Investigations into the September 24 Bitget hack, which affected an estimated $387.5 million in assets, have yielded new traceable data. Blockchain intelligence firm BitOK reported that approximately 87.82 BTC attributable to one branch of the stolen funds remained in ten unspent Bitcoin outputs on October 1. This finding contrasts with other traced funds that entered mixing transactions or decentralized exchanges, highlighting the persistent challenge of distinguishing recoverable assets from those obscured by privacy tools.
The updated analysis reveals significant movement across multiple networks. Eight storage wallets holding 50,163.84 ETH on September 28 contained negligible balances by October 1, indicating onward transfer. Meanwhile, 31 THORChain payouts delivered 87.82301390 BTC, consolidated into the ten monitored outputs. Separately, BitOK identified nine direct inputs totaling 14.61453223 BTC entering Wasabi CoinJoin rounds and 13 Tornado Cash deposits totaling 9.4 ETH. The investigation links the incident to North Korean actors, with Chainalysis attributing the attack to DPRK groups and noting it pushed 2026 thefts above $1 billion.
The identification of unspent transaction outputs (UTXOs) containing a specific portion of the stolen funds provides investigators with a concrete monitoring target, yet it underscores the limitations of blockchain forensics in isolation. While the visibility of these ten outputs allows for real-time tracking, the protocol’s inability to freeze coins at the network level means recovery depends entirely on downstream intervention. The divergence between the static Bitcoin branch and the rapidly moving Ethereum and mixed-fund trails illustrates how attackers utilize cross-chain bridges and privacy mechanisms to fragment and obscure asset provenance, complicating the establishment of clear ownership chains.
From an institutional perspective, this case reinforces the critical importance of centralized exchange cooperation and regulatory frameworks in crypto security. As noted by BitOK analysts, the most effective intervention point occurs when funds reach service providers capable of freezing withdrawals and identifying account holders. The attribution to North Korean actors, alongside the broader context of over $1 billion in 2026 thefts, highlights the escalating sophistication of state-linked laundering operations. Stakeholders must watch whether law enforcement can leverage the established link to the stolen assets to disrupt the pre-planned over-the-counter infrastructure often used to convert digital proceeds into fiat currency.


