Sun. Sep 27th, 2026

Bitget Attacker Routes Traced Funds Through Four Networks Into Wasabi CoinJoin

ByJohan Shamshad

September 27, 2026 #Bitget
BitgetBitget

Funds linked to the $387.5 million Bitget breach have moved through a multi-chain conversion route ending in a Wasabi CoinJoin transaction, giving investigators their clearest look yet at how part of the stolen portfolio is being prepared for harder-to-trace movement.

Blockchain compliance firm AMLBot said it connected roughly 4 BTC participating in a Wasabi CoinJoin round to funds originating from a Bitget-linked TRON wallet. According to the firm’s tracing, the route began with stolen TRX, which was converted into USDT on Tron before moving through USDT0 to Ethereum.

The funds were then converted into roughly 145 ETH, routed through THORChain and exchanged into approximately 4.59 BTC. The Bitcoin was subsequently divided into smaller amounts before around 4 BTC entered the CoinJoin transaction.

The activity represents only a small portion of the assets taken in the September 24 attack, which Bitget now estimates at approximately $387.5 million after additional Zcash and TRON transactions expanded the original loss estimate of $351.6 million.

AMLBot said it has blacklisted addresses associated with the route and is monitoring for additional CoinJoin activity. That does not mean the underlying BTC has been frozen. In this context, a compliance blacklist is primarily a risk label that can be consumed by exchanges, wallet providers and other screening systems. Bitcoin itself has no issuer capable of disabling an address.

The attribution also remains an analytical conclusion rather than something encoded directly into the blockchains. Public records establish the transfers, conversions and cross-chain movements. Connecting those transactions back to the Bitget theft depends on address attribution and transaction-flow analysis performed by AMLBot.

The Route Moved Through Several Very Different Control Points

The sequence is significant because each stage offered investigators a different level of potential intervention.

The first important chokepoint was USDT on Tron. Unlike native assets such as BTC, ETH or XRP, USDT contains issuer-controlled mechanisms that allow Tether to blacklist specified addresses. Tether has repeatedly exercised that capability, including a recent case in which it froze $3.75 million across 18 USDT addresses.

Bitget-related wallets have already demonstrated the value and limits of that mechanism. Circle and Tether reportedly froze roughly $320,000 in USDC and USDT connected to the breach, but those balances represented only a tiny portion of the stolen portfolio. Similar controls allow USDC addresses to be blacklisted when Circle takes action.

USDT0 introduced another potential compliance layer. The omnichain system uses a lock-and-mint architecture to move Tether-backed value across networks, and its current EVM token implementation includes an on-chain compliance blocklist. A blocked address cannot send the affected tokens. That means stablecoin legs can offer an intervention point, but only while the attacker still holds an asset subject to those controls.

Once the route reached native ETH, that issuer-level option disappeared. Ethereum has no company capable of freezing ether held in a self-custodied wallet. Authorities or investigators instead have to wait for funds to reach a cooperative centralized exchange, custodian or another identifiable service.

THORChain Removed the Need for a Centralized Exchange

The next step helps explain why cross-chain protocols have become so important in post-hack tracing.

THORChain allows native assets on different blockchains to be swapped without an account, registration or centralized exchange. Its documentation describes swaps as permissionless and processed automatically by the network’s state machine.

In this case, AMLBot says roughly 145 ETH was converted through THORChain into around 4.59 BTC. That allowed the flow to move from Ethereum into native Bitcoin without first depositing the ETH at a conventional exchange where an account could potentially be frozen or tied to customer identification.

That does not make the movement invisible. THORChain swaps leave on-chain records and analytics companies can attempt to connect incoming and outgoing transactions. But the route reduces the number of centralized intermediaries capable of stopping funds in real time.

The same problem is visible elsewhere in the Bitget breach. About $83 million in stolen XRP had moved from three original holding wallets by September 26. Native XRP, like BTC and ETH, cannot be frozen by its network operator. The distinction between issuer-controlled assets and native cryptocurrencies has also become important in other theft investigations, including the D’CENT XRP drain.

