Bitget said $351.6 million. We followed it across eight chains.
On 24 September 2026, at 18:31 UTC, Bitget's security systems flagged unauthorised transfers out of a limited number of hot wallets. Bitget puts the affected assets at about $351.6 million. It says it has flagged the transfer addresses. It has not published a list.
So we read the chains instead. Every figure below with a transaction hash next to it was read from a public node or explorer, one transfer at a time, across eight networks — including the XRP Ledger half, traced here address by address. Our total is $357.3 million.
Two days after we finished reading, on 27 September, every address in this article that was holding funds is empty — including the five XRP Ledger accounts that held 102 million XRP between them. That is below, with the times each was drained.
We are a blockchain forensics company and this is the kind of work we do, so a second question was unavoidable: does our own product get the same answer? At the end of this piece we run it against the same address and publish what it returns, including the parts where it answers a different question from the one we asked by hand.
What Bitget says
At 18:31 UTC Bitget's security systems identified unauthorized transfers from a limited number of hot wallets. Bitget puts the affected assets at about $351.6 million, says cold wallets are unaffected, that a user protection fund covers the loss, and that withdrawals are suspended. It says it has flagged the transfer addresses; it has not published a list. The CEO's notice describes a three-tier wallet architecture and says the incident touched a portion of the hot and warm layers.
In her later written summary the CEO says the affected assets include ETH, XRP ("the largest single chain loss"), BNB, AVAX, USDT and USDC, across Ethereum, the XRP Ledger, Arbitrum, Avalanche, Optimism, BSC and Base; that some foundations have already frozen attacker addresses; and that IP patterns and on-chain signatures are consistent with techniques used by DPRK-linked groups. That last point is Bitget's assessment; we do not repeat it as ours.
The sources, all read on x.com:
- Bitget, 2026-09-24 21:34 UTC — x.com/bitget/status/2103236552482848927
- CEO Gracy Chen, 2026-09-24 21:30 UTC — x.com/GracyBitget/status/2103235655879074084
- @bitget, 2026-09-25 03:10 UTC — the protection fund holds 5,500 BTC; losses from this incident will be borne by the fund.
- @GracyBitget, 2026-09-25 05:43 UTC — a written summary of the CEO's live session, which names the affected chains and assets.
- @bitget, 2026-09-25 07:10 UTC — ["[UPDATES]"](https://x.com/bitget/status/2103381494056288658): Mandiant and SlowMist are investigating; withdrawals remain paused; Bitget Wallet runs on separate infrastructure and was not affected. No addresses, no amount, no vector.
No written post on either profile lists addresses. We have not reviewed the live audio session.
The shape of it: two bursts, five networks each

Twenty transfers, eight networks, two hours and fifty-two minutes. Thirteen of the twenty land inside two windows of a quarter of a minute each.
What we measured
Times are UTC on 2026-09-24. The first transfer we find into the address that later received
most of the funds — 0x770b10b273fC44Fe9197D6bF20F145c2e98463Ee, which had no prior history on
any chain — is at 18:31:11, the minute Bitget gives for detection.
Inflows to 0x770b10b273fC44Fe9197D6bF20F145c2e98463Ee
Senders carry a "Bitget" label in third-party address data — a label, not a confirmation from Bitget. USD = amount × the DefiLlama historical price at the transfer's block time (one method throughout; see Method).
