
SlowMist founder Yu Xian said the laundering activity illustrates how sophisticated operators increasingly work: split the stolen assets across multiple addresses, test different cross-chain services and keep rotating infrastructure until a route accepts the funds.
The eventual objective is often to reach Bitcoin, where funds can be fragmented further and moved through additional wallets or privacy-enhancing infrastructure without the blacklist functions attached to centralized stablecoins.
That pattern is already visible in the Bitget case. Funds have moved across several networks and swap systems as the attacker searches for paths from stolen tokens into BTC.
This is why cross-chain infrastructure has become such an important part of crypto forensics. A hacker does not need one bridge capable of laundering $100 million in a single transaction. Ten services capable of moving smaller pieces can produce the same result over time.
The security assumptions around these systems are already under pressure for other reasons. Dave Finances recently covered the KelpDAO dispute over a $292 million cross-chain exploit, which highlighted how multiple infrastructure providers can participate in a transaction while responsibility for security remains distributed between them.
The Rejected Deposit Shows Where Decentralization Meets Compliance
On its own, one rejected deposit is tiny compared with a $387.5 million theft.
But the mechanism matters.
The crypto industry often talks about cross-chain protocols as though the choice is binary: either a system is decentralized and cannot interfere with transactions, or it is centralized and can freeze whatever it wants.
Real infrastructure is becoming much messier than that.
A protocol may remain permissionless while the broker opening deposit channels screens addresses. A decentralized exchange may be accessible through a frontend that blocks sanctioned wallets. A bridge may execute automatically while analytics companies flag the destination to exchanges before the funds arrive.
That creates compliance checkpoints without necessarily giving one organization control over the underlying protocol.
For legitimate users, that can be irritating when screening produces false positives or delays. For investigators following hundreds of millions of dollars in stolen cryptocurrency, however, every extra checkpoint increases the chance that one part of the laundering chain breaks.
The Real Contest Is Speed
The Bitget attacker’s problem is getting harder with every transaction.
Immediately after a hack, investigators are still identifying addresses. Hours later, analytics providers begin tagging them. Then exchanges, stablecoin issuers, bridges and brokers start integrating those labels into their own controls.
The attacker therefore has an incentive to move quickly before the compliance perimeter catches up.
Investigators face the opposite challenge: distribute reliable attribution fast enough that infrastructure providers can act before the assets move again.
The rejected Chainflip deposit is a good example of that race working in the defenders’ favor. It did not recover the funds. It did not prevent the attacker from trying somewhere else. And it certainly did not undo the original Bitget breach.
But it closed one door.
For an attacker attempting to turn hundreds of millions of dollars of highly visible stolen assets into harder-to-trace Bitcoin, enough closed doors can make laundering slower, more expensive and more operationally risky.
That may ultimately be where the recovery effort has its best chance. The blockchain makes the money visible. The difficult part is ensuring that enough of the infrastructure surrounding it recognizes the funds before the attacker finds the next route that does not.
Shane Neagle is a financial markets analyst and digital assets journalist specializing in cryptocurrencies, memecoins, prediction markets, and blockchain-based financial systems. His work focuses on market structure, incentive design, liquidity dynamics, and how speculative behavior emerges across decentralized platforms.
He closely covers emerging crypto narratives, including memecoin ecosystems, on-chain activity, and the role of prediction markets in pricing political, economic, and technological outcomes. His analysis examines how capital flows, trader psychology, and platform design interact to create rapid market cycles across Web3 environments.
Alongside digital assets, Shane follows broader fintech and online trading developments, particularly where traditional financial infrastructure intersects with blockchain technology. His research-driven approach emphasizes understanding why markets behave the way they do, rather than short-term price movements, helping readers navigate fast-evolving crypto and speculative markets with clearer context.

