On September 28, a sum of stolen funds that had been "lying still" on the chain suddenly began to stir. The address 0xf7bC92103F23EF312658CD9b81dc2713f7b396C3, marked by Lookonchain as related to the Bitget security incident, was monitored for frequent transactions: this batch of suspicious assets, previously flagged as approximately 351.6 million dollars (the amount also comes from Lookonchain's singular monitoring measure), started exchanging ETH for BTC through the decentralized cross-chain protocol THORChain. Lookonchain shared the on-chain path on social media and provided links to Arkham and the THORChain browser, leading multiple Chinese media outlets such as Deep Tide TechFlow, Jinse Finance, and Odaily to quickly report on this monitoring, propelling "Bitget stolen funds exchanged for BTC" into the center of public discourse. Compared to centralized exchanges that have KYC and freezing capabilities, cross-chain exchange tools like THORChain, which do not rely on traditional account systems, being chosen as an "outlet" by hackers is not surprising; what is truly worth questioning is: as the stolen ETH is gradually converted to BTC, extending from a single address to multiple chain paths, to what extent is the difficulty of on-chain tracking and the pattern of the offensive and defensive game being reshaped by this cross-chain exchange.
After 350 Million: THORChain on ETH
Pulling the timeline back to the event itself: after Bitget was reported to have lost approximately 351.6 million dollars, the stolen funds were thought to be concentrated in a few key addresses, among which address 0xf7bC92103F23EF312658CD9b81dc2713f7b396C3 was marked by Lookonchain as the core wallet "related to the stolen funds." In other words, before the cross-chain actions occurred, the on-chain story was relatively simple — large assets flowed out of the Bitget system, accumulating in an ETH address under close watch, still in a "waiting period" of static status.
The turning point occurred on September 28. On that day, Lookonchain alerted on social media that this address began exchanging its held ETH for BTC through the cross-chain protocol THORChain, providing links to query on Arkham and the THORChain browser, effectively publicly laying out the fund movements for everyone to see. It is important to emphasize that the only visible and clearly identified on-chain action at this time is this main line: ETH from the address flows into THORChain-related contracts and then appears in BTC form on the other side. The publicly available materials have not disclosed the specific scale of ETH or BTC involved in the exchange, nor have they indicated whether the operation was executed in a single transaction or batches, and even less can be said about tracking the subsequent flow of BTC. More importantly, this entire narrative is currently almost entirely based on Lookonchain's tagging and interpretation, representing an on-chain assessment of "highly followed addresses," rather than a final characterization confirmed by judicial means; readers must consider this premise when understanding this pathway.
From ETH to BTC: Why Hackers Favor Cross-Chain Exchanges
For attackers, leaving the marked ETH on the original chain is a state of being "exposed under the spotlight"; and the path pointed out by Lookonchain is one where chips are concentrated at address 0xf7bC92103F23EF312658CD9b81dc2713f7b396C3, then directly exchanging ETH for native BTC through THORChain. Cross-chain protocols like THORChain do not require traditional accounts and KYC; users only need to initiate an on-chain transaction to non-custodially convert between assets on different public chains, without needing to deposit money into a centralized account that can be "paused." This forms a sharp contrast to the centralized exchange model — which generally has KYC, risk control, and account freezing capabilities; once a request is made by the exchange or law enforcement, suspicious accounts can theoretically be locked at any time.
Under this structure, cross-chain exchange + BTC constitutes the "exit template" commonly used by gray funds. Historically, operators in multiple attack incidents have often first concentrated various tokens into BTC or other major assets, then split them into multiple addresses, utilizing cross-chain protocols and mixing services to elongate the fund paths and weaken the readability of a singular chain. The marked Bitget-related address has not publicly shown direct withdrawals through large centralized exchanges but is seen circumventing to exchange for BTC via THORChain, continuing the industry practice of "first turning to BTC and then figuring out how to exit," thereby reinforcing the special position of BTC as a targeted asset in the exit path for gray funds.
THORChain's Decentralized Design is a Double-Edged Sword
As a cross-chain exchange protocol, THORChain's core design entails a multi-node collective management of the fund pool, where assets are guaranteed by the protocol's smart contracts and nodes, rather than centralized in a single custody account. For ordinary users, this means they can complete exchanges between native assets like ETH and BTC across multiple chains directly without relying on centralized intermediaries; the entire process only requires interaction with the public contracts, without the need to set up a traditional real-name account or undergo platform risk assessment, greatly compressing the entry barrier and time cost for cross-chain exchanges.
