Following the Bitget Hack: BitOK Traces 87.8 BTC as Stolen Funds Reach Mixers

1 hour ago 4

Rommie Analytics

Bitget hack story

Research and reporting by Alexander Manev, BitOK. Reporting and adaptation by Brave New Coin.

Investigators following the Bitget hack have identified approximately 87.82 BTC attributable to one branch of the stolen funds that remained in ten unspent Bitcoin outputs on October 1, even as other traced funds entered mixing transactions.

The finding comes from blockchain intelligence firm BitOK, which supplied Brave New Coin with an updated investigation and supporting transaction records. Its analysis shows how funds moved through intermediary wallets, decentralized exchanges and cross-chain services, gradually converging on Ethereum and Bitcoin.

The investigation offers a detailed view of what happened after the September 24 attack, which Bitget estimates affected $387.5 million in assets. It also illustrates a persistent difficulty in crypto investigations: identifying where money went does not necessarily establish who controls it, how much remains recoverable, or which subsequent balances belong entirely to the theft.

BitOK’s October 1 Bitcoin snapshot

BitOK’s October 1 update follows its initial investigation covering September 24–28. The newer evidence materially changes the picture on Ethereum. Eight storage wallets that collectively held 50,163.84 ETH on September 28 contained just 0.000754316 ETH at the October 1 verification.

That decline represents onward movement from the monitored wallets. It does not establish that the funds were recovered, sold for cash or successfully concealed.

The Bitcoin branch provides a more clearly defined monitoring target. According to BitOK, 31 THORChain payouts delivered 87.82301390 BTC, which was subsequently consolidated into ten outputs. Its final check, completed at 11:23:46 UTC on October 1, found all ten still unspent, with no entry into CoinJoin established for that group.

After allowing for transaction fees, BitOK placed the traced contribution at approximately 87.82290–87.82297 BTC. The outputs themselves held 101.78385303 BTC because two consolidations also incorporated funds from other sources. Reporting the entire 101.78 BTC as stolen Bitget money would therefore overstate what the analysis establishes.

Bitget

BitOK’s October 1 snapshot maps traced fund movements across Ethereum, Bitcoin, TRON and XRP Ledger. Approximately 87.82 BTC attributable to one branch remained in ten unspent Bitcoin outputs; larger gross-flow figures include attribution limits. Credit: BitOK.

“The 87.82 BTC branch is especially important because, at the latest snapshot, those ten UTXOs had not been spent, which means they could still be monitored directly,” BitOK analyst Alexander Manev said in comments supplied to Brave New Coin.

UTXOs, or unspent transaction outputs, are discrete amounts of bitcoin available to be spent. Their visibility gives investigators something concrete to watch. It does not give them the ability to freeze those coins at the Bitcoin protocol level.

Other funds enter Wasabi and Tornado Cash

Elsewhere, the trail has become harder to follow. BitOK’s updated report identifies nine direct inputs totaling 14.61453223 BTC entering six Wasabi CoinJoin rounds on September 28 and 30. On Ethereum, it records 13 Tornado Cash deposits totaling 9.4 ETH on September 30.

CoinJoin combines inputs from multiple participants into a shared transaction, complicating attempts to connect individual inputs with subsequent outputs. BitOK has not matched the relevant mixer withdrawals to specific recipients. The identified deposits demonstrate entry into privacy mechanisms; they do not prove which later wallets received the corresponding funds.

These mixing flows are separate from the ten-output Bitcoin position. The distinction matters: some traced funds had entered privacy transactions, while the approximately 87.82 BTC branch remained directly observable at the report’s cutoff.

Following the money across blockchains

Across the wider investigation, BitOK describes repeated splitting, swapping and bridging. Ethereum served as a major transit point, receiving funds from other networks before onward conversions. THORChain and Chainflip featured in routes into Bitcoin, while LayerZero and other services appeared in cross-chain movements. A service’s appearance in a transaction trail does not establish that its operator participated in the theft.

bitget hack transaction chart

Caption: BitOK’s earlier investigation maps transfers from two addresses labelled as linked to the Bitget exploit through intermediary wallets and onward to bridges, swap services and other destinations. This historical flowchart illustrates transaction routes; its displayed balances are not the October 1 snapshot. Credit: BitOK Graph, from BitOK’s September 24–28 investigation.

