An attacker linked to the Bitget hack has left nearly $700,000 stranded after sending stolen crypto to Chainflip deposit channels on the wrong networks.
AMLBot spotted the transfers on October 2. They involved roughly 267,000 USDC and 160 ETH, with Ethereum and Arbitrum apparently switched in opposite directions.

Source: X
Hacker Sends Crypto to Wrong Chains
The first mistake involved about 267,000 USDC on Ethereum. The attacker sent it to a Chainflip deposit channel meant for Arbitrum.
Chainflip could not process the Ethereum deposit. Circle later blacklisted the receiving address, which prevents the USDC from being moved.
The ETH transfer went wrong in the opposite direction.
The attacker moved roughly 160 ETH from Ethereum to Arbitrum, then sent it to a Chainflip channel that was set up for Ethereum. AMLBot valued the coins at around $430,000 when it reported the transaction.
That left the ETH sitting on Arbitrum outside the intended Chainflip route. AMLBot said the funds remain stranded because the deposit channel cannot process them on that network.
The two transfers add up to roughly $697,000.
Automated Transfers Swapped Networks
AMLBot said the transfers were likely made using automated software. They happened only seconds apart, and both involved the wrong blockchain network.
In one transfer, Ethereum-based funds were sent to a Chainflip address meant for Arbitrum. In the other, the attacker moved ETH to Arbitrum before sending it to a Chainflip channel set up for Ethereum.
The two mistakes suggest the software may have used the wrong network settings. However, there is no public evidence showing exactly what caused the error.
The activity also follows earlier tracking of funds linked to the Bitget hack through Chainflip and other services. MistTrack, SlowMist’s blockchain tracking team, previously found automated CoW Protocol transactions involving Chainflip deposit addresses.
The problem is fairly simple. Cross-chain services use different deposit addresses for different networks. If someone sends crypto through the wrong network, the funds can end up stuck.
Blockchain transactions also generally cannot be reversed once they are confirmed. Recovering the funds then depends on the company or service controlling the receiving address.
Bitget Loss Reaches $387.5M
The nearly $700,000 stuck in Chainflip channels is only a small part of the Bitget theft.
Bitget now estimates that about $387.5 million in crypto was sent to addresses controlled by the attacker during the September 24 incident. The exchange initially estimated the loss at $351.6 million before adding transfers involving Zcash and TRON.
Bitget said the higher figure came from a more complete review of the incident, rather than from additional unauthorized transfers.
The exchange detected the transfers at about 18:31 UTC on September 24. Bitget said some of its hot and warm wallets were affected, while its separate Bitget Wallet product was not.
Bitget has also said the attackers did not get its private keys. Instead, the exchange said fake transaction instructions were processed by its wallet system.
SlowMist and Mandiant have also investigated the incident. SlowMist reported suspicious activity linked to the attack weeks before the September 24 transfers.
Bitget has since launched a Recovery Bounty Program. It offers 5% of frozen funds and 5% of eligible funds that are recovered. The exchange has also said its User Protection Fund will cover the loss.
Cross-Chain Routes Remain Under Watch
The stolen crypto has moved through several services that allow users to swap assets between blockchains. Public blockchain tracking has identified activity involving THORChain and Chainflip.
NEAR Intents also rejected most of more than $50 million that attackers tried to move through its system, according to the supplied tracking data.
Tether and Circle have frozen some stablecoins linked to the attacker. Those actions have stopped some of the stolen funds from moving.
AMLBot also followed Bitcoin linked to the theft through USDT, Ethereum and THORChain before the funds entered a Wasabi CoinJoin transaction.
CoinJoin combines crypto from several users into one transaction. This can make it harder to determine where individual coins originally came from.
AMLBot also identified three THORChain affiliates connected to attacker wallets. Those wallets reportedly used the affiliates to carry out thousands of swaps involving millions of dollars.
North Korea Attribution Remains Disputed
Bitget CEO Gracy Chen has linked the attack to North Korean hackers, pointing to internet activity and blockchain transactions. Other security researchers have also reported signs pointing to North Korea-linked groups.
However, no government has formally said that North Korea was behind the Bitget attack.
Investigators are continuing to follow the blockchain trail and monitor wallets linked to the theft.
The two Chainflip transfers provide another clue. Instead of helping the attacker move the stolen crypto, the network mistakes appear to have left about $700,000 stuck.
Circle has blacklisted the USDC address, while the ETH remains on Arbitrum outside the intended Chainflip route. It is still unclear whether either balance can be recovered.





