BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
Policy

AMLBot Traces 4 BTC From Bitget Hack to Wasabi

Blockchain analytics firm AMLBot says it traced approximately 4 BTC linked to the Bitget hack into Wasabi CoinJoin, a Bitcoin privacy protocol that pools transactions to obscure their origins

AnonymousCryptoCompass newsroom
September 27, 2026
4 min read
NEWS
AMLBot Traces 4 BTC From Bitget Hack to Wasabi
CryptoCompass editorial visual for policy coverage.

Blockchain analytics firm AMLBot says it traced approximately 4 BTC linked to the Bitget hack into Wasabi CoinJoin, a Bitcoin privacy protocol that pools transactions to obscure their origins. The finding puts a compliance lens on one of crypto’s most persistent tensions: the gap between following illicit funds on-chain and actually stopping them.

How AMLBot Connected the BTC to the Bitget Hack

AMLBot, a crypto compliance and blockchain analytics platform, identified a trail of roughly 4 BTC moving from wallets associated with the Bitget hack into the Wasabi CoinJoin service. CoinJoin works by combining multiple users’ Bitcoin inputs into a single transaction, making it significantly harder for investigators to trace which output belongs to which sender. For related coverage, see Coinbase Launches Fixed-Rate USDC Loans Backed by cbBTC.

The trace is notable precisely because it reached a CoinJoin entry point. Getting that far is not trivial. It means AMLBot’s attribution logic held across multiple hops before the funds disappeared into the mixing pool. What happens inside that pool is where blockchain visibility breaks down. For related coverage, see GoBTC Pay Tests Bitcoin Payments for Agentic Commerce at Agnic.AI Hackathon.

Exchange-linked security incidents like this one have drawn growing scrutiny from compliance teams across the industry. The Bybit hack earlier in 2025, which resulted in a $1.5 billion loss, triggered a similar wave of on-chain investigation and compliance response, underscoring how quickly post-hack attribution work has become standard practice.

Why a Wasabi CoinJoin Trail Raises the Stakes

Wasabi Wallet is a legitimate, open-source Bitcoin wallet that offers CoinJoin functionality as a built-in privacy feature. That legitimacy makes it a common destination for funds that need to be obscured quickly, whether by privacy-conscious users or by actors trying to break an investigative trail.

Tracing funds to a CoinJoin entry is not the same as recovering them. Once Bitcoin enters a CoinJoin round, the link between inputs and outputs is deliberately severed. An investigator can establish that funds arrived at the mixing service; establishing where they went after requires probabilistic analysis, exchange cooperation, or a lucky on-ramp back to a KYC-verified wallet.

That gap, between visibility and control, is the core problem for anyone trying to recover hacked crypto. The compliance push that followed the $1.7 billion crypto theft wave of 2025 showed that even strong attribution work rarely translates directly into asset recovery without law enforcement and exchange cooperation at multiple points in the trail.

What the Trace Means for Exchanges and Crypto Compliance

For exchanges, a hack that routes funds into a privacy tool is a compliance event as much as a security one. Compliance teams are obligated to report suspicious transaction flows to financial intelligence units, and a documented trail into a CoinJoin service gives investigators a concrete last-known location, even if it is not a final destination.

AMLBot’s role here is representative of how compliance analytics now functions in post-hack response: rapid on-chain tracing to establish fund movement before the trail cools. Firms like AMLBot monitor wallet clusters, flag addresses linked to known hacks, and attempt to follow funds across mixing hops using heuristic analysis.

The regulatory scrutiny that exchanges face around sanctions compliance extends to how they respond when hacked funds pass through their platforms or their users’ wallets. An exchange that can demonstrate it flagged and reported a Wasabi-linked inflow is in a materially different legal position than one that processed the coins silently.

The harder question is whether analytics alone can close the loop. Once approximately 4 BTC enters a CoinJoin round, the compliance record shows a trail that ends at a wall. Investigators can document the entry point. Whether they can follow the exit is a different problem entirely, and one that analytics platforms have not yet solved at scale.

Will the next generation of CoinJoin analysis tools change that calculus, or will privacy protocols continue to stay one step ahead of compliance infrastructure?

Additional source references: source document 1, source document 2.

Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.

The article AMLBot Traces 4 BTC From Bitget Hack to Wasabi first featured on theccpress.com.