Some assets linked to the Bitget security breach have entered Wasabi CoinJoin after moving through several blockchains and swap routes, according to blockchain compliance firm AMLBot.
Summary
- AMLBot traced roughly four BTC linked to Bitget theft into a Wasabi CoinJoin transaction round.
- Funds moved from TRON through USDT0, Ethereum and THORChain before reaching Bitcoin addresses for mixing.
- Bitget now confirms approximately $387.5 million was transferred to attacker-controlled addresses during the September breach.
- About $343 million remained dormant across thirteen attacker wallets as of September 25, AMLBot estimated.
- Bitget plans phased withdrawals from September 28 after identifying and fixing the underlying security vulnerability.
AMLBot said on Sept. 27 that its tracing connected roughly 4 BTC in one CoinJoin round to funds originating from a Bitget-linked TRON wallet. The firm described the activity as an apparent attempt to obscure the movement of stolen assets.
The finding comes after Bitget revised the value of assets transferred to attacker-controlled addresses to approximately $387.5 million. The exchange’s official investigation update said the new total includes Zcash and TRON assets that were missing from its initial $351.6 million estimate.
Bitget funds moved through four networks before CoinJoin
AMLBot traced a multi-stage route beginning on TRON. According to the firm’s account, the attacker first converted TRX into USDT. The funds were then moved to Ethereum through USDT0, an omnichain version of Tether designed for transfers between supported networks.
Once on Ethereum, the assets were swapped into approximately 145 ETH. AMLBot said the ETH subsequently moved through THORChain and was converted into around 4.59 BTC.
The Bitcoin was then divided into smaller amounts before reaching a Wasabi CoinJoin round. AMLBot said its analysis could connect roughly 4 BTC in that transaction back to the Bitget TRON wallet.
CoinJoin combines Bitcoin inputs and outputs from multiple participants in a single transaction. The technique can make transaction tracing more difficult because blockchain observers cannot simply map one input to one corresponding output.
AMLBot characterized the activity as laundering through Wasabi CoinJoin and said it had blacklisted the linked addresses. The company is continuing to monitor the Bitcoin for further CoinJoin activity.
The attribution remains AMLBot’s blockchain analysis. Public blockchain records show transfers between addresses, swaps and cross-chain activity, but the purpose of each transaction is inferred from the observed flow and address attribution.
A Binance News summary published Sept. 27 repeated the same sequence, citing reports based on AMLBot’s tracing.
Bitget raises confirmed loss to $387.5 million
Bitget initially said the Sept. 24 incident affected approximately $351.6 million in assets after unauthorized transfers from portions of its hot and warm wallet infrastructure.
The exchange detected the activity at 18:31 UTC and suspended withdrawals while leaving deposits and trading operational. Cold wallets remained secure, according to Bitget’s initial security notice.
By Sept. 25, Bitget’s transaction classification had raised the confirmed amount to approximately $387.5 million. The exchange said the increase did not result from new thefts after the breach. Investigators had instead identified additional Zcash and TRON assets involved in the original incident.
Affected assets included ETH, XRP, USDT, USDC, USDT0, ZEC, XAUt, BNB, AVAX and TRX. Bitget published primary attacker-controlled addresses on Ethereum-compatible networks, XRP Ledger, Zcash and TRON as part of its recovery work.
Bitget’s preliminary findings pointed toward a compromise involving backend wallet infrastructure rather than a leak of private keys. CEO Gracy Chen said private keys remained secure while investigators worked to identify the exact intrusion path.
Bitget later said its security team had identified the attack path and the method used to bypass existing controls. The company said the underlying vulnerability had been fixed, though it has not publicly released a complete technical root-cause report detailing the exploit.
AMLBot says most stolen assets remain dormant
The CoinJoin activity represents only a small part of the funds linked to the breach.
In a Sept. 25 update, AMLBot said approximately $343 million, representing around 88% of the roughly $389 million it was tracking, had not moved. The firm’s figure was based on addresses it had attributed to the attacker.
AMLBot identified 13 dormant wallets holding several asset types. Eight Ethereum wallets contained approximately 68,300 ETH, while four XRP addresses held around 83 million XRP. Another wallet contained close to 18,900 ZEC.
The firm said none of those 13 addresses had sent a transaction since receiving the funds. Its subsequent Wasabi update concerns a different portion of the stolen assets that had already begun moving between chains and assets.
Other researchers have traced separate conversion activity. Crypto.news reported on Sept. 25 that security researcher Taylor Monahan identified stolen USDC being moved and converted into ETH after the attack.
Her findings showed attacker-controlled assets being bridged and swapped after leaving Bitget. The report noted that Circle can freeze USDC at specified addresses when legal requirements are met, though the public transaction trail did not establish whether a qualifying legal order had reached Circle at the time.
The subsequent AMLBot tracing shows another part of the flow crossing from TRON to Ethereum and then into Bitcoin through THORChain before entering CoinJoin.
Bitget prepares phased withdrawal reopening
Bitget is preparing to restore withdrawal services after saying the vulnerability responsible for the incident has been remediated.
The exchange’s withdrawal schedule starts with Bitcoin at 08:00 UTC on Sept. 28. ETH withdrawals on Ethereum, BSC, Arbitrum, Base and Optimism are scheduled for Sept. 29.
USDT withdrawals on Ethereum, BSC, Solana and TRON are scheduled to resume on Sept. 30. Other token withdrawals, fiat services and peer-to-peer withdrawals are expected to return on Oct. 2.
Bitget said Mandiant and SlowMist continue to assist with the security investigation while its technical teams perform validation work on the withdrawal infrastructure.
As crypto.news reported on the reopening plan, Bitget says its Protection Fund will cover the financial loss from the incident and customer account balances remain unchanged. The exchange reported that the fund held more than $464 million during the withdrawal pause.
Bitget’s September proof-of-reserves update, published before the breach, showed a total reserve ratio of 135% across 19 covered assets. The exchange states that it maintains at least a 1:1 reserve ratio for user assets covered by the program. CEO Gracy Chen is scheduled to host a live AMA at 07:30 UTC on Sept. 28 covering the incident, restoration of withdrawals and the exchange’s next steps.






