Bitget Launderers Asked for Support in Open Chats

Investigators say the crew moving $387 million stolen from Bitget filed customer-support complaints in the same Discord and Telegram channels they used to launder it.

Read as article

Bitget Launderers Asked for Support in Open Chats

By @sharedot · · 6 pages

Investigators say the crew moving $387 million stolen from Bitget filed customer-support complaints in the same Discord and Telegram channels they used to launder it.

Launderers Bungled in Plain Sight

The Cryptonomist reports that the Chinese money launderers allegedly moving Bitget's stolen $387 million made an unforced error: they filed customer-support requests inside the very Discord servers and Telegram channels tied to the services they were using to move funds. Blockchain investigator ZachXBT named five accounts, matched each to a specific transaction, and backed the claim with screenshots. One account, "Cc," complained that 277,724 XRP went into a swap but only 431 came out; another, "jack," said losing the assets "would cause a lot of trouble in my life." In one exchange, a SwapKit moderator replied with a photo of Kim Jong Un.

Same Infrastructure as Kelp DAO and TraderTraitor

The Cryptonomist reports that one flagged account, "lolo," had already laundered proceeds from the $292 million Kelp DAO exploit in April, and confirmed in chat logs operating as "Marin" on Telegram — linking two multi-hundred-million-dollar thefts to the same laundering network. ZachXBT said he has "observed the same pattern after multiple TraderTraitor attributed exploits." TraderTraitor is the FBI's name for a North Korean group previously blamed for the $308 million DMM Bitcoin theft in 2024. Bitget CEO Gracy Chen called North Korea "very likely" behind the September 24 breach, while telling Cointelegraph the attribution indicators are still being assessed by Mandiant and SlowMist.

How the $387.5 Million Was Taken and Moved

Attackers did not compromise private keys. According to Cointelegraph, Chen said the exploit stemmed from a vulnerability in a third-party security product that let the attacker obtain "high-level internal credentials" and issue fraudulent withdrawal commands; cold wallets were untouched. The Cryptonomist reports Bitget first estimated losses at $351.6 million, later raising them to roughly $387.5 million after identifying Zcash and TRON transactions, with affected assets spanning ETH, XRP, USDT, ZEC, USDC, BNB, AVAX and TRX. Funds hopped chains via bridges and THORChain swaps before landing in Wasabi mixers.

THORChain Refuses, Bitget Restores

Chen formally asked THORChain on September 26 to refuse service to the tracked attacker addresses, arguing "decentralization is a design principle, not a shield for facilitating known stolen funds," but the protocol said its halts protect the protocol itself and it cannot selectively blacklist addresses — a stance Cointelegraph notes Bitget says it respects given the technical constraints. GoPlus Security pushed back, arguing THORChain's validator set can already pause activity; security executive Michael Perklin defended the protocol, telling The Cryptonomist node operators make "no active choice to sign." Bitget resumed Bitcoin withdrawals September 28, Ethereum September 29 and USDT September 30, with fiat and P2P returning October 2; Circle and Tether froze about $318,000 in stablecoins, and ZachXBT plans to publish more data on the laundering network in coming weeks.

Sources

  1. en.cryptonomist.ch › Bitget Hack Investigation Uncovers Laundering Trail, North Korean Links
  2. cryptonews.net › Bitget CEO says $388M hack exploited third-party security vulnerability

More on Crypto

Bitget Launderers Asked for Support in Open Chats · ShareDot