Skip to main content
WIDTH Intelligence›Digital asset risk
Digital asset risk analysis

Bitget Hack: Where Did the Stolen Funds Go?

A snapshot of the stolen fund trail, from XRP swaps to the deposit risk facing receiving platforms.

14-min readPublished 29 September 2026Data snapshot 27 September 2026
Bitget incident fund-flow analysis by WIDTH DART
Why this analysis matters

When assets leave a compromised exchange wallet, the first transfer is only the beginning. The funds may be split across addresses, exchanged for other assets and moved between networks. By the time a portion reaches another platform, its connection to the original incident may be several transactions away.

That is the operational question raised by the Bitget incident of 24 September 2026: can a platform recognise the source of a deposit after the funds have crossed chains and changed form?

Bitget initially reported approximately US$351.6 million in affected assets. On 25 September, it revised that figure to approximately US$387.5 million after identifying additional Zcash and TRON assets. Separately, WIDTH DART’s analysis of the routes covered in this article valued the traced transfers at approximately US$357.8 million using 24 September prices. These figures have different scopes and should not be treated as competing estimates of the same total. [1][2]

This article records DART’s findings as at 01:10 UTC on 27 September 2026. The addresses, balances and movement percentages are a historical snapshot, not a live status report.

What happened in the Bitget incident?

Bitget says its systems detected unauthorised transfers at 18:31 UTC on 24 September. It temporarily suspended withdrawals, identified and flagged affected addresses, and began working with security firms and relevant authorities. The exchange said the breach affected part of its hot and warm wallet layers, while cold wallets remained secure. It also said its User Protection Fund, then valued above US$464 million, would cover the loss. [1]

Bitget subsequently stated that the vulnerability had been identified and remediated, and that the revised US$387.5 million estimate reflected a more complete classification of the incident rather than new transfers after containment. [2]

DART reconstructed 20 unauthorised transfers within its analysed scope and followed the subsequent movement of assets across Ethereum and other EVM networks, TRON and the XRP Ledger (XRPL). Its work focuses on what happened after the funds left: where assets accumulated, which routes were used to exchange them and which addresses may matter to a receiving platform.

The sequence of transfers and swaps

Timeline of the Bitget stolen funds
Period (UTC) What DART observed
24 September, 18:31–19:16 An initial 0.84 ETH transfer was followed by a 34.75 million USDT outflow on Ethereum. Transfers then appeared in quick succession across Arbitrum, Ethereum, OP, Base and XRPL. Further outflows included 91.42 million XRP and 20.59 million TRX.
24 September, 19:30–23:43 Stablecoins and XAUt were exchanged for ETH. One aggregation address received 22,320 ETH; on Arbitrum, 19.67 million USDT0 was exchanged for about 7,111 ETH. Later transfers included ETH, USDC and XRP. Approximately 103 million XRP was divided among five new addresses, while 43,213 ETH was distributed to five others.
25 September, 00:11–01:50 A small amount of XRP crossed into Ethereum through NEAR Intents and Bridgers. At the 01:50 snapshot, approximately 67,980 ETH and 102.6 million XRP were still in addresses DART classified as dormant.
25 September, from 02:13 XRP began moving through newly activated accounts towards THORChain swaps. The BNB and TRON holdings also started moving through intermediary addresses, swaps and bridges.
25–27 September XRP movement accelerated. By DART’s 01:10 UTC snapshot on 27 September, around 81.3 million XRP had been exchanged through THORChain, largely into BTC.

The recorded unauthorised transfers span almost three hours. The blockchain timestamps establish the movement, but they do not by themselves establish precisely when each security control was applied or what the attacker controlled at each moment. Bitget’s incident reporting should be used for conclusions about the breach mechanism and remediation.

Where did the stolen assets move?

Breakdown of assets traced from the Bitget incident

The routes diverged by asset. Some funds were exchanged rapidly, while substantial ETH balances remained at addresses that had not sent assets onward by the stated snapshot. A change of token or chain complicates tracing, but it does not automatically erase the transaction history.

XRP moved towards BTC through THORChain

From 25 September, XRP was distributed through newly activated XRPL accounts before entering THORChain. DART observed about 200 new accounts in the layered transfer paths. By 01:10 UTC on 27 September, approximately 81.3 million XRP, valued by DART at roughly US$125 million, had been swapped through THORChain. That was about 79% of the XRP in the original DART-traced outflow. Most of it became BTC across approximately 90 BTC addresses; around 5.6 million XRP was exchanged into ETH, BNB or DAI on other networks.

