Analysis of the $387 Million Bitget Hack Attributed to North Korean Actors
Recent investigations by Chainalysis identified the perpetrators of a significant $387 million hack of the cryptocurrency exchange Bitget as linked to North Korean operatives. This incident has intensified concerns regarding the scale of crypto theft orchestrated by the Democratic People’s Republic of Korea (DPRK), bringing the total to over $1 billion for the year 2026 alone.
Details of the Hack
The cyber breach occurred on September 24, 2026, and was characterized by a rapid movement of funds across multiple transactions. Within a mere three hours, the stolen assets were funneled through 23 separate transfers, predominantly to Ethereum (49.7%), followed by XRP (40.8%), Zcash (7.6%), and Tron (1.8%).
Following the initial transfer, the hacked funds were strategically routed through various blockchain protocols aimed at obscuring the trail, utilizing methods such as instant swaps and liquidity protocols.
Tracking the Stolen Funds
Chainalysis has been actively collaborating with Bitget and law enforcement to trace the diverted funds. The firm’s report highlighted their use of proprietary artificial intelligence, significantly reducing the time required for tracing operations — compressing what would typically take over 20 hours into less than 10 minutes.
Notably, some of the stolen XRP was converted to Bitcoin through cross-chain liquidity protocols, amounting to tens of millions of dollars being processed in this manner over approximately 36 hours.
Response from the Cryptocurrency Community
The laundering tactics employed by the hackers have been closely monitored by blockchain analysts. The attackers initially started obscuring funds in Zcash’s shielded pool, while cryptocurrency exchanges and services took varied stances on processing transactions linked to the hack. For instance, Near Intents rejected over $50 million in transactions related to the attackers but faced its own security breach shortly thereafter. In contrast, Thorchain continued to facilitate such swaps.
In the wake of these events, stablecoin issuers Circle and Tether took preventive action by freezing around $318,000 linked to the hack.
Expert Assessments and Attribution
The conclusion drawn by Chainalysis aligns with previous statements made by Bitget’s CEO, Gracy Chen, who noted that the attack patterns mirrored those associated with North Korean cyber actors. The blockchain analytics firm Elliptic further emphasized that a DPRK connection was “highly likely.”
As the situation develops, the focus remains on enhancing security measures across exchanges and improving protocols to track and mitigate such cyber threats in the future.
