Nearly 5,000 BTC leaves Bitget as hackers begin laundering $387 million haul
After Bitget resumed Bitcoin withdrawals at 08:00 UTC on Sept. 28, CEO Gracy Chen said the exchange had processed 9,585 withdrawal orders totaling 4,098.036 BTC as of 17:00 UTC+8. Separate DeFiLlama data showed Bitget's tracked Bitcoin balance falling to about 30,770 BTC from 35,412 BTC, a decline of roughly 4,642 BTC (about $391 million).
The rapid outflow is the first indication of how users are responding after Bitget froze withdrawals for four days while investigating the largest security incident in its eight-year history. At the same time, investigators are racing to trace the $387.5 million haul as laundered assets are scattered across chains and privacy tools.
The reserve decline is larger than the withdrawal volume Chen reported, and DeFiLlama tracks assets held in wallets attributed to exchanges, so changes can also reflect wallet movements or differences in address coverage rather than customer withdrawals alone. Ethereum withdrawals are scheduled to resume on Sept. 29, USDT on Sept. 30, and remaining tokens, fiat and peer-to-peer services on Oct. 2.
rss · CryptoSlate · · Single source
Background, discussion, and references
Market impact
Roughly 4,642 BTC of tracked exchange-held bitcoin leaving a single venue tightens on-venue spot liquidity for BTC and is a visible confidence signal for other centralized-exchange assets as traders watch for further withdrawals or contagion. The laundering chain — bridges, mixers and THORChain — keeps recovery and compliance pressure on the protocols and intermediaries handling those flows, even as Bitget says user losses will be covered by its Protection Fund, which it plans to replenish above $300 million within a week.
Background
Bitget froze customer withdrawals after a hack in which roughly $350 million in crypto was stolen; CEO Gracy Chen said cold wallets remained fully secure and that only hot wallets were affected. The exchange has since said the incident involved a critical backend system in its wallet infrastructure, that attackers exploited vulnerabilities in third-party products to obtain internal credentials used to submit fraudulent withdrawal instructions, and that it remediated the vulnerability before withdrawals returned. Blockchain investigator ZachXBT said Chinese illicit actors were laundering proceeds on behalf of hackers he described as allegedly linked to North Korea, chain-hopping funds into mixing services including Wasabi; the activity has put THORChain at the center of a dispute over whether permissionless infrastructure should intervene when stolen assets pass through its systems, with THORChain saying it will not selectively block wallets or swaps.
References
Tags
#bitget#exchange-hack#bitcoin#withdrawals#money-laundering#THORChain