Following the September 24th security breach that drained $351.6 million from Bitget, attackers have begun converting stolen Ethereum into Bitcoin using the decentralized exchange THORChain. Blockchain investigator ZachXBT reported that these illicit actors are chain-hopping assets across bridges and directing them toward privacy-focused mixing services like Wasabi to obscure their origins. The exploit involved high-level internal credentials being used to insert fraudulent withdrawal commands, bypassing normal risk controls without compromising private keys.

Bitget CEO Gracy Chen stated in a September 28th livestream that the attack was likely linked to North Korean groups based on matching IP and VPN patterns. While Bitget has contained the incident and resumed BTC withdrawals, it faced resistance when urging THORChain to block attacker addresses. THORChain rejected the request, citing its permissionless design which prevents selective censorship of transactions. User funds remain protected by Bitget’s $464 million User Protection Fund, with cold wallets unaffected by the breach.