| Time | Chain | From | Amount | USD at transfer | Tx |
|---|---|---|---|---|---|
| Time18:31:11 | ChainEthereum | From0x1AB4…8F23 | Amount0.84 ETH | USD at transfer$2.3K | Tx0xc19560f5fe5308c9ec8aa5721d7acb9a713cbf6166e2a8e34b6ecd5327c37be6 |
| Time18:58:59 | ChainEthereum | From0x1AB4…8F23 | Amount34,751,168 USDT | USD at transfer$34.74M | Tx0xa3ae35a0006ff4299f8f18614c2c21750eb8e0f5c047df4a526e1cc6ae599ce5 |
| Time19:01:20 | ChainArbitrum | From0x1AB4…8F23 | Amount19,668,851.77 USDT0 | USD at transfer$19.66M | Tx0xd032320ad8a3cddc61ec0db5e6e26a6dcf813243a77b7edc5a65451ade0b84e3 |
| Time19:01:23 | ChainEthereum | From0x1AB4…8F23 | Amount12,852,046 USDC | USD at transfer$12.85M | Tx0x40903fbeb10a17b198293543e7dd70c5862b4dcdf438522d2f3708043b7ad7ae |
| Time19:01:23 | ChainEthereum | From0x5bdf…F7Ef | Amount3,000.32 XAUT | USD at transfer$12.82M | Tx0xa976f0400bfb866162306c68ce7195cca9606b1f8c68d1af98da01632f5a9d29 |
| Time19:01:29 | ChainOptimism | From0x5bdf…F7Ef | Amount5,737.68 ETH | USD at transfer$15.41M | Tx0xf1a2fe16d5dc20e99d2cfda2ec8f209b3cb6a898e05bf85417a598f44c57cc2c |
| Time19:01:33 | ChainBase | From0x97b9…8689 | Amount1,555.32 ETH | USD at transfer$4.18M | Tx0x7692aacb2eeb06632bdf2fa4697f66f369b8fe7408e8c3fe7d1b9592ee44f5c8 |
| Time19:01:35 | ChainEthereum | From0x1AB4…8F23 | Amount7,130.86 ETH | USD at transfer$19.15M | Tx0x67a7ac52e0de05aa3e9a3901cbd6315d3317c8ec191e175067d49c709b48930c |
| Time19:03:23 | ChainEthereum | From0xffa8…cD54 | Amount0.65 ETH | USD at transfer$1.7K | Tx0x37fa457faa6a82163dbcdddb7ad4cdbe424e04779a49b4bfa61f5ddcc7702ebe |
| Time19:16:14 | ChainBSC | From0xffa8…cD54 | Amount12,719.46 BNB | USD at transfer$9.93M | Tx0xd456a40329a45a3714dfd573eef0ab115a5fd083deecd28db08190cc24f46903 |
| Time19:16:15 | ChainAvalanche | From0xffa8…cD54 | Amount821,011.97 AVAX | USD at transfer$8.57M | Tx0x98659b02262ccc475e7402b8f1e84349cba6569fcadb25a2e46f055f8936ddd6 |
| Time19:16:23 | ChainEthereum | From0xffa8…cD54 | Amount13,965.93 ETH | USD at transfer$37.58M | Tx0x8469803a082c4d106c642874509ffb8b7a730cd52934ccd44af0c479d8f60bfa |
| TimeSubtotal through 19:16 | Chain | From | Amount | USD at transfer$174.9M | Tx |
| Time20:09:11 | ChainEthereum | From0x1AB4…8F23 | Amount1,879.2 ETH | USD at transfer$5.06M | Tx0xdd07e8803db0fe31c4935399737d389442228a1b2d595545a7cd0e41625af606 |
| Time20:09:23 | ChainEthereum | From0xffa8…cD54 | Amount1,395.9 ETH | USD at transfer$3.76M | Tx0x0c63cd7d8244419cf7e172da394cc98ed37d8d3965a1a20227ba962a84f2e97e |
| Time20:55:07 | ChainAvalanche | From0x1AB4…8F23 | Amount8,204,678.80 USDC (0xB97EF9Ef…8a6E) | USD at transfer$8.20M | Tx0x4d2d95dadf9722df7c2cfa92e3a2954f966505d1cc0dfea5b015c4d7a6014499 |
| Time21:23:11 | ChainEthereum | From0x1AB4…8F23 | Amount223.2 ETH | USD at transfer$0.60M | Tx0x230558293435e59d693438867995b6398a9b9cc8d30291d0c07d68f0ca449afb |
| TimeTotal through 21:23 | Chain | From | Amount | USD at transfer$192.5M | Tx |
Valued at prices at the cut instead, the total is $192.2M — the choice of method moves it by less than 0.2%. Only labelled Bitget senders and native or real-contract transfers are counted. Treat the total as a floor: ERC-20 inflows were checked on Ethereum, Arbitrum, Optimism, Base and Avalanche; on BSC only BNB was confirmed independently.
Inflows on the XRP Ledger
The two XRP Ledger accounts that XRPScan's public name list labels "Bitget Global"
(rGDreBvnHrX1get7na3J4oowN19ny4GzFn, rwTTsHVUDF8Ub2nzV2oAeWxfJzUvobXLEf) sent XRP to one
account, rwNhefsz1UQEusxhCvHip3RANinWi4CTck. Successful payments only; USD by the same method.
