Key facts
- Chainalysis AI compressed over 20 hours of manual bridge reconciliation to under 10 minutes while tracing the Bitget hack.
- The firm attributed the September 24, 2026 breach to DPRK-linked actors.
- The incident pushes North Korea’s crypto theft in 2026 past $1 billion.
- Bitget reported losses of $387.5 million from the hack.
- Stolen XRP was pushed through a cross-chain liquidity protocol and received as Bitcoin.
- Chainalysis provided near real-time address labels to compliance teams and law enforcement.
Blockchain analytics firm Chainalysis announced that its in-house artificial intelligence technology significantly reduced the time required to trace funds stolen in the Bitget hack. The AI compressed over 20 hours of manual bridge reconciliation work into less than 10 minutes.
The firm has attributed the September 24, 2026 breach to actors linked to North Korea (DPRK), stating that this incident brings the total estimated crypto theft by North Korea in 2026 to over $1 billion.
Bitget detected unauthorized transfers from its hot and warm wallets on September 24, 2026, with cold wallets remaining untouched. CEO Gracy Chen explained that a critical backend system was compromised, allowing the attacker to spoof transaction data and initiate the authorization process. The initial estimated loss was $351.6 million, later revised to $387.5 million to include Zcash and TRON balances.
Chainalysis reported that the $387 million was moved in 23 transfers across three hours and landed on four blockchains: Ethereum (49.7%), XRP (40.8%), Zcash (7.6%), and Tron (1.8%). Over $157 million in XRP was identified as the largest single-asset portion, with on-chain data suggesting Lazarus-style activity in the routing patterns. The stolen XRP was later pushed through a cross-chain liquidity protocol and converted to Bitcoin, with tens of millions traced to attacker-controlled Bitcoin addresses over approximately 36 hours.
When the hacker began swapping Ethereum for Bitcoin, Bitget's CEO publicly requested THORChain to freeze the routed funds, but THORChain declined. This left cross-chain bridges, instant swaps, decentralized exchanges (DEXs), and laundering services as the primary channels for fund movement, areas where manual reconciliation is particularly challenging.
Chainalysis developed custom automations using over a decade of cross-chain attribution data to match deposits and payouts across protocols. This enabled the rapid mapping of bridge hops linked to the Bitget hack. The identified addresses were then pushed to compliance teams and law enforcement in near real-time. While the sub-10-minute reconciliation does not directly recover the funds, it significantly shortens the gap between the outflow of stolen assets and their labeling by the industry, which is crucial for recovery efforts.
The broader context of the Bitget hack includes a G7 warning about North Korea's crypto theft operations, which have been linked to funding nuclear development programs. The Chainalysis findings highlight the increasing speed at which these illicit funds are moved, adding an AI-driven dimension to the systemic risk conversation surrounding North Korean cyber activity.