Latest News

THORChain Liquidity Earned $573,000 From Bitget-Linked…

Moving funds stolen in Bitget’s $387.5 million September breach generated at least $761,725 in identifiable fees for crypto protocols and services, while a separate analysis of THORChain affiliate payments found about $259,718 went to seven recipients with additional transaction links to wallets involved in the laundering routes.

The figures come from independent on-chain researcher Andrey Sergeenkov, who analyzed swaps involving assets traced from the Sept. 24 attack through Oct. 2. His dataset does not establish that affiliate recipients controlled the attacker wallets or knowingly facilitated laundering, and the calculated fees should not be treated as net profits.

The research adds a financial layer to the laundering activity that followed the Bitget breach: cross-chain swaps create revenue for liquidity providers, interfaces and routing services even when the assets moving through them have been linked to a hack.

Which Protocols Collected the Most Fees?

THORChain liquidity fees dominated the measured sample at approximately $573,226, representing 75.3% of the $761,725 total.

Transfers identified by Sergeenkov as MetaMask-related fees accounted for another $149,417. Chainflip broker fees totaled approximately $26,751, while executed protocol and partner fees associated with CoW EthFlow contributed roughly $12,332.

The calculation uses historical dollar prices and excludes separate BNB Smart Chain fees. It also does not allocate THORChain liquidity fees among individual liquidity providers or determine who ultimately received CoW-related fees, making the total a measurement of recorded charges rather than a complete accounting of economic beneficiaries.

The distinction matters because infrastructure providers can play very different roles. FinanceFeeds previously reported that a Chainflip broker rejected a Bitget-linked transaction before the stolen funds could enter the protocol, showing that some access points can screen flows even when the underlying network is permissionless.

Investor Takeaway

The fee totals quantify an overlooked part of post-hack activity: stolen assets can create legitimate protocol revenue while being moved. Investors should distinguish automated fee collection from evidence that a service knowingly assisted an attacker.

Why Do THORChain Affiliate Payments Matter?

THORChain swaps can include an affiliate identifier and fee. An interface or routing service can insert that information before the user signs the transaction, meaning the appearance of an affiliate recipient in a hacker-linked swap is not evidence that the attacker owns or controls the recipient address.

Sergeenkov therefore separated affiliate recipients according to whether additional transaction links could be identified.

Seven recipients collected approximately $259,718 in affiliate fees and had further financial connections to wallets involved in the laundering routes. The largest received about $177,499, while another collected roughly $56,514.

Some links involved multiple swap routes delivering their principal Bitcoin proceeds to the same destination addresses. Others were stronger: one recipient that earned about $18,080 later exchanged part of its RUNE fees and sent proceeds to a wallet that had submitted swaps using that affiliate identifier. That wallet subsequently received ETH connected to Bitget’s compromised-address cluster.

A smaller recipient earning roughly $196 also converted accumulated RUNE and directed the resulting ETH back toward the address that had submitted the transactions generating those fees.

Those transfers create investigative leads, but they still do not establish common ownership or intent.

Investor Takeaway

Affiliate data becomes more useful when combined with subsequent fund movements. A fee identifier alone is weak attribution evidence; return flows, shared destinations and interactions with known attacker clusters provide more meaningful leads for investigators.

Could the Fee Trail Help Identify the People Behind the Funds?

The largest linked affiliate route produced one potentially useful off-chain lead. Sergeenkov traced part of the recipient’s RUNE fees into USDT, through two Ethereum wallets and eventually to an address labeled by Etherscan as an OKX hot wallet.

That does not establish that OKX directly received stolen assets or that the affiliate recipient holds an account there. It could, however, provide investigators with a point where blockchain tracing potentially intersects with customer records held by a centralized exchange.

Another $206,196 in THORChain affiliate fees and credits went to recipients for which the research had found no additional hacker-related financial links by the Oct. 2 cutoff. The largest was associated with the THORName “naswap,” at approximately $102,344, while a THORChain holding account containing credits associated with several names accounted for about $92,438.

The control group reinforces why affiliate payments should not be treated as evidence of wrongdoing.

What Does the Fee Data Add to the Bitget Laundering Story?

Bitget has said the September attack transferred approximately $387.5 million after attackers compromised a third-party security product and manipulated the exchange’s withdrawal infrastructure without stealing private keys. FinanceFeeds has since tracked movements including more than $83 million in stolen XRP and the debate over THORChain’s refusal to block hacker-linked transactions.

The new research shifts part of that discussion from where stolen funds moved to who collected fees while they moved.

Investor Takeaway

The dollar value of the fees is secondary to the attribution opportunities they create. Every affiliate payment, broker interaction and centralized-exchange deposit can add another observable relationship to an otherwise fragmented laundering trail.

You may also like