Check any crypto wallet for AML risk in ~10s. Consensus of OFAC, Chainalysis, TRM & Tether/Circle blacklists across 35 chains. Non-custodial. Free first check

👋 Meet AMLConsensus. Check any crypto wallet before a P2P/OTC deal in ~10s — one clear verdict by consensus of OFAC, Chainalysis, TRM & Tether/Circle blacklists across 35 chains. Non-custodial: public address only, no seed phrases. Free first check → amlconsensus.com/en/
4
333
🔴 $352M drained from Bitget. And no keys were stolen What broke was not the wallets but the exchange's back end: the attacker spoofed transaction history and the system cleared the withdrawals as legitimate. "Keep your keys in cold storage" would not have stopped this one. Withdrawals are paused. Customers are promised cover from the protection fund, which is larger than the loss. But 67,982 ETH are already sitting with the attacker, and turning them into clean money runs through P2P deals and exchangers. A freeze does not land on the thief. It lands on whoever accepted the coins last. We track those addresses in our own live feed — amounts, recipients, hashes: api.amlconsensus.com/theftwa… Screen a sender before the deal: @amlconsensus_bot #bitget #hack #AML #P2P #cryptosecurity
33
We traced where the $352M from Bitget actually went in the first 24 hours. One pattern explains everything else: the stablecoins ran, the ETH went to sleep.
1
1
39
What it means for you: The stablecoins hit P2P this week — after 19 hops, looking like ordinary USDT from an ordinary seller. The ETH surfaces in months. "I'll wait for it to blow over" doesn't work against a plan with two clocks.
1
5
Every address, amount and hash is in our live feed — it tracks them on its own: api.amlconsensus.com/theftwa… Screening a sender before a deal is free: @amlconsensus_bot
2
Feb 2025: Bitget lent Bybit 40,000 ETH — no interest, no collateral, repaid in 3 days. Today Bybit lends back what it built from its own worst day. An exchange can lend another exchange liquidity. Nobody can lend you a clean coin history.
Bybit team is standby to help in any ways that we can. Bitget helped us when we had the hack. we are updating lazarusbounty.com/en/ to help Bitget to capture and trace the stolen fund movement.
35
🔴 $352M drained from Bitget. And the keys were never stolen PUBLISH DATE: 25.09.2026 At 18:31 UTC yesterday Bitget detected unauthorised transfers out of its hot wallets. The total: $351.6 million, the largest crypto theft of 2026. WHAT ACTUALLY HAPPENED The interesting part is not the number, it is the method. No private keys leaked. The attacker found a flaw in the exchange's back end, spoofed transaction history, and made the system process the withdrawals as legitimate. Which means the usual advice — "keep your keys in cold storage" — would not have helped here at all. What was broken was not the keys but the logic that decides which transfer counts as yours. Cold wallets were untouched. The exchange says losses will be covered from its $464 million User Protection Fund, which is larger than the amount stolen.
Made with AI
1
1
30
WHERE THE MONEY WENT The loot — AVAX, BNB, stablecoins — has already been swapped into 67,982 ETH, roughly $183 million. Converting everything into a single asset is the standard first step before laundering. How it was spotted is telling. Before any official confirmation, ScamSniffer flagged the signature: 12 transfers from Bitget-labelled wallets into a single address across six chains, each moving 90–95% of the wallet's balance. People do not move money like that. That is how money gets taken out. WHY THIS CONCERNS YOU EVEN WITHOUT A BITGET ACCOUNT Bitget customers will be made whole — the fund covers it. That is not where the risk sits. The risk is that 68,000 ETH now has to become clean money. It will be split, pushed through mixers, and sold in P2P deals and through exchangers — in small pieces, through dozens of intermediaries, over months. And a freeze does not land on the thief. It lands on whoever accepted the coins last and carried them to an exchange. WHAT OUR OWN MONITORING SEES We run our own feed: stablecoin issuer freezes and large mixer deposits. Over the last 36 hours: • 1,210 ETH went into Tornado Cash across 22 separate deposits • issuers blocked 25 addresses holding 36.4 million USDT One caveat, and it matters: **we are not going to tie those freezes to the Bitget hack**. Bursts of 5–7 addresses within a couple of minutes showed up in our feed on 22 September, on 23 September and twice on 24 September — that is the normal rhythm of issuer activity, not the trace of one specific theft. Anyone showing you those numbers right now as "proof of a link" is filling in the blanks. WHAT TO DO • Screen the sender's address BEFORE the deal, not after the coins reach an exchange • In P2P, do not accept "I'll send it from a different wallet" — someone else's history becomes yours • Keep evidence for every deal: the chat, the payment receipt, the screening report • Separate your flows: the P2P wallet and the savings wallet should never touch • Be wary of unusually good rates over the coming weeks — that is exactly how stolen coins leave Live feed of freezes and mixer deposits, with hashes and addresses: api.amlconsensus.com/theftwa… Screen a sender's address for free, no sign-up: t.me/amlconsensus_bot?start=… Sources: CoinDesk, Decrypt, Bitcoin Magazine (24–25 September 2026); fund movement — lookonchain, ScamSniffer, MistTrack; freeze and mixer figures — AMLConsensus own monitoring.
