Skip to content
News Crypto News

Crypto: Bitget Hackers Hide $3.9 Million in Zcash

Funds stolen in the Bitget hack are beginning to disappear behind Zcash’s privacy layer. Around 2,746 ZEC, worth approximately $3.9 million, were transferred on Wednesday into Ironwood, the network’s new shielded pool. The transactions were flagged by ZachXBT and verified on-chain by CoinDesk. They account for only around 15% of the ZEC stolen in the $387.5 million hack, but are already making the funds significantly harder to track.

Zcash entering an opaque vault as an investigator loses the visible trail
The transfer of stolen ZEC into a protected pool makes the transactions harder to track publicly.

Stolen ZEC become much harder to trace

Until now, the ZEC linked to the hack could still be tracked from transparent addresses. The move into Ironwood changes that. BrefCrypto had already shown how wallets attributed to Lazarus move tens of millions of dollars across multiple networks. With Zcash, investigators now face an additional challenge: privacy is built directly into the protocol.

CoinDesk identified three deposits made between 08:15 and 08:46 UTC, totaling 2,746 ZEC. The funds came from two intermediary addresses that had themselves been funded by a wallet Bitget identified as belonging to the attacker. ZachXBT had initially reported around 2,700 ZEC.

The wallet received nearly 18,917 ZEC during the September 24 attack, worth approximately $28.3 million based on estimates published at the time.

Ironwood masks the relationships between transactions within its shielded pool. The sender, recipient and amount are no longer publicly visible in the same way as they are with a transparent address.

That does not mean every investigation becomes impossible. Analysts can still monitor the amounts entering the pool and try to correlate their reappearance at public addresses. Timing, amounts and interactions with exchanges may provide clues.

The trail simply becomes far less clear.

Ironwood shows exactly what Zcash is designed to do

Ironwood is very recent. The pool was activated on the Zcash mainnet on July 28, 2026, as part of the NU6.3 upgrade. It was developed in particular after the discovery of a soundness vulnerability in the former Orchard pool. Zcash says Ironwood has now undergone formal verification to strengthen the integrity of its supply.

Privacy nevertheless remains at the heart of the system.

BrefCrypto had already examined Grayscale’s bet on Zcash, whose core arguments include the ability to protect transaction information.

Technically, Zcash uses zk-SNARK cryptographic proofs. They make it possible to demonstrate that a transaction follows the network’s rules without publicly disclosing all the information used to generate the proof.

A legitimate user can therefore transfer value without publishing their entire financial activity.

A hacker can benefit from the same property.

That is the central challenge for privacy protocols: the technology cannot tell whether a user is protecting their salary, a commercial transaction or assets originating from a hack.

In the Bitget case, Ironwood therefore gives potential attackers a particularly effective tool for breaking part of the visible continuity between the address that received the stolen funds and their final destination.

This is not a flaw in Zcash. It is how its privacy system is designed to work.

Bitget already had little hope of recovering the money

The migration to Ironwood comes at a bad time for Bitget.

The exchange has officially confirmed that $387.5 million was transferred to addresses controlled by the attacker. The initial estimate was $351.6 million, before a full analysis added, among other assets, funds stolen on Zcash and TRON. ETH, XRP, USDT, USDC, ZEC, BNB, AVAX and several other tokens were among the assets affected.

Bitget attributed the incident to a zero-day vulnerability in a third-party security product. According to CEO Gracy Chen, the attacker may have obtained high-level internal credentials that allowed them to issue fake withdrawal commands. The private keys and cold wallets were reportedly not compromised.

The North Korean connection remains an attribution, not a confirmed conclusion. ZachXBT referred to suspected attackers linked to the DPRK, while Bitget also cited methods consistent with those used by North Korean groups. This is not yet a definitive official attribution. That caution matters, even though groups linked to Pyongyang have already stolen several billion dollars in crypto.

Gracy Chen is no longer hiding her pessimism. Earlier this week, she said she was “not very optimistic” about the chances of recovering all the assets. She pointed to the Bybit precedent: after the theft of $1.5 billion in 2025, only a small fraction of the funds could be frozen or recovered.

Some funds from the Bitget hack have already been blocked. Tether and Circle notably froze more than $318,000, while NEAR Intents reportedly prevented certain assets from moving further.

Ironwood falls into a different category.

Once ZEC enter the shielded pool, there is no central issuer able to blacklist an address and halt the transfer. Investigators must return to on-chain analysis, exit points and operational mistakes made by the attackers.

For Bitget, the race has therefore changed in nature.

The issue is no longer simply where the stolen ZEC are. Nearly $3.9 million has entered a system specifically designed to ensure that the answer is no longer publicly obvious.

Sources cited1
BrefCrypto Crypto news from Africa and around the world
Follow us on Google News →
Lydie Musekwa
Author

Lydie Musekwa