I kept coming back to one number that felt almost rude in its smallness. Five days after an exchange said attackers had walked off with about $387.5 million, the publicly visible freezes added up to roughly $840,000. That is around 0.2 percent. Not a rounding error in the poetic sense. A rounding error in the literal sense. If you have ever watched a large theft and assumed someone, somewhere, would slam a door shut, this case is a useful correction. The door mostly stayed open, and the money changed clothes.
The breach began on September 24. Ordinary customer withdrawals were not the path. The exchange later said a flaw in a third-party security product handed over high-level internal credentials, and those credentials were used to push forged withdrawal commands straight into the wallet system. Private keys, it said, were not taken. Cold storage stayed out of reach. Hot and warm wallets did not. That distinction matters more than the press-release tone suggests, because it tells you what kind of failure this was: access and process, not a cartoon villain cracking a seed phrase on a laptop.
What Actually Left The Building
Early estimates put the loss near $351.6 million. The figure later widened to about $387.5 million once Zcash and Tron movements were folded in. Security researchers counting published tracker addresses landed on 13 stolen assets across 12 chains. XRP was the largest single-chain slice. I find that detail easy to miss, because the later story is so dominated by Bitcoin that people forget the theft started as a messy, multi-chain grab.
The opening moves were small, which is a classic tell. At 18:31 UTC the first transactions were tiny test transfers: 0.84 ETH and 93 TRX. Larger withdrawals began at 18:58 UTC. The reconciliation system noticed a mismatch seven minutes after that and blocked ordinary customer withdrawals. Seven minutes is fast for a human desk and slow for a script. By then the test had already worked.
Independent forensic reviews later backed the exchange’s account that compromised third-party security software opened the wallet environment. I am not interested in turning that into a morality play about vendors. The practical lesson is narrower. If a tool sitting beside your signing flow can mint authority, your “keys were safe” sentence is only half a sentence.
Why Freezable Coins Went First
Assets an issuer can freeze are a liability if you are the thief and a brief window if you are the issuer. Researchers found roughly $75.48 million in USDT, USDC and USDT0, plus 3,000 XAUt tokens, converted into ETH or AVAX within 41 minutes of the theft. Routes included large decentralized exchanges, an intent-style swap system, an aggregator, and a wallet’s built-in swap. All of that, they said, finished before the chief executive publicly disclosed the breach.
Forty-one minutes. That is the part I would tape above a compliance desk. Disclosure timelines, status pages, and carefully worded posts are downstream of a clock the attacker already started. Once a stablecoin becomes ether or avalanche, the issuer’s freeze button is mostly a souvenir.
The freeze that arrives after the swap is a press release, not a recovery.
Perhaps the most interesting aspect is how ordinary the tools were. No exotic bridge invented for the occasion. Familiar swap venues, used quickly, before the public even had a name for the incident. Speed beat branding.
A Snapshot, Not A Final Ledger
The tracing picture that circulated came from addresses on the exchange’s tracking dashboard and a September 29 snapshot. Balances after that date can move. Anyone treating a five-day cut as a closing balance is going to be wrong by Thursday. I have found that readers still want a still frame, so here is the still frame, with the caveat stapled to it.
- About $342 million still sat in wallets researchers linked to the attacker, roughly 88.3 percent of the stolen amount.
- Bitcoin made up about 83.7 percent of that remaining balance, near 3,386 BTC.
- Publicly visible freezes from stablecoin issuers and one intent service clustered around $840,000.
- Pass-through value on one major cross-chain network was estimated near $269 million across 7,804 transactions. That is not a separate pile of stolen money.
Read the last bullet twice. Pass-through value counts the same coins as they hop. Adding every protocol total into one grand sum is how rumor threads invent a billion-dollar ghost.
Three Paths, One Preference For Bitcoin
Researchers described three habits, not three neat piles. First, convert anything an issuer might freeze. Second, pull value from several chains into Bitcoin. Third, drip some of that Bitcoin into CoinJoin-style mixing. The preference for Bitcoin is not a mystery if you have watched prior mega-thefts. Bitcoin is deep, portable, and awkward to freeze at the protocol layer. It is also where a certain kind of laundering service already lives.