| Time | From | Amount | USD at transfer | Tx |
|---|---|---|---|---|
| Time19:01:32 | FromrGDre…GzFn | Amount2,248,871.54 XRP | USD at transfer$3.44M | Tx9926E440BC17F3EE7ACB91DB09A44B9781876B19C6E2D046E5E225F758FB25F4 |
| Time19:16:20 | FromrwTTs…XLEf | Amount91,420,942.76 XRP | USD at transfer$140.09M | Tx8DF2ECF67268117A34B89BE9B452D3E888A22CBF03E5C196AD72D8B414A84195 |
| Time21:19:21 | FromrwTTs…XLEf | Amount9,306,865.80 XRP | USD at transfer$14.28M | Tx41EFBB55219A89AB33F0E6EAFD3420EE8CBA7F03EC08F8BE546CE5DF5F26D42A |
| TimeTotal | From | Amount102,976,680.10 XRP | USD at transfer$157.8M | Tx |
Onward: rwNhefsz… sent 20,000,000 XRP to each of rDRV9nLg8xbLsafKZnhNgWuE1TiSLE95hs
(21:42:02), r3UGfDM4ZyFSCzKH7TQEjgago9QoUJagtJ (22:03:41),
rH7oMFKBgdK99TPQctFVzddD7srRzyCqZn (22:04:42), rwSjBrtxBC75TqZ5YvJ1TGfaRpQvVNsAKw
(22:06:01), and 22,976,677 XRP to r6NcwN3dR5ciyBv9XsLyMNc9Kg2FBCs7Y (23:43:41), leaving 3 XRP
behind. At about 10:00 UTC on 25 September those five still held roughly 19.45M / 20M / 20M /
20M / 22.98M XRP. They do not any more — see "Where it stands on 27 September" below.
Inflows on Tron
| Time | From | To | Amount | USD at transfer | Tx |
|---|---|---|---|---|---|
| Time18:31:00 | From"Bitget 9" (Tronscan tag) | ToTBWNguTTgezw9dVorX441C6nDrZpRxYwKD | Amount93 TRX — the first transaction this account ever received | USD at transfer~$0 | Tx698c02a8549b96783bf16a6d61d279485ee8abb6f245e7a9c223d170795fec4b |
| Time19:16:18 | FromTJxe1MWrb5ppk3beWArqU2Dwg3jvhGUGx5 (no tag; received 3.04M TRX from "Bitget 9" at 20:40:12) | ToTBWNguTT…KwKD | Amount20,593,283.57 TRX | USD at transfer$7.01M | Txce9b366cacadf7a2947d4149f0dcb16d1ed5f9abf524a0859a67fff54fa7d13f |
TBWNguTT… was created on 24 September, and the 93 TRX at 18:31:00 is the first transaction it
ever received — eleven seconds before the first Ethereum transfer to 0x770b…, and in the
minute Bitget gives for detection. A very small transfer to a new address before a very large
one is the same shape as the 0.84 ETH and 0.65 ETH transfers on Ethereum. We do not know who
initiated any of them, or why.
At 10:04 UTC on 25 September the account held 4,369,190 TRX. From 08:25 UTC that morning it
sent 16.2M TRX onward in 19 transfers of 214K–1.75M TRX to about fifteen addresses; we did not
follow them. The largest repeat recipients are TDcu2CMpyLK4M5wmE5tstAZv9ZjK7xPHNX and
TSqLrg8UNatjcoy2ZBWmf7jsSnxmV8m52N. That account is empty today; again, see below.
How the Tron leg was found, and why it matters. TJxe1M… carries no label on Tronscan. It
appeared because we read the recipient's history — not because we started from a list of
Bitget-labelled wallets. Every label-first scan of ours (26.8K EVM addresses, 11 tagged Tron
addresses) had missed it. The XRP Ledger leg, by contrast, was found through a public name
list. A trace that only follows names finds only what somebody has already named.
All parts together: $192.5M (EVM chains) + $157.8M (XRP Ledger) + $7.0M (Tron) = $357.3M, against Bitget's approximately $351.6 million — $5.7M, or 1.6%, above it. Three things could explain a difference of that size: the date at which the assets are valued, the perimeter of what Bitget counts as "affected", and assets returned or frozen. We claim none of them.
For scale, one independent primary datum: Lookonchain's post on x.com (2026-09-24 ~23:39 UTC) reports 67,982 ETH ($183M) in the EVM part of the flows, and its Arkham entity screenshot shows $188.9M across 22 EVM addresses. Our EVM inflows are 31,889 ETH direct plus the stablecoins and XAUT later sold for ETH ($192.5M in all); the ETH those flows became sits on about nine addresses. We did not use anyone's XRP or Tron figure — those are ours, read on their ledgers.
