Key facts
- The Bitget hacker started shielding about 2,700 ZEC, worth $3.8 million, in Zcash's Ironwood pool on Sept. 30.
- Near Intents rejected more than $50 million in swaps linked to the hack.
- Bitget estimates the theft at $387.5 million.
- Bitget CEO Gracy Chen and Elliptic suggest North Korean involvement.
- The hacker split funds into wallets holding round amounts of ETH or XRP.
- Thorchain stated network halts are for protocol protection, not selective freezes.
The hacker responsible for draining $387.5 million from the crypto exchange Bitget has begun to obscure a portion of the stolen funds within Zcash's privacy-enhancing features. On September 30, approximately 2,700 ZEC, valued at around $3.8 million, were moved into Ironwood, a shielded pool on the Zcash network, according to on-chain investigator ZachXBT.
Shielded pools on Zcash encrypt transaction details, making it difficult to trace funds once they enter. The amount deposited represents about one-seventh of the total ZEC stolen in the hack.
Bitget CEO Gracy Chen has indicated that the attack's characteristics, including IP addresses and patterns, align with North Korean hacking groups. Blockchain analytics firm Elliptic also considers a North Korean connection "highly likely," labeling it the largest suspected North Korean crypto theft of 2026 and pushing the year's total above $1 billion.
The heist commenced on September 24 when Bitget's systems detected unauthorized transfers from its internet-connected hot wallets. Chen stated that attackers gained access to backend systems and manipulated transaction data rather than stealing private keys. Bitget has assured customers that its protection fund covers the losses, ensuring customer balances remain unaffected.
Following the theft, the attacker reportedly split the funds into multiple wallets, with some holding approximately 10,000 ETH or 20 million XRP each. Smaller amounts were processed through cross-chain swap services like Thorchain, Across, Bridgers, Chainflip, and FixedFloat, which help obscure the transaction trail.
Near Intents reported that its screening system, SHIELD, blocked over $50 million in swaps associated with the Bitget attacker, freezing about $503,000 mid-swap and allowing approximately $166,000 to proceed. Near plans to pursue legal and recovery proceedings for the frozen funds.
In contrast, Thorchain declined Bitget's request to block the attacker's addresses. The network stated that its halts are an emergency security measure for protocol protection, not a tool for freezing specific assets or individual swaps, and are decided by independent node operators. Thorchain had previously halted its entire network for five weeks in May 2026 following a $10.7 million exploit.
