A wallet linked to the Bitget security breach has exchanged about $6.3m (£4.7m) in Ethereum for Bitcoin through THORChain, after the network rejected a request from the cryptocurrency exchange to block addresses associated with the attacker.
The wallet completed 27 swaps, converting about 2,390 ETH into 75.2 BTC. A further four transactions involving 400 ETH were pending when CoinDesk reviewed THORChain’s records.
All of the completed Bitcoin was sent to one receiving address. The orders came from an Ethereum wallet previously identified by blockchain tracker Lookonchain as being involved in the attacker’s activity.
The transactions were submitted between about 03:55 and 06:23 UTC on Monday, with most involving roughly 100 ETH. CoinDesk valued each batch at approximately $265,000 at the prices used in its review.
Two 100 ETH orders were only partially completed because some funds failed to meet the minimum price set for the trade. About 114 ETH was returned to the sending wallet, according to CoinDesk.
THORChain enables users to exchange assets held on different blockchains without using a centralised exchange. In these transactions, ETH entered the network and BTC was transferred to an address on the Bitcoin blockchain. The movements remain visible on public blockchains, allowing investigators to follow the funds despite the change of network.
A separate route had already moved Bitget-linked Bitcoin into a privacy transaction. On Sep. 27, blockchain compliance firm AMLBot traced about four BTC into a Wasabi CoinJoin round after the funds moved from TRON to Ethereum and then through THORChain. AMLBot said its analysis linked the Bitcoin to a TRON wallet associated with Bitget.
CoinJoin combines inputs and outputs from multiple users in one transaction, making it more difficult to establish which funds were sent to which recipient.
THORChain rejects request to block wallets
Bitget chief executive Gracy Chen asked THORChain over the weekend to refuse transactions involving published addresses the exchange had identified and was monitoring.
THORChain rejected the request for an address-specific block. The team said its emergency controls could halt activity across the network or restrict activity on a connected blockchain, but that a network halt “is not a selective freeze of specific funds or an individual swap”.
It added that either measure would also disrupt transactions involving other users.
Security firm GoPlus has disputed THORChain’s description of its controls. As reported on Sep. 27, it pointed to validator votes, signing controls and chain-specific pauses outlined in the network’s documentation. GoPlus said those mechanisms gave node operators ways to intervene when funds were at risk.
THORChain maintains that its emergency halt is designed to protect the network itself and cannot operate as a blocklist for individual wallets.
The network used its emergency controls after an attacker stole about $10.7m from a THORChain vault in May. Operators halted activity while developers repaired the vulnerability, with trading resuming in June after about five weeks. THORChain said the addresses linked to that attack were not individually blacklisted.
Bitget raises estimate of stolen assets
Bitget initially estimated that assets affected by the Sep. 24 breach were worth approximately $351.6m. After including Zcash and TRON assets omitted from its first calculation, it raised the value transferred to attacker-controlled addresses to about $387.5m.
The exchange said the higher figure reflected a fuller review of the original incident and did not represent additional theft after the breach.
Bitget detected unauthorised transfers at 18:31 UTC on Sep. 24 and suspended withdrawals during its investigation. It said its cold wallets remained secure.
The exchange later said investigators had identified and fixed the vulnerability, while Mandiant and SlowMist were assisting with the investigation and security checks. Bitget has not published a complete account of how the attacker gained access to its systems.
Chen subsequently announced a recovery bounty programme offering separate 5% rewards for eligible attempts to freeze stolen assets and recover them. Bitget published primary attacker addresses across Ethereum-compatible networks, XRP Ledger, Zcash and TRON, as well as a dashboard tracking further movements.
The exchange said eligibility and payments would be decided according to each participant’s contribution. Work carried out under a court order or at the request of law enforcement would not qualify.
Bitget said Circle had frozen 99,990 USDC linked to the attack, while Tether had frozen 218,023 USDT. Those actions involved identified stablecoin balances and were separate from Bitget’s request for THORChain to stop ETH-to-BTC swaps.
Bitget has also discussed establishing a future US business. Chen said in July that the company would seek the necessary licences and approvals before offering services to American customers.
Bitcoin withdrawals first in phased reopening
Following its security checks, Bitget announced a phased reopening of withdrawals.
Bitcoin withdrawals on the Bitcoin network were scheduled to resume at 08:00 UTC on Sep. 28. ETH withdrawals through Ethereum, BNB Smart Chain, Arbitrum, Base and Optimism were due to restart at the same time on Sep. 29.
USDT withdrawals on Ethereum, BNB Smart Chain, Solana and TRON were scheduled for 08:00 UTC on Sep. 30.
Other tokens, fiat services and peer-to-peer transactions were assigned to the final stage, scheduled for Oct. 2. Bitget told customers to consult its official notices for confirmation that each service had become available.
