Chainalysis Attributes $387M Bitget Heist to North Korea Using AI-Driven Tracing
Highlights
Chainalysis has attributed a $387 million breach of the Bitget exchange to actors tied to the Democratic People's Republic of Korea, concluding the theft moved quickly across multiple blockchains. Within three hours the funds were split across Ethereum, XRP, Zcash and Tron, then processed through cross-chain liquidity, swaps and laundering services. Chainalysis emphasized that custom in-house AI compressed more than 20 hours of manual tracing into under 10 minutes, accelerating investigators while keeping human oversight front and center.
Sentiment Analysis
- The article's overall tone is cautious and investigative, blending factual reporting with concern about the scale and speed of the theft. It underscores the seriousness of the incident and the effectiveness of modern analytic tools without sensationalism. The sentiment leans toward a mix of alarm and technological confidence, since the report highlights both the large loss and the advanced methods used to trace it.
Article Text
Blockchain analytics firm Chainalysis has publicly linked the recent $387 million intrusion at the Bitget cryptocurrency exchange to actors associated with the Democratic People's Republic of Korea. The company’s report, released in the weeks following the Sept. 24 incident, places the theft among the year’s most significant crypto heists and states that the cumulative value of crypto attributed to DPRK-linked groups in 2026 has now exceeded $1 billion.
According to Chainalysis, the attackers moved funds off Bitget very quickly. In roughly three hours after the breach, the stolen assets were transferred in 23 transactions across four different networks: nearly half to Ethereum, a substantial portion to XRP, and smaller amounts to Zcash and Tron. From those entry points, the funds were funneled through a sequence of cross-chain liquidity protocols, instant swap services and other mixing techniques designed to obscure origin and destination.
One notable aspect of the laundering pathway involved the stolen XRP. Rather than sending the tokens directly to centralized exchanges, the threat actors pushed XRP through a cross-chain liquidity mechanism and emerged with Bitcoin on the other side. This pattern — converting assets across chains and then consolidating into attacker-controlled Bitcoin addresses — continued over approximately a day and a half, drawing close attention from analysts tracking the flow.
Chainalysis reports that it collaborated with Bitget and law enforcement to trace those movements across multiple blockchains. To keep pace with the rapid tempo of the transfers, the firm developed custom automation powered by its internal AI systems. Chainalysis estimates that tasks which would have taken investigators more than 20 hours of manual bridge reconciliation were completed in under 10 minutes thanks to these tools. The company emphasized that the AI served to accelerate human analysts rather than replace them: investigators still directed the workflow, validated results and made attribution judgments.
The attribution to DPRK-linked actors aligns with earlier statements from Bitget’s leadership and other forensic firms. Bitget’s CEO noted similarities in the attack patterns to previous incidents tied to North Korea, and Elliptic, another analytics firm, described a DPRK connection as "highly likely." Public sleuthing and analytics have also followed the laundering trail in near real time. Observers documented that some of the stolen funds were routed into Zcash’s shielded pool, a privacy feature that can obscure transaction links. Swap services and liquidity providers responded unevenly: some refused or froze suspicious transactions, while others continued processing them.
Actions by intermediaries had mixed effects. A few services rejected swaps related to the theft, and major stablecoin issuers acted to freeze certain addresses, limiting quick conversion of some seized tokens. Nonetheless, substantial portions of the stolen value were successfully converted and consolidated before all avenues could be blocked. The incident illustrates the persistent challenge of tracing and interdicting illicit flows when attackers rapidly use multiple chains, cross-chain protocols and privacy tools.
Chainalysis’ use of AI-driven automation highlights a broader trend in blockchain forensics: analysts increasingly rely on machine assistance to process large volumes of chain data and reconcile complex cross-chain movements. This integration of AI and human oversight appears central to keeping investigations timely as thefts grow faster and more sophisticated, but it also underscores the ongoing cat-and-mouse dynamics between defenders and illicit actors.
Ultimately, the Bitget hack reinforces several recurring themes in crypto security: the speed of post-breach fund movements, the attractiveness of cross-chain mechanisms for laundering, and the need for coordinated responses by exchanges, analytics firms and law enforcement. While attribution to state-linked groups raises geopolitical concerns, the technical lessons are practical: improved monitoring, rapid coordination and targeted countermeasures remain key to limiting the impact of large-scale thefts in the digital-asset ecosystem.
Key Insights Table
| Aspect | Description |
|---|---|
| Attribution | Chainalysis links the Bitget breach to DPRK-associated actors, consistent with other analysts’ assessments. |
| Funds Movement | $387M moved in 23 transfers within three hours across Ethereum, XRP, Zcash and Tron. |
| Tracing Method | Custom in-house AI automation reduced manual reconciliation time from 20+ hours to under 10 minutes, aiding investigators. |
| Laundering Techniques | Cross-chain liquidity protocols, instant swaps, privacy pools (Zcash) and stablecoin freezes were involved. |
Last edited at:2026/10/3