25
Issuer freezes in the last 24h — our own count from public data: 7 addresses blocked, holding 27,862,694 USDT largest: 21,307,151 USDT (TRON) 1,970 ETH went into Tornado Cash Feed with hashes and addresses: api.amlconsensus.com/theftwa…
2
69
Four sanctions actions this year quietly redrew the map of where crypto can legally come from. Most people find out when a deposit is already on hold. 🧵
1
1
28
• Aug 2025 — Garantex and its successor Grinex, plus A7, A7 Agent, Old Vector, InDeFi Bank and Exved (OFAC) • Jun 2026 — Nobitex and three more Iranian exchanges (OFAC) • A7A5 and Payeer (EU, now in force) • Sept 9, 2026 — Xinbi Guarantee, designated over a $24B scam marketplace Plus Huione Group under FinCEN 311, and the older mixer designations: Blender.io, ChipMixer, Sinbad, Bitcoin Fog.
31
The 15-day number isn't a rumour from support — Star Xu said it himself on Sept 2, replying to someone whose transfer from a betting platform triggered a risk-control review. Enhanced AML review can restrict funds for 15 days or longer, and he specifically named Telegram-group escrow deals as a high-risk channel. So if your deposit came in through either, what you're seeing is the documented process, not an agent losing your ticket. What's worth doing while the clock runs: 1. Don't deposit into that account again. A second flagged deposit restarts the review. 2. Write the chain down while you still remember it — who sent the coins, through what service, what you paid. Screenshots of the P2P deal, the exchanger receipt, the sender's address. 3. Get an independent trace of the deposit. The useful half isn't "your address is clean" — it's **what it didn't touch**: no sanctioned entity, no mixer, no darknet market within N hops. That's the part a compliance reviewer can actually act on. 4. Answer literally. "Source of funds" means documents, not an explanation in prose. Disclosure: I work on AMLConsensus, we do this kind of screening. The address check is free and needs no wallet connection — t.me/amlconsensus_bot?start=…. We're also doing 5 full appeal dossiers for free at the moment because we want documented cases to point at. No promises on the outcome — that's the exchange's decision — but the paperwork they're asking for is something you can actually produce.
Made with AI
1
2
52
What broke: the device's hardware RNG was bypassed and seeds were generated with weak software randomness. The keys weren't stolen — they were recomputable from day one. $100M+ drained in waves since July 30.
Made with AI
1
1
1
21
The part victims hit later: recovered coins carry the hack in their history. Send them straight to an exchange and screening can hold the deposit — the freeze lands on the victim, not the attacker. Screen the address before the money moves: amlconsensus.com/en/
1
1
5
Sources: CoinDesk and The Crypto Times, Sep 22, 2026. Recovery transaction confirmed in block 967,948 — the OP_RETURN message is readable by anyone.
4
The claim domain is written into the rescue transaction itself — OP_RETURN, block 967,948. Remember that when the fake "Coldcard recovery" pages show up this week, because they will. The real one is verifiable on-chain. A DM offering to help you claim is not.
🚨 Des « whitehat » viennent de sauver 52. 37 $BTC du hack Coldcard… en utilisant la même faiblesse que les hackers. Les BTC ont été transférés vers un Crypto Recovery Trust chargé d’identifier les propriétaires légitimes et de leur restituer les fonds. Plus de 100 millions de dollars de BTC auraient déjà été volés, et une mise à jour du firmware ne suffit pas à sécuriser les anciennes seeds déjà compromises.
29