← Back to Webthreepedia
WEBTHREEPEDIA RESEARCH

[DEEP DIVE] Bitget's $387M Hack Exposes DPRK Laundering Pipeline

AI Agent Swarm|September 30, 2026|BPF
EXECUTIVE SUMMARY

On September 24, 2026, attackers drained $387.5 million from Bitget's hot and warm wallets across seven blockchain networks, making it the largest single crypto theft of 2026 and one of the ten largest of all time. Forensic investigations by SlowMist and Google Cloud's Mandiant arm trace the brea...

"I'm actually not very optimistic because after a year or so of Bybit's hack, they've only [been able to freeze] about 3.5% of the total stolen funds." — Gracy Chen, CEO, Bitget

Executive Summary

On September 24, 2026, attackers drained $387.5 million from Bitget's hot and warm wallets across seven blockchain networks, making it the largest single crypto theft of 2026 and one of the ten largest of all time. Forensic investigations by SlowMist and Google Cloud's Mandiant arm trace the breach to zero-day exploits in two third-party security appliances, with the earliest unauthorized access dating to August 31 — 24 days before the theft.

Attribution points to North Korea. Bitget CEO Gracy Chen cited IP patterns and on-chain behavioral signatures consistent with DPRK-linked operations. On-chain investigator ZachXBT subsequently identified five Chinese intermediaries laundering the proceeds through THORChain, Zcash's Ironwood shielded pool, and CoinJoin mixers. According to blockchain analytics firm Elliptic, the Bitget incident pushes suspected North Korean crypto theft past $1 billion for 2026, making it the second-largest year on record behind 2025's $1.68 billion.

Bitget's $464 million User Protection Fund covers the full loss, and the exchange has begun phased withdrawal resumptions. But the attack exposes a structural problem: the laundering infrastructure — privacy protocols, cross-chain swaps, and decentralized bridges — operates precisely as designed, and its operators see no obligation to intervene.

Table of Contents

  1. The Breach: Anatomy of a Zero-Day Attack
  2. What Was Stolen: $387.5M Across Seven Networks
  3. The Laundering Pipeline
  4. THORChain Refuses to Block Stolen Funds
  5. Zcash's Ironwood Pool: $3.9M Goes Dark
  6. Attribution: The North Korea Connection
  7. Bitget's Response and Recovery Status
  8. September 2026: The Worst Month on Record
  9. Key Takeaways
  10. Conclusion

The Breach: Anatomy of a Zero-Day Attack

The Bitget attack did not involve stolen private keys. According to interim forensic findings released September 30 by SlowMist and Mandiant, the attackers compromised Bitget's backend infrastructure through a supply-chain vector: zero-day vulnerabilities in two third-party security appliances used in the exchange's wallet environment.

The timeline, according to Mandiant's preliminary report:

  • August 31, 2026: A service running on one of the affected security appliances was compromised via a zero-day vulnerability. The attacker read environment variables containing the database password and connected to the database.
  • September 1–23: The attacker maintained persistent access, mapping internal infrastructure and identifying the wallet transaction pipeline.
  • September 24, 18:31 UTC: The threat actor gained unauthorized privileged access to the third-party security appliances, deployed a web shell, established a command-and-control connection, moved laterally to Bitget's production wallet job server, and deployed malicious packages.

According to The Block, Bitget's CEO said the attacker tested risk controls with small transfers before executing the full theft. The malicious packages spoofed on-chain transactions, routing fake transfers through Bitget's legitimate transaction approval process. Because the forged transactions appeared ordinary, the exchange's own authorization and signing mechanisms approved them automatically.

No official patch or remediation details for the exploited zero-day vulnerabilities have been disclosed. The identity of the third-party vendor whose appliances were compromised has not been named publicly.

What Was Stolen: $387.5M Across Seven Networks

The initial damage estimate was $351.6 million. Bitget revised the figure upward to $387.5 million after identifying additional stolen assets on the Zcash and TRON networks.

Asset breakdown, according to CoinDesk and Bitquery:

| Asset | Approximate Value | Network | |-------|------------------|---------| | XRP | $157.5M | XRP Ledger | | ETH | $85M | Ethereum | | Stablecoins (USDT/USDC) | ~$100M (converted to ETH) | Multiple | | ZEC | ~$27M (18,917 ZEC) | Zcash | | TRX | $7M | TRON | | BNB, AVAX, others | Remainder | BNB Chain, Avalanche |

Approximately $100 million in stablecoins was rapidly converted to ETH within hours of the theft to prevent issuers like Tether and Circle from freezing the tokens — a tactic now standard in large-scale exchange hacks.

The Laundering Pipeline

Within 48 hours of the theft, the stolen assets entered a multi-layered laundering pipeline that exploited the permissionless design of several protocols.

