The hackers moving funds stolen from Bitget generated more than $761,000 in identifiable fees for crypto protocols and services, while a separate analysis of THORChain affiliate payments found approximately $259,700 went to seven recipients with additional financial links to wallets involved in the laundering routes.
The findings come from independent on-chain research by Andrey Sergeenkov, who analyzed swaps involving assets traced from Bitget’s September 24 security breach.
The research does not establish that the affiliate recipients controlled the hacker wallets or knowingly assisted the laundering. Some of the links involve shared Bitcoin destinations, transfers between fee recipients and wallets submitting the swaps, or later movements connecting those wallets to Bitget’s compromised-address cluster.
But the data exposes an underexamined side of large crypto hacks: moving hundreds of millions of dollars across chains does not happen for free. Liquidity providers, interfaces, routers and brokers can collect substantial fees while stolen funds pass through their infrastructure.
THORChain Liquidity Generated More Than $573,000 in Fees
Sergeenkov calculated $761,725.47 in protocol and service fees across the tracked sample using historical USD prices.
THORChain liquidity accounted for by far the largest portion, at approximately $573,226, or 75.3% of the measured total.
MetaMask-related fee transfers accounted for another $149,417, while Chainflip broker fees totaled approximately $26,751. Executed protocol and partner fees associated with CoW EthFlow added roughly $12,332.
Those numbers should not be interpreted as net profit. They represent recorded fees associated with the observed laundering transactions, and the dataset does not claim to capture every route used by the attackers.
The figures also exclude separate BNB Smart Chain fees, while individual recipients of THORChain liquidity fees and CoW fees were not allocated.
The scale nevertheless adds another dimension to the role cross-chain protocols played after the Bitget breach. Previous attention focused largely on whether protocols should block suspected hacker transactions. The new research asks a different question: who financially benefited while those transactions were being processed?
THORChain’s Affiliate System Created a Second Layer of Fees
THORChain allows swaps to specify an affiliate address or registered THORName and a fee expressed in basis points. The protocol deducts that affiliate fee from the swap and credits it to the designated recipient.
An interface can insert an affiliate into a transaction before the user signs it. That means the presence of an affiliate address in a hacker’s signed swap does not prove the attacker personally owns that address.
Sergeenkov therefore separates affiliate recipients into two categories.
Seven addresses received approximately $259,718 in affiliate fees and also had additional financial links to wallets connected with the laundering activity. Another group received approximately $206,196 in fees or credits but had no such additional links established in the transaction history reviewed through October 2.
The largest linked recipient alone collected approximately $177,499.
Swaps paying that address were submitted by XRP wallets connected through transfers to Bitget’s compromised XRP address. Some of those transactions also sent their principal Bitcoin proceeds to the same destination wallets seen in another affiliate route.
A second recipient received about $56,514. One of the relevant swap senders was connected to Bitget’s compromised EVM address, while all four principal BTC recipients matched destinations used by another reviewed affiliate route.
Two Fee Routes Show Money Flowing Back Toward Swap Senders
Some of the evidence goes beyond shared destinations.
One affiliate address that earned approximately $18,080 later exchanged part of its RUNE fee proceeds. Those proceeds were directed toward a wallet that had itself submitted transactions using that affiliate. The same wallet later received ETH from Bitget’s compromised EVM cluster.
Another affiliate, which received a much smaller amount of roughly $196, signed a swap of its accumulated RUNE and directed the resulting ETH back to the address that had submitted the transactions generating the affiliate fees. An Ethereum internal transfer confirmed the payment.
That sender was also connected through consecutive transfers to the original stolen-ETH address.
These transaction paths create stronger financial links than simply appearing as an affiliate in a swap memo. They still do not prove that the hacker and affiliate address share an owner. An operator, interface or service could legitimately receive fees and later transact with a customer for unrelated reasons.
But the return flow gives investigators a clearer trail to examine.
One $177,000 Affiliate Route Eventually Reached an OKX-Labeled Wallet
The largest linked affiliate address presents another potentially useful investigative path.