These observations describe movements traced at a particular time. It does not mean every downstream BTC address was controlled by the same person, nor does it establish how much was ultimately recovered or frozen.

BNB and TRON took different cross-chain routes

DART observed the full 5,896.58 BNB balance leave the previously dormant BNB Chain address identified in its investigation. Approximately 5,030 BNB then moved through intermediary addresses and was exchanged into BTC via THORChain.

On TRON, approximately 20.59 million TRX sat at a newly created address for about 13 hours before being split and moved. Roughly 20.04 million TRX was exchanged for about 6.8 million USDT on SunSwap, then bridged to 16 Ethereum addresses. From there, DART traced approximately US$4.41 million towards BTC swaps through THORChain, US$1.84 million into about 682 ETH via UniswapX and onwards to Umbra, and about US$300,000 into Chainflip. An additional approximately 557,000 TRX went to an external wallet that DART had not identified. One BTC path, amounting to roughly 4.6 BTC, later entered a CoinJoin transaction pattern.

Illustration of the laundering routes identified in DART’s analysis

Some ETH entered privacy protocols while larger balances remained in place

One route delivered approximately 2,486 ETH to an Ethereum address after a THORChain swap. DART then observed transfers through Umbra, distribution into 220 tranches, movement between Ethereum and Arbitrum through Stargate, and onward activity involving Chainflip. Four sampled paths followed the same broad pattern.

Meanwhile, DART’s eight monitored dormant Ethereum wallets showed no outgoing transfers by the 27 September snapshot. Some balances increased as funds returned from other routes. One wallet held approximately 4,326.46 ETH after receiving ETH from OP and other addresses. DART also traced a 457.9 ETH transfer to an aggregation address from a wallet funded by withdrawals associated with publicly labelled Binance hot wallets. That trail may offer an investigative lead for the relevant exchange; it does not identify the exchange account holder or prove that account holder’s role in the incident.

At the snapshot, approximately 68,923 ETH and 16.96 million XRP remained at addresses DART classified as dormant. DART estimated those holdings represented roughly 60% of the value in its traced scope. This percentage must not be applied uncritically to Bitget’s later, broader US$387.5 million incident total.

Why does the fund trail matter beyond this incident?

Crypto security incidents in the first half of 2026

Crypto security incidents create a continuing screening problem for exchanges, custodians, OTC desks and payment platforms. CertiK recorded 344 incidents and approximately US$1.316 billion in gross losses in the first half of 2026. That is a separate industry-wide reporting period, not an estimate of the Bitget incident. [3]

In the Bitget routes DART analysed, some USDT and USDC were exchanged into ETH within minutes of receipt. Other assets were split, bridged or swapped through multiple services. A check limited to a single wallet label or a single blockchain could miss relevant upstream context when those assets later appear as an incoming deposit.

The practical task is to retain the connection between the original incident, intermediate transactions and the current deposit address. A reviewer needs to know which path triggered an alert, how much of the deposit may be linked to it and whether the evidence justifies escalation under the platform’s own policy.

What did DART find when it linked addresses across chains?

The analysis produced two investigative leads: address reuse across EVM networks and an on-chain wallet connection to the earlier AFX Trade incident.

Reused addresses connect otherwise separate routes

DART found that several externally owned addresses appeared on more than one EVM network, including addresses labelled Exploiters 1, 2, 3, 6 and 7 in its case analysis. Addresses such as 0x274e and 0x5085 received assets on Avalanche and also appeared in Ethereum flows involving CCTP-minted USDC. The address 0xa6dd appeared in both an Ethereum aggregation route and a BNB Chain intermediary path.

Because an EVM address can be reused across compatible networks, these overlaps help analysts reconnect flows that might look unrelated when viewed chain by chain. They are evidence of an on-chain relationship, subject to the usual limitations of address attribution.

The AFX connection is an investigative lead

Bitget and AFX wallet path analysis

DART also examined a connection to wallets associated with the AFX Trade incident of 22 July 2026, in which approximately 24.15 million USDC was lost. On-chain analyst @SpecterAnalyst first disclosed the proposed connection. DART then reviewed the route hop by hop.

