An address linked to the attacker behind the $387.5 million Bitget hack was still converting DAI stablecoins and bridging the proceeds to the Tron blockchain early on Thursday, October 1, a week after the breach, according to blockchain tracking firm MistTrack.
Public tracing since September 25 shows that most of the stolen stablecoins were swapped within minutes, a small slice of bitcoin reached a privacy mixing round, and the large ETH and XRP balances that sat untouched on the first day have since moved. Stablecoin issuers Circle and Tether have frozen about $318,000, roughly 0.08% of the disclosed loss.
Bitget, a Seychelles-based centralized cryptocurrency exchange, first put the loss at $351.6 million on September 24 before raising it to about $387.5 million. Unauthorized transfers left parts of its hot and warm wallet infrastructure between 18:31 and 21:23 Coordinated Universal Time (UTC), a window of 2 hours and 52 minutes, according to interim forensic findings from SlowMist and Mandiant. Blockchain security firm GoPlus earlier reconstructed how about $185 million was left in a single minute.
DAI Still Moving to Tron Through USDT0
MistTrack, the on-chain tracking unit of blockchain security firm SlowMist, posted at 01:37 UTC on October 1 that an address it links to the Bitget exploiter was still swapping DAI, a dollar-pegged stablecoin, on Ethereum and bridging the proceeds to Tron.
One transaction it flagged swapped 100,000 DAI for 100,034.89 USDT on Uniswap, a decentralized exchange (DEX) on Ethereum. USDT is the dollar stablecoin issued by Tether.
According to MistTrack, the USDT then moved through USDT0, a version of Tether’s stablecoin built to move between blockchains using the Omnichain Fungible Token (OFT) standard. The firm identified the Ethereum-side USDT0 OFT contract as 0x1f748c76de468e9d11bd340fa9d5cbadf315dfb0 and the Tron-side contract as 0x3a08f76772e200653bb55c2a92998daca62e0e97.
On Tron, MistTrack said activity on SunSwap, a Tron-based DEX, converted 90,967 USDT into USDD, a Tron-based stablecoin, and 19,000 USDT into TRX, Tron’s native token. Those Tron-side amounts total 109,967 USDT, more than the single Uniswap swap, which fits MistTrack’s description of a repeated flow. MistTrack described the activity as ongoing laundering of existing proceeds, not a new theft.
About 4 BTC Entered a Wasabi CoinJoin Round
Blockchain analytics firm AMLBot said on September 26 that about 4 BTC in a Wasabi CoinJoin round traced back to a Bitget-linked Tron wallet. CoinJoin is a technique that combines bitcoin payments from many users into one transaction, making it harder to link senders and receivers. Wasabi is a Bitcoin wallet that offers it.
AMLBot’s traced path ran from TRX to USDT, across to Ethereum through USDT0, into about 145 ETH, and then through THORChain, a cross-chain swap protocol, into about 4.59 BTC. Roughly 4 BTC of that then entered the CoinJoin round. On-chain investigator ZachXBT had separately described the stolen funds being moved across chains before reaching mixers such as Wasabi.
AMLBot also reported, in a September 27 snapshot, that about $343.2 million, or 88.1% of roughly $389.4 million it was tracking, still sat across 13 wallets. The CoinJoin figure and the 13-wallet snapshot describe different moments and should not be added together.
The Early ETH and XRP Piles Did Not Stay Parked
The first public maps of the attacker’s holdings captured a moment that has since passed. Blockchain analytics firm Scorechain counted, as of 11:00 UTC on September 25, about 68,300 ETH worth about $183 million and about 102.6 million XRP worth about $158 million still in attacker wallets, with only small XRP test transfers. XRP was then the largest single slice of the stolen assets.
Later updates from blockchain data provider Bitquery changed that picture. By its September 26 note, 27.63 million XRP had left attacker accounts. In its September 29 update, Bitquery said XRP Ledger balances were down to dust, that 90.5% of the stolen XRP had been swapped for bitcoin, and that two Ethereum holding wallets had emptied on September 27. One wallet still held 10,000 ETH and had never sent a transaction as of 09:10 UTC on September 29.
Any report still describing roughly $184 million in ETH and $157 million in XRP as untouched is relying on the September 25 snapshot. Separately, wallets linked to the attacker have moved about 2,700 Zcash (ZEC) into the network’s Ironwood shielded pool, according to ZachXBT.
