Bitget Hack: Chainalysis Links $387M Theft to DPRK Actors
The theft pushes DPRK-linked crypto losses above $1B in 2026, while rapid cross-chain transfers show how quickly stolen funds can be dispersed.
Every Zipp story tagged #Bitget, newest first.
The theft pushes DPRK-linked crypto losses above $1B in 2026, while rapid cross-chain transfers show how quickly stolen funds can be dispersed.
A single exchange hack accounted for nearly a third of the damage, putting the concentration of crypto security risk in focus.
The $388M draw on Bitget's self-managed backstop is one of the larger disclosed exchange losses, and the real test is whether the 131% reserve snapshot holds through the Oct 2 withdrawal restart.
A handful of mega-breaches now define the industry's annual security tally, and a state-sponsored adversary sits behind 37% of the bill, raising the stakes for every exchange and protocol custody…
The transfer represents part of the 18,900 ZEC stolen from Bitget, while Zcash’s shielded pool is designed to increase transaction privacy.
The timeline places malicious activity more than three weeks before Bitget's hot wallets were drained, making the lead-up central to the investigation.
The deposits cover about 15% of the stolen ZEC, adding a privacy layer that complicates tracing but does not erase every potential clue.
The cross-chain path converts stolen assets into BTC, making the trail harder to follow as attribution for the roughly $350M hack remains under investigation.
The rejected deposit was refunded to the sender rather than frozen, blocking this route without securing the funds themselves.
The case puts a practical boundary around “permissionless”: NEAR Intents can screen swaps, but the rules for releasing held funds and correcting false flags remain unclear.
The reported blocks highlight how transaction-level safeguards can limit the movement of stolen funds, though they do not establish that the money was recovered.
The reserve drop exceeds Bitget's reported customer withdrawals, while investigators say stolen funds are moving through bridges, cross-chain protocols and mixers.
The intervention shows how cross-chain risk controls can target known stolen funds while keeping a permissionless protocol open.
The reopening is a first step, not proof that customer transfers are completing. ETH, USDT and other services remain on a phased schedule.
The response adds approval layers and resets credentials, but the affected third-party security functions will remain disabled until remediation is complete.
Two small test transfers triggered no alerts before the attacker exploited a third-party security product's zero-day to issue fraudulent withdrawals.
The breach shifts scrutiny from initial access to incident response: Bitget’s own systems flagged unauthorized transfers before the largest losses began.
The alleged laundering trail overlaps with funds from a separate Kelp DAO exploit, while ZachXBT says more data is forthcoming.
The dispute pits Bitget’s effort to recover stolen funds against THORChain’s refusal to selectively block addresses, while cross-chain swaps keep the attacker’s activity visible.
The exchange says the pause was a security measure, not a sign of insufficient user assets, and that losses were covered by its Protection Fund.