According to that review, the Ethereum address 0xa077, which received assets originating from Bitget XRP routes, had interacted with 0xcbcf months earlier. Another wallet, 0x989c, funded 0xcbcf and supplied gas to an AFX-linked address in July. On 25 September, 0xa077 also combined funds with wallets publicly labelled as Bitget exploit addresses. Together, these observations support examining a shared wallet cluster.

A wallet connection is not proof that the same individual or group carried out both attacks. Attribution requires evidence beyond shared transaction paths, including the possibility of shared services or other intermediaries. The link is useful for investigation and screening, but should be presented with that limitation.

Could funds from the incident reach your platform?

How stolen funds may reach a receiving platform

Consider a future deposit of ETH that has passed through a bridge, several intermediary wallets and a swap service. The incoming address may carry no obvious label. Yet part of its transaction history might trace back to an address associated with the Bitget incident.

A platform needs a process that can:

  1. Trace the source of funds beyond the immediate sending address, across supported networks and bridges.
  2. Match relevant incident labels while recording how direct or remote the connection is.
  3. Assess the exposure using the amount, direction, number of hops and the platform’s own risk rules.
  4. Route the alert for review, with the supporting transaction path visible to the analyst.
  5. Document the decision and next action under the organisation’s policies and applicable obligations.

An alert is a reason to investigate, not a finding of wrongdoing against every intermediary or depositor. Equally, a transfer that does not hit a known label is not automatically low risk; the address and incident data will continue to change.

How DART supports deposit risk review

Tracing the source of an incoming deposit

DART combines fund-flow investigation, address labels and configurable screening rules to help teams examine an address or transaction. Its published product manual describes upstream and downstream path analysis, followed by path-matching rules and a separate scoring stage. The output gives a risk score and a disposition for review under the customer’s configured rules. [4]

In its Bitget case analysis, DART reports that it:

  • reconstructed cross-chain routes and identified address reuse across networks;
  • added 55 EVM-chain address labels, representing 45 distinct addresses because some were reused across chains;
  • cross-referenced incident addresses with historical wallet activity, including the AFX investigative lead; and
  • configured continuous monitoring for 32 addresses, including the eight Ethereum wallets classified as dormant at the stated snapshot.

For an integrated platform, this type of information can help surface an incoming transaction for assessment when it touches a labelled address or a relevant fund-flow path. The team still needs to decide how to handle the alert. Chain coverage, alert latency, scoring thresholds and the ability to act on a deposit depend on the implementation and the platform’s operating controls. No screening system can guarantee that every stolen deposit will be identified or stopped.

The operational lesson from Bitget

As at 01:10 UTC on 27 September 2026, DART had observed extensive XRP and BNB movement into cross-chain swaps, further TRON-linked transfers and some ETH entering privacy-related routes. At the same time, substantial ETH balances remained at addresses DART was monitoring. The picture will change as funds move, labels improve and Bitget’s recovery efforts continue.

For a receiving platform, the lesson is practical: keep incident labels current, preserve cross-chain context, send material matches to an accountable reviewer and record the reasons for each decision. A sound control is a review process that can follow an explainable fund path from an incoming deposit back to the relevant source.

To discuss how DART can support address screening, transaction risk assessment and fund-flow investigations, visit width.info.

Frequently asked questions

Bitget’s initial estimate was approximately US$351.6 million. It later revised the total to approximately US$387.5 million after classifying additional affected assets. DART’s US$357.8 million figure refers to the transfers in its own analysed scope, valued using its stated price snapshot. [1][2]


Data and source note: All DART-specific transaction counts, amounts, wallet links and percentages above are attributed to the supplied WIDTH DART investigation. They reflect its snapshot at 01:10 UTC on 27 September 2026. USD values use its stated 24 September 2026, 19:00 UTC conversion point. Its stated sources are Etherscan V2, XRPL public nodes, THORNode, public exchange labels and the DART label library. This article does not provide transaction hashes or a public methodology appendix for independent verification of every traced path. “Dormant” means no outgoing movement was observed from the specified wallet at the snapshot, not that the assets were frozen.

Sources

  1. Bitget’s initial security notice, 24 September 2026.
  2. Bitget’s updated incident statement and recovery programme, 25 September 2026.
  3. CertiK Hack3D: H1 2026 Report.
  4. DART Product Manual.
DART · Digital Asset Risk Targeting

See the fund path behind a deposit

Connect incoming transactions to address labels, cross-chain context and a reviewable risk decision.