Blockchain analytics firms continue to monitor the movement of funds linked to Bitget’s recent security incident, with a portion of the stolen assets now traced into a privacy-enhancing transaction. As of reports around September 26–27, 2026, approximately 4 BTC connected to the exchange’s compromised wallets entered a Wasabi CoinJoin round.

The activity still represents only a small fraction of the overall incident, which Bitget has valued at roughly $387.5 million. The tracked path involved multiple chains and asset conversions before the Bitcoin portion reached the mixing service. This comparison underscores how attackers attempt to obscure the trail of stolen cryptocurrency after a major exchange breach.

The Drivers of the CoinJoin Movement

The key factor remains the use of cross-chain routing and mixing tools to complicate tracing. According to analytics firm AMLBot, the funds originated from a Bitget TRON wallet. They were converted from TRX into USDT, moved via USDT0 onto the Ethereum network, exchanged for approximately 145 ETH, and then swapped through THORChain into about 4.59 BTC. After splitting, roughly 4 BTC entered a single Wasabi CoinJoin transaction.

This stacks with standard post-hack obfuscation patterns in which stolen assets are rapidly moved across networks and into privacy protocols. CoinJoin combines inputs from multiple users into a single transaction, increasing the difficulty of linking specific inputs to outputs. Related addresses have been blacklisted by monitoring firms, and further CoinJoin activity tied to the remaining attacker-controlled Bitcoin is under observation. Only the portion successfully traced into this specific round has been publicly quantified at about 4 BTC; the majority of the stolen value remains under separate tracking.

It is essential to distinguish: the approximately 4 BTC figure represents the amount linked to one identified CoinJoin round originating from a Bitget-associated wallet, whereas the total incident loss is far larger and includes assets across multiple chains. The movement is mostly an on-chain laundering step linked to efforts to break the transaction graph after the September 24 security event.

Impact and Broader Context

As a small slice of the Bitget-linked funds enters Wasabi CoinJoin, the development advances ongoing efforts by analytics firms and the exchange to follow residual stolen assets. Identifying even limited mixing activity grows the data available for blacklisting and potential future recovery or law-enforcement action. Stablecoin issuers have separately frozen some related addresses holding USDT and USDC totaling a few hundred thousand dollars.

This sustained tracking fuels discussions on the effectiveness of CoinJoin and similar tools in post-hack scenarios, the challenges of cross-chain tracing, the role of decentralized liquidity protocols such as THORChain in fund movement, and the broader difficulty of recovering assets once privacy techniques are applied. Security researchers highlight that while mixing reduces traceability, coordinated monitoring can still flag associated addresses. Exchange and compliance observers note that the 4 BTC represents a minor fraction of the overall haul.

Industry participants emphasize that rapid multi-hop routing followed by mixing remains a common tactic after large incidents. The September tracing of Bitget-linked Bitcoin into Wasabi offers insight into the early stages of how portions of the stolen funds are being handled on-chain.

As further analytics updates, additional CoinJoin detections, or recovery actions emerge, the status of these and other related assets will become clearer.

This analysis draws from AMLBot tracing reports and contemporaneous coverage of the Bitget incident for precision. On-chain attributions rely on clustering and labeling methodologies and remain subject to ongoing investigation.

Leave a Reply

Your email address will not be published. Required fields are marked *

WP Twitter Auto Publish Powered By : XYZScripts.com