Attackers who stole $387.5 million from Bitget on Sept. 24 have pushed most of the funds toward Bitcoin through cross-chain services, while only about $840,000 — 0.2% of the haul — had been publicly frozen five days later. North Korean involvement remains an assessment, not a confirmed attribution.
Attackers who stole $387.5 million from Bitget on Sept. 24 have pushed most of the funds toward Bitcoin through a web of cross-chain services, according to blockchain security firm BlockSec. Five days into the laundering operation, exchanges and issuers had frozen just $840,000 of the haul — 0.2% of the amount stolen.
BlockSec's tracking, based on a Sept. 29 snapshot, found the attacker still controlled roughly $342 million, equal to 88.3% of the original theft. Bitcoin made up 83.7% of that balance, or about 3,386 BTC.
How the hacker moved the money
The breach began at 18:31 UTC on Sept. 24, when attackers used forged withdrawal commands to drain portions of Bitget's hot and warm wallets, the exchange said. A vulnerability in a third-party security product had handed the attackers high-level internal credentials, while Bitget said its private keys and cold wallets remained untouched.
BlockSec found that roughly $75.48 million in USDT, USDC, USDT0 and 3,000 XAUt tokens were swapped into ETH or AVAX within 41 minutes of the theft, routed through Uniswap, UniswapX, 1inch and MetaMask's built-in swap service — all before Bitget publicly disclosed the breach.
THORChain becomes the main route
THORChain emerged as the largest cross-chain route, handling about $269 million in pass-through value across 7,804 transactions by BlockSec's count. Chainflip processed roughly $37.27 million, while USDT0/LayerZero, Circle's CCTP, Across and Stargate carried smaller volumes.
Bitget CEO Gracy Chen publicly asked THORChain to reject known attacker addresses, arguing that, according to Chen: "decentralization is a design principle, not a shield." THORChain rejected the request, saying its emergency halt function is not a selective freeze of a specific transaction or user.
Other stolen funds reached Bitcoin mixers, with about $3.94 million entering CoinJoin transactions by Sept. 29.
North Korea suspected, not confirmed
North Korean involvement remains an assessment rather than a confirmed attribution. Bitget said some IP addresses matched VPN infrastructure previously tied to a North Korean group, though the underlying technical evidence has not been made public.
BlockSec cautioned that overlapping laundering methods and shared use of THORChain and CoinJoin do not establish the attacker's identity, since those tools serve many unrelated users. The firm said the evidence points more toward possible reuse of laundering groups than proof of who carried out the breach.
What comes next
Bitget is offering a bounty of 5% of funds frozen and another 5% of funds recovered as forensic investigators continue tracing wallets. The exchange has restored Bitcoin, Ether and USDT withdrawals in phases, with other tokens, fiat withdrawals and P2P services scheduled to resume at 08:00 UTC on Oct. 2.
Bitget says the exploited vulnerability has been fixed. Its forensic investigation and fund tracing remain open.
Source: crypto.news
Trading involves risk.