Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    Is ‘Paul Le Roux’ Really Satoshi Nakamoto What the Record Actually Shows
    Is ‘Paul Le Roux’ Really Satoshi Nakamoto? What the Record Actually Shows
    Bitget exchange coin token set in front of a blurred FTX building backdrop.
    Is Bitget the Next FTX? What the $351.6 Million Hack Does and Doesn’t Have in Common
    Gold Bitcoin BTC coin standing vertically in front of a rising green financial candlestick chart
    Inside Bitcoin’s September 2026 Rally: BTC Reclaiming $87K, $2B in ETF Inflows and a Short Squeeze
    CLARITY Act Fails 49-50 in US Senate as SEC & CFTC Move Ahead on Crypto Rules Within 48 Hours
    CLARITY Act Fails 49-50 in US Senate as SEC & CFTC Move Ahead on Crypto Rules Within 48 Hours
    Illustrated collage featuring diverse people surrounded by crypto symbols and a corporate boardroom backdrop.
    Quiet Racism in Crypto Gets “Obvious” During Circle’s Arc Mainnet Launch
  • Opinion
    OpinionShow More
    Comparison of Bybit 12-hour, Bitget 85-hour, and WazirX 463-day response timers
    Bitget, Bybit Paid in Hours; WazirX Lost Least in Hacks at $235M, Held Users Hostage for 463 Days
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    The Architecture of Trust Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust: Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust What 4,000 Years of Trade Teach Us About RWA Tokenisation
    The Architecture of Trust: What 4,000 Years of Trade Teach Us About RWA Tokenisation
    One P2P Trade, Months of Limbo Why Innocent Indian Crypto Users Keep Paying the Price
    One P2P Trade, Months of Limbo: Why Innocent Indian Crypto Users Keep Paying the Price
  • Learn
    • Explained
    • How To
    • Insights
  • IndicesNew
    • India USDT Premium Index
    • India USDC Premium Index
  • Videos
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • Daily Crypto Puzzles
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • IndicesNew
    • India USDT Premium Index
    • India USDC Premium Index
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
    • Daily Crypto Puzzles
  • Videos
  • Glossary
Follow US
© 2026 By Crypto Times. All Rights Reserved.
Industry

Bitget Hack Funds Hit Wasabi CoinJoin as DAI Flows to Tron, Freezes Catch Just $318K

Most of the stolen assets remain on the move, with DAI shifting to Tron, Bitcoin entering CoinJoin, and ETH and XRP balances being rapidly depleted.

Written By Dishita Malvania
Published 56 minutes ago
Make The Crypto Times preferred on GoogleGoogle
Bitget Hack Funds Hit Wasabi CoinJoin as DAI Flows to Tron, Freezes Catch Just $318K

An address linked to the attacker behind the $387.5 million Bitget hack was still converting DAI stablecoins and bridging the proceeds to the Tron blockchain early on Thursday, October 1, a week after the breach, according to blockchain tracking firm MistTrack. 

Public tracing since September 25 shows that most of the stolen stablecoins were swapped within minutes, a small slice of bitcoin reached a privacy mixing round, and the large ETH and XRP balances that sat untouched on the first day have since moved. Stablecoin issuers Circle and Tether have frozen about $318,000, roughly 0.08% of the disclosed loss.

Bitget, a Seychelles-based centralized cryptocurrency exchange, first put the loss at $351.6 million on September 24 before raising it to about $387.5 million. Unauthorized transfers left parts of its hot and warm wallet infrastructure between 18:31 and 21:23 Coordinated Universal Time (UTC), a window of 2 hours and 52 minutes, according to interim forensic findings from SlowMist and Mandiant. Blockchain security firm GoPlus earlier reconstructed how about $185 million was left in a single minute.

AI Summary
Show
Thousands of Bitget users face potential loss and trust erosion after the $387.5 million hack.
Impostors targeted Bitget’s CEO, exposing executives to social‑engineering threats and reputational risk.
Address‑poisoning scams risk innocent victims by confusing users with look‑alike wallet addresses.

DAI Still Moving to Tron Through USDT0

MistTrack, the on-chain tracking unit of blockchain security firm SlowMist, posted at 01:37 UTC on October 1 that an address it links to the Bitget exploiter was still swapping DAI, a dollar-pegged stablecoin, on Ethereum and bridging the proceeds to Tron.

One transaction it flagged swapped 100,000 DAI for 100,034.89 USDT on Uniswap, a decentralized exchange (DEX) on Ethereum. USDT is the dollar stablecoin issued by Tether.

According to MistTrack, the USDT then moved through USDT0, a version of Tether’s stablecoin built to move between blockchains using the Omnichain Fungible Token (OFT) standard. The firm identified the Ethereum-side USDT0 OFT contract as 0x1f748c76de468e9d11bd340fa9d5cbadf315dfb0 and the Tron-side contract as 0x3a08f76772e200653bb55c2a92998daca62e0e97.

