Blockchain compliance firm AMLBot detected the movement of approximately 4 BTC stolen in the Bitget exchange hack flowing into Wasabi CoinJoin mixing rounds as of September 27, 2026. The four Bitcoin originated from a hacker-controlled holding wallet on the TRON network. The series of cross-chain transfers demonstrates a systematic maneuver by the perpetrator to obscure the trail of the stolen assets.
Laundering Route Across Four Networks
The hacker orchestrated a multi-layered asset transfer route before touching the privacy mixing protocol. They initiated the laundering process by swapping TRX coins for USDT stablecoins within the TRON ecosystem. The perpetrator then transferred the funds to the Ethereum network via the USDT0 bridge, Tether’s omnichain line that bridges liquidity across blockchains.
The conversion process continued once the funds landed on Ethereum. The perpetrator swapped their USDT balance for approximately 145 ETH. From there, the hacker leveraged the THORChain cross-chain protocol to swap the 145 ETH back into around 4.59 BTC, completing the cross-chain transfer without having to disclose their identity on centralized exchanges.
Splitting Bitcoin Prior to Mixing
The perpetrator did not deposit the entire 4.59 BTC from THORChain into Wasabi CoinJoin all at once. Instead, they first split the primary coins into several smaller denominations. These smaller batches of Bitcoin were then funneled into the mixing transactions.
Wasabi CoinJoin works by combining multiple inputs and outputs from various users simultaneously. This mass pooling pattern complicates forensic investigations because the algorithm breaks the direct link between the sender’s wallet address and the ultimate recipient’s wallet address.
Fresh Audit Pushes Losses to $387.5 Million
AMLBot’s transaction findings emerged just after Bitget revised its estimated losses from the platform exploit. The exchange updated its total loss figure to $387.5 million, up from the initial estimate of $351.6 million. The revised estimate followed a follow-up audit confirming that the company’s TRON and Zcash asset reserves were also breached by the attacker.
In response to the hacker’s laundering activities, AMLBot blocked the associated wallet addresses. The security firm blacklisted all addresses linked to the laundering route. Investigators confirmed that they continue to monitor any movement of the remaining stolen funds still sitting in the hacker’s wallets.
Reported via crypto.news.
Previously: Bitget Offers 10% Bounty to Track $351.6M Stolen Funds - But Hacker Already Moved 54M XRP
Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.