The expanded report identifies 1,425 Bitcoin payouts totaling approximately 1,259.44 BTC across the examined Ethereum-to-THORChain routes. That is a gross flow figure, subject to mixed sources and repeated conversions. It cannot be treated as additional losses or a single balance still controlled by the attackers.

Similar limits apply to XRP. BitOK records four payments totaling 49,000 XRP from a mixed-source address to a Binance deposit address on September 25. Because the sending address combined funds from different origins, the precise Bitget contribution is undetermined. The report does not identify the receiving Binance customer or establish that Binance froze those payments.

For Manev, the most useful intervention point is often where a trace reaches an identifiable service provider.

“The best opportunity to intervene is when stolen funds reach a centralized exchange or another service able to freeze withdrawals and identify the receiving account,” he said. “At that point, law enforcement may be able to request account information and prevent further movement.”

How attackers reached Bitget’s wallet infrastructure

The theft itself appears to have exploited the infrastructure surrounding Bitget’s wallets. In a preliminary incident-response report, Mandiant said an attacker gained privileged access to third-party security appliances, established persistent access and moved into Bitget’s production wallet job server, where malicious packages were deployed. Mandiant described its investigation as ongoing.

Bitget’s September 30 update said investigations by Mandiant and SlowMist broadly supported its previously disclosed attack path. The exchange’s own account says compromised credentials enabled fraudulent withdrawal commands to bypass risk controls.

According to Bitget’s incident timeline, the first unauthorized transfers occurred at approximately 18:31 UTC on September 24. The exchange says private-key compromise was ruled out, cold wallets were unaffected and user account balances remained unchanged. Those statements describe Bitget’s assessment of the incident and its customer impact.

Bitget confirmed that Bitcoin withdrawals resumed on September 28 and Ethereum withdrawals on September 29. In an October 2 announcement, the exchange said withdrawals for the remaining tokens, along with fiat and customer-to-customer services, had resumed, completing its previously announced restoration plan.

Investigators point to North Korean actors

Investigators have also linked the incident to North Korean actors. In an October 1 analysis, Chainalysis described the attack as DPRK-attributed and said it pushed the value stolen by North Korean actors during 2026 above $1 billion. Scorechain separately attributed attacker wallets to the Lazarus Group.

Blockchain investigator ZachXBT added allegations about the laundering operation. In a September 28 post on X, reproduced in Coin360’s coverage, he alleged that Chinese intermediaries moving Bitget proceeds for suspected North Korean attackers were requesting transaction support in public Discord and Telegram channels. He also described funds moving through bridges and into mixing services, including Wasabi.

These are attributed investigative assessments. BitOK’s fund-flow report does not independently identify the people behind the intrusion, and the preliminary Mandiant report reviewed for this article does not name a responsible state or group.

Crypto’s security problem extends beyond Bitget

The wider security backdrop remains severe. CertiK’s dashboard, marked updated October 3, recorded approximately $772.4 million in September losses and $1.27 billion for the third quarter. Those totals cover its broader security-incident categories and should not be read as a measure of funds permanently lost after recoveries.

September also brought the approximately $320 million Liquid Network exploit. Chainalysis reported that the actors returned 3,400 BTC, roughly 85% of the bitcoin withdrawn, after exploiting a flaw in the network’s transaction-validation software. The incident involved a different mechanism but reinforced the exposure created by the systems built around digital assets.

North Korea’s involvement in earlier crypto thefts is more firmly established. The FBI attributed the approximately $1.5 billion Bybit theft in February 2025 to North Korea. That precedent provides context for investigators’ scrutiny of Bitget, without proving attribution in this case.

For Bitget, the immediate challenge is turning transaction intelligence into recoveries before further transfers obscure the trail. Manev cautioned that sophisticated attacks often have laundering plans prepared in advance, involving over-the-counter infrastructure and multiple jurisdictions.

“Even after funds pass through a mixer, the investigation is not necessarily over if the link to the stolen assets has already been established,” he said.

BitOK’s October 1 snapshot leaves investigators with a specific target: ten unspent outputs containing approximately 87.82 BTC traced to one branch of the attack. Whether that visibility translates into recovery depends on where those funds move next—and whether investigators can act when they reach a service capable of intervening.

Research and reporting by Alexander Manev, BitOK. Further reporting and adaptation by Brave New Coin.

Read Entire Article