Cryptelio

Hacks & Exploits

Bitget Hack: $387M Laundering Operation Exposed on Public Channels

Cryptelio Editorial Published 28 Sep 2026 · 12:17 UTC

In a striking development, nearly $400 million stolen from the Bitget exchange is being laundered through widely accessible online platforms rather than the dark web. The September 24 breach, which resulted in approximately $387.5 million being drained from Bitget's wallets, marks the largest digital asset theft of 2026.

Blockchain investigator ZachXBT has identified that the laundering activities are being coordinated through public Discord servers and Telegram groups. The perpetrators are utilizing bridging services and mixers, such as Wasabi, to obscure their transaction trails. Notably, some of the usernames involved, including cc02006 and jack_34808, have been linked to previous exploits, indicating a well-organized laundering network.

The breach was executed by compromising a third-party backend system used by Bitget, allowing attackers to spoof transaction data without compromising private keys, thus keeping cold wallets secure. In response to the incident, Bitget suspended withdrawals and has since resumed them in phases, with plans to cover user losses through its User Protection Fund, which exceeds $464 million.

Bitget has enlisted the help of cybersecurity firms Mandiant and SlowMist to investigate the breach, with law enforcement agencies also involved. The connection to the earlier $292 million Kelp DAO exploit raises alarms about a potential pattern of attacks linked to North Korean hacker groups.

In a related response, DeFi project THORChain declined a request from Bitget to block addresses associated with the hack, citing its decentralized nature. This decision has sparked debate within the crypto community, especially given THORChain's previous actions to halt trading after its own hack.

New Developments in the Bitget Hack Case

  • Blockchain investigator ZachXBT revealed that suspects involved in laundering money from the $387 million Bitget hack have been seeking help in public chat rooms.
  • The suspects are identified as Chinese money launderers allegedly working for North Korean attackers.
  • They have been posting in Discord servers and Telegram channels related to the services they use for moving the stolen funds.
  • Bitget lost $387.5 million on September 24, with CEO Gracy Chen suggesting that North Korea was likely behind the attack.
  • ZachXBT has identified five accounts linked to the laundering operations and provided evidence of their complaints regarding failed transactions.
  • One user reported that 277,724 XRP was sent but only 431 XRP was received back, expressing concerns about the impact of the loss on their life.
  • ZachXBT noted that one of the accounts had previously laundered funds from the $292 million Kelp DAO exploit in April.
  • The FBI has attributed similar exploits to the North Korean hacking group known as TraderTraitor, which was also linked to a $308 million theft from DMM Bitcoin in 2024.
  • Funds from the Bitget hack are reportedly being transferred between blockchains and mixed through services like Wasabi to obscure their origin.
  • THORChain has not blocked the wallets associated with the attackers, and Bitget plans to reopen withdrawals on Monday.
  • ZachXBT is expected to release additional information about these groups in the upcoming weeks.

Latest Updates on Bitget Security Incident

  • Bitget has resumed withdrawals in phases, starting with BTC on September 28, 2023.
  • The exchange has confirmed that user balances remain unaffected and a full security report is expected this week.
  • Approximately $388 million in assets were transferred out during the incident, with ongoing investigations by Mandiant and SlowMist.
  • ETH withdrawals are scheduled to resume on September 29, 2023, and USDT withdrawals on September 30, 2023.
  • As of September 28, 2023, 9,585 users had initiated withdrawals totaling approximately 4,098 BTC since the resumption.
  • Bitget is introducing two limited-time programs: the Bitget Alliance Program and Project Stand Together, both starting from September 28, 2023.

FAQ

What happened in the Bitget hack?

On September 24, 2026, Bitget experienced a major breach resulting in approximately $387.5 million being stolen from its wallets. This incident is considered the largest digital asset theft of the year.

How are the stolen funds being laundered?

The stolen funds are being laundered through public online platforms, specifically Discord servers and Telegram groups. Perpetrators are using bridging services and mixers like Wasabi to obscure their transaction trails.

What measures is Bitget taking in response to the hack?

Bitget has suspended withdrawals temporarily but has since resumed them in phases. The exchange plans to cover user losses through its User Protection Fund, which exceeds $464 million, and has enlisted cybersecurity firms to investigate the breach.

What connection does this hack have to previous incidents?

The Bitget hack has been linked to earlier exploits, including a $292 million theft from Kelp DAO, raising concerns about a possible pattern of attacks associated with North Korean hacker groups.

Why did THORChain decline Bitget's request to block addresses associated with the hack?

THORChain declined the request due to its decentralized nature, which prioritizes open access and trading, despite previous actions taken to halt trading after its own hack.

Read story →