The two bursts, in words
At 19:01:20–19:01:35 — fifteen seconds — transfers landed on Arbitrum, Ethereum (three of
them), Optimism, the XRP Ledger and Base. Five networks. Four different sending addresses:
0x1AB4…8F23, 0x5bdf…F7Ef, 0x97b9…8689 and the XRP Ledger account rGDre…GzFn.
At 19:16:14–19:16:23 — nine seconds — transfers landed on BSC, Avalanche, Tron, the XRP
Ledger and Ethereum. Five networks again, and this time three of them came from one sending
address: 0xffa8…cD54 sent BNB on BSC at 19:16:14, AVAX on Avalanche at 19:16:15 and ETH on
Ethereum at 19:16:23. One address, three independent networks, nine seconds — which points to
automated execution by a single process able to sign for that address on all three. The other
two legs of that burst, on Tron and the XRP Ledger, came from different addresses.
The second burst carries the largest single amount of the day, the 91.42M XRP at 19:16:20.
Not claimed: that one party controlled all the senders in either burst, how any transfer was authorised, that a key was compromised, that a contract was or was not exploited, or any attack vector. Bitget's written posts name none.
The same address on two chains
0x7c96279Ec1e888Aa56b9B836e0dB26ca48573E1C received funds from 0x770b… on both Ethereum
(stablecoins and XAUT, 19:07–19:22) and BSC (12,719.45 BNB, tx
0x999c012afcec5ab171b8e7e61c859e2f2ec69fb5ae43d35b3ae0c52153fee4b1, 19:45:16). On Ethereum it
is an EIP-7702 delegated account. On both chains it then made bridge calls with the same
function selector (0x3ce33bff, bridge(string adapterId, address srcToken, uint256 amount,
bytes data)): on Ethereum to the contract labelled MetaBridge (0x0439e60F…C3f1), on BSC to
0xaec23140408534b378bf5832defc426df8604b59 (2 × 1,000 BNB at 19:45:54 and 19:46:49; adapter
id lifiAdapterV2). The BSC contract's identity is not verified beyond that matching selector
and the calldata text; we do not name its operator.
Same address, same tooling, two networks: a fact about the chains, no inference about intent.
Onward movement
From the recipient outward. No labels involved.
| Time | Chain | Movement | Note |
|---|---|---|---|
| Time19:07 / 19:17 / 19:22 | ChainEthereum | Movement0x770b… → 0x7c96… USDT, USDC, XAUT | Note |
| Time19:24–19:29 | ChainEthereum | Movement0x7c96… → DEX contracts, sold for ETH | NoteUniswap Universal Router, UniswapX reactor, v4 pool manager |
| Time19:30:35 | ChainEthereum | Movement0x7c96… → 0xA6dD3F218B65E32Ccc37BE30f74884133c655545 22,320 ETH | Note |
| Time19:20 / 19:34 / 19:44 | ChainBase / Arbitrum / Optimism | Movement0x770b… → 0x469A…25DC 1,555.31 ETH / 0xe410a2E5…d946 19.67M USDT0 / 0x94A43df7…5DA0 5,737.67 ETH | Notelater returned to Ethereum as ETH (4,645 + 1,541.5 + 12,557.7 ETH into 0xA6dD…) |
| Time19:45 | ChainBSC | Movement0x770b… → 0x7c96… 12,719.4 BNB | Notethen out of 0x7c96… in 9 transactions; onward path not resolved |
| Time20:13 / 20:19 | ChainEthereum | Movement0x770b… → 0xD2C2…F899, 0x600c…84b2 | Note10,000 ETH each |
| Time21:57–22:45 | ChainEthereum | Movement0xA6dD… → 0x9FA3…4FA0, 0xA6BF…B272, 0xFd5E…9e54, 0xeD5a…1A51 | Note10,000 ETH each |
| Time22:02:00 | ChainAvalanche | Movement0x770b… → 0xD2C0A958343A3745F0b8BC591947dA6a5aB7b664 821,000 AVAX | Note |
At 23:00 UTC on 24 September roughly 66K ETH sat on nine Ethereum addresses, most with nothing sent since. That was true of that evening and is not true now. No address here is attributed to anyone.
