Swaps of funds stolen from Bitget on 24 September generated at least $761,725 in protocol and service fees in one tracked sample, according to a ledger published by Andrey Sergeenkov on 2 October.
The largest line is THORChain. Liquidity fees on the swaps he reviewed come to $573,226. A separate affiliate-fee stream, credited to recipients named in the swap instructions, comes to $465,914, including $92,438 held as credits in a THORChain holding account whose final payouts have not been traced. Of that, he says $259,718 went to recipients with a further on-chain link to wallets that moved the stolen funds, and $206,196 to recipients where he has not established that link.
Those are fees on a sample, priced in historical dollars and updated by hand. They are not a recovery total, and they are not a claim that the protocols stole the money. Bitget’s own figure for the theft remains about $387.5 million. Fee income of this size is roughly 0.2 percent of that loss.
The write-up is Who Earned Fees From the Laundering of Bitget’s Stolen Funds. The underlying table is his data file, snapshot 2026-10-02T10:22:39 UTC.
What left Bitget on 24 September
Bitget said its systems detected unauthorized transfers from some hot and warm wallets at 18:31 UTC on 24 September. The first public estimate was $351.6 million. On 25 September the exchange raised it to about $387.5 million after adding tokens and TRX from the same window, not from a second breach.
The Crypto Times reported that Bitget tied the transfers to a third-party security product and that chief executive Gracy Chen described patterns consistent with the Democratic People’s Republic of Korea. No government has formally attributed the attack in the material reviewed for that story.
Laundering started the same week. THORChain declined a request from Chen to block published attacker addresses, citing its design. NEAR Intents said attackers tried to route more than $50 million through its rails. The Crypto Times reported that about $669,000 reached the system, of which $503,000 was frozen mid-swap and $166,000 completed.
On 28 September ZachXBT published five aliases he said were moving the funds for the alleged DPRK attackers and asking for help in public Discord and Telegram channels. On 30 September he said about 2,700 ZEC, roughly $3.8 million, had entered Zcash’s Ironwood pool. Sergeenkov’s ledger does not price those shielded coins. It prices swap fees on the routes he tracked.
Who collected the $761,725
Sergeenkov splits protocol and service fees four ways, through 10:22 UTC on 2 October:
- THORChain liquidity fees, recorded in Midgard swaps: $573,225.63
- MetaMask, transfers to 0xf326e4de8f66a0bdc0970b79e0924e33c79f1915: $149,416.68
- Chainflip broker fees on matched swap requests: $26,750.72, allocated to a broker address he aliases to swap.chainflip.io
- CoW EthFlow, executed protocol and partner fees: $12,332.44
The four lines sum to about $761,725. He says individual shares of the THORChain liquidity fees and the CoW fees have not been calculated, so the $573,226 is a pool of liquidity-provider fees, not a payment to a named person. BSC fees are outside the calculation.
The MetaMask line is a fee contract, marked “not assessed” for any link to the hacker wallets. The Chainflip broker line is also not assessed.
Which affiliate addresses he links to the stolen funds
THORChain swaps can name an affiliate who takes a cut. Sergeenkov writes that the parties moving the stolen funds signed instructions naming these recipients. An interface can insert a recipient before the sender signs, so the name alone does not show who controls the address.
He treats a recipient as linked only where he documents a further movement. In some cases fee proceeds went back to a wallet that submitted a stolen-fund swap. In others, swaps naming different affiliates sent the main bitcoin proceeds to the same destination wallets. The linked total is $259,718.
The largest is thor18dvgrgpvxlh7rhhld4qjyrxs9c7tvwdakrkjm4, at $177,499. He says XRP senders on those swaps connect by transfers to Bitget’s compromised XRP address, and that some main bitcoin proceeds landed in recipients shared with another affiliate route. Part of this address’s RUNE fees were swapped to USDT and, after two Ethereum wallets, reached an address labeled Etherscan as OKX Hot Wallet 5 in the transaction. He says OKX could check whether that deposit maps to a customer. He does not say OKX handled the theft.
The other linked recipients in his table:
- thor1rj9f7m7n72nwslau7jzla09u0l4zr4ru8277d2, $56,514. One swap sender connects to Bitget’s compromised EVM address. All four main bitcoin recipients match another reviewed route.
- thor199tl2t4fkxqn7pawk8dgera79dl70rnczu6jsl, $18,080. Fee RUNE was swapped and sent to a wallet that had used this affiliate. That wallet later received ETH from Bitget’s compromised EVM cluster.
- thor1c9wvfltxuj43622x8nc2ljf3qn7q9udc7dp79x, $4,544. Main bitcoin proceeds went to two recipients also used by two other routes.
- thor1kufulp8x9r4r22ntl20rfhsj2wddujynyzxwxs, $2,885. Shares an ETH sender and a main Bitcoin recipient with the next address. The ETH sender connects by consecutive transfers to the original stolen-ETH address.
- thor19ya3vcnzfdu4f9s5t3rjn75dzqf936djewkcwz, $196. Swapped its fee RUNE and sent the ETH back to 0x5c768…eaea0, the sender of the swaps that generated the fee.
- thor1g5ajjv2lt5dhepfnj5amy7yd3dppc92mcazeel, under $1. A later RUNE transfer to thor199tl…u6jsl. He counts the link and does not add it to the fee total.
Evidence dates on those rows are 30 September and 1 October.
Who was named, with no further link yet
A second affiliate bucket totals $206,196. These addresses or registered names appeared in the signed instructions. He says further transfer links to the hacker wallets have not been established in the history he has reviewed.
- thor148sahwr5pg44cy0n23zwc723ugy2fptw0m8sau, name used in swaps: naswap, $102,344
- thor1dl7un46w7l7f3ewrnrm6nq58nerjtp0dradjtd, a THORChain holding account credited under the names w1, t, vi, -_, ss, dx, ej and symbiosis, $92,438. He says these are credits, and the final payouts have not been traced.
- thor1epz4l9jat4uqrag5j9d5aqrawrn0uhvdfxyxec, name tch, $7,245
- thor1dz5le8q2gytyn5gkfgcma4wueat4y655meyvnx, name ns, $2,994
- thor1ul3wekxelwcyuc4d85eza5s0qkhxqa2y9n7dar, $1,176
A registered name routes a fee. It is not an identity.
What the ledger does not answer
Sergeenkov’s own limits are in the method note. The figures cover the tracked sample. They use historical USD prices. He has not calculated each liquidity provider’s share. Holding-account amounts are credits, not traced payouts. Receiving an affiliate fee does not establish common ownership.
The $761,725 and the $465,914 should not be added into a single “earned from the hack” total without saying they are different mechanisms. Liquidity fees pay the pool. Affiliate fees are paid to the named recipient. MetaMask and Chainflip are service lines he has not assessed for a hacker link.
No protocol named in the ledger has, in this article, published a response. Bitget has not adopted the fee table as its own accounting. The sample also stops on 2 October, so later swaps, including anything that moved after the Ironwood deposits, are outside it.
Also Read: Bitget Hackers Lose $700K as Script Error Sends USDC, ETH to Wrong Chainflip Channels
