0x64f284d564f2…64f284d8

ConfirmedSecurity701 vB157 sat/vB4 min decode

Bitget Resumes Withdrawals After $387M Hack as THORChain Debate Erupts

Bitget processed 9,585 withdrawals totaling 4,098 BTC after reopening, ending a four-day freeze tied to a $387.5 million exploit. ZachXBT links the laundering ring to North Korea as THORChain faces scrutiny over fees from illicit flows.

Outputs

  1. Bitget processed 9,585 withdrawal orders totaling 4,098.036 BTC on Sept. 28 after reopening Bitcoin withdrawals.

  2. DeFiLlama-tracked Bitget reserves fell by 4,642 BTC, from 35,412 BTC to 30,770 BTC, roughly $391 million at prevailing prices.

  3. GoPlus estimates 101.5 BTC (~$8.5M) and 27.63M XRP (~$43M) from the exploit have already moved through THORChain.

  4. ZachXBT linked the laundering network to North Korea and the TraderTraitor campaign, citing behavior similar to the $292M Kelp DAO exploit.

  5. Bitget's Protection Fund will be replenished with internal capital to more than $300 million within one week.

Bitget processed 9,585 withdrawal orders totaling 4,098.036 BTC in the first hours after reopening Bitcoin withdrawals on Sept. 28, CEO Gracy Chen said in a post on X. The restart ended a four-day freeze tied to the exchange's $387.5 million hack, its largest security incident in eight years.

Bitget resumed Bitcoin withdrawals at 08:00 UTC after completing additional checks on its withdrawal infrastructure. Ethereum withdrawals are scheduled for Sept. 29, USDT for Sept. 30, and remaining tokens, fiat, and peer-to-peer services for Oct. 2.

What does the reserve data show?

DeFiLlama-tracked Bitcoin holdings attributed to Bitget fell to roughly 30,770 BTC from 35,412 BTC over the same window, a decline of about 4,642 BTC, or $391 million at prevailing prices. The drop exceeds the amount Chen confirmed had moved through customer withdrawal orders, a gap that may reflect wallet coverage changes or internal address reshuffling rather than retail outflows alone.

Chen said customers will bear no losses from the incident, with the company's Protection Fund covering the shortfall. She added that Bitget plans to replenish the fund with internal capital to more than $300 million within a week.

How did the attackers breach Bitget?

Chen said a completed internal trace found that attackers exploited vulnerabilities in third-party products to obtain internal credentials. Those credentials were then used to submit fraudulent withdrawal instructions that bypassed Bitget's risk controls, she wrote.

The exchange has since isolated affected systems, revoked and reissued internal credentials, and restructured access to sensitive infrastructure. Bitget disabled the affected third-party functionality while the vendor works on a patch. Mandiant and SlowMist continue to assist with forensic analysis and tracing.

Bitget previously said the incident involved a critical backend system in its wallet infrastructure and that it had remediated the vulnerability before withdrawals resumed.

Where are the stolen funds moving?

Blockchain investigator ZachXBT said Chinese illicit actors were laundering proceeds on behalf of hackers he described as allegedly linked to North Korea. He identified chain-hopping and deposits into mixing services, including Wasabi.

ZachXBT also linked one participant in the laundering network to wallet movements following the $292 million Kelp DAO exploit earlier this year, citing similar behavior after attacks attributed to the TraderTraitor campaign.

Security firm GoPlus estimated that roughly 101.5 BTC, worth about $8.5 million, had already exited through THORChain from the Bitget exploit. Another 27.63 million XRP, valued near $43 million, was being converted into Bitcoin through the same protocol.

Why is THORChain at the center of the dispute?

The laundering flow has put the cross-chain swap network at the heart of a debate over whether permissionless infrastructure should intervene when stolen assets pass through its systems. THORChain has said it would not selectively block wallets or swaps, framing its role as comparable to censorship-resistant networks such as Bitcoin and Ethereum.

GoPlus challenged that comparison, pointing to THORChain's threshold-signature vaults, where active nodes jointly authorize outbound transfers. The firm cited per-chain signing halts, network-wide pauses, and Mimir governance as evidence that operators can coordinate intervention.

THORChain disputes that read, arguing that a network halt is designed to protect the protocol itself, rather than to selectively censor a particular user. The protocol also noted that attacker addresses were not blacklisted during its own $10.7 million exploit in May, when the network paused as part of containment.

GoPlus has gone further, accusing THORChain of benefiting financially from the stance. The firm cited the protocol's role in laundering proceeds from the 2025 Bybit hack, when the attacker moved hundreds of thousands of ETH and generated millions of dollars in fees. It argued the fee revenue creates an incentive conflict when operators decline to interfere with illicit flows.

What comes next for Bitget and the wider market?

As Ethereum, USDT, and remaining services reopen through Oct. 2, investigators face a laundering apparatus that fragments funds across bridges and mixing services whose operators may refuse to intervene. The dispute over THORChain's emergency controls is likely to harden into a precedent-setting question for any cross-chain protocol with similar pause-and-sign architecture.

via x.com (Original)

More from Nathan Brooks

Nathan Brooks

Show full bio

Market editor covering business strategy at Mempool Brief.

451 articles