Bitget Hack Funds Reach Wasabi CoinJoin After Cross-Chain Moves

11 min read
1 views
Sep 27, 2026

Only a sliver of the Bitget theft has started moving. Analysts just tied about four bitcoin to a CoinJoin round after a messy multi-chain route. Most of the pile is still sitting still, and that quiet is the part that should worry you.

Financial market analysis from 27/09/2026. Market conditions may have changed since publication.

Four bitcoin does not sound like much when the headline number sits near four hundred million dollars. That is exactly why this latest trail is worth sitting with. A sliver of funds tied to the late September exchange breach has now been followed through several networks and into a Wasabi CoinJoin round. The rest of the pile, by most public estimates, has barely twitched. I have covered enough of these incidents to know that the first small movement is rarely the whole story. It is usually a test run.

What The Latest Tracing Actually Shows

Blockchain analysts say they can connect roughly 4 BTC inside one CoinJoin transaction back to a TRON wallet linked to the theft. That is not a courtroom verdict. It is an on-chain attribution. Public ledgers show hops, swaps and bridges. People then infer intent from the pattern. Sometimes that inference is tight. Sometimes it is a best guess dressed up as certainty.

Still, the route itself is messy enough to take seriously. The path did not stay on one chain. It jumped. TRON first. Then a stablecoin hop. Then Ethereum. Then a cross-chain swap into bitcoin. Then smaller cuts. Then a mixing round. If you have ever tried to follow stolen coins by hand, you already know how quickly that sequence turns into a headache.

A Short Route Map Without The Jargon Fog

Here is the sequence as currently described by compliance researchers, stripped of the usual buzzword pile-up.

  1. Assets start on TRON and get converted from TRX into USDT.
  2. Those tokens move toward Ethereum through an omnichain form of Tether often labeled USDT0.
  3. On Ethereum, the stack is swapped into about 145 ETH.
  4. The ETH then travels through a cross-chain liquidity network and comes out as roughly 4.59 BTC.
  5. The bitcoin is split into smaller pieces before entering a Wasabi CoinJoin round.
  6. Analysts say they can still tie about 4 BTC in that round back to the original TRON wallet.

That last step is the part people will argue about in comment threads. CoinJoin is not magic. It is a coordination trick. Several participants put inputs into one transaction and take outputs out of the same transaction. A casual observer cannot casually say output A belongs to input B. That is the point. It does not erase history. It just makes the mapping expensive and imperfect.

Mixing does not delete a theft. It only raises the cost of saying, with confidence, where each coin went next.

In my experience, that cost is exactly what thieves are buying. Not invisibility. Friction.

Why Four Bitcoin Still Matters

Because it is a signal, not a settlement. If most of the stolen stack is still sitting in a handful of wallets, a small bitcoin slice moving through a mixer can mean the operator is probing rails. Can this route clear? Do any counterparties freeze? Does the mixer set even complete? Does anyone tag the outputs fast enough to matter?

Think of it like a scout party. You do not send the whole army through the first mountain pass. You send a few riders and watch who notices.


The Loss Number Keeps Getting Revised

The first public figure after the September 24 incident sat around $351.6 million. That number did not hold. A later classification put assets moved to attacker-controlled addresses closer to $387.5 million. The exchange has said the jump was not a second heist. Investigators simply found more Zcash and TRON exposure that had been missing from the first tally.

That kind of revision is painfully common. Hot and warm wallet incidents are ugly in real time. Teams are counting under pressure. Some tokens sit on quieter rails. Some balances look dormant until someone opens the right dashboard. I would rather see an upward correction with an explanation than a pretty number that never moves again.

Affected assets reportedly included ETH, XRP, USDT, USDC, USDT0, ZEC, XAUt, BNB, AVAX and TRX. That list alone tells you this was not a single-chain smash and grab. It was infrastructure-level access across several ledgers.

ItemReported figureWhy it matters
Initial transferred valueAbout $351.6 millionFirst public snapshot after detection
Revised attacker totalAbout $387.5 millionAdded Zcash and TRON assets from the same incident
Mostly untouched stackAbout $343 millionLarge share still sitting in attributed wallets
CoinJoin sliceAbout 4 BTCSmall moving piece after multi-chain conversion
Protection fund citedMore than $464 millionExchange says customer balances stay whole

Those rows will age. Prices move. Attributions change. Treat the table as a snapshot of the current public story, not a carved tablet.

Detection, Pause, And The Wallet Layer

The exchange said it spotted unauthorized transfers at 18:31 UTC and halted withdrawals while leaving deposits and trading up. Cold storage, according to the company, stayed intact. That last claim is the one every customer reads twice. If the deep vault is untouched, the damage is operational and reputational rather than existential. If the deep vault is not untouched, the conversation changes overnight.