By the September 29 cut, attacker-linked wallets still held the bulk. That does not mean the coins were idle in one address with a bow on it. Control can mean a swarm of wallets, some already mid-swap, some parked, some peeled. “Still held” is an estimate of custody, not a photograph of a single vault.
How The Cross-Chain Leg Worked
Once the freezable tokens were out of their original clothes, value started hopping chains. The largest route researchers identified ran through a well-known decentralized swap network: about $269 million in pass-through value and 7,804 transactions by that snapshot. A second protocol handled roughly $37.27 million. Other legs touched a stablecoin messaging system, a native burn-and-mint bridge, and two general messaging or liquidity routes. Same warning as before. Overlap is the rule, not the exception.
The exchange publicly asked that network to reject known attacker addresses. The argument, in plain language, was that decentralization is a design choice, not a costume you put on when stolen funds arrive. The network declined. Its emergency halt, it said, exists to protect the protocol as a whole. It is not a selective freeze of one user or one swap.
An emergency halt is not a selective freeze of a specific transaction or user.
Position attributed to the cross-chain network after the request
You can disagree with that stance and still understand the engineering claim. A halt that can be aimed at one address is a blacklist with extra steps. A halt that stops everyone is a blunt instrument the operators are reluctant to swing, because it punishes unrelated users and advertises a kill switch. I have watched this argument recycle after every large theft. It never gets cleaner. It just gets louder.
After the public request, a wallet linked to the incident still swapped about $6.3 million of ETH into Bitcoin on that same route. Twenty-seven swaps produced roughly 75.2 BTC. Whether you read that as defiance or as business as usual depends on how romantic you are about permissionless systems. The chain did not care either way.
The Tiny Freeze, Explained Without Comfort
Stablecoin issuers immobilized around $340,000. A lot of that money stayed at addresses long enough to be answered. That is the unglamorous truth of issuer freezes. They work on coins that have not finished running. They do not reach backward through a completed swap into ether, and they do not reach into Bitcoin at all.
A separate intent service said its risk system caught attempts to route more than $50 million. A review of that disclosure found about $503,000 stopped during execution, while around $166,000 passed. The service itself flagged an error margin up to 10 percent. Earlier notes on the same episode said some funds sat in pending transactions after being flagged mid-swap. Pending is not the same as returned. Pending is a hallway.
Add the issuer freezes to the stopped intent flow and you land near $840,000. Against $387.5 million, the percentage is the number people quote because it stings. I would not treat it as proof that nobody tried. I would treat it as proof that the attacker’s first hour was the one that counted.
| Slice of the story | Rough figure | What it actually means |
| Reported theft | $387.5 million | Expanded total after Zcash and Tron were included |
| Still attacker-linked after five days | About $342 million | Estimate from a September 29 snapshot, not a final balance |
| Share sitting as Bitcoin | About 83.7 percent | Near 3,386 BTC inside that remaining estimate |
| Largest cross-chain pass-through | About $269 million | Value moving through one network, with double-counting risk |
| Second cross-chain route | About $37.27 million | Another hop, not a new theft |
| Issuer freezes | About $340,000 | Stablecoins that had not fully escaped |
| Intent service stop | About $503,000 | Caught in execution; margin of error up to 10 percent |
| CoinJoin inflows by snapshot | About $3.94 million | Early mixing, not the whole Bitcoin pile |
Tables like that are a mercy and a trap. Mercy, because the scale stops being a blur. Trap, because a reader skims the left column and walks away thinking every row is a separate pot of cash. It is not.
CoinJoin, Peel Chains, And The Slow Fade
By September 29, about $3.94 million had entered CoinJoin transactions. One September 27 join had 356 inputs and 401 outputs. Four inputs of 2.5 BTC each came from addresses the exchange tracker tied to the attacker. That is a small slice of 3,386 BTC. It is also the start of the part tracers hate, because a join is built to blur ownership, not to announce it.