What else happened around 20:40 UTC
Between 20:40:02 and 20:43:11, on six networks, Bitget-labelled wallets moved balances into a small set of destination addresses:
| Time | Chain | Movement | Tx |
|---|---|---|---|
| Time20:40:02 | ChainXRP Ledger | MovementrGDre…GzFn → rwTTs…XLEf 2,183,079.52 XRP (both labelled Bitget Global) | Tx5DBD1295C3502AFD3B283E0135065B5E41C7FDE73ACE45A6AE94AAC814992308 |
| Time20:40:03 | ChainSolana | MovementA77HEr… → 7TWnq4… 35,044.7 SOL (both labelled Bitget) | Tx2qxcmxS7kcVZ9jt3Pve7UgRn4tdrr41gpHk3ENUpUSs85EumQGywcseT8wrQPxnL2z8sxp8b3jUFrVg3PNKAsq7J |
| Time20:40:33 | ChainBase | Movement0x97b9…8689 → 0xaDFf…116D 176.5 ETH | Tx0xcabf3006341cd11f8af96d383b160e8070ee1f338643f2a9b1c7dad8c54d7b5c |
| Time20:40:33 | ChainOptimism | Movement0x5bdf…F7Ef → 0xffa8…cD54 637.5 ETH | Tx0xa4f39758545a20d5fa787bc82089123eb80db52ed5b8f589eb4c6e2ffb0da702 |
| Time20:40:37 | ChainOptimism | Movement0x1AB4…8F23 → 0xaDFf…116D USDT0 | Tx0xf44cffc65edbf53f139a6d9a2b96ac6f840ad717951c0d6f8f88eabad477bcfd |
| Time20:41:23 | ChainPolygon | Movement0x1AB4…8F23 → 0xffa8…cD54 1,065,801 POL | Tx0xdb7a80e40ee36cedc66d3fe92e1340c03bfd120a1af6ccd1c992a3c24840112c |
| Time20:41–20:43 | ChainEthereum | Movement0x1AB4…, 0x5bdf… → 0xaDFf…116D, 0x2620…8c66, 0xffa8…cD54 (dozens of tokens) | Tx— |
0xaDFf… and 0x2620… have months of history (first activity 20 May and April 2026);
0xaDFf… had also received smaller transfers from the same source wallets on a regular
schedule since August.
What this shows: simultaneous balance movements on six networks inside three minutes. It is consistent with the emergency response Bitget describes.
What it does not show: that it *was* that response. A scheduled sweep would look similar.
The open point. One destination, 0xffa8…cD54, is the address that sent the 19:16
transfers to 0x770b…. So the 20:40 movements did not take everything away from an address
involved in the earlier transfers. As of 23:00 UTC 0xffa8…, 0xaDFf… and 0x2620… had sent
nothing since 20:40 on Ethereum, and 0x1AB4… and 0x5bdf… were still transacting normally
until at least 21:54.
Now the other question: what does our own tool say?
Everything above is a chain read, done by hand. This section is our product's answer to the
same question, run as anonymous, read-only requests to the public source-of-funds endpoint on
2026-09-27 at 10:37 UTC — three days after the hand-walk, on production, with no cached result
(every response carried cached: false). The endpoint asks one question: who sent funds to
this address?
It answers on all six EVM chains. Every provider leg reports ok — four chains served by
Alchemy, BSC and Avalanche by Ankr — and every chain is scored: true, which is this product's
way of saying it read the data rather than failing quietly.
Here is the part worth publishing. The hand-walk and the tool identify the same inflows, and the amounts agree to every digit the hand-walk recorded:
| Chain | Asset | Hand-walk, 24 Sep | Our tool, 27 Sep |
|---|---|---|---|
| ChainEthereum | AssetETH | Hand-walk, 24 Sep24,596.58 | Our tool, 27 Sep24,596.579269 |
| ChainEthereum | AssetUSDT | Hand-walk, 24 Sep34,751,168.12 | Our tool, 27 Sep34,751,168.12099 |
| ChainEthereum | AssetUSDC | Hand-walk, 24 Sep12,852,046.24 | Our tool, 27 Sep12,852,046.242513 |
| ChainEthereum | AssetXAUt | Hand-walk, 24 Sep3,000.32 | Our tool, 27 Sep3,000.322053 |
| ChainOptimism | AssetETH | Hand-walk, 24 Sep5,737.68 | Our tool, 27 Sep5,737.680149787 |
| ChainBase | AssetETH | Hand-walk, 24 Sep1,555.32 | Our tool, 27 Sep1,555.318215225 |
| ChainArbitrum | AssetUSDT0 | Hand-walk, 24 Sep19,668,851.77 | Our tool, 27 Sep19,668,851.773202 |
| ChainBSC | AssetBNB | Hand-walk, 24 Sep12,719.46 | Our tool, 27 Sep12,719.460681306 |
| ChainAvalanche | AssetAVAX | Hand-walk, 24 Sep821,011.97 | Our tool, 27 Sep821,011.9711424671 |
| ChainAvalanche | AssetUSDC | Hand-walk, 24 Sep8,204,678.80 | Our tool, 27 Sep8,204,678.8 |
Sixteen transfers, ten asset legs, six chains, two completely separate ways of reading the same public data — the hand-walk through RPC nodes, Blockscout and Routescan, the tool through Alchemy and Ankr. Not one quantity differs.