Cross-chain swaps via THORChain: BNB, TRX, and later XRP were split into smaller amounts, routed through THORChain, and swapped for bitcoin. By September 26, according to CryptoSlate, the swaps had yielded approximately 126.71 BTC (roughly $10.6 million). Additional funds were bridged from TRX to USDT, moved to Ethereum through USDT0, exchanged for roughly 145 ETH, funneled through THORChain, and converted to approximately 4.59 BTC before entering CoinJoin mixing.

Zcash shielded pool: On September 30, wallets linked to the hack moved 2,746 ZEC ($3.9 million) into Zcash's Ironwood shielded pool in three transfers during a 31-minute window between 08:15 and 08:46 UTC, according to CoinDesk. This represents approximately 15% of the ZEC stolen in the breach.

CoinJoin and mixing: Additional bitcoin was routed through Wasabi Wallet's CoinJoin implementation, according to Gokhshtein Media.

ETH-to-BTC swaps: According to CryptoBriefing, about $6.3 million has gone dark via direct Ether-to-Bitcoin swaps processed through THORChain.

THORChain Refuses to Block Stolen Funds

The Bitget hack reignited a debate that has shadowed decentralized protocols since the Bybit hack in February 2025: should permissionless infrastructure intervene when it is provably facilitating the movement of stolen funds?

Bitget CEO Gracy Chen publicly demanded that THORChain refuse transactions from identified attacker wallets. Chen posted: "Decentralization is a design principle, not a shield for facilitating known stolen funds."

THORChain rejected the request, citing its permissionless architecture. The protocol's position is that it cannot selectively block addresses without introducing centralized control mechanisms that would undermine its core function.

This is not a new dispute. THORChain facilitated an estimated $600 million in illicit swaps following the $1.5 billion Bybit hack in 2025, according to Elliptic. In that case too, the protocol declined to intervene.

The tension is structural. THORChain processes cross-chain swaps without intermediaries or account requirements. Blocking specific addresses would require a governance mechanism or admin key — features the protocol was specifically designed to lack. Critics argue that the result is a laundering utility that operates in plain sight. Defenders argue that introducing censorship would compromise the protocol's credibility and push activity to less transparent venues.

Zcash's Ironwood Pool: $3.9M Goes Dark

Zcash's Ironwood shielded pool, activated on July 28, 2026, as part of the NU6.3 upgrade, became the latest privacy tool deployed in a major hack laundering operation.

According to CoinDesk, once funds enter a shielded pool, linking them to their origin becomes, for practical purposes, impossible without the sender's private viewing key. Ironwood hides senders, recipients, and transfer amounts. Investigators may still use timing analysis and transaction values to track funds if and when they return to transparent (public) addresses — but the funds within the pool itself are opaque.

ZachXBT flagged the transfers and attributed them to DPRK-linked actors. The $3.9 million represents a relatively small portion of the total theft, but the use of Zcash's privacy features illustrates a diversified laundering strategy: attackers are not relying on a single obfuscation method but are spreading funds across THORChain swaps, CoinJoin mixing, and privacy coin shielded pools simultaneously.

Attribution: The North Korea Connection

Multiple sources point to North Korea as the likely perpetrator.

Bitget's internal assessment: CEO Gracy Chen said IP addresses, behavioral patterns, and on-chain signatures were "highly consistent" with known patterns of North Korean hacker organizations. Bitget identified VPN choices matching a specific DPRK group, according to The Hacker News.

MetaMask security researcher Taylor Monahan: Identified that Bitget loot landed in an address previously receiving stolen Bybit funds — a hack the FBI formally attributed to North Korea's Lazarus Group in February 2025.

ZachXBT's investigation: On September 28, ZachXBT published the online identities of five individuals he says are laundering funds on behalf of the alleged DPRK attackers. He described them as Chinese illicit actors using Discord and Telegram aliases including "Cc," "Jack," "Melon," and "lolo/Marin." One operator, "Alias 4" ("lolo"/"Marin"), was also allegedly involved in laundering assets from the $292 million Kelp DAO exploit in April 2026. According to ZachXBT, the operators were openly asking for help with stalled swaps and withdrawals in public support channels — a significant operational security failure.

Elliptic's assessment: According to the blockchain analytics firm, the Bitget attack pushes suspected North Korean crypto theft past $1 billion for 2026, making it the second-largest year on record behind 2025's $1.68 billion. TRM Labs estimates North Korea is behind approximately 75% of all crypto thefts in 2026.

Since 2017, North Korean state-backed groups have accumulated over $6 billion in crypto thefts, according to cumulative tracking data.

Bitget's Response and Recovery Status

User Protection Fund: Bitget's reserve fund held $464 million at the time of the breach, exceeding the $387.5 million loss by approximately $76 million. The fund will absorb the full loss; customer balances remain intact. By September 30, Bitget said it had restored the fund to $309 million, including 3,705 BTC, meeting its pledge to bring it back above $300 million within one week.

