Skip to content
News Crypto News

Crypto: Chainalysis links Bitget hack to North Korea

The $387 million theft from Bitget is taking on a geopolitical dimension. Chainalysis now attributes the September 24 attack to North Korean-linked actors. Within three hours, the funds had moved across Ethereum, XRP, Zcash and Tron before passing through bridges, swaps and laundering services. The operation brings crypto theft attributed to North Korean actors to more than $1 billion in 2026.

Investigator symbolically linking transfers between Ethereum, XRP, Zcash and Bitcoin on a tracing table
Illustration of a multi-chain investigation following the theft from Bitget, which Chainalysis attributes to North Korean-linked actors.

Crypto: $387 million leaves Bitget within three hours

The attack began on September 24 at 18:31 UTC. Bitget detected unauthorized transfers from some of its hot and warm wallets. The exchange now estimates the affected funds at approximately $387.5 million, up from the initial estimate of $351.6 million.

The case joins a long series of North Korean operations tracked by Chainalysis and South Korean police in their fight against Pyongyang’s crypto networks.

According to Chainalysis’s new analysis, the attackers distributed the funds across four networks during the first three hours: 49.7% on Ethereum, 40.8% in XRP, 7.6% on Zcash and 1.8% on Tron.

Bitget, for its part, says its private keys were not compromised. The attack allegedly exploited a vulnerability in a third-party security product to obtain internal credentials and then generate fake withdrawal orders capable of bypassing certain controls.

The exchange’s cold wallets were not affected.

Chainalysis goes further than Bitget on one point, however: the blockchain analytics firm now attributes the operation to actors linked to the Democratic People’s Republic of Korea. At this stage, the attribution comes from Chainalysis and does not constitute a public announcement by the FBI or any other judicial authority.

XRP turns into Bitcoin as Zcash obscures the trail

Once the funds had left Bitget, the hackers did not simply send the crypto to a few wallets and wait.

XRP illustrates the method well. Rather than transferring the tokens directly to an exchange, the attackers routed them through a cross-chain liquidity protocol and received Bitcoin on the other side. Chainalysis estimates that several tens of millions of dollars followed this path over roughly a day and a half.

Other assets moved through decentralized protocols, swap services and laundering infrastructure. Zcash already accounted for 7.6% of the funds moved during the first hours, reflecting the shift in strategy observed after the attack.

North Korea has long used this kind of dispersal. BrefCrypto reported in September that Lazarus-linked wallets had moved more than $30 million in Bitcoin through Hyperliquid before converting the funds across several networks.

The principle remains the same: spread assets across multiple blockchains to make the investigation take longer.

That does not make the funds invisible, however. Every bridge creates transactions that must be linked together. Every swap generates an entry and an exit.

The main challenge is speed and scale.

AI cuts 20 hours of investigation to 10 minutes

This is where Chainalysis adds an interesting element to the Bitget case.

Its investigators say they built automated tools using their internal AI to link movements across different blockchains more quickly. A bridge-reconciliation task that would have required more than 20 hours of manual work was reportedly reduced to less than 10 minutes.

AI does not determine on its own that an address belongs to a hacker. Chainalysis emphasizes that its investigators still define the logic, verify the results and direct the investigation. Automation is mainly used to reconstruct the hundreds of transfers generated by the attackers much more quickly.

This race for speed is becoming strategic. The G7 had already identified North Korean crypto theft as one of the mechanisms Pyongyang uses to circumvent international sanctions. Chainalysis also estimates that the Bitget hack brings the amount stolen by North Korean actors to more than $1 billion in 2026.

Bitget has launched a program offering up to 5% of frozen or recovered funds to individuals or organizations providing decisive assistance. The exchange is also working with Mandiant, SlowMist, Chainalysis and several industry partners.

The initial vulnerability was located in third-party security infrastructure. The laundering operation, meanwhile, immediately moved across several blockchains.

This is now one of the most difficult signatures of North Korean attacks: steal quickly, switch networks even faster, then force investigators to keep pace.

Sources cited1
BrefCrypto Crypto news from Africa and around the world
Follow us on Google News →
Gregoire Lacroix