Preliminary comments pointed toward backend wallet infrastructure rather than a simple private-key leak. The chief executive has said keys remained secure while the team hunted the exact intrusion path. Later, the company said it found the attack path, understood how controls were bypassed, and patched the underlying flaw. A full public root-cause paper has not been released. That absence will bother security people, and it should.

Perhaps the most interesting part is the tone of the language. “Backend wallet infrastructure” is a polite way of saying the machines that assemble and authorize hot transfers were in play. You can keep keys in a nice ceremony and still lose coins if the system that decides when those keys get used is compromised.

Most Of The Money Has Not Moved

This is the detail that keeps me up more than the mixer headline. A September 25 tracing update put about $343 million in a holding pattern, described as roughly 88 percent of a tracked pile near $389 million. Thirteen wallets were called out as dormant. No outgoing spend since they received the loot.

  • Eight Ethereum wallets holding around 68,300 ETH
  • Four XRP addresses holding around 83 million XRP
  • One wallet holding close to 18,900 ZEC

Dormant does not mean safe. It means unused. Thieves wait for heat to drop. They wait for bridges to loosen. They wait for a market dip that makes conversion cheaper. They wait for a legal process to stall. Sitting still can be a strategy.

Separate researchers also described stolen USDC being shifted and converted into ETH after the attack. Stablecoins are a special case because an issuer can freeze tokens at named addresses when a qualifying order arrives. Whether that order exists in this case is not something a public explorer can tell you. The chain only shows movement. It does not show courtrooms.

How CoinJoin Changes The Hunt

Let me be blunt. CoinJoin is a privacy tool with a dual use problem. Ordinary users reach for it because bitcoin’s default ledger is too transparent for comfort. Criminals reach for it because that same transparency is a problem for them too. The software does not ask for a motive. The transaction just happens.

Wasabi-style rounds typically try to standardize output amounts so that many people exit with similar-looking coins. That sameness is the camouflage. If twenty people leave with 0.1 BTC outputs, you cannot point at one of those outputs and shout a name. You can still watch what happens next. You can still cluster later behavior. You can still get lucky when someone cashes out sloppily at an exchange that actually checks origin risk.

Compliance firms will blacklist linked addresses and keep watching for another round. That is the predictable next step. Blacklists are useful and incomplete. Coins move. New addresses appear. Heuristics break. Anyone who tells you a mixer is either invincible or useless is selling a simple story.

What tracing can show:
  hops between addresses
  swap routes and bridge events
  timing clusters
  reused change patterns

What tracing cannot prove by itself:
  the human identity behind a key
  the legal purpose of a transfer
  whether a freeze order exists
  the final cash-out destination

Cross-Chain Hops Are The Real Headache

The TRON-to-Ethereum-to-Bitcoin path is more important than the mixer brand. Each hop changes the investigative toolkit. TRON analytics is not Ethereum analytics. Bitcoin clustering is not the same as watching a smart-contract swap. THORChain-style conversions add another layer because the liquidity network is designed to move value without a conventional centralized custodian sitting in the middle of every hop.

I’ve found that readers often treat “bridged” as a synonym for “gone.” It is not gone. It is translated. Translation creates seams. Seams are where good analysts live. A sloppy swap, a reused destination, a timing overlap, a memo field, a residual dust output. Those little leftovers are how 4 BTC still gets tied backward to a TRON wallet after all that theater.

Is the attribution perfect? No. Could later research revise the link? Yes. That uncertainty belongs in the article, not in a footnote nobody reads.

What The Exchange Says It Will Do Next

Withdrawals are scheduled to return in phases. Bitcoin first, at 08:00 UTC on September 28. Ether on several networks the next day. USDT on a set of chains the day after that. Broader token, fiat and peer-to-peer flows are penciled in for October 2. Outside security firms have been named as helpers on the investigation while internal teams validate the withdrawal stack.

A live briefing from the chief executive is planned for 07:30 UTC on September 28. That timing is not accidental. It sits just before bitcoin withdrawals reopen. Customers will want two answers at once. Is the hole closed. And can I leave if I want to leave.

The company also says a protection fund will cover the financial hit and that account balances remain unchanged. During the pause the fund was described as holding more than $464 million. A proof-of-reserves update published before the breach showed a 135 percent reserve ratio across 19 covered assets, with a stated floor of at least one-to-one for assets inside the program. Those figures will be picked apart. They should be. A ratio on a slide is not the same thing as cash in the right wallet on the right day.

A Bounty Mentality After The Fact

After large thefts, platforms often dangle a percentage for anyone who can freeze or recover funds. It is part recovery tactic, part public relations. Sometimes it works because an intermediary wants the reward more than the risk. Sometimes it does nothing except generate screenshots. I am skeptical of bounty theater when the bulk of the coins has not moved. The people holding 68,000 ETH are not filling out a tip form this week.

