One week after the $387.5 million Bitget hack, blockchain security firm MistTrack reported that attacker-linked addresses continue converting DAI stablecoins on Ethereum and bridging proceeds to the Tron network. This activity involves swapping USDT for TRX and USDD through decentralized exchanges like SunSwap, indicating ongoing laundering efforts rather than new thefts.
Stablecoin issuers Circle and Tether have collectively frozen approximately $318,000, representing just 0.08% of the disclosed loss. The limited recovery is attributed to the rapid conversion of freezable assets into non-custodial tokens like ETH and AVAX within minutes of the breach. Meanwhile, analytics firm AMLBot traced about 4 BTC from the attack into a Wasabi CoinJoin privacy round, complicating further tracking.
The minimal success of centralized freeze mechanisms highlights a critical vulnerability in current regulatory frameworks for crypto asset recovery. With stablecoin issuers capturing less than 1% of the stolen funds due to the speed of cross-chain swaps and conversions to non-custodial assets, traditional compliance tools appear insufficient against sophisticated, multi-chain laundering strategies. The reliance on permissionless protocols like THORChain, which declined to block attacker addresses, further underscores the tension between operational freedom and law enforcement cooperation.
From an institutional adoption perspective, this incident exposes significant operational risks associated with hot wallet infrastructure and third-party security dependencies. The interim forensic findings linking malicious activity to a third-party product suggest supply chain vulnerabilities may be more prevalent than previously understood. As attribution debates continue regarding North Korean involvement, the market must watch whether remaining large balances, such as the 10,000 ETH still held by attackers, will move or if exchange restoration timelines proceed without further security breaches.