On Tron, MistTrack said activity on SunSwap, a Tron-based DEX, converted 90,967 USDT into USDD, a Tron-based stablecoin, and 19,000 USDT into TRX, Tron’s native token. Those Tron-side amounts total 109,967 USDT, more than the single Uniswap swap, which fits MistTrack’s description of a repeated flow. MistTrack described the activity as ongoing laundering of existing proceeds, not a new theft.

About 4 BTC Entered a Wasabi CoinJoin Round

Blockchain analytics firm AMLBot said on September 26 that about 4 BTC in a Wasabi CoinJoin round traced back to a Bitget-linked Tron wallet. CoinJoin is a technique that combines bitcoin payments from many users into one transaction, making it harder to link senders and receivers. Wasabi is a Bitcoin wallet that offers it.

AMLBot’s traced path ran from TRX to USDT, across to Ethereum through USDT0, into about 145 ETH, and then through THORChain, a cross-chain swap protocol, into about 4.59 BTC. Roughly 4 BTC of that then entered the CoinJoin round. On-chain investigator ZachXBT had separately described the stolen funds being moved across chains before reaching mixers such as Wasabi.

AMLBot also reported, in a September 27 snapshot, that about $343.2 million, or 88.1% of roughly $389.4 million it was tracking, still sat across 13 wallets. The CoinJoin figure and the 13-wallet snapshot describe different moments and should not be added together.

The Early ETH and XRP Piles Did Not Stay Parked

The first public maps of the attacker’s holdings captured a moment that has since passed. Blockchain analytics firm Scorechain counted, as of 11:00 UTC on September 25, about 68,300 ETH worth about $183 million and about 102.6 million XRP worth about $158 million still in attacker wallets, with only small XRP test transfers. XRP was then the largest single slice of the stolen assets.

Later updates from blockchain data provider Bitquery changed that picture. By its September 26 note, 27.63 million XRP had left attacker accounts. In its September 29 update, Bitquery said XRP Ledger balances were down to dust, that 90.5% of the stolen XRP had been swapped for bitcoin, and that two Ethereum holding wallets had emptied on September 27. One wallet still held 10,000 ETH and had never sent a transaction as of 09:10 UTC on September 29.

Any report still describing roughly $184 million in ETH and $157 million in XRP as untouched is relying on the September 25 snapshot. Separately, wallets linked to the attacker have moved about 2,700 Zcash (ZEC) into the network’s Ironwood shielded pool, according to ZachXBT.

Circle and Tether Froze About $318,000

Circle, the issuer of the USDC stablecoin, blacklisted the address Etherscan labels “Bitget Exploiter 8” at 05:00 UTC on September 25, locking about 99,990 USDC. Tether added the same address to its USDT blacklist about seven hours later, locking about 218,023 USDT. Together, the two freezes total about $318,000.

The same wallet still held about 170 ETH, which neither issuer can freeze because ETH has no central issuer.

The $318,000 equals about 0.08% of the $387.5 million Bitget disclosed and about 0.4% of the roughly $75.5 million in USDT, USDC and USDT0 taken. Blockchain security firm Blocksec said in a September 30 laundering note that those freezable assets were swapped into ETH or AVAX within 41 minutes of leaving Bitget. Circle’s freeze came about 7 hours and 37 minutes after the last transfer out of Bitget, which explains why little freezable value remained.

Protocol-level action has also been limited. NEAR Intents, a cross-chain swap system, said it rejected more than $50 million in attempted swaps but froze only about $503,000, while THORChain declined Bitget’s request to refuse service to attacker-linked addresses, citing its permissionless design.

Look-Alike Dust Transfers Hit the Attacker Cluster

Scorechain reported on September 25 that nearly every wallet in the attacker cluster was receiving tiny “dust” transfers from look-alike addresses that match the first and last characters of the real ones. This technique, known as address poisoning, aims to trick someone into copying the wrong address from a transaction history. On BNB Chain, one swap wallet received more than 100 such transfers in about two hours.

Web3 security firm Hypernative separately described the look-alike traffic as third-party poisoning, not part of the theft itself. For compliance teams, the practical risk is narrow but real: a freeze list built by copying addresses from transaction history can capture a dust address instead of the exploiter’s address.

Impersonators Targeted Bitget’s CEO After the Breach

Bitget Chief Executive Officer (CEO) Gracy Chen told Unchained, in an episode published September 29, that a group impersonating a well-known investment firm approached her on Monday, September 28.

Chen said the approach was social engineering rather than a hack, and that the impostors knew she was in talks with outside partners. She said Bitget came close to opening a real conversation before she verified the firm’s leader through a separate channel.

Unchained’s September 30 write-up of the same interview also cites Chen as saying about $632,000 had been frozen across issuer and protocol actions by that point. That is a broader figure than the $318,000 Circle and Tether freeze alone, and the published account does not break it down by source.

