The attacker behind the $387.5 million Bitget hack attempted to route stolen cryptocurrency through cross-chain swap protocol Chainflip, but the transaction was rejected by a broker before it could be executed through the network.Chainflip disclosed the attempted transaction after addresses associated with the Bitget exploiter tried to use its infrastructure to convert stolen assets across blockchains.The incident provides another example of crypto infrastructure identifying and blocking assets connected with the September 24 attack as the exploiter attempts to move funds away from addresses monitored by investigators.Crucially, Chainflip said the attempted transaction was stopped by a broker operating at the entry point to the protocol, rather than being reversed or frozen after settlement.That distinction matters because Chainflip itself is designed as a decentralized cross-chain automated market maker. Brokers provide users with access to swaps and can implement their own compliance and transaction-screening policies before submitting transactions to the underlying protocol.
Broker Screening Stops Attempted Swap
Chainflip allows users to exchange native assets between different blockchains without relying on wrapped tokens or conventional centralized exchanges.Its architecture separates the underlying decentralized protocol from brokers and other services that help users initiate transactions.In the Bitget case, the broker identified the source of the attempted swap as being associated with the exploit and refused to process it.The assets therefore did not complete the intended Chainflip swap.This differs from an asset freeze by a centralized exchange or stablecoin issuer. The broker did not seize the attacker’s cryptocurrency; it simply refused to provide the route into Chainflip through its service.An attacker could theoretically attempt to access decentralized infrastructure through another route that applies different screening policies, illustrating the distinction between censorship at an application or broker layer and censorship within a permissionless protocol itself.The attempted Chainflip transaction follows a separate intervention by NEAR Intents, which said it rejected more than $50 million of attempted swaps connected with the Bitget attacker and froze approximately $503,000 that had already reached its infrastructure.Together, the incidents show how cross-chain services are increasingly becoming part of the immediate response to large cryptocurrency thefts.
Bitget Hacker Searches for Cross-Chain Liquidity
Bitget detected unauthorized transfers at 18:31 UTC on September 24. The exchange initially estimated the incident at $351.6 million before increasing the figure to $387.5 million after identifying additional affected Zcash and TRON assets. Bitget said the higher figure represented more complete accounting rather than another drain.The attack affected assets across multiple networks, including Ethereum-compatible chains, XRP Ledger, TRON and Zcash.Investigators including GoPlus have said the incident appears to have compromised Bitget’s transaction-signing trust chain rather than its private keys.According to that analysis, attackers were able to feed fraudulent transaction information into an authorized signing process, resulting in valid signatures for transfers Bitget had not legitimately intended to execute.Bitget has said its cold wallets were unaffected, customer balances remain intact and the underlying vulnerability has been remediated. Mandiant and SlowMist are assisting with the investigation.The attacker’s subsequent movements are now being watched closely because converting assets across chains can make stolen funds harder to recover.Cross-chain protocols are particularly useful for legitimate users because they reduce dependence on centralized exchanges when moving between assets such as Bitcoin, Ether and stablecoins. Those same characteristics can attract hackers seeking to fragment or transform stolen holdings.The Chainflip incident highlights an increasingly important layer in that infrastructure. A decentralized protocol may remain permissionless at its core while the brokers, interfaces and routing services surrounding it independently screen transactions.In this case, that distinction worked against the Bitget exploiter: the broker recognized the source of the funds and refused the transaction before the stolen assets could be routed through Chainflip.