Circle and Tether Froze About $318,000
Circle, the issuer of the USDC stablecoin, blacklisted the address Etherscan labels “Bitget Exploiter 8” at 05:00 UTC on September 25, locking about 99,990 USDC. Tether added the same address to its USDT blacklist about seven hours later, locking about 218,023 USDT. Together, the two freezes total about $318,000.
The same wallet still held about 170 ETH, which neither issuer can freeze because ETH has no central issuer.
The $318,000 equals about 0.08% of the $387.5 million Bitget disclosed and about 0.4% of the roughly $75.5 million in USDT, USDC and USDT0 taken. Blockchain security firm Blocksec said in a September 30 laundering note that those freezable assets were swapped into ETH or AVAX within 41 minutes of leaving Bitget. Circle’s freeze came about 7 hours and 37 minutes after the last transfer out of Bitget, which explains why little freezable value remained.
Protocol-level action has also been limited. NEAR Intents, a cross-chain swap system, said it rejected more than $50 million in attempted swaps but froze only about $503,000, while THORChain declined Bitget’s request to refuse service to attacker-linked addresses, citing its permissionless design.
Look-Alike Dust Transfers Hit the Attacker Cluster
Scorechain reported on September 25 that nearly every wallet in the attacker cluster was receiving tiny “dust” transfers from look-alike addresses that match the first and last characters of the real ones. This technique, known as address poisoning, aims to trick someone into copying the wrong address from a transaction history. On BNB Chain, one swap wallet received more than 100 such transfers in about two hours.
Web3 security firm Hypernative separately described the look-alike traffic as third-party poisoning, not part of the theft itself. For compliance teams, the practical risk is narrow but real: a freeze list built by copying addresses from transaction history can capture a dust address instead of the exploiter’s address.
Impersonators Targeted Bitget’s CEO After the Breach
Bitget Chief Executive Officer (CEO) Gracy Chen told Unchained, in an episode published September 29, that a group impersonating a well-known investment firm approached her on Monday, September 28.
Chen said the approach was social engineering rather than a hack, and that the impostors knew she was in talks with outside partners. She said Bitget came close to opening a real conversation before she verified the firm’s leader through a separate channel.
Unchained’s September 30 write-up of the same interview also cites Chen as saying about $632,000 had been frozen across issuer and protocol actions by that point. That is a broader figure than the $318,000 Circle and Tether freeze alone, and the published account does not break it down by source.
Forensics Still Do Not Name the Vendors
SlowMist and Mandiant, Google Cloud’s incident response unit, released interim findings on September 30 that date the earliest logged malicious activity to August 31 on a third-party security product. The findings describe an unauthorized login and a custom withdrawal tool on September 24. Neither firm has named the vendors involved.
SlowMist also recorded two fabricated BTC withdrawal orders that entered processing after the on-chain theft window and returned errors.
Attribution remains split in public. Bitget has cited IP address and VPN patterns consistent with earlier operations linked to North Korea, formally the Democratic People’s Republic of Korea (DPRK). Scorechain attributes the wallets to the Lazarus Group, a North Korean state-linked hacking unit. Blocksec’s September 30 note cautions that on-chain overlaps can point to shared money launderers rather than the same attackers. As of September 28, no government had issued a formal attribution.
Protection Fund Back Above $300 Million, With Fewer Bitcoin
Bitget said on September 30 that it had restored its User Protection Fund above $300 million. The fund stood at $309 million, including 3,705 BTC, after covering the loss from a pre-breach holding of 5,500 BTC worth more than $464 million.
That leaves the fund with 1,795 fewer bitcoin than it held when the breach was disclosed. Because the fund is held mainly in bitcoin, its dollar value moves with the BTC price. Bitget has said customer balances were not reduced.
Withdrawals have returned in phases: BTC on September 28, ETH on September 29, and USDT on September 30, which followed a record $463 million customer outflow. Remaining tokens, fiat and peer-to-peer (P2P) services are scheduled to reopen at 08:00 UTC on October 2.
What to Watch
Three items remain open: whether the final withdrawal phase opens on schedule on October 2, whether the 10,000 ETH wallet Bitquery flagged begins moving, and whether the DAI-to-Tron flow MistTrack identified continues.
With freezable stablecoins already converted and THORChain declining to intervene, further recovery is likely to depend on centralized issuers, exchanges, and swap services acting on addresses before funds move onward.
Also Read: MetaMask Security Incident: Staking Exits Lido Ethereum Validators, No Wallet Threat
