Bitget Hacker Moves Stolen Funds After $350M Breach

Bitget’s hacker begins moving stolen funds, swapping ETH into BTC through THORChain after the exchange’s $350M-plus security breach.
Table of Contents

TL;DR:

  • The Bitget hacker began moving stolen funds for the first time since the September 24 breach, swapping ETH into BTC through THORChain.
  • Bitget later revised the incident’s impact to roughly $387.5 million, while customer balances remain protected by its User Protection Fund.
  • The new cross-chain activity complicates recovery efforts, while attribution remains unconfirmed despite similarities Bitget has noted with tactics associated with North Korean hacking groups during earlier crypto attacks.

A wallet tied to the Bitget exploit has begun moving stolen funds for the first time since the exchange suffered a $350 million-plus breach. In a Lookonchain update, the tracker said the attacker was swapping ETH into BTC through THORChain. The movement marks the first major post-hack transfer from wallets linked to the September 24 breach, renewing attention on how stolen assets may move across chains.

THORChain Becomes a Route for Stolen Bitget Funds

The attacker initially converted much of the stolen value into assets that were harder to freeze, while Bitget later revised the overall impact to roughly $387.5 million after additional transfers surfaced. The latest activity shows the laundering phase shifting from consolidation toward cross-chain conversion. The original Bitget hack affected multiple networks and left investigators tracking attacker-controlled addresses closely.

The Bitget hacker began moving stolen funds

THORChain lets users swap native assets across blockchains without relying on a centralized intermediary. That architecture also complicates recovery when stolen assets enter the protocol. Moving ETH into BTC can reduce reliance on assets whose issuers or custodians may be able to freeze balances. Similar cross-chain laundering routes have appeared in previous exploit investigations involving movement between native assets.

The transfer comes as Bitget continues restoring services after containing the breach and saying customer balances remain protected by its User Protection Fund. The exchange launched recovery efforts with security firms and industry participants to track the assets. Renewed wallet activity raises the urgency because every additional swap can spread funds across more addresses and networks. The revised Bitget loss estimate underscores the scale investigators are attempting to trace.

Attribution remains unsettled. Bitget has pointed to technical and behavioral similarities with activity associated with North Korean hacking groups, but the investigation has not produced a final public attribution. The THORChain movement does not identify the attacker, but it gives investigators another onchain trail to follow. Other Lazarus-linked fund movements illustrate how stolen crypto can pass through several networks and venues before reaching later destinations.

The immediate question is how much of the remaining balance will move. The first major transfer suggests the attacker may be entering a more active laundering phase after several days of limited movement. Continued monitoring of THORChain swaps, destination wallets and subsequent BTC transfers will show whether this was an isolated move or the start of a broader effort to disperse the proceeds.

RELATED POSTS

Ads

Follow us on Social Networks

Crypto Tutorials

Crypto Reviews