Bitget Hack Launderers Beg Support After Swaps Stall
Alleged Launderers Hit an Unexpected Snag
People linked to laundering the $387.5 million stolen from Bitget have run into a surprising problem. Some swaps of XRP for Bitcoin stalled, and payouts never arrived. Consequently, the alleged launderers turned to public Discord and Telegram chats of the very services they used. There, they begged for help.
Blockchain researcher ZachXBT linked five accounts to specific transactions in the chain of stolen funds.
Frozen Swaps and Desperate Messages
One attempt ended especially badly. A user under the alias Cc tried to swap 277,724 XRP. According to screenshots that ZachXBT published, the user complained of receiving only 431 XRP back.
Another participant, called jack, wrote to support. He said the loss would cause him “a lot of problems in life.” A moderator of a service tied to SwapKit offered no comfort. Instead, the moderator replied with a photo of Kim Jong Un.
What Is Not Proven
No evidence yet shows that the exchange operators deliberately kept the money. The available data shows stuck operations, refunds, and undelivered payouts. It does not prove that intermediaries chose to rob the alleged launderers.
A rumored version also lacks support. It claimed an XMR-to-BTC swap that the exchanger’s owner later deleted. ZachXBT’s published material concerns mainly XRP operations that paid out in Bitcoin.
Five Accounts Tied to Chinese Intermediaries
The situation looks ironic, given how public the infrastructure around the stolen money has become. ZachXBT says the five accounts belong to Chinese intermediaries. He claims they launder funds for alleged North Korean participants in the attack.
The researcher linked the aliases Cc, jack, Melon, lolo/Marin, and HELP ME to the operations. The last name proved an apt description of events.
How the Attack Unfolded
The attack took place on September 24. At first, Bitget estimated the damage at $351.6 million. After further review, it raised the figure to $387.5 million.
The money left hot and warm wallets on Ethereum, XRP Ledger, Zcash, TRON, and several EVM networks. Bitget says its cold wallets were not hit. Those wallets hold most reserves. It also says no private keys were stolen.
A Zero-Day in Third-Party Software
According to Bitget CEO Gracy Chen, the attacker used a zero-day flaw in a third-party security product. He obtained valid internal credentials. Then he sent forged withdrawal commands straight to the wallet infrastructure backend.
The system saw the commands as legitimate and signed the transfers. Before the main theft, the attacker ran several small test operations. They checked whether control mechanisms would let them through.
Public Addresses and a Bounty
After the breach, Bitget published the known attacker addresses. It also announced a reward of 5% of any sum that a third party or researcher helps freeze or recover.
Public addresses complicate laundering greatly. Analytics firms, exchanges, and stablecoin issuers can track the onward movement of funds.
THORChain Refuses to Block the Hacker
Even so, not every route closed. Through THORChain, a wallet tied to the attack swapped about $6.3 million in ETH for 75.2 BTC.
Bitget asked THORChain not to serve the known addresses. However, the protocol’s developers refused to add selective blocking. In their view, the built-in emergency halt can stop all swaps at once. It was not designed to freeze individual addresses.
A Rare Picture of Digital Traces
The result is an unusual picture. Some routes successfully turn stolen crypto into Bitcoin. On others, alleged launderers hunt for missing money themselves. They post transaction IDs and plead with support teams.
The longer such exchanges continue, the more digital traces investigators gain. In turn, participants find it harder to stay anonymous.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.