The story of Bitget encountering a hacker attack did not abruptly end at the moment the assets were stolen; the truly critical part is how these funds were gradually "laundered." As the attackers began to move chips on-chain, the incident officially entered the money laundering phase: according to results from AMLBot tracked by several media outlets on September 27, the TRON wallet related to the Bitget incident became the starting point for the funds, with its TRX being exchanged in batches for USDT, then transferred across a cross-chain bridge from the TRON network to Ethereum, continuing to be processed in the new chain environment. After entering Ethereum, this portion of USDT was exchanged for about 145 ETH, forming a clearly visible transfer node; subsequently, on-chain analysis pointed further to the Bitcoin network—AMLBot reported that during one mixing round in Wasabi CoinJoin, about 4 BTC's origin could be traced back to this route from TRON to Ethereum. In other words, although the attackers attempted to sever traces through cross-chain exchanges and privacy mixing, the current public materials can still outline an on-chain trajectory of part of the funds extending from Bitget's associated wallet to Wasabi CoinJoin.
Bitget TRON Wallet Cross-Chain to Ethereum
The attackers did not clear out a single large amount on the TRON network; instead, around this wallet associated with the Bitget hacker incident, they took a "exchange—cross-chain—re-exchange" layered approach. According to public analysis, this attacker initially held a large amount of TRX on TRON, then exchanged it step by step for USDT, using USDT as an intermediate asset for subsequent concealment and transfer. Compared to directly cross-chain converting the original assets, this prior conversion structure added another layer of "asset appearance" concealment along the path, making simple entry and exit account comparisons insufficient to restore all the changes in funds.
After completing the asset restructuring on the TRON side, the relevant USDT was sent to the Ethereum network through a cross-chain bridge, continuing to be processed in the new chain environment. According to a single source, this portion of cross-chain USDT was subsequently converted into about 145 ETH on Ethereum, forming a financial node that can be clearly identified on the Ethereum side. Despite the attackers' attempts to elongate traces through multiple exchanges and cross-chains, the generation of approximately 145 ETH still constituted one of the few clearly directional anchor points when currently tracking this financial path.
Wasabi CoinJoin Hacker Privacy Distorts Clues
Continuing the trace from the approximately 145 ETH on the Ethereum side, AMLBot's report shows that some related funds did not remain in a single-chain environment but further entered the Bitcoin network to participate in Wasabi CoinJoin mixing rounds. As a privacy-enhancing service operating on Bitcoin, Wasabi, based on the CoinJoin scheme, aggregates multiple users' multiple inputs and outputs within the same transaction, intentionally obscuring the exact correspondence between individual addresses and single funds. Under this structure, traditional on-chain tracking methods that rely on "single input—single output" to establish paths are significantly weakened; analysts can often only restore a probabilistic relationship rather than providing a definitive flow of assets for each transaction.
Even so, in the current public materials, AMLBot still marked a relatively clear intersection point: in one Wasabi CoinJoin round, the source of about 4 BTC can be traced back to the previously associated TRON wallet of the Bitget incident. This short identifiable path, on one hand, demonstrates that the attackers have tried to use cross-chain and mixing tools to layer conceal their traces, and on the other hand, once again brings services like Wasabi into the center of controversy. For a long time, the security and compliance community has been concerned about the use risks of mixing tools in potential money laundering scenarios; they create a gray area that is difficult to neatly separate between protecting ordinary users' transaction privacy and being abused by hackers. The presence of funds linked to the Bitget incident in Wasabi CoinJoin thus becomes the latest example when this gray area is touched by specific cases.
AMLBot Tracks 4 BTC Cross-Chain Still Traceable
Just as Wasabi is once again pushed into the limelight, an institution focused on on-chain compliance review and anti-money laundering analysis began to outline more specific coordinates for this gray area. AMLBot (@AMLBotHQ) pointed out in a public report that the source of about 4 BTC during a Wasabi CoinJoin round can still be traced back along the on-chain records to the previously associated TRON wallet with the Bitget incident. They linked the attacker's actions of converting TRX to USDT on the TRON network, migrating this portion of funds to Ethereum via a cross-chain bridge, exchanging USDT for about 145 ETH, and ultimately entering the Bitcoin network to participate in multiple transactions of Wasabi CoinJoin, forming a complete clue from the compromised exchange wallet to the mixing round, where the 4 BTC is just one clearly marked node.
