Services that processed stolen Bitget funds collected at least $761,725 in fees, according to researcher Andrey Sergeenkov, with THORChain taking $573,226 of it. That figure does not show who profited, but it gives investigators a new trail to follow.
Independent researcher Andrey Sergeenkov analyzed transactions through Oct. 2 at 10:22 UTC to estimate how much the movement of the stolen assets generated for the services involved. His tally puts identifiable protocol and service fees at $761,725.
THORChain liquidity fees accounted for the largest share at $573,226. MetaMask-related Ethereum fee transfers represented another $149,417, while Chainflip generated $26,751 in broker fees and CoW EthFlow accounted for $12,332 in protocol and partner fees.
Sergeenkov stressed an important limitation: the figures represent recorded fees in the tracked transaction sample, not necessarily net profits or a complete accounting of every route used by the stolen assets.
THORChain affiliate payments draw closer scrutiny
The analysis separately examined affiliate fees attached to THORChain swap instructions. Such fees can be directed to a separate recipient, meaning that the address named in a transaction does not, by itself, prove who controls it or whether its owner knew the source of the assets.
Sergeenkov identified $259,718 paid to seven affiliate recipients where additional transaction activity created financial links to wallets involved in the stolen-fund movements.
The largest recipient collected $177,499. Sergeenkov found links involving shared recipients of the main funds and transaction flows connecting the reviewed swap activity to compromised Bitget addresses. Another recipient received $56,514, while a third collected $18,080 after fee proceeds were moved back toward a wallet connected to the swap activity.
Smaller linked amounts included $4,544, $2,885 and $196, while another recipient received less than $1 and later transferred funds to another reviewed fee recipient.
The distinction matters in the Bitget hack. The investigation is tracing transaction relationships, not automatically assigning criminal responsibility to every address that received a fee.
Part of the fee trail reached an OKX-labeled wallet
The most notable trail involved the affiliate address that received $177,499. According to Sergeenkov, part of its RUNE-denominated fee income was exchanged for USDT, passed through two Ethereum wallets and ultimately reached an address labeled “OKX Hot Wallet 5” by Etherscan.
That destination does not establish OKX involvement or identify the exchange customer who may have controlled the account.
Sergeenkov said an exchange with access to internal deposit records could potentially determine whether the transfers corresponded to a customer account and, if so, identify the account holder.
Blockchain tracing can expose wallet movements, but centralized exchanges generally hold the customer information needed to connect addresses to people or entities.
The Bitget hack has also highlighted competing approaches to handling suspicious cross-chain activity. NEAR Intents said its SHIELD system identified more than $50 million in attempted transfers linked to the incident, with about $503,000 frozen and roughly $166,000 passing through. General Manager Alex Shevchenko said the system uses risk intelligence to decide how transactions should be handled.
$206,196 in affiliate fees remains unexplained
A separate $206,196 in THORChain affiliate fees went to recipients for which Sergeenkov did not establish additional financial links to the wallets involved in moving the stolen funds.
The largest recipient in that group, associated with the name “naswap,” received $102,344. A THORChain holding account credited under several names accounted for another $92,438, while other recipients received $7,245, $2,994 and $1,176. Sergeenkov said the final payouts from the holding account had not been traced in his analysis.
That separation is crucial to interpreting the Bitget hack data. Receiving an affiliate fee from a swap involving stolen assets does not establish common ownership, intent or knowledge of the theft. The research instead categorizes addresses according to whether additional transaction links were found in the reviewed data.
The broader debate extends beyond the stolen $387.5 million. Every Bitget hack-related swap can leave fee records that investigators use as additional clues.
For exchanges and investigators, those records can be valuable. The financial footprint of a crypto theft includes not only assets attackers move, but also fees generated along the route.