Separate tracking described a route that began on Tron, passed through Ethereum and the big cross-chain swap, landed in Bitcoin, and only then met a mixer. That sequence is almost a template now. Chain of origin, neutral hop, Bitcoin, then noise. If you have followed exchange incidents for a few years, the template feels tired. Tired does not mean ineffective.
Analysts also pointed at peel-chain behavior, the habit of shaving a little value off a large holding and sending the rest onward, again and again, so no single transfer looks like the whole haul. Peel chains show up in plenty of crimes that have nothing to do with any one state. They are a technique, not a signature carved into the block. Worth noting. Not worth a conviction.
The North Korea Question, Held At Arm’s Length
North Korean involvement has been floated. It has not been confirmed by any law-enforcement agency in public, as of the latest verified updates around this incident. The chief executive said IP behavior and on-chain patterns were consistent with techniques used by groups linked to that state. The exchange said some IP addresses matched VPN infrastructure previously associated with such a group. The technical comparison behind that claim was not published.
Other possible echoes showed up in the laundering, not in a signed confession. Overlap with methods seen in attacks attributed to a known state-linked operation. Heavy use of the same cross-chain network to reach Bitcoin. A peel-chain style that chain analysts often mention alongside those operations. Independent tracers also identified several Chinese-speaking underground money launderers they believed were handling funds, including one who had reportedly shown up around an earlier exploit.
Security researchers warned against treating resemblance as identity. Laundering shops work for more than one client. Open protocols are open. Reuse of a cash-out crew is a weaker claim than “the same operators did the break-in,” and it is also the claim the evidence supports more cleanly. In my experience, comment sections collapse that distinction in about four replies.
The comparison that keeps returning is a 2025 theft at another major exchange, about $1.5 billion, which U.S. authorities formally tied to a state-linked operation, with the same style of cross-chain conversion into Bitcoin. Formal attribution there does not travel backward onto this case. It explains why people reached for the analogy. Analogy is not attribution.
What the public record supports: Access via third-party security software Forged withdrawals, keys reportedly intact Fast exit from freezable assets Bitcoin as the consolidation asset What it does not yet support: A named state actor A closed recovery number A single protocol “holding” the whole theft
What The Exchange Says Happens Next
Tracing continues, alongside a recovery bounty. Qualifying participants are offered 5 percent of funds they directly help freeze and another 5 percent of funds actually recovered. That structure is more interesting than the headline percentage. Freeze and recovery are different jobs. One is a block. The other is getting coins back into a controlled wallet. Paying both admits that a blacklist entry is not the same as a returned balance.
Forensic work, exchange cooperation, and law-enforcement contact were already underway when the bounty went live. Bitcoin, ether, and USDT withdrawals came back in phases. The published schedule put other tokens, fiat withdrawals, and peer-to-peer services at 08:00 UTC on October 2, though a separate confirmation on the incident page had not been posted when that schedule was last checked. User balances, the exchange says, were unaffected. The exploited flaw, it says, is fixed. Further findings are promised through official security updates.
I will believe the “unaffected balances” line in the narrow accounting sense: customer ledgers were made whole from the company’s side, or were never debited by the forged commands. I will not read it as “the market is unchanged.” A nine-figure hole in hot and warm wallets is a balance-sheet event even if the app still shows your number.
Why So Little Stuck To The Freeze Tools
People ask this as if the answer should be a villain. The answer is mostly timing and asset choice. Coins with an admin key were swapped before the admin key was used. Coins without an admin key were walked toward Bitcoin, where admin keys do not exist. Cross-chain networks that refuse selective blocks did what their operators said they would do. Mixers started taking a trickle, not the whole stack, which means the visible freeze window was already behind the bulk of the value.
There is a second, quieter reason. Public freezes are the freezes someone announces. A private request to a venue, a delayed withdrawal at a centralized shop, an account quietly locked, none of that has to show up in a five-day on-chain note. The $840,000 figure is the visible slice. It is not a certificate that 99.8 percent is gone forever. It is a certificate that 99.8 percent was not publicly immobilized in that window.
