In section Cryptocurrency

Bitget Hackers Use Wasabi CoinJoin to Obfuscate Stolen Funds

Blockchain compliance firm AMLBot has tracked roughly 4 BTC linked to the Bitget security breach into a Wasabi CoinJoin transaction. This movement represents an attempt to obscure the trail of stolen assets, which the exchange now estimates at approximately $387.5 million following the September incident.

Bitget Hackers Use Wasabi CoinJoin to Obfuscate Stolen Funds

The funds originated from a Bitget-linked TRON wallet before undergoing a complex multi-chain conversion. According to AMLBot, the assets were swapped from TRX to USDT, bridged to Ethereum via USDT0, and then converted into approximately 145 ETH. These assets subsequently moved through THORChain and were swapped into Bitcoin. By the time the funds reached the Wasabi CoinJoin mixing service, they had been divided into smaller amounts to evade standard transaction mapping.

While the CoinJoin activity marks a shift in the attacker's tactics, the bulk of the stolen capital remains stationary. As of September 25, AMLBot estimated that approximately $343 million—roughly 88% of the tracked total—remained dormant across 13 attacker-controlled wallets. These addresses contain large holdings of ETH, XRP, and ZEC that have seen no outbound transactions since the initial breach.

Bitget, which recently raised its loss estimate after identifying additional missing Zcash and TRON assets, claims the underlying vulnerability has been remediated. The exchange plans to restore withdrawal services in phases beginning September 28. CEO Gracy Chen stated that private keys were not compromised during the attack, and the company intends to cover all losses using its $464 million Protection Fund.

Share:on TelegramXFacebook

Subscribe to our newsletter

Once a week — the best stories from our editors, no ads or push notifications. Delivered Sunday morning.

Comments (0)

Leave a comment

No comments yet. Be the first!