The dollars differ, and it is worth saying exactly why
The tool's inbound totals for that address, from our run:
| Chain | Our tool (valued 27 Sep) | Inbound transfers | Priced | Provider legs |
|---|---|---|---|---|
| ChainEthereum | Our tool (valued 27 Sep)$127,103,194.41 | Inbound transfers31 | Priced18 | Provider legsalchemy ok, alchemy ok |
| ChainOptimism | Our tool (valued 27 Sep)$15,551,717.46 | Inbound transfers4 | Priced1 | Provider legsalchemy ok, alchemy ok |
| ChainBase | Our tool (valued 27 Sep)$4,215,618.30 | Inbound transfers7 | Priced1 | Provider legsalchemy ok, alchemy ok |
| ChainArbitrum | Our tool (valued 27 Sep)$19,662,053.38 | Inbound transfers6 | Priced2 | Provider legsalchemy ok, alchemy ok |
| ChainBSC | Our tool (valued 27 Sep)$9,913,555.64 | Inbound transfers8 | Priced1 | Provider legsankr ok, ankr ok |
| ChainAvalanche | Our tool (valued 27 Sep)$17,276,592.23 | Inbound transfers13 | Priced2 | Provider legsankr ok, ankr ok |
| ChainTotal | Our tool (valued 27 Sep)$193,722,731.42 | Inbound transfers69 | Priced25 | Provider legs |
That is 0.63% above the hand-walk's $192.5M, and the reason is not a disagreement about what happened. The two numbers are valued on different dates. The hand-walk prices each transfer at its own block time on 24 September. The tool prices every leg at the price on the day you run it — so the same transfers, read on 27 September, are quoted in 27 September money.
Take the tool's own quantities and re-price them at each transfer's block-time price, and the total comes to $192,517,098.74 — the hand-walk's figure, to four significant figures.
The single biggest gap is Avalanche, where the tool reads 4.4% higher than one earlier summary of the hand-walk. It is entirely AVAX. DefiLlama quotes AVAX at $10.4440 at 19:16:15 on 24 September and $11.0509 on 27 September — the coin moved 5.8% in three days, and it is the only asset in the set that moved that far. The tool counts exactly the two Avalanche legs the hand-walk counts, at exactly the same amounts. Nothing is over-counted. On BSC the drift runs the other way (BNB fell), which is why the aggregate gap is smaller than Avalanche's.
We ran the endpoint twice, six minutes apart, over the same transfers. The totals differed by $38,608 — nothing had happened on any chain in between; the prices had simply moved. That is the cleanest proof that the dollar comparison was the weaker half of this: for a dated event, this endpoint reports today's value of what moved, not the value at the time it moved. It is a live screening tool, and on a historical incident that is a real limitation, not a rounding question. The quantities are what carry the claim.
What the tool reports that a table would not
Of the 69 inbound transfers it found across the six chains, 25 carried a price, 33 were valued
below a cent, and 11 were assets nothing quotes a price for. It filtered 20 senders as
address-poisoning lookalikes. Nothing was left unpriced because a price source failed to
answer: price_unread and price_rejected were both zero on all six chains.
That residue is the real texture of a busy address. Most of the 69 "inflows" are dust sent by addresses whose first and last characters mimic the real participants — noise designed to be copied out of a wallet's history by someone in a hurry. It contributes nothing to the dollar figure, and it is the reason the transfer count and the money count are different numbers.
The tool also names 0x1ab4973a48dc892cd9971ece8e01dcc7688f8f23 as the largest single sender
into this address on Ethereum: $72,636,407.12 over 6 transfers. We are naming the address and
nothing else about it.
One number we deliberately do not quote is the sender count. On Ethereum the tool lists sixteen senders and reports *none* filtered as address poisoning — while twelve of those sixteen are dust from addresses whose characters mimic other addresses in this very case. On the other five chains the same filter removed twenty. A sender count on Ethereum would therefore be counting noise as counterparties, so every count in this piece is a count of transfers, not of senders. On Base there is a second reason: one of the senders the tool marks as "identified" is itself a poisoning address, and the name attached to it comes from an unverified row. We publish no name out of that field.
