Mastodon Skip to content
LIVE - NYSE/-/- CRYPTO/OPEN/24/7
BTC$84,171▲ 1.68%ETH$2,716▲ 2.57%SOL$119.77▲ 1.45%TOTAL CRYPTO$2.87T▼ 1.10%S&P 5007,657.47▼ 0.70%NASDAQ26,767.69▲ 1.38%DOW51,138.54▼ 4.52%GOLD4,187.00▼ 7.57%WTI90.79▲ 8.86%BRENT96.91▲ 8.51%EUR/USD1.1337▼ 2.74%USD/JPY157.51▼ 1.14%DXY101.49▲ 1.79%
Crypto

Bitget Hacker Converts $6.3M to Bitcoin on THORChain

The Bitget attacker swapped 2,390 ETH for 75.2 BTC through THORChain after the network refused a freeze request. ETH withdrawals reopen September 29.

Pexels – Melvin Silva

The hacker behind the $387.5 million Bitget breach has started converting stolen ether into bitcoin, moving roughly $6.3 million through THORChain in 27 separate swaps after the network rejected Bitget’s request to block the funds.

On-chain data shows the attacker-controlled wallet exchanged about 2,390 ETH for 75.2 BTC. The swaps went through THORChain, the decentralized cross-chain exchange, days after Bitget asked the community to refuse transactions from addresses tied to the September 24 breach. Each conversion takes stolen ether one step further from any freeze mechanism an exchange or token issuer can apply, and the pace of the swaps suggests the attacker is working through the stolen inventory methodically rather than dumping it all at once.

How the breach unfolded

The theft came to light on September 24, when Bitget disclosed that an attacker had drained customer funds using a flaw in a third-party security product combined with stolen internal credentials. Initial estimates put the loss at $351.6 million. After further on-chain tracing, the exchange raised that figure to roughly $387.5 million.

Bitget stressed that private keys and cold wallets were not touched, and that customer assets held in cold storage were protected throughout. The hot wallet infrastructure, which keeps funds available for withdrawals, was where the damage landed.

The incident ranks among the largest exchange thefts of 2026. It also lands badly for an industry trying to argue that centralized custody has learned the lessons of previous cycles. Within days, the attacker was already moving funds through routes designed to resist intervention, and the exchange had to suspend withdrawals entirely while it rebuilt its security perimeter.

THORChain says it cannot freeze a swap

THORChain’s response set the terms of the dispute. The network confirmed its emergency controls can halt network activity in extremis, but said it has no mechanism to freeze an individual swap or a specific address. The request was effectively refused, and the conversions proceeded.

The decision has reignited a familiar argument inside decentralized finance. After the breach, stolen funds first moved through THORChain and sparked a public dispute over whether decentralized networks should cooperate with freeze requests at all. Developers of the chain have consistently taken the position that censorship at the protocol level would break the network’s core promise, and the latest swaps put that stance into practice under real pressure.

Critics see it differently. They argue that a network with an emergency halt switch already accepts intervention in principle, so refusing a targeted freeze in a documented $387 million theft is a choice, not a technical necessity. Supporters counter that address-level blacklists turn into permanent censorship tools once created, and that no single exchange should get to define who may transact. Both sides have dug in, and the argument has played out publicly on social media rather than in any formal governance process.

The laundering arithmetic

The episode echoes the laundering pattern already visible in the earlier stages of the theft, where most of the stolen funds moved through routes beyond any issuer’s freeze powers. Roughly $75 million in XRP from the same hack remains catchable if exchanges move quickly, since centralized venues can block deposits from tagged addresses. Ether converted to bitcoin on a decentralized bridge is far harder to intercept.

That is what makes the THORChain swaps significant. Bitcoin offers fewer issuer-level freeze options than ERC-20 tokens on chains where stablecoin issuers and exchanges can blacklist addresses. Once the funds sit in bitcoin, recovery depends almost entirely on the attacker making a mistake at a centralized off-ramp, such as sending coins to a venue with strict deposit screening.

Bitget is trying to speed up that mistake. The exchange is offering a 5 percent bounty for funds frozen by outside parties and another 5 percent for assets successfully recovered, an incentive program open to exchanges, security firms, blockchain projects and independent researchers. Whether that is enough to overcome the economics is doubtful. A launderer who pays 10 percent in effective leakage still keeps 90 percent of a nine-figure haul, which is a cost of doing business most attackers would accept.

Withdrawals resume in stages

While the laundering continues, the exchange is restoring service. Bitcoin withdrawals reopened at 08:00 UTC on September 28, four days after the breach. Ether withdrawals across Ethereum, BNB Smart Chain, Arbitrum, Base and Optimism are scheduled for the same time on September 29. USDT withdrawals on Ethereum, BNB Smart Chain, Solana and TRON follow on September 30, with other tokens, fiat services and peer-to-peer trading due by October 2.

The phased schedule is meant to let the exchange verify that the vulnerability is closed before reopening each rail. Traders have watched the timeline closely, since withdrawal suspensions of even a few days tend to push customers toward venues that have not been hit. Bitget’s market share through the rest of the year will partly depend on whether the restoration goes smoothly and whether any further suspicious outflows surface.

What it means for the sector

The breach and the laundering run together illustrate a gap that regulation has not closed. Exchanges can freeze, issuers can blacklist, but decentralized infrastructure can legally and technically decline to help. Law enforcement agencies have pushed for cooperation from cross-chain protocols after previous thefts, with mixed results, and THORChain has so far held its line even in a case with a clear victim and clear stolen funds.

It also raises uncomfortable questions for the exchanges themselves. A nine-figure hot wallet loss in a single incident is the kind of event that historically reshapes proof-of-reserves practices and insurance arrangements across the industry. Competitors have so far been careful in their public comments, but several have quietly promoted their own cold storage ratios since the news broke.

For Bitget, the calculus is blunt. Tracing firms continue to follow the funds, but attribution is not recovery. How much of the $387.5 million comes back will depend on the bounty program, exchange cooperation and how long the attacker stays patient. For everyone else holding funds on centralized venues, the episode is another reminder that hot wallet risk is priced into nothing until it happens.

SourcesCryptoDunia, September 29, 2026; The Block; CoinDesk
Share: X