Bitget hackers swap Ethereum for Bitcoin via THORChain — What’s happening?
The Bitget hack has entered a new phase, with attackers now chain-hopping stolen assets.
The Bitget episode on 24th September led to $351.6 million being drained. Its culprits have now started to swap Ethereum for Bitcoin via THORChain.

Pseudonymous blockchain investigator ZachXBT reported that funds linked to the exploit are being chain-hopped through bridges and moved towards mixing services such as Wasabi.
For perspective, in chain-hopping, stolen assets are moved from one blockchain to another. This, while mixing services, is designed to make it harder to connect specific transactions with the original source.
How did Bitget attackers drain and launder funds?
ZachXBT further alleged that Chinese-speaking illicit actors are helping move the funds. And, for this they are seeking assistance through public Discord and Telegram channels.

In fact, according to a previous report by AMBCrypto, Gracy Chen claimed that the attack was likely linked to a North Korean group, citing matching IP and VPN patterns.
In a 28th September livestream, Bitget’s Chen divulged that the attackers obtained high-level internal credentials through this vulnerability and used them to access Bitget’s wallet backend. The attackers then inserted fraudulent withdrawal commands that bypassed normal risk controls, allowing roughly 380–387.5 million in assets to be transferred out.
The exec added,
This is a sophisticated targeted attack. Along the way, there isn’t any private key compromised. We don’t think it’s an inside job.
Here, it’s worth noting that the incident also stirred a debate around THORChain’s permissionless design.
THORChain rejects Bitget’s propsal
According to a recent report by AMBCrypto, Bitget’s CEO urged THORChain to block publicly identified attacker addresses. However, THORChain argued that its permissionless and decentralized design does not allow selective censorship of transactions.
The DeFi exchange noted,
A THORChain network halt is an emergency security mechanism designed to protect the protocol. A halt is not a selective freeze of specific funds or an individual swap.
The debate intensified after OKX founder Mingxing Xu argued that THORChain’s validator and threshold-signature model differ from Bitcoin’s base-layer design.
Bitget’s defense mechanism
As it stands, Bitget has identified and fixed the attack path, contained the incident, and found no further unauthorized transfers.
Moreover, BTC withdrawals have resumed while Mandiant and SlowMist continue to assist with the investigation and on-chain tracing.
Finally, the good news here is the fact that Bitget’s cold wallets and most platform assets were unaffected by the exploit. Meanwhile, user funds remain protected by its $464 million User Protection Fund as it will cover the estimated losses.
Final Summary
- The attackers obtained high-level internal credentials through this vulnerability.
- Bitget’s CEO urged THORChain to block publicly identified attacker addresses, but THORChain disagreed.