CoinJoin Makes Attribution Harder Without Making Bitcoin Disappear

The final stage of the tracked route moved the Bitcoin into Wasabi CoinJoin.

CoinJoin works by combining Bitcoin inputs belonging to multiple participants into one collaborative transaction with multiple outputs. Rather than leaving a simple one-input-to-one-output trail, it breaks the straightforward relationship between the coins entering the transaction and the addresses receiving the outputs.

That does not erase the blockchain history. Investigators can still see which UTXOs entered the CoinJoin transaction and which outputs emerged. What becomes more difficult is proving which output belongs to the holder of a specific input.

Wasabi’s documentation describes its implementation as centrally coordinated but non-custodial. Coordinators can also reject or ban inputs from participation, meaning identified stolen UTXOs could potentially be refused by a particular coordinator. That is different from freezing Bitcoin itself: a holder can still move BTC elsewhere or attempt to access another service.

The distinction becomes crucial once mixed outputs later reach a regulated exchange. A centralized platform can restrict an account or hold funds if its compliance systems identify sufficient links to stolen assets. But the more hops, swaps and CoinJoin rounds that occur first, the more difficult attribution can become.

The 4 BTC May Matter More as a Test Case Than as a Recovery Amount

Four Bitcoin is small relative to a breach approaching $400 million. That is exactly why the movement deserves attention.

The route looks less important as a recovery event than as a demonstration of what could happen if larger attacker-controlled balances begin moving through the same sequence.

AMLBot estimated on September 25 that approximately $343 million, or about 88% of the funds it was then tracking, remained dormant across 13 wallets. That figure was a point-in-time snapshot and should not be treated as the current dormant total, particularly because substantial XRP movements were subsequently recorded.

The question now is whether this TRON-to-Bitcoin route was a relatively isolated conversion or an early attempt to establish a repeatable path for larger balances.

From the attacker’s perspective, the sequence has an obvious logic. Stablecoins provide deep liquidity and inexpensive movement, USDT0 moves value across chains, Ethereum provides access to broad decentralized liquidity, THORChain removes the need for a centralized exchange during the ETH-to-BTC conversion, and CoinJoin weakens the final transaction graph.

For investigators, the logic runs in reverse. The best opportunities to intervene are generally earlier in the chain, while value remains in freezeable stablecoins or reaches identifiable custodial infrastructure. Once funds become native ETH or BTC and stay entirely inside permissionless systems, recovery becomes far more dependent on tracing where they eventually surface.

That makes speed increasingly important. AMLBot placing an address on a blacklist can help exchanges and compliance providers recognize the risk, but it cannot immobilize native cryptocurrency. Stablecoin issuers can freeze certain tokens. Centralized exchanges can block deposits or accounts. Decentralized protocols and base-layer assets often provide no equivalent intervention mechanism.

Bitget has meanwhile moved into the operational recovery phase and plans to restore withdrawals in stages beginning September 28. The exchange has also offered a 5% bounty on qualifying funds successfully frozen or recovered.

For Bitget, the danger is therefore no longer limited to the original compromise. It is also a race against the stolen portfolio becoming progressively harder to recover. A few BTC moving through CoinJoin barely changes the financial impact of a $387.5 million breach. But if the same route proves workable at larger scale, the recovery window for the remaining holdings could narrow quickly.

Financial Markets Analyst and Journalist at  |  More Posts

Johan Shamshad is a financial markets writer at Dave Finances covering cryptocurrencies, trading platforms, brokers, fintech, financial regulation, and developments across global markets. He previously worked at Gulf News, adding newsroom experience to his coverage of fast-moving financial and digital-asset markets.

His work focuses on identifying market-moving events, company developments, regulatory changes, product launches, and shifts in trading and financial infrastructure.

Johan contributes news and analysis designed to help readers understand not only what happened, but why a development matters and how it may affect the wider financial landscape.

Leave a Reply

Your email address will not be published. Required fields are marked *