Skip to content

exploit

Chainalysis attributes $387M Bitget heist to DPRK, pushing 2026 crypto theft past $1B

Chainalysis formally pins the September Bitget hack on North Korea-linked actors, says in-house AI compressed 20 hours of bridge reconciliation to minutes. Bitget publicly credits Near Intents.

by 3 min read

Chainalysis on October 3 formally attributed the $387M Bitget hack of September 24 to North Korea-linked actors, saying the heist pushes the DPRK's 2026 crypto theft total past $1 billion, Decrypt reported. It is the third named analytics firm — after Elliptic and Bitget's own executive statement — to tie the breach to the DPRK; no government has publicly designated the actor to date.

Separately on the same day, Bitget published a recovery post-mortem that publicly credits Near Intents for blocking $50M in laundering attempts and criticizes unnamed DeFi protocols for refusing to help trace stolen funds, Crypto Briefing reported.

What Chainalysis says

  • Attribution: North Korea-linked actors, aligned with earlier assessments from Elliptic and Bitget CEO Gracy Chen. Chainalysis cites collective investigation work with Bitget and law enforcement rather than a single named researcher.
  • Milestone: the heist pushes DPRK-linked crypto theft past $1 billion for 2026, per Chainalysis's running tally.
  • AI tracing: the firm says its in-house automation "compressed what it estimated as more than 20 hours of manual bridge reconciliation into under 10 minutes." The methodology is not public.

Early fund dispersion

Chainalysis tracked the stolen funds across four blockchains within the first three hours, split across 23 transfers:

  • Ethereum: 49.7%
  • XRP Ledger: 40.8%
  • Zcash: 7.6%
  • Tron: 1.8%

The subsequent movement into Zcash's Ironwood shielded pool — previously covered on this site — accounts for most of the ZEC leg's visibility loss. Analysts can see the deposits land in Ironwood; they cannot follow the funds once settled inside.

Bitget's post-mortem — what moved

  • Entry point: zero-day vulnerability in third-party security software, consistent with Bitget's September disclosures.
  • Near Intents SHIELD: Bitget confirms the system "identified and halted over $50 million in illicit laundering attempts" at the solver level. Direct freezes were modest in dollar terms: ~$503,000 blocked mid-swap and roughly $166,000 slipped through before flags applied. Near waived its 5% bounty.
  • Stablecoin freezes: Tether and Circle froze between $320,000 and $340,000 in stablecoin transfers.
  • Overall recovered share: approximately 0.2% of stolen funds.
  • DeFi callout: Bitget argues that "some DeFi protocols refuse to help recover stolen funds" but does not name them beyond labeling Near Intents the "notable exception."

Attribution — hedged, standard-of-practice

Reports from analytics firms are not government designations. Elliptic labeled a North Korean link "highly likely" in September. Bitget's Gracy Chen said "the attack's IP addresses and pattern match North Korean hackers." Chainalysis today joins that chorus. Neither the FBI's IC3 nor OFAC has issued a public designation or a sanctions entry tied to this specific heist at the time of writing. We report the attribution as claimed by named firms, not as a settled fact.

Pattern

This is the latest in a 2026 run of DPRK-attributed heists that collectively now cross the $1B threshold per Chainalysis. The Bitget breach alone eclipses most of the year's prior incidents in dollar terms and demonstrates the same dispersion-first, mix-later playbook on-chain investigators have documented across prior North Korea-linked attacks: fast fan-out across chains, then into shielded or privacy-adjacent primitives — in this case, Ironwood — once initial laundering vectors (centralized routers, intents networks) start to close.

What to watch

  1. Whether OFAC or the FBI's IC3 issues a formal designation tying the Bitget heist to a named DPRK unit.
  2. Whether other DeFi protocols respond publicly to Bitget's criticism, and whether that pressure yields more frozen or returned funds.
  3. The size and timing of the next Ironwood or privacy-pool withdrawal from the attacker-labeled address cluster.
  4. Whether Chainalysis publishes the specific transaction graph behind its attribution — currently only the methodology summary is public.

Related stories