Chainalysis AI Traces $387M Bitget Hack to North Korea
In this article
Blockchain analytics firm Chainalysis has attributed the $387 million Bitget exchange hack to North Korea-linked actors, pushing the country’s 2026 crypto theft total past $1 billion, according to a report published Wednesday and covered by Decrypt. The Sept. 24 breach saw $387 million leave Bitget in 23 transfers across four blockchains within three hours. Chainalysis said it used in-house AI to accelerate tracing, compressing what it estimated as more than 20 hours of manual bridge reconciliation into under 10 minutes.
How the investigation unfolded
Chainalysis said its investigators built custom automation to match deposits on one blockchain with payouts on another, using more than a decade of cross-chain attribution data. The firm stressed the technology accelerated the case rather than replacing human judgment: “Our investigators still defined the logic, reviewed the outputs, and directed the investigation,” the report said.
The stolen XRP drew particular attention. According to Chainalysis, the attackers routed it through a cross-chain liquidity protocol that paid out Bitcoin rather than sending the XRP to an exchange. Tens of millions of dollars moved that way over roughly a day and a half before reaching attacker-controlled Bitcoin addresses now under watch.
The attribution echoes earlier assessments. Bitget CEO Gracy Chen said the attack’s patterns matched North Korean hackers, while the blockchain analytics firm Elliptic called a DPRK link “highly likely.” Chainalysis said it had been working with Bitget and law enforcement to trace the funds across multiple blockchains since the attack.
Bitget’s recovery efforts and industry pushback
Bitget said its systems detected unauthorized transfers at 18:31 UTC on Sept. 24 from parts of its hot and warm wallet infrastructure. The exchange later raised its loss estimate from $351.6 million to $387.5 million after including additional Zcash and Tron transfers. According to crypto.news, Bitget confirmed in its Sept. 30 update that major asset withdrawals had been restored, with Bitcoin returning on Sept. 28, Ether on Sept. 29, and USDT on Sept. 30. Remaining token, fiat, and P2P withdrawals were scheduled for Oct. 2. Chen also said the Protection Fund had returned above $300 million, and the exchange’s Sept. 29 reserve snapshot reported a 131% overall ratio across 19 covered assets.
The attacker’s laundering played out in public. The attacker began hiding funds in Zcash’s shielded pool, while swap services split in their response: Near Intents rejected more than $50 million in swaps tied to the hacker, only to be hacked itself days later, while Thorchain kept processing. Chen sought to block attacker addresses from using THORChain after the stolen funds began moving through the protocol, but THORChain rejected selective blocking, arguing its emergency controls protect network security rather than freeze individual wallets. Chen argued that decentralization should not shield services facilitating known stolen funds. Security firm GoPlus challenged the protocol’s comparison with Bitcoin and Ethereum, pointing to its validator-controlled vaults and signing system.
In a separate U.S. case reported Sept. 8, a federal court ordered stablecoin forfeiture of approximately $212,700 linked to wages earned by North Korean IT workers, according to crypto.news. Prosecutors alleged that workers concealed their identities, obtained overseas jobs, and routed earnings through cryptocurrency.
Why it matters
The attribution adds institutional weight to growing consensus that North Korea was behind one of 2026’s largest crypto thefts. The reported time saving on cross-chain matching matters because attackers move funds across multiple blockchains within hours, making rapid tracing essential for exchanges, compliance teams, and law enforcement. Bitget’s recovery terms and stablecoin freezes show the multi-front effort to claw back stolen assets, though the bulk remains unaccounted for.
What to watch
Chainalysis said its team continues to monitor the identified Bitcoin destinations and plans to label additional addresses as the funds move. Further attribution or recovery announcements could follow as Bitget’s reward program and law enforcement tracing progress.
Frequently Asked Questions
How much did North Korea steal in crypto in 2026?
Chainalysis said the $387 million Bitget hack pushed the total value of crypto stolen by North Korea-linked groups in 2026 past $1 billion. This figure combines the Bitget breach with other DPRK-linked thefts reported earlier in the year.
Which blockchains did the Bitget attacker use?
Within the first three hours, the attacker moved funds across four networks: Ethereum (49.7%), XRP (40.8%), Zcash (7.6%), and Tron (1.8%), according to Chainalysis.
How did Chainalysis’s AI speed up the investigation?
Chainalysis said its in-house automation reduced an estimated 20-plus hours of manual bridge reconciliation to under 10 minutes. Investigators still directed the case, set matching rules, and reviewed outputs.
What is Bitget offering for help recovering the stolen funds?
Bitget’s recovery terms offer a 5% bounty for qualifying assistance that results in funds being frozen, plus a separate 5% reward for successful recovery.
Sources: Decrypt, crypto.news



