Bitget Hack Update: BTC Withdrawal Test Starts Sep. 28 as Stolen Funds Move Through THORChain

एब्स्ट्रैक्ट:Bitget’s BTC withdrawals are scheduled to restart Sep. 28 at 08:00 UTC after the $387.5M backend breach. On-chain researchers now track large portions of stolen XRP and other assets through THORChain and other routes toward Bitcoin.

Bitgets September 24 security incident has entered two simultaneous phases:

  • exchange recovery, with BTC withdrawals scheduled to restart on September 28 at 08:00 UTC;
  • on-chain laundering, with attacker-linked assets increasingly converted and consolidated into Bitcoin.
  • These two tracks must be evaluated separately. Bitget can fix the backend flaw and restore customer withdrawals while the attacker continues moving assets already stolen from the exchange.

    BTC withdrawals are the first live recovery test

    Bitgets official schedule says:

    • Sep. 28, 08:00 UTC: BTC / Bitcoin;
    • Sep. 29, 08:00 UTC: ETH on Ethereum, BSC, Arbitrum, Base and Optimism;
    • Sep. 30, 08:00 UTC: USDT on Ethereum, BSC, Solana and Tron;
    • Oct. 2, 08:00 UTC: other tokens, fiat and P2P.

    This report is published before the first 08:00 UTC milestone.

    Therefore, WikiBit records the status as:

    Scheduled — not yet verified operational.

    The next evidence is an actual user withdrawal broadcast to Bitcoin and sustained processing without another emergency pause.

    What Bitget says is fixed

    Bitget says:

    • the wallet-backend vulnerability has been identified;
    • it has been remediated;
    • the incident is contained;
    • no further unauthorized transfers are possible through the identified path;
    • customer account balances are unaffected;
    • deposits and trading continue;
    • Mandiant and SlowMist continue to assist.

    The exchange has ruled out a private-key compromise and describes the failure as a backend system spoofing transaction data into the authorization process.

    The incident amount remains approximately $387.5M

    Bitgets current accounting remains approximately:

    $387.5 million

    in assets transferred to attacker-controlled addresses.

    That is not the same as final unrecoverable economic loss.

    Recovery can come through:

    • issuer freezes;
    • exchange freezes;
    • voluntary return;
    • law-enforcement seizure;
    • bounty-assisted recovery.

    The XRP position has materially changed

    Earlier snapshots showed large attacker-controlled XRP balances sitting in a small number of XRP Ledger accounts.

    By September 27, a detailed public reconstruction using Bitgets published attacker addresses found the original large XRP holding accounts had effectively been emptied, with most traceable XRP routed through cross-chain swap infrastructure toward Bitcoin.

    One earlier dated snapshot found 27.63 million XRP had moved while approximately 75.35 million XRP remained. Later September 27 tracing showed the large accounts had continued to empty.

    The moving numbers should not be mixed into one static “current balance” because attacker wallets are changing continuously.

    Attacker-linked Bitcoin holdings

    At 14:28 UTC on September 27, one transaction-by-transaction reconstruction counted approximately:

    1,889.58 BTC

    in attacker-linked wallets, worth about $160 million at the prices used by that analysis.

    The same snapshot counted approximately:

    • 67,237.94 ETH;
    • 18,669.98 ZEC;
    • 10.11M ALGO;
    • smaller stablecoin/XRP balances.

    These are independent on-chain estimates, not Bitget-confirmed holdings.

    THORChain becomes a central route

    The attacker used THORChain repeatedly to convert stolen XRP/BNB/ETH-linked flows toward Bitcoin.

    A public reconstruction counted thousands of XRP deposits into THORChain vault accounts and traced substantial net XRP flow out of the XRP side of the route.

    The key risk is conversion away from assets that have stronger centralized intervention points.

    For example:

    • USDT/USDC can be issuer-frozen;
    • a centralized exchange can freeze an attacker account;
    • native BTC cannot be frozen by an issuer.

    Bitget asked THORChain to block attacker addresses

    Bitget CEO Gracy Chen publicly called for THORChain to refuse service to addresses linked to the hack.

    Reports of THORChains response say the protocol declined, citing its decentralized and permissionless design.

    GoPlus Security challenged the simplicity of that answer, arguing that THORChains vault outflows rely on validator threshold signatures and therefore involve a different operational model from Bitcoin or Ethereum.

    WikiBit treats this as a governance/policy dispute, not a settled technical fact about whether censorship is or is not possible.

    What is established is that flagged stolen assets have continued to use THORChain.

    CoinJoin and privacy routes

    The attackers Bitcoin has also begun to fragment.

