TLDR: AMLBot traced about 4 BTC into a Wasabi CoinJoin after the funds moved through TRON, Ethereum and THORChain. About $343.2M, or 88.1% of roughly $389.4M tracked by AMLBot, remained dorma
TLDR:
- AMLBot traced about 4 BTC into a Wasabi CoinJoin after the funds moved through TRON, Ethereum and THORChain.
- About $343.2M, or 88.1% of roughly $389.4M tracked by AMLBot, remained dormant across 13 attacker wallets.
- Bitget raised its confirmed loss estimate to $387.5M after adding previously uncounted Zcash and TRON assets.
- Bitget will resume withdrawals on September 28 with Bitcoin, with broader restoration through October 2.
Funds linked to the Bitget security breach have started entering Bitcoin privacy infrastructure, adding a new layer to investigators’ efforts to follow stolen assets. AMLBot reported on September 27 that roughly 4 BTC entered a Wasabi CoinJoin after moving through several assets, blockchains, and cross-chain services.
The movement covers only a small fraction of the theft. Meanwhile, about $343.2 million of tracked assets remained dormant across attacker-controlled wallets.
Attacker Routes Funds From TRON to Bitcoin
According to AMLBot, the transaction path began with a Bitget-linked TRON wallet before the attacker converted TRX into USDT. The USDT was then bridged to Ethereum through USDT0, where the funds were exchanged for approximately 145 ETH.
Those assets later moved through THORChain and produced about 4.59 BTC, extending the trail from TRON to Ethereum and then Bitcoin. The attacker subsequently divided the BTC into smaller amounts before roughly 4 BTC entered a Wasabi CoinJoin round.
Wu Blockchain separately reported the same transaction path, while CertiK’s security feed also recorded AMLBot’s finding. Wasabi describes CoinJoin as a Bitcoin transaction that combines inputs from several participants and creates multiple new outputs.
That structure weakens the visible connection between individual inputs and outputs, making the origin-to-destination relationship harder to establish directly from blockchain records. However, CoinJoin participation does not indicate wrongdoing by other users as the privacy method is designed for general Bitcoin transactions.
For investigators, attribution matters as CoinJoin reduces the clarity of subsequent transaction paths. AMLBot said it blacklisted associated addresses and would keep monitoring the funds for additional CoinJoin activity.
$343M in Bitget Hack Funds Remains Dormant Across 13 Wallets
Despite the latest movement, most funds linked to the Bitget breach remained dormant in AMLBot’s September 25 assessment. The firm estimated that about $343.2 million, representing 88.1% of roughly $389.4 million tracked, had not moved across 13 attacker wallets.
Those wallets held about 68,300 ETH across eight addresses, nearly 83 million XRP across four wallets, and around 18,900 ZEC elsewhere. That concentration leaves the latest privacy movement small compared with assets remaining stationary across the attacker wallets.
Bitget’s accounting was slightly lower, with the exchange confirming approximately $387.5 million transferred to attacker-controlled addresses. That figure revised an earlier $351.6 million estimate after additional Zcash and TRON assets were included in the total.
Bitget said the underlying vulnerability had been identified and remediated, while Mandiant and SlowMist continued assisting with the investigation. Withdrawals are scheduled to resume gradually from September 28, starting with Bitcoin, before broader restoration continues through October 2.
The CoinJoin activity therefore represents the clearest confirmed movement into privacy-focused infrastructure so far, while most tracked stolen assets remain unmoved.
The post Bitget Hacker Moves 4 BTC Into Wasabi CoinJoin as $343M Stays Dormant appeared first on Blockonomi.