That said, the moving 4 BTC is exactly the kind of slice where a freeze-or-flag campaign can still matter. Once coins enter a mixer, the window gets narrower. After they leave, the window is a set of new outputs and a lot of guessing.

What This Means If You Keep Coins On An Exchange

I do not enjoy the lecture voice, so I will keep this short and a bit blunt.

  • Hot and warm wallets exist because customers want instant withdrawals. Instant is a tradeoff.
  • A pause on withdrawals is painful and, in a live incident, often the least bad option.
  • Proof of reserves is useful and still not a substitute for withdrawal capacity under stress.
  • Protection funds are only as good as the assets inside them and the rules around payouts.
  • Leaving a long-term stack on a trading venue is a business decision, not a law of nature.

None of that is a call to panic-sell into a thin book. It is a reminder that custody is a product. Products fail. When they fail, the people who treated an exchange balance like a vault learn an expensive vocabulary very quickly.

The Quiet Politics Of Mixers

Every time stolen bitcoin touches a CoinJoin, the policy argument wakes up. One camp says privacy tools are oxygen and should not be judged by their worst users. The other camp says any tool that regularly shows up in theft traces should face tighter chokepoints. Both camps are talking past the actual mechanics.

If you ban a named desktop mixer, the next operator uses a different coordinator, a different amount denomination, or a different chain entirely. If you ignore mixers, stolen coins get cheaper to park. The adult version of this debate is about on-ramps and off-ramps. The dangerous moment is rarely the CoinJoin itself. It is the later attempt to turn mixed outputs into spendable value at a regulated desk.

That is why I watch cash-out behavior more closely than the first mixer headline. Four bitcoin in a round is a breadcrumb. The bakery is wherever those outputs try to become dollars, goods, or fresh clean UTXOs months from now.

Questions That Still Do Not Have Clean Answers

Was the intrusion a compromised internal service, a poisoned dependency, a social-engineering wedge into wallet operations, or something quieter? The public still does not have a complete technical narrative. “We found the path and fixed it” is a statement, not a post-mortem.

Will the dormant wallets stay dormant through the withdrawal reopening? Reopenings change the noise on a network. Attackers sometimes move when attention shifts. Sometimes they wait even longer.

Can any of the stablecoin portion still be frozen in a useful way? That depends on legal process and issuer policy, not on a Twitter thread.

And the awkward one. If customer balances are truly unchanged because a fund absorbs the loss, who ultimately pays for that absorption over the next year? Fees, spreads, slower listings, tighter risk limits. Losses do not vanish. They get allocated.

A covered loss is still a loss. The only question is which balance sheet wears it, and for how long.

How To Read The Next Few Days Without Getting Spun

Watch three clocks. The AMA. The bitcoin withdrawal reopen. The first large movement out of those thirteen quiet wallets. Everything else is color.

If withdrawals resume on schedule and nothing new leaves the attributed stash, the story becomes operational recovery. If withdrawals slip, the story becomes trust. If the quiet wallets wake up during the reopen, the story becomes a chase again. Simple framework. Easy to forget once the quote tweets start flying.

I would also treat any sudden “full recovery” claim with a raised eyebrow until addresses, transaction IDs and independent confirmations line up. This industry loves a victory lap. The chain is less sentimental.

A Plain-Language Recap You Can Keep

A large September breach moved hundreds of millions to addresses tied to an attacker. The confirmed total was later raised after more assets were counted, not because a second raid landed. Most of that value has sat still. A much smaller stream was converted across TRON, Ethereum and a cross-chain bitcoin swap, then pushed toward a CoinJoin round. Analysts say about four bitcoin in that round still link backward. The exchange says the hole is patched, withdrawals will return in stages, and a protection fund will keep user balances whole.

That is the state of play. It is incomplete. It is already being simplified in headlines. Resist the simplification. Four bitcoin in a mixer is a clue. Three hundred million sitting quiet is the weight.

If you trade on the venue, decide your own custody comfort before the comment section decides it for you. If you just follow the market, keep an eye on whether this stays an isolated operations failure or turns into another week of forced selling and rumor spikes. Those are different movies. They just happen to share the same opening scene.


One last thought, and then I will get out of your way. The industry keeps promising that the next security stack will be boring. Boring would be a gift. What we keep getting instead is another multi-chain treasure map and another press note that says the keys were safe while the machinery around the keys was not. Until that gap closes, four bitcoin through a CoinJoin will keep feeling less like an ending and more like a first footprint on a longer trail.

❝
The stock market is the story of cycles and of the human behavior that is responsible for overreactions in both directions.
— Seth Klarman
Author

Steven Soarez passionately shares his financial expertise to help everyone better understand and master investing. Contact us for collaboration opportunities or sponsored article inquiries.

Related Articles

?>