Skip to content
RegionAsia-Pacific

MediumII Cyber Warfare & Critical Infrastructure27 September 2026, Sunday

Bitget attacker moves first slice of stolen funds into Wasabi mixer

AMLBot said on 27 September that about 4 BTC had entered a Wasabi CoinJoin round and was linked to a TRON wallet belonging to the Bitget attacker. Of the 387.5 million dollars lost on 24 September, about 343 million dollars was still sitting idle in 13 wallets as of 25 September.

Location: PYONGYANG

Cryptonomist and crypto.news reported on 27 September that the funds were first converted from TRX to USDT, bridged to Ethereum via USDT0 and swapped into about 145 ETH. That ETH was converted into about 4.59 BTC through THORChain, a cross-chain swap protocol, then split into small amounts and fed into CoinJoin. CoinJoin is a mixing method that blurs the trail by combining transactions from multiple users. The attack was detected at 18:31 UTC on 24 September, and the loss was revised from 351.6 million dollars to 387.5 million dollars.

According to crypto.news, the idle assets comprise 68,300 ETH in 8 Ethereum wallets, 83 million XRP across 4 addresses and 18,900 ZEC in 1 wallet. The exchange has announced a phased timetable for reopening withdrawals: Bitcoin on 28 September, ETH on 29 September, USDT on 30 September and other assets on 2 October. Bitget says the loss will be covered by its user protection fund of more than 464 million dollars. Elliptic had earlier attributed the attack to North Korea with high probability; an official government attribution could not be verified.

Talay assessment

Bottom line

The amount sent into the mixer is a small fraction of the 387.5 million dollar loss. But the route through TRON, Ethereum, THORChain and the Bitcoin chain shows that staged laundering has begun. With about 343 million dollars of the assets still idle, the real chance to freeze funds will come in the first days after these wallets start moving.

Likely effects

  • Crypto exchange trustUncertainWeeks

    The phased reopening of withdrawals between 28 September and 2 October, backed by a protection fund of more than 464 million dollars, may limit customer attrition; any slippage in the timetable would damage trust again.

  • North Korean financingNegative1–6 months

    A first tranche of 4.59 BTC from funds Elliptic linked to North Korea has entered a mixer; if the remaining ETH, XRP and ZEC are laundered, the sanctioned regime will have secured a flow of hard currency.

  • Cross-chain bridgesNegative1–6 months

    The USDT0 bridge and the THORChain route may draw renewed regulatory attention to the role of decentralised swap tools in laundering chains.

Possibilities, ranked

  1. 1
    Gradual, staged laundering60%

    Assets in the 13 idle wallets are moved to bridges and mixers in small batches over several weeks, and the amount frozen stays limited.

    Watch: First major outflow from the wallets holding 68,300 ETH and 83 million XRP

  2. 2
    Partial freezing success30%

    Exchanges and issuers catch larger amounts at bridge points, and the recovery rate rises markedly.

    Watch: Bitget updates on amounts frozen or recovered

  3. 3
    Withdrawal timetable slips10%

    A new finding about the security breach pushes the reopening of withdrawals beyond 2 October.

    Watch: Bitget announcements on reopening withdrawals between 28 September and 2 October

Probabilities are calibrated judgement based on the sources, not measurement, and are revised as new information arrives. Not investment advice.

Market reaction

Indicators affected

  • BTC sent into mixer▼ ≈4 BTC
  • Idle stolen assets▼ ≈$343 million
  • User protection fund▲ $464 million+

Sources

  1. Cryptonomist — Bitget hack tracing reveals crypto laundering techniques
  2. crypto.news — Bitget hacker routes 4 BTC through Wasabi CoinJoin