Invest1 publisher2 min readPublished
Most of Bitget's $387.5 million hack loss sits untouched in attacker wallets
Bitget now puts its September breach at $387.5 million, and AMLBot estimates $343 million of it sat untouched in 13 attacker wallets on Sept. 25. The phased withdrawals due from Sept. 28 are the better guide to whether customer money is safe.
The Investor · Invest desk

What happened
- The coins went from TRX into USDT, to Ethereum via USDT0, into about 145 ETH, then through THORChain into roughly 4.59 BTC before being split up.
- Bitget first put the Sept. 24 loss at $351.6 million, then added Zcash and TRON assets taken in the original incident, saying there were no new thefts.
- The stolen assets included ETH, XRP, USDT, USDC, USDT0, ZEC, XAUt, BNB, AVAX and TRX.
Compiled by The InvestorSomething wrong?How this is made
Why it matters
- cost Every batch that follows the 4 BTC through CoinJoin is harder to trace or blacklist, and whatever cannot be recovered is a loss that Bitget or its customers end up absorbing.
- decision Depositors face a queueing choice: an early phase gets money out sooner, while waiting buys evidence about whether later phases clear on time.
- constraint With no full root-cause report published, customers and counterparties deciding whether to leave balances on Bitget have only the exchange's word that the flaw is fixed.
Take AMLBot's roughly $389 million tracked total and subtract the $343 million it counted as dormant, and about $46 million had moved by Sept. 25 [2][2]. crypto.news reported that the CoinJoin activity is only a small part of the funds linked to the breach [14]. Of the 4.59 BTC the route produced, AMLBot tied roughly 4 BTC, about 87%, back to the Bitget TRON wallet [3]. Its tracked base also sits about $1.5 million above Bitget's own $387.5 million [1][5].
The mixer link rests on one firm's analysis. Public ledgers record the transfers, swaps and cross-chain activity, but the purpose of each transaction is inferred from the flow and from address attribution [12]. The Binance News summary that repeated the sequence on Sept. 27 cited reports based on AMLBot's tracing [12].
From here the attacker can stay patient and leave the thirteen wallets alone while the addresses stay on Bitget's published list and AMLBot's blacklist [15][11]. Or the 4 BTC round was a trial. By Sept. 27, three days after the breach, the route had already crossed four networks (TRON, Ethereum, THORChain, Bitcoin) [4][5]. CoinJoin makes tracing harder because observers cannot match one input to one output [13]. The third possibility is that Bitget's figure moves again. Its first revision added $35.9 million, or 10.2%, by reclassifying assets from the original incident [1].
The breach hit portions of the hot and warm wallets. The cold wallets stayed secure, and deposits and trading ran through the withdrawal suspension [7]. An exchange in that position has lost the float it pays withdrawals from. Whether the rest of the balance sheet covers that gap shows up only when customers start taking money out [3].
The counter-case is that a staged restart is ordinary caution after a patch. Bitget's preliminary findings pointed to a compromise of backend wallet infrastructure, and CEO Gracy Chen said private keys remained secure while investigators worked to identify the intrusion path [9]. The reporting does not describe how long each phase lasts or which of the ten affected assets come first [8].
The worry is wrong if every affected asset, ZEC and XAUt included, can be withdrawn on the schedule Bitget sets, with no phase pushed back [3][8]. A delayed phase, or a second upward revision to the loss, would point the other way [1].
What to watch
- Any movement out of the thirteen wallets AMLBot counts as dormant, or further CoinJoin rounds it ties to Bitget addresses.
- A Bitget statement on whether customer balances in the affected assets are covered in full, and from which funds.