The funds originated from a Bitget-linked TRON wallet before undergoing a complex multi-chain conversion. According to AMLBot, the assets were swapped from TRX to USDT, bridged to Ethereum via USDT0, and then converted into approximately 145 ETH. These assets subsequently moved through THORChain and were swapped into Bitcoin. By the time the funds reached the Wasabi CoinJoin mixing service, they had been divided into smaller amounts to evade standard transaction mapping.
While the CoinJoin activity marks a shift in the attacker's tactics, the bulk of the stolen capital remains stationary. As of September 25, AMLBot estimated that approximately $343 million—roughly 88% of the tracked total—remained dormant across 13 attacker-controlled wallets. These addresses contain large holdings of ETH, XRP, and ZEC that have seen no outbound transactions since the initial breach.
Bitget, which recently raised its loss estimate after identifying additional missing Zcash and TRON assets, claims the underlying vulnerability has been remediated. The exchange plans to restore withdrawal services in phases beginning September 28. CEO Gracy Chen stated that private keys were not compromised during the attack, and the company intends to cover all losses using its $464 million Protection Fund.

Comments (0)
No comments yet. Be the first!