Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    Elon Musk with folded arms flanked by a giant Bitcoin coin, Tesla electric car, and SpaceX rocket launch
    Elon Musk’s Tesla and SpaceX Still Hold Over 30,000 Bitcoin: Why Is He Not Selling?
    Is ‘Paul Le Roux’ Really Satoshi Nakamoto What the Record Actually Shows
    Is ‘Paul Le Roux’ Really Satoshi Nakamoto? What the Record Actually Shows
    Bitget exchange coin token set in front of a blurred FTX building backdrop.
    Is Bitget the Next FTX? What the $351.6 Million Hack Does and Doesn’t Have in Common
    Gold Bitcoin BTC coin standing vertically in front of a rising green financial candlestick chart
    Inside Bitcoin’s September 2026 Rally: BTC Reclaiming $87K, $2B in ETF Inflows and a Short Squeeze
    CLARITY Act Fails 49-50 in US Senate as SEC & CFTC Move Ahead on Crypto Rules Within 48 Hours
    CLARITY Act Fails 49-50 in US Senate as SEC & CFTC Move Ahead on Crypto Rules Within 48 Hours
  • Opinion
    OpinionShow More
    Donald Trump speaking at a presidential podium with the White House and U.S. Capitol building in the background.
    Trump Just Declared the Super Intelligence Era in the “Unites States.” So Who Controls It?
    Comparison of Bybit 12-hour, Bitget 85-hour, and WazirX 463-day response timers
    Bitget, Bybit Paid in Hours; WazirX Lost Least in Hacks at $235M, Held Users Hostage for 463 Days
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    The Architecture of Trust Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust: Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust What 4,000 Years of Trade Teach Us About RWA Tokenisation
    The Architecture of Trust: What 4,000 Years of Trade Teach Us About RWA Tokenisation
  • Learn
    • Explained
    • How To
    • Insights
  • IndicesNew
    • India USDT Premium Index
    • India USDC Premium Index
  • Videos
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • Daily Crypto Puzzles
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • IndicesNew
    • India USDT Premium Index
    • India USDC Premium Index
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
    • Daily Crypto Puzzles
  • Videos
  • Glossary
Follow US
© 2026 By Crypto Times. All Rights Reserved.
Industry

Bitget Hackers Lose $700K as Script Error Sends USDC, ETH to Wrong Chainflip Channels

A $267K USDC transfer hit an Arbitrum-only address on Ethereum, while 160 ETH landed at an Ethereum-only Chainflip channel on Arbitrum.

Written By Dishita Malvania
Edited by Divya Mistry
Published 1 hour ago·Updated 26 minutes ago
Make The Crypto Times preferred on GoogleGoogle
Bitget Hackers Lose $700K as Script Error Sends USDC, ETH to Wrong Chainflip Channels

Wallets linked to the $387.5 million Bitget hack have stranded about $700,000 in stolen crypto after two automated transfers sent USD Coin (USDC) and Ether (ETH) to Chainflip deposit channels on the wrong blockchain networks, blockchain compliance firm AMLBot reported on October 2, 2026. 

AMLBot said the two transfers, made seconds apart, mixed up Ethereum and Arbitrum in opposite directions, and that one receiving address has since been blacklisted by Circle, the issuer of USDC.

AI Summary
Show
Circle’s blacklist may lock USDC permanently, requiring regulatory clearance before any recovery to Bitget.
Stuck ETH on Arbitrum lacks a sweep contract, leaving technical solutions as the only possible retrieval route.
Repeated script errors highlight urgent need for automated cross-chain checks to prevent future fund misrouting.

What AMLBot Traced

Chainflip is a decentralized cross-chain swap protocol that exchanges native assets across Bitcoin, Ethereum, Solana, Arbitrum, and Polkadot Asset Hub without wrapped tokens or traditional bridges. To start a swap, a user opens a deposit channel, a temporary address assigned to one asset on one specific blockchain. Funds sent to that address on any other chain are not recognized by the protocol.