However, when the same mechanism is applied to the wallet address 0xf7bC92103F23EF312658CD9b81dc2713f7b396C3, which is marked as related to Bitget's stolen funds, it presents another aspect. Under the public positioning of "free cross-chain asset exchange," the protocol automatically facilitates transactions by contract logic without manually identifying and blocking specific addresses; KYC and list filtering are not built into the basic processes, and tools like the THORChain browser and Arkham can only restore the fund paths based on transparent data afterward, rather than hitting the pause button before transactions occur. Thus, the debate over whether decentralized protocols should impose restrictions on suspicious funds has long existed; one side argues for user privacy and accessibility, while the other side highlights the risk of gray fund abuse. This recent case of Bitget’s stolen funds being exchanged for BTC through THORChain again clearly places this value conflict on the table.
On-Chain Hunters Focus on Hackers: Tracking Yet Difficult to Intercept
For a "key wallet" like address `0xf7bC92103F23EF312658CD9b81dc2713f7b396C3`, the work of on-chain analysts is never to identify based on intuition, but rather to trace along the transaction paths, jumping forward and backward. Lookonchain this time used data from multi-chain browsers to link wallets previously seen as related to Bitget's stolen funds with the address that became active on THORChain starting September 28, then threw public links to Arkham and the THORChain browser to the market, allowing everyone to follow the same path to see when ETH entered the cross-chain pool and when it was withdrawn in BTC form. Tools like Arkham are responsible for aggregating addresses and transactions across different chains into the same "profile," aiding in determining whether these seemingly independent addresses might point to the same group of operating entities.
What truly makes tracking difficult is the hackers' ability to "take a detour" on-chain. It is known that this batch of marked funds was exchanged from ETH to BTC via THORChain, effectively restarting a new journey for these funds on another chain; once the cross-chain is successful, these BTC can be further split into multiple new addresses or flow to other service nodes, resulting in the path map transforming from a clear backbone into a multi-branched network. Historical experience shows that cross-chain protocols, mixing services, and multiple address splitting are often used by gray funds to weaken the readability of on-chain data for ordinary observers, but they cannot erase the permanent record of each transaction on the ledger. The issue lies in that accounts like Lookonchain and Arkham play more of a "warning system" role: to date, no public materials show that the BTC generated post-cross-chain on THORChain have been confirmed as final destinations or effectively frozen; whether or when they are frozen depends on whether the centralized exchanges and related institutions with KYC and account permissions catch this information, rather than whether on-chain hunters can see the fund trajectory itself.
After Normalizing Cross-Chain Money Laundering, How Are Security Boundaries Redefined?
The stolen funds from Bitget sat still for a considerable amount of time at the marked address 0xf7bC92103F23EF312658CD9b81dc2713f7b396C3 until September 28, when monitoring detected the exchange of ETH for BTC via THORChain. This rhythm reveals a weak link: as long as cross-chain protocols can operate under the framework of "no KYC, direct asset exchange," hackers can wait for the storm to pass before completing inter-chain migration, upgrading tracking from single-chain analysis to multi-chain puzzles. For exchanges, the security boundary has expanded from "guarding their hot and cold wallets" to "integrating cross-chain intelligence and setting risk control thresholds in advance on target chains like BTC"; for cross-chain protocols, how to respond to industry calls for compliance requirements, blacklist mechanisms, or self-regulatory consensus while maintaining decentralization will directly affect the space open to abuse; for ordinary users, such cases remind people to view "cross-chain convenience" as a potential risk amplification channel, rather than a presumed safe infrastructure. Moving forward, the further flow of hacker addresses on the BTC side, whether Bitget and related parties disclose clearer tracking and disposal paths, and whether the cross-chain protocol industry can form executable self-restraint measures around malicious fund restrictions, will all become critical observational variables in judging "whether cross-chain money laundering is becoming normalized" and "whether security boundaries are truly being redefined."
Join our community, let's discuss, and become stronger together!
AiCoin exclusive Hyperliquid benefits: https://app.hyperliquid.xyz/join/AICOIN88
AiCoin exclusive Aster benefits: https://www.asterdex.com/zh-CN/referral/9C50e2
On-chain Telegram community: https://t.me/AiCoinWhaleData
On-chain community: https://www.aicoin.com/link/chat?cid=N6OVMor5g
AiCoin on-chain Twitter: https://x.com/aicoinwhaledata
免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。



