The security firm BlockSec, which has tracked the movement of the stolen assets, estimates that roughly $342 million remained under the attackers' control as of late September. The laundering operation relied heavily on THORChain, which processed approximately $269 million in pass-through value, allowing the perpetrators to consolidate diverse tokens into Bitcoin. Despite direct appeals from Bitget CEO Gracy Chen to halt transactions associated with the breach, THORChain maintained that its protocol is designed to operate without selective censorship, leaving the stolen funds to continue flowing through privacy-focused CoinJoin transactions.
While suspicions regarding the identity of the attackers have turned toward North Korean-linked groups—citing similarities in IP behavior and the use of specific peel-chain techniques—no law enforcement agency has formally confirmed this attribution. The exchange, which has since restored most withdrawal services, maintains that its own cold wallets remained secure during the incident. Instead, the breach was facilitated by forged withdrawal commands submitted through high-level credentials gained by exploiting a third-party security product. As the investigation continues, Bitget has launched a recovery bounty, offering a 10% reward for assistance in freezing and returning the remaining assets.

Comments (0)
No comments yet. Be the first!