One limitation, stated because the response states it: an anonymous request reads a window of "25 transfers per asset class — the 13 newest and the 12 largest of the 75 most recent read." For this address, on 27 September, that window happens to contain every leg that matters. On a busier address, or later, it would not. A window that holds the answer today is not a promise about tomorrow.
What this is, and what it is not
It would be easy to call the agreement above a benchmark. It is not one, and we would rather say so than sell it.
A benchmark, in the sense we hold ourselves to, compares our answer against a total somebody outside this company computed and published — Sky Mavis's own disclosure of the Ronin Bridge theft, the FBI's Bybit advisory. We have run those, and they are the standard. What this piece contains is two of our own methods, run by the same team, agreeing with each other. That is a regression check on our pipeline, not external validation, and the fact that both methods now return the same sixteen amounts to the digit says only that our reading of the chain is internally consistent.
The one figure here that *was* established outside ChainHint is Bitget's "approximately $351.6 million", and we do not agree with it: we are $5.7M above, and we have named three ordinary reasons a difference of that size appears without claiming which of them applies. That is an honest disagreement, not a benchmark pass.
Where it stands on 27 September
The tables above are cut at 2026-09-25 ~10:30 UTC. This piece goes out two days later, so we re-read the balances from public nodes on 2026-09-27 between 11:07 and 11:09 UTC — the XRP Ledger from Ripple's public rippled server, Tron from TronGrid, Ethereum and Avalanche over public RPC. One thing changed, and it changed completely.
Every address in this article that was holding funds is now empty.
| Address | Chain | At the cut (25 Sep) | 27 Sep, 11:07–11:09 UTC |
|---|---|---|---|
AddressrwNhefsz1UQEusxhCvHip3RANinWi4CTck | ChainXRP Ledger | At the cut (25 Sep)3 XRP | 27 Sep, 11:07–11:09 UTC3.091975 XRP |
AddressrDRV9nLg8xbLsafKZnhNgWuE1TiSLE95hs | ChainXRP Ledger | At the cut (25 Sep)~19.45M XRP | 27 Sep, 11:07–11:09 UTC22.832391 XRP |
Addressr3UGfDM4ZyFSCzKH7TQEjgago9QoUJagtJ | ChainXRP Ledger | At the cut (25 Sep)~20M XRP | 27 Sep, 11:07–11:09 UTCaccount no longer exists |
AddressrH7oMFKBgdK99TPQctFVzddD7srRzyCqZn | ChainXRP Ledger | At the cut (25 Sep)~20M XRP | 27 Sep, 11:07–11:09 UTC1.573634 XRP |
AddressrwSjBrtxBC75TqZ5YvJ1TGfaRpQvVNsAKw | ChainXRP Ledger | At the cut (25 Sep)~20M XRP | 27 Sep, 11:07–11:09 UTC1.497963 XRP |
Addressr6NcwN3dR5ciyBv9XsLyMNc9Kg2FBCs7Y | ChainXRP Ledger | At the cut (25 Sep)~22.98M XRP | 27 Sep, 11:07–11:09 UTC1.315356 XRP |
AddressTBWNguTTgezw9dVorX441C6nDrZpRxYwKD | ChainTron | At the cut (25 Sep)4,369,190 TRX | 27 Sep, 11:07–11:09 UTC0.399939 TRX |
Address0x770b10b273fC44Fe9197D6bF20F145c2e98463Ee | ChainEthereum | At the cut (25 Sep)— | 27 Sep, 11:07–11:09 UTC0.008793 ETH |
Address0x7c96279Ec1e888Aa56b9B836e0dB26ca48573E1C | ChainEthereum | At the cut (25 Sep)— | 27 Sep, 11:07–11:09 UTC0.000115 ETH |
Address0xA6dD3F218B65E32Ccc37BE30f74884133c655545 | ChainEthereum | At the cut (25 Sep)— | 27 Sep, 11:07–11:09 UTC0.004269 ETH |
Address0x770b10b273fC44Fe9197D6bF20F145c2e98463Ee | ChainAvalanche | At the cut (25 Sep)— | 27 Sep, 11:07–11:09 UTC10.970950 AVAX |
Address0xD2C0A958343A3745F0b8BC591947dA6a5aB7b664 | ChainAvalanche | At the cut (25 Sep)821,000 AVAX | 27 Sep, 11:07–11:09 UTC0.000026 AVAX |
r3UGfDM4ZyFSCzKH7TQEjgago9QoUJagtJ returning "account not found" is not an error on our side:
the XRP Ledger lets an account that has been emptied be deleted outright, and this one was. Its
20,000,000 XRP arrived at 22:03:41 on 24 September, and the account is gone.