    One public reconstruction traced approximately 19.23 BTC into coinjoin activity during the observed period and followed ZEC through privacy-pool and swap paths.

    Again, these are on-chain research findings.

    A coinjoin does not automatically prove that funds are unrecoverable, but it increases tracing complexity by intentionally breaking simple input-output heuristics.

    Stablecoin freezes remain small

    Tether and Circle have frozen only a small amount relative to the incident.

    Current public tracing puts linked frozen USDT/USDC in the low hundreds of thousands of dollars.

    That is useful recovery, but economically small next to the roughly $387.5M incident.

    Why the attacker's asset conversion matters to Bitget users

    Customer balances and stolen-fund recovery are separate.

    If Bitgets Protection Fund and corporate balance sheet cover customers, the attacker can still create:

    • recovery losses for the exchange;
    • operational costs;
    • legal costs;
    • future insurance/protection-fund depletion.

    The percentage ultimately recovered determines how much of the incident Bitget must absorb economically.

    Protection Fund

    Bitget says its User Protection Fund exceeded $464 million around the incident and covers the financial impact.

    WikiBit continues to treat this as a project statement until the incidents final accounting and any fund deployment are disclosed.

    Attacker attribution

    Bitget leadership has said DPRK involvement is highly likely.

    TRM Labs reported multiple on-chain links consistent with North Korean laundering infrastructure but has not definitively attributed the theft.

    Therefore:

    • DPRK attribution: Developing / high confidence by some investigators;
    • government-confirmed attribution: not established in the sources reviewed.

    Evidence Status

    Confirmed / Official Bitget

    • Incident detected Sep. 24 at 18:31 UTC.
    • Current affected-value accounting ~ $387.5M.
    • Backend transaction-data spoofing identified.
    • Private-key compromise ruled out.
    • Cold wallets unaffected.
    • Vulnerability remediated.
    • Incident contained.
    • Phased withdrawal schedule.
    • BTC scheduled Sep. 28 08:00 UTC.

    On-chain / Security / Developing

    • Large XRP balances moved through cross-chain routes.
    • THORChain used heavily in conversion toward BTC.
    • ~1,889.58 BTC attacker-linked holdings at one Sep. 27 snapshot.
    • ETH movement toward BTC routes.
    • Coinjoin/privacy-routing activity.
    • Limited stablecoin freezes.

    Contested / Developing

    • Whether THORChain could or should censor flagged addresses.
    • Final DPRK attribution.
    • Final recovered percentage.

    Risk Assessment

    Critical, with improving exchange operations but worsening recovery complexity.

    The internal exploit path is reported fixed, yet stolen assets are moving into forms that are harder to freeze. The first BTC withdrawal reopening is the next customer-facing recovery test.

    What to Watch Next

    BTC withdrawal transactions after 08:00 UTC, service throughput, attacker BTC consolidation, THORChain/other swap routes, CEX deposit freezes, ETH-wallet movement, bounty recovery and final forensic disclosure.

    FAQ

    Are BTC withdrawals already open?

    At this reports cutoff, no. They are scheduled for 08:00 UTC on September 28.

    How much did Bitget report as affected?

    Approximately $387.5 million.

    How much Bitcoin does the attacker hold?

    One independent on-chain snapshot at Sep. 27 14:28 UTC counted about 1,889.58 BTC linked to the attacker. It is a developing estimate.

    Why is THORChain important?

    Stolen assets have been converted across chains toward Bitcoin through THORChain, reducing the usefulness of issuer-level freezing.

    Did THORChain block the attacker?

    Public reporting says it declined Bitgets request, citing permissionless operation.

    Is North Korea confirmed as the attacker?

    No final government attribution is established in the sources reviewed.

अस्वीकरण

इस लेख में विचार केवल लेखक के व्यक्तिगत विचारों का प्रतिनिधित्व करते हैं और इस मंच के लिए निवेश सलाह का गठन नहीं करते हैं। यह प्लेटफ़ॉर्म लेख जानकारी की सटीकता, पूर्णता और समयबद्धता की गारंटी नहीं देता है, न ही यह लेख जानकारी के उपयोग या निर्भरता के कारण होने वाले किसी भी नुकसान के लिए उत्तरदायी है।
पिछली पोस्ट

Oil प्राइस गिरने से स्टॉक मार्केट में 10% की रैली आ सकती है, Wall Street strategist बोले

अगला

Korea के रिटेल ट्रेडर्स ने KOSPI गिरने पर भीड़ के खिलाफ $1.6 Billion की बड़ी शर्त लगाई