The attacker behind Bitget’s $387.5 million security breach is moving stolen assets on two separate fronts. Roughly $83 million in XRP has already left the attacker’s original wallets, while a separate portion of the haul has been traced through Ethereum, THORChain and into a Bitcoin CoinJoin, according to on-chain reviews from CoinDesk and crypto compliance firm AMLBot.
The two routes show the attacker pursuing different laundering strategies for different parts of one of the largest crypto exchange breaches of 2026.
Bitget confirms $387.5 million reached attacker-controlled wallets
Bitget detected unauthorized transfers from some of its hot and warm wallets at 18:31 UTC on September 24, 2026.
The exchange initially estimated the breach at approximately $351.6 million. It later raised the figure to approximately $387.5 million after on-chain tracing identified additional transfers involving Zcash and TRON that had not been included in the first calculation. Bitget said the revised amount did not represent a second breach or additional unauthorized transfers.
The affected assets included XRP, ETH, USDT, USDC, USDT0, ZEC, XAUt, BNB, AVAX and TRX across the XRP Ledger, Ethereum and other EVM networks, Zcash and TRON. Bitget has published four primary attacker-controlled addresses, including the XRP address “rwNhefsz1UQEusxhCvHip3RANinWi4CTck” and the TRON address “TBWNguTTgezw9dVorX441C6nDrZpRxYwKD”.
The exchange says it has identified and remediated the vulnerability used in the attack and is working with Mandiant and SlowMist on its investigation. Bitget’s Protection Fund will absorb the financial impact, and the exchange says customer account balances remain unaffected.
Hacker moves $83 million in XRP
By September 26, 2026, approximately $83 million worth of XRP had moved out of three of the five principal holding wallets tied to the theft, according to CoinDesk’s review of XRP Ledger transactions.
Two wallets had been almost completely emptied, while a third was being drained. Around $75 million in XRP remained across the five original wallets at the time of the review.
Moving the XRP is not the same as laundering it. The transfers show the attacker redistributing funds, not that the XRP has been sold or converted into fiat.
The movement still complicates recovery, because native XRP does not behave like an issuer-controlled stablecoin. Ripple cannot blacklist an XRP address or freeze XRP sitting in a wallet, only a centralized exchange or custodian can restrict an account once stolen XRP reaches its platform. The token itself stays transferable on the ledger.
That is a sharp contrast with the stablecoins caught up in the same breach. Circle and Tether have already frozen roughly $320,000 in stablecoins tied to the theft, a fraction of the total loss, but proof of how differently each asset class responds to intervention.
A separate portion takes a far more complicated route
While XRP was being redistributed, AMLBot says another part of the stolen funds was moving through a deliberately more complex cross-chain path.
According to AMLBot’s tracing, funds originating from a Bitget TRON wallet were first converted from TRX into USDT. The attacker then used USDT0 to move value onto Ethereum, converting it into approximately 145 ETH.
That ETH was routed through THORChain and converted into roughly 4.59 BTC, which was then split and processed through several addresses before an estimated 4 BTC entered a CoinJoin transaction.
Bitget has not independently confirmed these findings, so the CoinJoin route should be treated as AMLBot’s on-chain attribution rather than a finding verified by the exchange itself. AMLBot says it has blacklisted the addresses involved and is monitoring the attacker’s Bitcoin for further CoinJoin activity.
What CoinJoin changes for investigators
CoinJoin is a Bitcoin privacy technique that combines multiple users’ inputs and outputs into a single transaction, making it harder for outside observers to match a given input to its output. It doesn’t make transactions invisible, but it can significantly complicate blockchain tracing.
That matters here because the funds AMLBot traced left a relatively clear chain before reaching the CoinJoin: Bitget TRON wallet to TRX to USDT to USDT0 to Ethereum to roughly 145 ETH to THORChain to roughly 4.59 BTC to split wallets to CoinJoin. Each stage before the CoinJoin gives investigators transaction records, counterparties and infrastructure to examine.
THORChain’s role stands out because the protocol lets users swap native assets across blockchains without routing through a centralized exchange. Bitget CEO Gracy Chen has publicly called on platforms and protocols to help trace and recover assets tied to the breach.
There is no indication that THORChain or the software behind the CoinJoin knowingly participated in the theft, both can be used independently of their developers.
Only a small fraction has entered the CoinJoin so far
The traced 4 BTC is a small piece of a breach worth roughly $387.5 million, which makes what happens next significant. If this was an isolated attempt to obscure a few million dollars, its effect on overall recovery will be limited. If it was a test run for a laundering route the attacker later applies to much larger portions of the haul, investigators could be facing a far tougher tracing job ahead.
The attacker has already shown the ability to move assets across fundamentally different networks, one part of the haul sits on the XRP Ledger, where native XRP can’t be frozen by an issuer; another has reportedly passed through TRON, Ethereum and THORChain before reaching Bitcoin privacy infrastructure. That fragmentation creates a distinct recovery challenge for each asset class.
Bitget prepares to reopen withdrawals
Bitget suspended withdrawals after the September 24, 2026 incident to carry out security checks. The exchange says the underlying vulnerability has been identified and fixed.
Bitcoin withdrawals are scheduled to resume on September 28, 2026 at 08:00 UTC, followed by Ethereum withdrawals on September 29, 2026 and USDT withdrawals on September 30, 2026. Other tokens, fiat withdrawals and peer-to-peer services are scheduled to resume on October 2, 2026.
Bitget maintains that no additional unauthorized transfers are possible and that its investigation is ongoing. The open question is shifting from how much the attacker stole to how much of the $387.5 million investigators can still catch before it disappears through exchanges, cross-chain protocols and privacy-enhancing transactions.