The XRP Ledger accounts were emptied one at a time, in sequence, each over a few hours, each in dozens of payments of roughly 0.3M–2.4M XRP to a rotating set of further accounts:
| Account | Emptied over |
|---|---|
AccountrDRV9nLg… | Emptied over25 Sep 18:56 → 26 Sep 00:24 UTC |
AccountrH7oMFKB… | Emptied over26 Sep 12:06 → 15:49 UTC |
AccountrwSjBrtx… | Emptied over26 Sep 20:21 → 23:30 UTC |
Accountr6NcwN3d… | Emptied over27 Sep 05:32 → 07:43 UTC |
Several destination accounts recur across more than one source — rGDKxwQWvAXbcTk1jgZrSQWrcGVjfR2ph2,
r3ZqSCQ1MdYUc498XDW3gsumeN4PPJawAR, r4HFFpv8h7ZHotdJXsSku6Evj1MUEeukXp,
rUMntqQwnFM3KQHHi3zBZFPW6981QqQs4C, rGkWhwBucjVatAEj5AXFwFY9e6MQhkgAX7 among them.
What we are not saying. We read the most recent 60 ledger transactions of each account, which is enough to establish when each was drained and the shape of it, and not enough to enumerate every payment or to total them — so no total for the onward movement appears above, and the per-account destination lists are partial. We did not follow the funds beyond that first onward hop, we do not attribute any destination account to anyone, and we do not claim the draining was done by the same party that received the funds on 24 September, or that it was not.
The 0x770b… Avalanche balance of 10.97 AVAX and the sub-cent Ethereum balances are the residue
of gas, not a holding.
What we did not find
- Why our total ($357.3M) is $5.7M above Bitget's figure.
- The onward path of the 12,719 BNB after the BSC bridge calls, and of the TRX moving on Tron.
- Our scan covered labelled Bitget wallets (about 26.8K addresses on EVM chains, two
XRPScan-labelled XRP Ledger accounts, 11 Tronscan-tagged Tron addresses, a small set on
Solana and Bitcoin) plus their direct recipients. The Tron sender TJxe1M… was found from the
recipient side, not from a label: the labelled set alone would have missed it. Other
unlabelled wallets, including the "warm layer" the CEO's notice mentions, are outside what we
can see.
- The 14 labelled Bitcoin wallets sent nothing after 18:31 UTC.
Wallet tiers
Third-party data (Arkham) calls 0xffa8…cD54 a cold wallet. Bitget describes the affected
layers as hot and warm. We have no basis to say which description is right, and do not.
What this page does not claim
- That any address is an attacker, thief or laundering wallet. Recipients are "recipients of
the transfers described", and unconfirmed as to attribution — all of them.
- Any attack vector, or how signing access was obtained.
- That Bitget's figure is right or wrong.
- That the 20:40 movements were Bitget's response.
- That the agreement between our hand-walk and our own tool is an external verification of
either. It is not; see above.
- Anything about funds beyond the addresses traced here.
Method and limits
Chain data read directly from public nodes and explorers: RPC nodes, Blockscout, Routescan, the Solana RPC and the XRP Ledger's public rippled server. The transfer tables are cut 2026-09-25 ~10:30 UTC, with the EVM tables cut 2026-09-24 ~23:10 UTC and re-verified. Balances were re-read on 2026-09-27 between 11:07 and 11:09 UTC and are reported separately, in "Where it stands on 27 September"; a balance is true of the moment it is read and of no other moment.
Prices: the DefiLlama historical price API at each transfer's block timestamp, retrieved 2026-09-24 ~23:10 UTC (EVM) and 2026-09-25 ~10:00 UTC (XRP, TRX); native assets by their market identifiers, tokens by contract address; stablecoins valued at market price, not at $1.
Transfers spoofed by lookalike tokens and lookalike addresses (address poisoning) are excluded — only native transfers and transfers emitted by the real token contracts count. An asset's identity is its contract, never the ticker it calls itself.
Labels are third-party (EVM, Solana, XRP Ledger) and are not confirmed by Bitget.
The product figures in "what does our own tool say" are a separate, later run — anonymous
requests to the public source-of-funds endpoint at 2026-09-27 10:37 UTC, valued at that day's
prices, as described in that section.