๐Ÿ“… Sunday, 27 September 2026 ยท --:-- UTC Follow us
Ecosystem โ–ผ
ID EN
Hacker Bitget Cuci 4 BTC Curian Lewat Wasabi CoinJoin - Jejak Pelarian Lintas 4 Jaringan Terbongkar

Bitget Hacker Launders 4 Stolen BTC via Wasabi CoinJoin - Trail Across 4 Networks Exposed

Blockchain compliance firm AMLBot detected the movement of approximately 4 BTC stolen in the Bitget exchange hack flowing into Wasabi CoinJoin rounds as of September 27, 2026. These four Bitcoin originated from a hacker holding wallet on the TRON network. Consecutive cross-chain transfers illustrate a systematic maneuver by the attacker to obfuscate the origin of the stolen assets.

Laundering Route Spans Four Networks

The attacker mapped out a multi-layered transfer route before touching the privacy mixing protocol. They began the laundering process by swapping TRX for the USDT stablecoin within the TRON ecosystem. The perpetrator then transferred the funds to the Ethereum network via the USDT0 bridge, Tether’s omnichain solution connecting liquidity across blockchains.

The conversion process continued once the funds landed on Ethereum. The perpetrator swapped their USDT balance for around 145 ETH. From there, the hacker used cross-chain protocol THORChain to swap the 145 ETH back into approximately 4.59 BTC, completing the cross-chain hop without exposing their identity on centralized exchanges.

Splitting Bitcoin Prior to the Mixing Process

The attacker did not deposit the entire 4.59 BTC from THORChain into Wasabi CoinJoin at once. Instead, they first broke down the primary funds into several smaller denominations. It was these smaller portions of Bitcoin that the perpetrator subsequently sent into mixing transactions.

Wasabi CoinJoin works by combining multiple inputs and outputs from various users at the same time. This mass pooling pattern complicates forensic work, as the algorithm breaks the direct link between sender and recipient wallet addresses.

Fresh Audit Pushes Losses to $387.5 Million

AMLBot’s fund tracking findings emerged shortly after Bitget revised the estimated impact of the attack on its platform. The exchange adjusted its total losses to $387.5 million, up from an initial estimate of $351.6 million. The increased loss estimate followed a follow-up audit confirming that the platform’s TRON and Zcash reserves were also breached by the attacker.

Responding to the laundering activity, AMLBot flagged the associated wallet addresses. The security firm blacklisted all addresses tied to the laundering route. Investigators confirmed they continue to monitor any movement of the remaining stolen funds sitting in the hacker’s wallets.

Reported via crypto.news.

Previously: Bitget Offers 10% Bounty to Track $351.6M Stolen Funds - But Hacker Already Moved 54M XRP


Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.

Share this article:
๐Ÿ“ฉ KABAR BITCOIN IN 1 MINUTE

Daily crypto news, straight to your inbox

A 1-minute digest for people always on the move. Free, unsubscribe anytime.

Total
0
Share