
AI-generated summary
Bitget is a cryptocurrency exchange that suffered a $387.5 million hack on September 24, involving unauthorized transfers from its hot wallets. The attacker allegedly accessed backend systems and faked transaction data rather than stealing private keys. On-chain investigators have traced portions of the stolen funds through various blockchain networks.
The hacker who drained $387.5 million from crypto exchange Bitget has started hiding some of the loot inside Zcash's private pool. On-chain investigator ZachXBT said Wednesday that the attacker began moving about 2,700 ZEC—roughly $3.8 million—into Ironwood, a shielded pool on the privacy-focused Zcash blockchain.
A shielded pool is a part of the Zcash network that encrypts the sender, the receiver, and the amount, so nobody can follow the money once it goes in. Ironwood launched July 28 to replace an older pool, Orchard, after a researcher found a bug that could have let someone print counterfeit coins.
The deposit is roughly one-seventh of the ZEC stolen in the hack, according to on-chain tracking. Investigators can still see coins go into the pool and come out, but not what happens in between.
Bitget CEO Gracy Chen has said the attack's IP addresses and pattern match North Korean hackers, and blockchain analytics firm Elliptic calls a North Korean link "highly likely." Elliptic also ranks it the largest suspected North Korean theft of 2026, pushing the year's total past $1 billion.
How the money got here
The heist began Sept. 24, when Bitget's systems flagged unauthorized transfers out of its hot wallets—the internet-connected wallets that hold an exchange's day-to-day funds. Chen said the attackers got into backend systems and faked transaction data rather than stealing private keys. Bitget says its protection fund covers the damage, so customer balances are unaffected.
Then came the laundering. TRM Labs found the attacker split the funds into fresh wallets holding round amounts, roughly 10,000 ETH or 20 million XRP each. Smaller chunks went through cross-chain swap services—tools that trade one coin for another on a different blockchain, which muddies the trail—including Thorchain, Across, Bridgers, Chainflip, and FixedFloat.
Near Intents, meanwhile, said no. General manager Alex Shevchenko said Tuesday that its screening system, called SHIELD, rejected more than $50 million in swaps tied to the Bitget attacker. About $503,000 got frozen mid-swap, and roughly $166,000 slipped through, he said.
Near says the frozen funds will go through legal and recovery proceedings. The move set off a familiar crypto fight over the word "permissionless," which means anyone can use a network without approval. Near cofounder Illia Polosukhin argued that it doesn't oblige every app to process every transaction.
Thorchain went the other way. After Chen publicly asked it to refuse service to the attacker's addresses, Thorchain said in a post on X that a network halt is an emergency tool to protect the protocol, not a way to freeze specific funds or swaps. It is run by independent node operators who vote on halts, not by a company, according to its developers.
The obvious objection is that Thorchain has stopped transactions before. It halted its entire network for about five weeks after a $10.7 million exploit on May 15, according to its own report, and resumed June 22.
The hacker’s swaps kept flowing in the meantime. On Monday, several batches totalling roughly 2,390 ETH—about $6.3 million—were converted into 75.2 BTC through Thorchain, on-chain data show.
AI outlook — possibilities, not facts
Regulatory scrutiny of privacy-focused cryptocurrencies like Zcash will increase following this incident
Likely · Within months
Debate over 'permissionless' vs. responsible DeFi design will continue, particularly regarding transaction screening
Likely · Within weeks

A UK court has ordered former National Crime Agency officer Paul Chowles to repay £1,810,678.93 ($2.4 million) for stealing 50 Bitcoin from a seized wallet during the Silk Road 2.0 investigation in 2017. The coins, worth about £60,000 at the time, have appreciated significantly. Chowles was jailed for five and a half years in July 2025 after pleading guilty to theft and related offenses. The Crown Prosecution Service secured the confiscation order under the Proceeds of Crime Act 2002, noting that 30 of the 50 BTC were recovered from him, with the order reflecting Bitcoin's increased value since the theft.

Aiden Pleterski, Canada's self-styled 'Crypto King', will defend himself at a Toronto fraud and money laundering jury trial starting Monday after a judge denied his request for an adjournment.

Aiden Pleterski, a self-described 'crypto king' accused of defrauding investors of approximately $30 million through false profit claims on digital assets between 2021 and 2022, is set to stand trial in Ontario's Superior Court of Justice on October 5, 2024, after being charged with fraud and money laundering in May 2024. He is expected to represent himself due to inability to secure legal counsel, with the fraud charge carrying a maximum sentence of 14 years if convicted.

Samourai Wallet co-founder Keonne Rodriguez faces another prison transfer after the drug treatment program at FCI McKean was deactivated, disrupting his sentence reduction plan.

Ronald Spektor, 23, was sentenced to four to 12 years in prison for posing as a Coinbase representative and stealing nearly $16 million from about 100 users nationwide through a sophisticated cryptocurrency scam.

Polish prosecutors charged a former police officer over the collapsed Zondacrypto exchange, while investigators searched a fuel depot where its founder vanished four years ago.