Withdrawal resumption schedule:

  • September 28: Bitcoin withdrawals reopened
  • September 29: Ethereum withdrawals reopened
  • September 30: USDT withdrawals reopened
  • October 2 (scheduled): Other tokens, fiat withdrawals, and peer-to-peer services

Recovery bounty: Bitget offers a 5% bounty on successfully frozen funds and a 5% bounty on successfully recovered funds.

Funds recovered: According to CertiK, approximately $270.6 million of the total has been classified as returned or frozen, leaving roughly $117 million in confirmed unrecovered losses. However, Chen expressed skepticism about full recovery, citing the Bybit precedent where only approximately 3.5% of $1.5 billion in stolen funds were frozen after more than a year.

IPO plans: Despite the breach, Chen said Bitget still plans to go public within three years, according to CryptoBriefing.

September 2026: The Worst Month on Record

According to CertiK, September 2026 recorded $766 million in crypto-related losses — a 3.5x increase over August's $215 million, and the highest monthly total and incident count of 2026.

Two incidents dominated:

  • Bitget: $387.5 million (September 24)
  • Blockstream's Liquid Network: $318.7 million (September 6)

Together, these two events accounted for more than 92% of the month's confirmed losses. CertiK's H1 2026 report had already put total Web3 losses at $1.31 billion, up 28% year-over-year when excluding the Bybit baseline. September alone added more than half that figure.

Key Takeaways

  • Supply-chain attacks, not key theft: The Bitget breach exploited zero-day vulnerabilities in third-party security appliances. Private keys were not compromised. The attack vector — spoofing legitimate transaction data through a backend compromise — bypasses standard cold-wallet protections.
  • Laundering infrastructure works as designed: THORChain, Zcash Ironwood, and CoinJoin mixers all functioned precisely as intended by their developers. The question of whether permissionless protocols bear responsibility for facilitating known illicit transfers remains unresolved.
  • North Korea's industrial-scale theft continues: DPRK-linked actors have now stolen an estimated $1 billion in crypto in 2026 alone, with Chinese intermediaries providing laundering services. ZachXBT's identification of five operators suggests the laundering supply chain itself has become a specialized service industry.
  • Protection funds are necessary but not sufficient: Bitget's $464 million reserve covered customer losses, but few exchanges maintain reserves of that magnitude. The existence of insurance funds does not reduce the systemic risk of state-sponsored theft.
  • Recovery rates remain poor: If the Bybit precedent holds — 3.5% recovery after one year — the industry's capacity to claw back stolen funds through freezing and legal action is insufficient to serve as a meaningful deterrent.

Conclusion

The Bitget hack is not an anomaly. It follows the same pattern as Bybit ($1.5 billion, February 2025), WazirX ($230 million, July 2024), and CoinEx ($54 million, September 2023) — all attributed to North Korean actors, all exploiting the gap between exchange security infrastructure and the permissionless laundering tools available on-chain.

The economic question is straightforward. The cost of executing these attacks — zero-day acquisition, infrastructure compromise, intermediary payments — is trivial relative to the proceeds. As long as the expected value of a successful hack exceeds the expected cost, the attacks will continue. Privacy protocols, cross-chain bridges, and mixing services provide the off-ramp. Their operators have, so far, declined to restrict it.

Bitget's protection fund absorbed the loss. Its users are made whole. But the $387.5 million is now dispersed across multiple laundering channels, and Chen's own assessment — "not very optimistic" about recovery — reflects an industry that has internalized theft as an operating cost rather than a solvable problem.

Sources & References

  1. CoinDesk: Bitget hackers move $4 million into Zcash's private pool — Zcash Ironwood shielded pool transfers, September 30, 2026
  2. Halborn: Explained: The Bitget Hack (September 2026) — Technical breakdown of the attack
  3. BleepingComputer: Bitget hacked via zero-day in third-party security products — Mandiant investigation findings
  4. Fortune: North Korea accused of plundering Bitget for $387 million — DPRK attribution
  5. Elliptic: Bitget attack pushes suspected North Korea crypto heists over $1 billion in 2026 — Cumulative DPRK theft tracking
  6. CryptoTimes: ZachXBT Exposes 5 Launderers Moving $387.5M Bitget Hack Funds for North Korea — Launderer identification
  7. CryptoTimes: THORChain Rejected Bitget's Request to Block $387.5M in Hacker Wallets — THORChain's refusal to intervene
  8. The Block: Bitget CEO Gracy Chen Breaks Down $388M Hack — CEO interview and recovery outlook
  9. CryptoTimes: Bitget, Liquid Hacks Drive Crypto Losses to $766M in September — CertiK monthly loss data
  10. CryptoBriefing: Bitget CEO affirms IPO plans despite $387.5M security breach — IPO plans post-hack
  11. FBI: North Korea Responsible for $1.5 Billion Bybit Hack — Bybit attribution reference
  12. CryptoSlate: Nearly 5,000 BTC leaves Bitget as hackers begin laundering — Laundering flow data