AdvertisementAdvertisementAdvertisementAdvertisement
Cryptocurrency

Bitget Hacker Moves Stolen Funds for the First Time Since Breach

9/28/2026, 02:49 PM • Evgenia Sliv

(edited: 09/28/2026)

Bitget Hacker Moves Stolen Funds for the First Time Since Breach

The hacker associated with the attack on the Bitget platform has begun moving the stolen funds for the first time since the incident on September 24, during which the exchange suffered losses exceeding $350 million. According to blockchain trackers, the perpetrator started transferring Ethereum (ETH) to THORChain vaults, converting the assets into Bitcoin (BTC). These operations mark the first significant movement of funds since the breach and represent an important step in efforts to track and recover the stolen assets. Four days after the breach, Bitget discovered unauthorized transfers from several hot and warm wallets, initially estimating losses at $351.6 million, but subsequent tracking revealed that the confirmed amount reached approximately $387.5 million after accounting for additional assets associated with the attack. The hacker sent ETH to THORChain in several transactions, often in batches of 100 ETH, before exchanging the funds for BTC using a decentralized cross-chain protocol. Previously stolen assets, including XRP, BNB, and TRX, also passed through THORChain and similar bridge services.

Some of the converted BTC was processed using transaction obfuscation methods, complicating the tracking of the funds. Bitget stated that the perpetrators did not gain access to private keys, and the breach was related to the compromise of a critical backend component that allowed fraudulent data to pass through the exchange's authorization process. The attack enabled coordinated transfers across multiple blockchains and affected assets such as ETH, XRP, stablecoins, BNB, AVAX, and Tron-based tokens.

Bitget's cold wallets and separate self-service remained unharmed. The exchange published wallet addresses associated with the attackers and urged industry participants to help freeze and recover the stolen funds. Bitget also reached out to THORChain to block the identified wallets, but the protocol reported that its permissionless network cannot selectively restrict addresses. Withdrawals resumed on September 28, starting with Bitcoin and gradually expanding to other assets. Bitget emphasizes that client funds are protected through its User Protection Fund and that a full technical report will be published upon the completion of the investigation.

Popular news