- Test transfers proved the forged-command path before the large pulls.
- Freezable assets were swapped inside the hour, ahead of public disclosure.
- Value was bridged and swapped toward Bitcoin across several protocols.
- A minority of stablecoins and one intent flow were stopped.
- A smaller Bitcoin slice entered CoinJoin while most BTC remained in linked wallets.
That order is the whole plot. Everything else is commentary.
What This Does To The Old Hot-Wallet Story
Exchanges have spent years telling users that cold storage is the grown-up room and hot wallets are the till. This incident fits that sermon and also pokes a hole in it. Cold wallets were reportedly untouched. The loss still cleared $387 million, because the till was large, the warm layer was in scope, and the authority to move funds did not require stealing the key material itself. A third-party security product became the interesting door.
If you custody coins on an exchange, you are not auditing that vendor stack. You are trusting that the exchange did. After a week like this, “we use industry-standard security tooling” is not a soothing phrase. Industry-standard is where the bug lived.
Does that mean self-custody wins by default? Not for everyone, and I am not going to pretend a seed phrase on a scrap of paper is a risk-free personality. It means the failure mode to price in is operational access, not only a dramatic key leak. Forged commands from a trusted internal path will empty a hot wallet whether or not the marketing site has a picture of a steel plate.
A Reader’s Map Of The Money
Strip the jargon and the flow looks like this. Money leaves hot and warm wallets on several chains. Anything with a freeze switch is sold or swapped for something without one. Those proceeds, plus assets that never had a switch, are pushed through cross-chain venues until they look like Bitcoin. Some Bitcoin is joined with other people’s coins to blur the trail. Most of it, five days in, is still in wallets the tracers are willing to call attacker-controlled. A thin crust has been frozen or stopped. The rest is a moving target.
Where did the stolen $387 million go? Mostly toward Bitcoin, through pipes that do not do selective freezes, with a small amount stuck in issuer blacklists and a risk system, and a smaller amount already inside mixing transactions. That is the honest short version. The long version is the snapshot, the overlap warning, and the open attribution file.
Visible freeze / reported theft ≈ 840,000 / 387,500,000 ≈ 0.22%
I include that ratio because people argue about adjectives. “Almost none” is an adjective. The ratio is the thing.
What To Watch Without Refreshing Every Rumor
Later movement will matter more than the first week’s adjectives. Watch whether linked Bitcoin starts hitting larger joins, whether fresh clusters appear after a hop through a service that does not publish addresses, and whether any centralized venue announces a seizure rather than a tweet. Watch the bounty claims too. A real recovery will have a transaction, a court paper, or a painfully specific wallet note. A vibe will not.
Also watch the withdrawal reopening with a colder eye than the status page invites. Phased returns of BTC, ETH, and USDT are a sign the matching engine and the treasury desk can function. They are not a sign the forensic story is finished. An exchange can pay customers and still be arguing with insurers, vendors, and investigators about the hole.
One more thing I would not outsource to a headline: the identity question. Until a public agency attaches a name, the careful sentence is the one researchers already used. Patterns can match. Laundering crews can be shared. That is not the same as proving who sat at the keyboard on September 24.
The Part That Should Annoy You
The annoying part is not that a cross-chain network refused a blacklist. You can see that refusal coming from the design docs. The annoying part is the first hour. Test transaction, larger pull, stablecoins gone, public post still in draft. Everything after that is cleanup theater relative to the opening act. Freezes, bounties, dashboard maps, arguments about decentralization: all of it is downstream of 41 minutes.
If there is a useful opinion to leave you with, it is this. Treat “we will trace it” as a process, not a promise of return. Treat “cold wallets were safe” as a boundary, not a comfort. And treat any single protocol total as a route, not a pile, until someone shows you the addresses without double-counting the hops.
The money did not vanish. It changed chains, changed tickers, and started to fray at the edges. Five days on, most of it still had a trail. Trails are not the same as handcuffs, and handcuffs are not the same as a deposit back in the till. That gap, more than any one wallet label, is where the $387 million actually went.