In the first transfer, the attacker swapped funds through CoW Protocol, a decentralized exchange (DEX) aggregator that settles trades through batch auctions, and paid roughly 267,000 USDC on Ethereum to a Chainflip deposit channel that was opened only on Arbitrum. Arbitrum is a layer-2 network that processes transactions off the Ethereum mainnet and settles them back to Ethereum. Because the channel did not exist on Ethereum, the USDC arrived at an address Chainflip was not monitoring on that chain. Circle later blacklisted the receiving address, which prevents the USDC held there from being transferred.

In the second transfer, about 160 ETH, valued at roughly $430,000 at the time of AMLBot’s report, was bridged from Ethereum to Arbitrum and then sent to a Chainflip channel that exists only on Ethereum. AMLBot said no contract on Arbitrum is able to sweep those funds, so the ETH remains stuck at the address.

The @bitget hacker seems to have fumbled ~$700K while laundering the stolen funds😂

Our tracing shows the attacker sent funds to @Chainflip deposit channels on the wrong chains:

~267K USDC was swapped via CoW Swap and paid on Ethereum to a channel that only exists on Arbitrum.… https://t.co/yJAm6MhOdh pic.twitter.com/cDyGXsNcVH

— AMLBot (@AMLBotHQ) October 2, 2026

Combined, the two errors account for about $697,000, which AMLBot rounded to $700,000.

Why a Script Is the Likely Cause

AMLBot described both deposits as likely script-driven, citing the timing and the mirrored nature of the mistakes. One transfer sent Ethereum funds to an Arbitrum-only channel, while the other sent Arbitrum funds to an Ethereum-only channel, which points to a configuration error in which the two networks were swapped rather than a one-off manual slip.

The pattern fits earlier observations from MistTrack, the on-chain tracking unit of blockchain security firm SlowMist. In late September, MistTrack reported that operators were placing automated CoW Protocol orders with pre-set Chainflip deposit addresses as recipients to move Bitget proceeds toward Bitcoin (BTC). 

MistTrack also reported that Chainflip had rejected at least one related deposit at the broker level and refunded it along its original route instead of completing the swap. Brokers are the third parties that open deposit channels for users on Chainflip.

The October 2 errors show a concrete weakness in that automation: a script that pre-sets deposit addresses can route funds to a destination that never existed on the sending chain, with no human check before the transaction confirms.

Where the Wider Laundering Trail Stands

The stranded amount does not materially change the scale of the theft. Freezes and protocol rejections have so far blocked only a small share of the total.

NEAR Intents, a cross-chain swap system in the NEAR ecosystem, said it refused most of more than $50 million that attackers tried to route through it, but froze only about $503,000 mid-swap while roughly $166,000 completed. Tether and Circle have also frozen idle stablecoin balances linked to the attacker. 

Public tracing from blockchain security firm BlockSec and others shows the largest pass-through volumes moving through THORChain, a decentralized cross-chain liquidity network, with Chainflip appearing as a secondary route.

AMLBot has published several earlier findings on the case. The firm traced roughly 4 BTC linked to a Bitget TRON wallet into a Wasabi CoinJoin round, a privacy technique that combines many users’ coins in a single transaction to obscure their origin, after the funds moved through Tether (USDT), Ethereum, and THORChain. 

On September 29, AMLBot flagged three THORChain affiliates that, according to its data, were used only by attacker wallets for about 3,700 swaps worth roughly $58.7 million, mostly XRP and ETH converted into BTC.

Affiliates are interfaces or addresses that charge an optional fee on THORChain swaps, and those fees are paid in RUNE, THORChain’s native token, by default. AMLBot said one of the three affiliates later cashed out to the exchange OKX, while another sent its fees back to an attacker’s wallet.

Separately, on-chain investigator ZachXBT reported that alleged North Korean hackers moved Zcash (ZEC) linked to the theft into a shielded pool. No government has formally attributed the Bitget breach to North Korea.

How the Bitget Breach Happened

Bitget’s systems flagged unauthorized transfers from some hot wallets, which stay connected to the internet for daily withdrawals, and warm wallets, which sit between hot and offline cold storage, at 18:31 Coordinated Universal Time (UTC) on September 24. The exchange first estimated the loss at $351.6 million, then revised it to about $387.5 million after additional Zcash and TRON transactions from the same window were classified.

