📈 Get daily crypto insights that make you smarter about your money

The Bitget Hacker’s 2,000-Mile Laundering Route: From TRON to THORChain to a Wasabi CoinJoin

Stolen funds from the Bitget security breach have begun moving through Wasabi’s CoinJoin mixer after a multi-stage journey across four blockchains, according to blockchain compliance firm AMLBot — the first confirmed on-chain laundering activity since the exchange confirmed roughly 387.5 million USD was transferred to attacker-controlled addresses in the September breach.

AMLBot said on September 27 that its tracing connected roughly 4 BTC in one CoinJoin round back to funds originating from a Bitget-linked TRON wallet. The firm described the activity as an apparent attempt to obscure the movement of stolen assets, and said it had blacklisted the linked addresses.

## Following the money across four chains

The route AMLBot reconstructed reads like a checklist of cross-chain DeFi plumbing. According to the firm, the attacker first converted TRX into USDT on TRON. The funds were then bridged to Ethereum through USDT0, the omnichain version of Tether designed for transfers between supported networks.

Once on Ethereum, the assets were swapped into approximately 145 ETH. That ETH then moved through THORChain, the decentralized exchange protocol, where it was converted into roughly 4.59 BTC. The Bitcoin was divided into smaller amounts before reaching a Wasabi CoinJoin round, where AMLBot’s analysis connected about 4 BTC back to the original Bitget TRON wallet.

The choice of infrastructure is telling. Every leg of the journey — a stablecoin bridge, a decentralized swap protocol, and a Bitcoin mixer — represents a category of DeFi tooling that operates without a central operator capable of unilaterally freezing funds. It is the same property that has drawn renewed scrutiny to THORChain’s decentralization model in recent days, after separate analysis highlighted how a small number of node operators can effectively pause the network while attacker funds transit it.

CoinJoin works by combining Bitcoin inputs and outputs from multiple participants in a single transaction, making it harder for blockchain observers to map one input to a specific output. Mixers weaken that protection only partially — AMLBot was still able to connect the funds through its clustering analysis, which is precisely why the firm could publish the tracing at all.

## A revised loss figure and a dormant fortune

The laundering activity comes as Bitget continues to revise its accounting of the breach. The exchange’s official investigation update raised the total value of assets transferred to attacker-controlled addresses to approximately 387.5 million USD, a figure that includes Zcash and TRON assets missing from the initial 351.6 million USD estimate.

AMLBot estimated that about 343 million USD remained dormant across thirteen attacker wallets as of September 25 — meaning the overwhelming majority of the stolen funds have not yet moved, and the 4 BTC entering a CoinJoin round represents only the first trickle of what could become a much larger laundering campaign.

Bitget has said it identified and fixed the underlying security vulnerability and plans phased withdrawals starting September 28. The exchange has also offered a 5 percent bounty for help freezing stolen funds, and its chief executive has said IP address evidence points preliminarily toward North Korean involvement, echoing the pattern of the Bybit breach — the largest crypto theft on record.

## The attribution caveat

It is worth being precise about what is known. AMLBot’s reconstruction is blockchain analysis: public records show transfers between addresses, swaps and cross-chain activity, but the purpose of each transaction is inferred from the observed flow and address attribution. The firm itself framed its finding as an apparent attempt to launder funds, not a judicial conclusion.

What the tracing does establish is capability. The compliance industry can now follow stolen assets across a stablecoin bridge, a DEX swap and into a mixer round in near real time — a fact attackers increasingly have to design around, and one that argues for patience in recovery efforts. Dormant funds are frozen funds in practice, since any significant movement generates fresh clustering data for investigators.

## Why this matters for DeFi

The Bitget laundering route lands at an awkward moment for decentralized infrastructure. The same week, analysis of THORChain’s governance model questioned how decentralized the protocol really is when node operators can coordinate pauses, and the protocol’s role in moving attacker funds — again — will intensify that debate. The European Banking Authority is simultaneously pushing new MiCA rules that could tighten access to DeFi lending in the EU.

For users, the practical lessons are limited but real. Cross-chain bridges and mixers remain the path of least resistance for laundering stolen crypto, and every major incident strengthens the case — in Brussels and Washington alike — for guardrails on exactly these tools. The irony is that the transparency that makes the tracing possible is also what regulators cite when arguing the entire stack needs oversight.

For Bitget customers, the September 28 phased withdrawal restart is the more immediate concern. For the industry, the 343 million USD still sitting in thirteen wallets is a countdown: whoever controls those keys must eventually move the funds, and when they do, analysts will be watching every hop.

*Market snapshot (Sept. 27, 12:55 UTC): BTC 84,937 USD, ETH 2,712.74 USD, SOL 123.90 USD.*

11 thoughts on “The Bitget Hacker’s 2,000-Mile Laundering Route: From TRON to THORChain to a Wasabi CoinJoin”

  1. TRON to USDT0 to ETH to THORChain to a Wasabi CoinJoin. 387.5 million and they trace 4 BTC into one mixer round, the futility is the story

    1. @chainofsobs honestly the brazen part is using USDT0, an omnichain bridge literally built for auditability. picks the most traceable rail then tries to mix

      1. w take. USDT0 was literally built for auditability and THORChain has its own drama about halts. picking this route anyway tells you opsec was an afterthought

  2. AMLBot blacklisting the linked addresses does nothing to the laundered portion already through THORChain. good forensics, limited teeth

  3. TRX to USDT to USDT0 to ETH to THORChain to BTC then Wasabi. honestly impressive plumbing, every hop was permissionless so no freeze button anywhere

  4. every hop picked for having no freeze button and then the final step is wasabi, the one mixer every analytics firm fingerprints daily. bold strategy

  5. 4 BTC against 387.5 million USD total is a rounding error of a test batch. expect much bigger CoinJoin volume once they spin up real laundering

  6. AMLBot traced it in what, two days? blacklisting the linked addresses does nothing to stop the next route but at least the trail is public now

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$84,984.00+1.3%ETH$2,708.44+0.8%SOL$123.03+1.9%BNB$780.39+1.1%XRP$1.53-0.6%ADA$0.2563+0.3%DOGE$0.0978+0.7%DOT$1.24+0.6%AVAX$11.00+1.5%LINK$14.19-0.7%UNI$9.84+2.1%ATOM$1.86+1.1%LTC$71.07-1.4%ARB$0.2233+0.1%NEAR$5.23+8.6%FIL$1.13+2.8%SUI$1.25+6.7%BTC$84,984.00+1.3%ETH$2,708.44+0.8%SOL$123.03+1.9%BNB$780.39+1.1%XRP$1.53-0.6%ADA$0.2563+0.3%DOGE$0.0978+0.7%DOT$1.24+0.6%AVAX$11.00+1.5%LINK$14.19-0.7%UNI$9.84+2.1%ATOM$1.86+1.1%LTC$71.07-1.4%ARB$0.2233+0.1%NEAR$5.23+8.6%FIL$1.13+2.8%SUI$1.25+6.7%
Scroll to Top