Forensics Still Do Not Name the Vendors

SlowMist and Mandiant, Google Cloud’s incident response unit, released interim findings on September 30 that date the earliest logged malicious activity to August 31 on a third-party security product. The findings describe an unauthorized login and a custom withdrawal tool on September 24. Neither firm has named the vendors involved.

SlowMist also recorded two fabricated BTC withdrawal orders that entered processing after the on-chain theft window and returned errors.

Attribution remains split in public. Bitget has cited IP address and VPN patterns consistent with earlier operations linked to North Korea, formally the Democratic People’s Republic of Korea (DPRK). Scorechain attributes the wallets to the Lazarus Group, a North Korean state-linked hacking unit. Blocksec’s September 30 note cautions that on-chain overlaps can point to shared money launderers rather than the same attackers. As of September 28, no government had issued a formal attribution.

Protection Fund Back Above $300 Million, With Fewer Bitcoin

Bitget said on September 30 that it had restored its User Protection Fund above $300 million. The fund stood at $309 million, including 3,705 BTC, after covering the loss from a pre-breach holding of 5,500 BTC worth more than $464 million.

That leaves the fund with 1,795 fewer bitcoin than it held when the breach was disclosed. Because the fund is held mainly in bitcoin, its dollar value moves with the BTC price. Bitget has said customer balances were not reduced.

Withdrawals have returned in phases: BTC on September 28, ETH on September 29, and USDT on September 30, which followed a record $463 million customer outflow. Remaining tokens, fiat and peer-to-peer (P2P) services are scheduled to reopen at 08:00 UTC on October 2.

What to Watch

Three items remain open: whether the final withdrawal phase opens on schedule on October 2, whether the 10,000 ETH wallet Bitquery flagged begins moving, and whether the DAI-to-Tron flow MistTrack identified continues. 

With freezable stablecoins already converted and THORChain declining to intervene, further recovery is likely to depend on centralized issuers, exchanges, and swap services acting on addresses before funds move onward.

Also Read: MetaMask Security Incident: Staking Exits Lido Ethereum Validators, No Wallet Threat

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News

Daily Crypto Puzzles
Tickerdle Tickerdle Crypto Connections Crypto Connections Crypto Crossword Crypto Crossword
TAGGED:BitGetCrypto HackTron (TRX)
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link

Daily Crypto Puzzles

Tickerdle crypto game Tickerdle Crypto Connections game Crypto Connections Crypto Crossword game Crypto Crossword

Latest News

Chainlink Named Oracle for Open Standard’s OUSD Stablecoin
Chainlink Named Oracle for Open Standard’s OUSD Stablecoin
Fact Check Hackers Locked Elon Musk’s Starlink and Demanded $500M in Bitcoin
Fact Check: Hackers Locked Elon Musk’s Starlink and Demanded $500M in Bitcoin
Morpho Liquidity Drop Triggers Shift DeFi USDC Vault Exit, No Loss as Deposits Pause
Morpho Liquidity Drop Triggers Shift DeFi USDC Vault Exit, No Loss as Deposits Pause
Physical gold Bitcoin coins in front of a brightly lit white and yellow Bybit logo on a dark background.
Bybit Users Hold More BTC and ETH as USDT Balances Fall 11%
The DogeOS logo featuring a Shiba Inu icon on a yellow app-style badge alongside black block typography over a luminous network background.
DogeOS Launches Testnet to Bring DeFi Apps to Dogecoin

Find Us on Socials

You may also like

A hand holding a smartphone displaying the MetaMask logo in front of a blurred MetaMask fox wall art background.

MetaMask Security Incident: Staking Exits Lido Ethereum Validators, No Wallet Threat

Hand holding a smartphone displaying the Drift Protocol logo, with a blurred 3D Drift wall sign in the background.

Drift Recovers $9.2M of $295M Stolen Funds as Recovery Efforts Continue

Red TRON geometric logo alongside black 3D TRON typography mounted on a light grey wall.

TRON Releases Mandatory GreatVoyage-v4.8.2.3 Node Upgrade 

BTC Holds Range as Long-Term Holders Account for More Realized Profit

BTC Holds Range as Long-Term Holders Account for More Realized Profit

The Crypto Times Logo PNG

News

All News
Market News
Bitcoin News
Ethereum News
Altcoin News
Regulations & Policies
DeFi News
Blockchain News
Industry News

Sections

Exclusive
Opinions
Learn
Insights
Videos
Glossary

India Premium Indices

Stablecoins
USDT
USDC

Play

Daily Crypto Puzzles
Tickerdle
Crypto Connections
Crypto Crossword

Company

About Us
Our Authors
Masthead
Editorial Policy
AI Policy
Advertorial Policy
Contact Us
Career

Follow Us

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information