This result was rapidly magnified into a larger public opinion arena. According to AiCoin data, on September 27, multiple media outlets such as Shenchao TechFlow, Planet Daily, and PANews simultaneously cited AMLBot's monitoring and on-chain path reconstruction, viewing this suspected money laundering route crossing TRON, Ethereum, and the Bitcoin network and ultimately landing in Wasabi CoinJoin as one of the most representative follow-up samples of the Bitget hacker incident. This also raised the question of whether "cross-chain + mixing" is sufficient to sever on-chain tracking in both the market and compliance communities, implying that in the public chain environment, even if hackers cross-chain multiple times and use mixing tools, it is difficult to completely erase the verifiable association with the original attack incident.
Collision of Exchange Security and Privacy Tools
The Bitget incident placed the security responsibilities of centralized custody platforms alongside the complexities of the on-chain world. The hacker started from the TRON wallet associated with Bitget, initially converting their TRX to USDT on TRON, then migrating the USDT to Ethereum through a cross-chain bridge, subsequently exchanging it for about 145 ETH, and finally, part of the funds entered the Bitcoin network to participate in Wasabi CoinJoin mixing. For an exchange's security and risk control team, this means that tracking is no longer as simple as "locking a single address," but involves piecing together fragmented paths across multiple public chains, identifying abnormal cross-chain behaviors, and determining at each asset conversion node whether it belongs to money laundering steps following the attack.
The existence of privacy tools like Wasabi further intensifies this game. Wasabi CoinJoin essentially obfuscates the destination of individual Bitcoins by mixing the inputs and outputs of multiple users' funds; it meets certain compliance users' needs for transaction privacy, yet is also viewed by hackers as an option for evading tracking. AMLBot still provided on-chain links between the approximately 4 BTC and the TRON wallet associated with Bitget in public materials, indicating that even in the presence of cross-chain and mixing, professional on-chain analysis may still reconstruct monetary connections in certain rounds. As more exchanges and regulatory agencies rely on such tools for compliance review and risk control, while discussions surrounding the regulation of privacy mixing services have yet to solidify, the Bitget incident reflects a long-standing delicate balance that centralized platforms must maintain between on-chain monitoring, technology procurement, and privacy boundaries.
Progress in On-Chain Tracking After Hacker Money Laundering
Returning to the Bitget incident, the publicly identifiable on-chain path is merely a corner of the larger picture. The path that AMLBot can clearly string together roughly starts from the TRON wallet associated with Bitget, going through TRX exchanged for USDT, cross-chain to Ethereum, then exchanged for about 145 ETH, followed by the identification of approximately 4 BTC participating in Wasabi CoinJoin. Apart from this, whether larger-scale assets remain on TRON, are dispersed to other chains, or are split into more cryptocurrencies, the existing credible materials have not provided answers. The hacker's identity, specific attack methods, and complete asset distribution remain in an information vacuum, and the latest actions from Bitget's official sources and law enforcement have also not been clearly disclosed. In this structurally incomplete visibility scenario, the combination of cross-chain bridges, decentralized services, and mixing tools is likely to become a frequently used money laundering scheme for hackers in the future, and whether on-chain analysis can continuously retain the "visible segment" amidst complex paths will directly test the real capabilities of exchanges in detecting abnormal behaviors, on-chain monitoring, and information transparency. Users and the market can only gauge the level of security defenses of platforms through such observations.
Join our community to discuss and become stronger together!
AiCoin Exclusive Hyperliquid Benefits: https://app.hyperliquid.xyz/join/AICOIN88
AiCoin Exclusive Aster Benefits: https://www.asterdex.com/zh-CN/referral/9C50e2
On-chain Telegram Community: https://t.me/AiCoinWhaleData
On-chain Community: https://www.aicoin.com/link/chat?cid=N6OVMor5g
AiCoin On-chain Twitter: https://x.com/aicoinwhaledata
免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。



