Live Prices
Altcoins

Bitget Sees 5,000 BTC Outflow as Hackers Launder $387M Haul Via THORChain

TheCryptoDesk Editorial · 2m read
Bitget Sees 5,000 BTC Outflow as Hackers Launder $387M Haul Via THORChain

Cryptocurrency exchange Bitget has seen its tracked reserves drop by nearly 5,000 BTC (worth approximately $391 million) shortly after resuming Bitcoin withdrawals following a $387.5 million security breach. CEO Gracy Chen confirmed that Bitget processed 9,585 withdrawal orders totaling 4,098.036 BTC as of 17:00 UTC+8 on Sept. 28, shortly after restoring service at 08:00 UTC.

DeFiLlama tracking metrics revealed that Bitget's Bitcoin reserves fell from 35,412 BTC to approximately 30,770 BTC, reflecting a total decline of 4,642 BTC. The exchange froze all withdrawals for four days while remediating the largest exploit in its eight-year history.

Withdrawal Schedule and Security Remediation

Bitget plans a phased restoration of platform services following the containment of the exploit:

  • Bitcoin (BTC) withdrawals reopened at 08:00 UTC on Sept. 28.
  • Ethereum (ETH) withdrawals are scheduled to resume on Sept. 29.
  • USDT withdrawals are set to restart on Sept. 30.
  • Remaining tokens, fiat options, and peer-to-peer (P2P) services will return on Oct. 2.

Chen stated that an internal investigation determined attackers exploited third-party software vulnerabilities to obtain internal credentials, bypassing risk controls to submit fraudulent withdrawal commands. Bitget has since revoked and reissued all internal credentials, isolated affected systems, and disabled the compromised third-party functionality. Security firms Mandiant and SlowMist are aiding ongoing forensic analysis. Bitget reaffirmed that user funds remain intact and promised to replenish its Protection Fund to over $300 million within a week using its own capital.

Attackers Launder Funds Through THORChain and Wasabi

As Bitget restores platform operations, attackers have actively fragmented the stolen assets across cross-chain bridges, privacy tools, and decentralized protocols. On-chain investigator ZachXBT reported that Chinese illicit actors are laundering the haul on behalf of hackers allegedly linked to North Korea. The stolen funds have been chain-hopped into mixing services, including Wasabi, with additional funds moving toward THORChain. ZachXBT noted similarities between these transfers and prior movements linked to the $292 million Kelp DAO exploit and the TraderTraitor campaign, following earlier findings where investigators identified suspects in public chatrooms.

Blockchain security company GoPlus calculated that roughly 101.5 BTC ($8.5 million) has exited through THORChain, while 27.63 million XRP (approximately $43 million) is being converted into Bitcoin. GoPlus criticized THORChain for refusing to intervene, pointing out that its node operators utilize threshold-signature vaults and Mimir governance controls that could halt illicit flows, citing its previous response when Bitget was given a tight window to contain the initial exploit. THORChain maintains that its emergency controls exist solely to protect its protocol architecture rather than censor specific user transactions.

Why It Matters

The rapid reserve drain highlights fragile post-exploit user trust, even when exchanges commit to full coverage of customer losses. Furthermore, the dispute between security firms and decentralized protocols like THORChain underscores an escalating industry crisis over neutrality versus compliance. As sovereign-backed hackers refine cross-chain laundering techniques, decentralized liquidity hubs will face intensifying regulatory and technical scrutiny to prevent automated illicit capital flows.

Terms in this article

Read next