According to the review of the transaction records by CoinDesk of THORChain, a wallet associated with the hacker Bitget exchanged approximately 6.3 million US dollars in ETH for Bitcoin on THORChain. Previously, the network had rejected requests from exchanges to block addresses related to a vulnerability that occurred on September 24th.
- This wallet completed 27 exchanges, converting approximately 2390 ETH to 75.2 BTC.
- Bitget requires THORChain to reject transactions from addresses that have been identified as belonging to attackers.
- THORChain indicates that its emergency control can stop network activities, but it cannot freeze individual transactions.
- Bitget has raised the valuation of assets transferred to the attacker-controlled address to $387.5 million.
According to the review of the THORChain transaction records by CoinDesk, all 27 completed exchanges resulted in a total of 75.2 BTC being sent to the same receiving address. The related orders originated from one Ethereum wallet, which has been identified by blockchain tracking agency Lookonchain as part of the attacker's activities. Upon checking the records, there are another 4 transactions involving a total of 400 ETH that are still in a pending state.
Wallets related to Bitget exchanged for ETH through 27 transactions.
These orders were submitted approximately between 03:55 and 06:23 on Monday UTC. Most of them involved about 100 ETH each. Estimated at the price used during their review, each batch was worth about $265,000. Approximately 2,390 ETH were exchanged for 75.2 BTC; the 400 ETH that are still pending do not count towards this total.
The records also show that there was a limit to the quantity that could be redeemed at the selected price. Two orders of 100 ETH were only partially completed because some quantities did not meet the minimum price set for the transaction. Based on the review of CoinDesk, approximately 114 ETH were returned to the sent wallet.
THORChain allows users to exchange assets between different blockchains without going through centralized exchanges. In Monday's transactions, ETH was transferred into this exchange network, while BTC was sent to an address on the Bitcoin network. Both ends of the transfer are visible on the public blockchains; therefore, despite the cross-chain flow of assets, investigators were still able to track the movements in the records.
Another route had previously sent Bitcoin related to Bitget into a private transaction. On September 27th, blockchain compliance company AMLBot traced approximately 4 units of BTC entering the Wasabi CoinJoin round. Previously, the funds were transferred from TRON to Ethereum and then flowed through THORChain. AMLBot indicated that they traced these Bitcoins to a wallet associated with Bitget and TRON. CoinJoin combined the inputs and outputs of multiple users into a single transaction, making it more difficult to establish a direct correspondence.
THORChain states that stopping services cannot be targeted at a single address.
Bitget CEO Gracy Chen requested on weekends that THORChain refuse to provide services to addresses that have been published by the exchange and are being tracked. In her post on X, she stated that the network should take action regarding the identified funds:
Decentralization is a design principle, not a shield to facilitate the recovery of funds that have already been stolen.
THORChain rejected a request for address-based blocking. In a public response, the team stated that network downtime is an emergency tool used to protect the protocol, "not a selective freeze of specific funds or individual transactions." The team noted that their control measures can stop exchanges across the entire network or limit activities on a particular blockchain connection, but either approach will also interrupt the transactions of other users.
Security company GoPlus raises doubts about THORChain's claims regarding its available control measures. As reported on September 27th, the company pointed out that THORChain documents mentioned voter voting, signature control, and a chain suspension mechanism. GoPlus believes that these mechanisms give node operators the means to intervene when funds are at risk. THORChain, however, insists that its emergency shutdown was intended to protect the network itself and does not serve as a blacklist targeting specific wallets.
In May of this year, after an attacker stole approximately $10.7 million from the THORChain vault, the network implemented emergency controls. The operators ceased activities during the time developers spent fixing the vulnerabilities, and trading resumed around five weeks later in June. THORChain indicated that the attacker's address was not specifically added to the blacklist after the May attack.
Bitget Increases Vulnerability Estimation and Offers Rewards for Recovery
Bitget initially estimated the value of assets affected by the vulnerability on September 24 to be around $351.6 million. After deducting the assets of Zcash and TRON that were overlooked in the initial calculation, the exchange raised the value of assets transferred to the attacker's controlled addresses to around $387.5 million. Bitget indicates that this increase is due to a more comprehensive review of the original incident, rather than additional thefts occurring after the vulnerability was discovered.
On September 24th at UTC time 18:31, the exchange discovered unauthorized transfers and suspended withdrawals during the investigation period. Bitget stated that its cold wallets remained secure. Subsequent updates indicated that investigators had found and fixed the vulnerability, and Mandiant and SlowMist were assisting with the investigation and security checks. Bitget has not yet publicly explained how the attacker managed to gain access to their system.
Chen subsequently announced the launch of a bounty recovery program, offering a 5% reward to those who meet the criteria, are able to freeze the stolen assets, and assist in their recovery. Bitget disclosed the addresses of the main attackers targeting Ethereum-compatible networks, as well as XRP Ledger, Zcash, and TRON, along with a dashboard for tracking subsequent movements of the assets. The exchange stated that eligibility and payments would be determined based on each participant's contribution; work carried out in accordance with court orders or requests from law enforcement agencies does not qualify for the bounty.
For American readers, recovering their work also involves USDC, a issuer based in the United States. Bitget stated that Circle has frozen 99,990 USDC tokens related to this attack, while Tether has frozen 218,023 USDT tokens. These token freezes are targeted at identified stablecoin balances; THORChain's response was in response to individual requests from Bitget to stop exchanging ETH for BTC. Bitget is still discussing future business in the United States, and Chen stated in July that it will seek licensing and approval before providing services to American users.
Bitcoin withdrawals lead to the phased recovery of Bitget
After completing the security checks, Bitget announced a phased withdrawal schedule. According to the public arrangements, withdrawals on the Bitcoin network using BTC are scheduled to reopen at 08:00 on September 28. Withdrawals on Ethereum, BNB Smart Chain, Arbitrum, Base, and Optimism will also resume at the same time on September 29.
The schedule indicates that withdrawals using USDT on Ethereum, BNB Smart Chain, Solana, and TRON are scheduled to resume at 08:00 on September 30. Other token withdrawal services, fiat currency services, and peer-to-peer transactions are scheduled for the final phase, which is on October 2. The exchange reminds customers to check the official notifications to confirm whether all services have been restored.












