The protocols and services used to move funds stolen from Bitget have collectively collected $761,725 in fees, according to on-chain analysis by independent researcher Andrey Sergeenkov, published October 6 and shared with crypto.news. The work goes a step further than earlier flow tracking: it itemizes who profited from processing the loot, and follows a trail of THORChain affiliate fees that ends, in part, at an address labeled as an OKX hot wallet.

The analysis covers transactions through October 2 at 10:22 UTC and concerns the September 24 theft from Bitget's hot and warm wallets, which the exchange later valued at approximately $387.5 million. Attribution of the theft to North Korea-linked actors remains suspected: it rests on statements by Bitget's CEO and on tracing by Elliptic and Chainalysis, and has been contested in public reporting.

Who Collected the Fees

By Sergeenkov's tally, THORChain liquidity providers received $573,226 from swaps involving the stolen funds — the largest single share. MetaMask collected $149,417 in swap fees, Chainflip received $26,751, and CoW Protocol's EthFlow received $12,332. The figures reflect the mechanics of the laundering operation itself: cross-chain swaps through decentralized venues generated fees at each hop, paid to liquidity providers and front-end interfaces regardless of whether the funds were stolen.

The scale of the underlying flows was already public. BlockSec's September 29 snapshot, cited in the research, showed roughly $269 million passing through THORChain across 7,804 transactions — a pass-through figure that can count the same funds more than once. One Bitget-linked wallet alone completed 27 THORChain swaps converting roughly 2,390 ETH into 75.2 BTC, about $6.3 million at the time.

The Affiliate Fee Trail

The more sensitive finding concerns THORChain's affiliate fee mechanism, which routes a share of each swap to a recipient address specified in the swap instruction. Sergeenkov found $259,718 in affiliate fees paid to seven addresses where subsequent transaction activity provided what he described as additional financial links to the wallets moving the stolen funds.

The largest address in this group, thor18dvgrgpvxlh7rhhld4qjyrxs9c7tvwdakrkjm4, received $177,499. Sergeenkov linked it to the laundering activity through shared recipients of the principal funds. Another address collected $56,514 on the same pattern; a third took $18,080, with some of its fee proceeds returned to a wallet that had submitted one of the swaps.

Sergeenkov is explicit about the limits of the method. Being named as an affiliate recipient does not prove an address belongs to the attacker — any interface or script can insert a recipient address before the sender signs, as happens with ordinary referral fees. His separation of "linked" from "unlinked" recipients rests on transaction history, not on the recipient field alone. A further $206,196 in affiliate fees went to recipients for which he established no additional financial links.

The OKX Endpoint

From the largest linked affiliate address, part of the RUNE fee income was exchanged for USDT and passed through two Ethereum wallets before reaching an address labeled "OKX Hot Wallet 5" by Etherscan. The trail stops there: the research does not establish who owns the depositing account or whether the customer was involved in the theft. Sergeenkov notes that OKX could use its internal deposit records to make that determination — a decision now in the exchange's hands.

Why Fee Trails Matter

Incident response in crypto usually chases the principal: the stolen tokens, the bridge hops, the Bitcoin destinations. Fee flows are a quieter byproduct, and this analysis shows they carry signal of their own — links between affiliate recipients and laundering wallets, proceeds returning to swap senders, and cash-out endpoints at regulated exchanges. They also carry a governance question: $761,725 in fees from a suspected state-linked theft accrued to protocols and interfaces that processed the transactions neutrally, by design.

For the exchanges involved, the actionable item is narrow and concrete: deposit records tied to the traced addresses. For everyone else, the Bitget fee map is a reminder that every hop in a laundering chain leaves paid counterparties — and that some of them can be followed.

TrustGrade covers the enforcement and asset-recovery ecosystem around digital assets. Verified trust data: trustgrade.ai.