Bitget has said its private keys were not stolen. An analysis by GoPlus Security found that the attackers fed forged instructions into Bitget’s own signing system, which then approved the transfers as legitimate. Interim findings released on September 30 by SlowMist and Mandiant, Google Cloud’s incident response unit, said the attackers first gained access through a third-party product weeks before the theft.

Bitget said its User Protection Fund covers the loss and launched a Recovery Bounty Program offering 5% of funds frozen and 5% of funds recovered through eligible voluntary efforts. The exchange restarted withdrawals in phases, beginning with Bitcoin at 08:00 UTC on September 28.

What Comes Next

Circle’s blacklist applies to the USDC address identified in the Ethereum-side error. The ETH sent to the mismatched Arbitrum address remains inaccessible to any sweep contract, according to AMLBot. Whether either balance can eventually be returned to Bitget will depend on Circle’s processes for blacklisted funds and on whether any technical path exists for the stuck ETH.

On-chain monitoring of the remaining Bitget-linked wallets, as well as further Chainflip, THORChain, and mixer activity, is ongoing. Bitget has not issued a statement specifically addressing the mismatched Chainflip deposits.

The Bitget theft was the largest single incident in a month that CertiK ranked as 2026’s worst for crypto hack losses.

Also Read: Bitget Alliance Program Reward Pool Tops $1.9M in Three Days After $387.5M Hack

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News

Daily Crypto Puzzles
Tickerdle Tickerdle Crypto Connections Crypto Connections Crypto Crossword Crypto Crossword
TAGGED:BitGetCrypto HackStablecoin
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link

Daily Crypto Puzzles

Tickerdle crypto game Tickerdle Crypto Connections game Crypto Connections Crypto Crossword game Crypto Crossword

Latest News

UK Crypto Trader Beaten in Home Invasion as Gang Threatens to Kill Pregnant Wife
UK Crypto Trader Beaten in Home Invasion as Gang Threatens to Kill Pregnant Wife
Binance P2P Seller Says SBI Froze ₹4.5 Lakh After a Single $1,000 USDT Sale
Binance P2P Seller Says SBI Froze ₹4.5 Lakh After a Single $1,000 USDT Sale
Citigroup Raises Strategy (MSTR) Price Target to $240 on Higher Bitcoin Forecast
Citigroup Raises Strategy (MSTR) Price Target to $240 on Higher Bitcoin Forecast
India Hands ARIN-AP Presidency to Singapore as Crypto Enters the Agenda
India Hands ARIN-AP Presidency to Singapore as Crypto Enters the Agenda
Smartphone displaying a viral X tweet about bringing back Microsoft Clippy in front of a Microsoft logo background
Microsoft’s X Account Was Hijacked to Push a Clippy Token

Find Us on Socials

You may also like

Smartphone displaying MicroStrategy logo in front of Saudi National Bank SNB wall logo

Michael Saylor’s Strategy (MSTR) Surpasses Saudi National Bank in Market Cap

Porsche Ends Web3 Project and PIONEERS CIRCLE, 911 NFTs Stay On-Chain

Porsche Ends Web3 Project and PIONEERS CIRCLE, 911 NFTs Stay On-Chain

European Central Bank Eurosystem sign mounted on glass exterior representing digital euro and EU monetary policy

ECB Makes the Case for Central Banks On-Chain and a Tokenized Digital Euro

Aave Labs and MiCA regulation logos with a MiCA Review Consultation document under European Commission oversight

Aave Urges EU to Rethink MiCA Rules for DeFi and Stablecoins

The Crypto Times Logo PNG

News

All News
Market News
Bitcoin News
Ethereum News
Altcoin News
Regulations & Policies
DeFi News
Blockchain News
Industry News

Sections

Exclusive
Opinions
Learn
Insights
Videos
Glossary

India Premium Indices

Stablecoins
USDT
USDC

Play

Daily Crypto Puzzles
Tickerdle
Crypto Connections
Crypto Crossword

Company

About Us
Our Authors
Masthead
Editorial Policy
AI Policy
Advertorial Policy
Contact Us
Career

Follow Us

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information