According to the research, the address converted some of the RUNE it received as fees into USDT. Those funds then moved through two Ethereum wallets before reaching an address labeled by Etherscan as OKX Hot Wallet 5.
That does not establish that OKX received stolen funds directly or that the owner of the affiliate address has an account at the exchange.
It does potentially create an off-chain attribution point.
If the transfers correspond to an identifiable customer deposit, OKX could have information that cannot be recovered purely from public blockchain data, such as account records, login information or other compliance data.
Centralized exchanges have repeatedly emerged as possible choke points in the wider laundering effort. Dave Finances previously reported how a Bitget-linked transaction encountered a Chainflip broker that rejected the deposit, demonstrating that infrastructure providers can sometimes interrupt routes even when the underlying protocol remains permissionless.
More Than $206,000 Went to Affiliate Recipients Without Additional Links
The research also provides a useful control group.
Another $206,196 in THORChain affiliate fees and credits went to recipients for which Sergeenkov had not identified further financial connections to hacker-linked wallets as of the data cutoff.
The largest was an address associated with the THORName “naswap,” which received approximately $102,344.
A THORChain holding account credited with fees associated with several names, including “symbiosis,” accounted for another $92,438. Smaller recipients accounted for the remainder.
The research does not allege wrongdoing by those recipients. In fact, separating them from addresses with additional transaction links illustrates why the affiliate field alone is weak attribution evidence.
Someone laundering funds can use an ordinary swap interface that automatically inserts its own referral address. The service can earn money from the transaction without knowing the customer is moving stolen assets.
The Hack Created an Economy Around Moving the Money
Bitget ultimately put the September 24 breach at approximately $387.5 million after expanding its accounting across Ethereum, XRP, Zcash, TRON and other networks. The attackers then began converting, bridging and dispersing those assets across crypto infrastructure.
Dave Finances has tracked how more than $83 million in stolen XRP was moved during the laundering process, while other funds crossed decentralized exchange and bridge infrastructure.
Each route can generate revenue for somebody.
That creates a difficult incentive question for permissionless protocols. Liquidity providers earn normal market fees regardless of whether the counterparty is a legitimate trader or an attacker. Affiliate systems can separately reward interfaces and routing services whose identifiers are embedded in those swaps.
This does not make fee recipients accomplices. Automated protocols routinely process transactions without knowing the identity or intent of the sender.
But once stolen funds are publicly identified, the economic trail becomes useful in its own right.
Affiliate Fees May Provide Investigators With New Attribution Leads
The most important part of the research may therefore be the addresses rather than the aggregate fee total.
The original Bitget compromise reportedly bypassed withdrawal controls without exposing the exchange’s private keys, highlighting how the attack targeted infrastructure surrounding the wallets rather than blockchain cryptography itself.
The laundering investigation now creates a similarly layered problem.
The hacker wallets are visible. The protocols they use are visible. The affiliate identifiers embedded inside transactions are visible. And in some cases, fee proceeds can be followed back toward swap senders, across linked recipient networks or eventually into a centralized exchange.
None of those links should be treated as proof of common ownership without additional evidence.
But they create new places to investigate.
For the Bitget attackers, moving stolen assets has already generated at least hundreds of thousands of dollars in measurable fees. For investigators, those same payments may have created additional transaction trails that the attackers did not need to leave behind.
That may ultimately make the fee layer more valuable as an attribution tool than the dollar amount earned from it.
Johan Shamshad is a financial markets writer at Dave Finances covering cryptocurrencies, trading platforms, brokers, fintech, financial regulation, and developments across global markets. He previously worked at Gulf News, adding newsroom experience to his coverage of fast-moving financial and digital-asset markets.
His work focuses on identifying market-moving events, company developments, regulatory changes, product launches, and shifts in trading and financial infrastructure.
Johan contributes news and analysis designed to help readers understand not only what happened, but why a development matters and how it may affect the wider financial landscape.

