
Four days after Bitget's $387.5 million theft, on-chain investigator ZachXBT claims Chinese intermediaries are laundering funds on behalf of suspected North Korean attackers, publicly asking for help on Discord and Telegram when their XRP-bitcoin swaps on THORChain fail, captures of support tickets and transactions show.
AI-generated summary
The Bitget hack was detected on September 24 at 6:31 p.m. UTC, with a loss initially estimated at $351.6 million and then increased to $387.5 million after incorporating additional transfers to Zcash and Tron. Bitget blames a compromised backend service and names North Korea as a very likely lead.
Whitening complains out loud. Four days after Bitget's $387.5 million theft, on-chain investigator ZachXBT claims Chinese intermediaries are laundering funds on behalf of suspected North Korean attackers. And they do it by asking for help, publicly, on Discord and Telegram, when their XRP-bitcoin swaps stuck on THORChain do not work.
The screenshots published on September 28 show support tickets, transaction IDs and a graph that links these aliases to the hack wallets. Meanwhile, THORChain still refuses to block reported addresses.
Key Points
ZachXBT names five aliases, Cc, jack, Melon, lolo/Marin and HELP ME, as touts of the Bitget hack funds
These accounts write in plain text in the support rooms of the services they use, in particular for XRP to bitcoin swaps via THORChain
The alias lolo/Marin has already leaked funds from the Kelp DAO exploit, estimated at $292 million
Some of the loot is then bridged to other channels and deposited into mixers, including Wasabi
Bitget raised the loss from $351.6 million to $387.5 million and maintains its $464 million protection fund covers customer balances
Five aliases, public tickets, hashes pasted into chat
On September 28, ZachXBT, known for his on-chain investigative work, revealed a potential link between North Korean hackers and China. According to his post on
A procedure that does not seem unfamiliar to him. Indeed, he adds that he has already witnessed the same patterns after several hacks attributed to TraderTraitor, the attack cluster associated with North Korea. Additionally, ZachXBT is expected to share additional data in the coming weeks.
The screenshots shared on X speak for themselves. On September 27, an account named jack opened a ticket: he used “Thorium”, the common nickname for THORChain in these shows, to exchange XRP for bitcoin, and declared that he had not received anything for almost a day, and pasted in the transaction identifier. Another, Cc, explains having sent 277,724 XRP and having only recovered 431 after a swap marked as successful. Melon requests verification of two canceled bitcoin transactions “because the BTC network was on pause”.
So, it's hard not to see a link with the Bitget hack. Still according to information shared by ZachXBT, approximately 103 million XRP passed through various wallets, including those of our two anonymous Internet users, before reaching the THORChain. Also, the investigator specifies that part of the funds are then moved via bridges, then deposited in mixers like Wasabi.
It seems that these mysterious Internet users are not new to this. Thus, ZachXBT managed to link one of the addresses to the leak of the Kelp DAO exploit, a theft of $292 million earlier in the year.
Bitget Requests Freeze, THORChain Returns to Bitcoin
The hack was detected on September 24 at 6:31 p.m. UTC. Bitget first spoke of $351.6 million coming out of hot and warm wallets, before bringing the figure to 387.5 million after integrating additional transfers, notably on Zcash and Tron. The cold wallets would have remained intact. The exchange blames a compromised backend service, not a leak of private keys, and names North Korea as a “very likely” lead.
As of the weekend, Gracy Chen, CEO of Bitget, publicly asked THORChain to refuse service to the hacker's addresses, already listed. The protocol responded in the negative as usual. His argument is nevertheless solid: the protocol is permissionless, like Bitcoin, Ethereum or BNB Chain, and does not have a native mechanism for blacklisting an isolated wallet. Note that its operators could suspend outgoing signatures, pools or an entire chain more widely, at the cost of also blocking users unrelated to the attack.
The debate is not new. After the theft of $1.5 billion from Bybit in February 2025, already attributed to Pyongyang, a large part of the ether had taken the same bridge to bitcoin. The FBI then called on the sector to freeze the flows. THORChain hadn’t moved a finger. In May 2026, the protocol was shut down almost five weeks after the theft of $10.7 million from one of its own vaults.
There remains the point that support tickets make it difficult to ignore. Funds do not just circulate “like on Bitcoin”. Human intermediaries open tickets, paste hashes and wait for an operator to uncork an XRP-BTC swap. THORChain continues to treat these orders like any other.
AI outlook — possibilities, not facts
ZachXBT to share additional data linking Chinese intermediaries to Bitget hack in coming weeks
Likely · Within weeks
Bitget will continue to push for THORChain to block hack-related addresses
Very likely · Within days

Apple has released iOS 26.7.1 update to fix zero-day CVE-2026-86950 in CoreGraphics. The company SlowMist warns of attacks targeting crypto wallets, although Apple has not formally linked the vulnerability to these thefts.

NEAR Intents claims to have blocked more than $50 million linked to the Bitget hack and froze an additional $503,000 using its SHIELD filter before solvers intervened.

China's Ministry of State Security claims that the anonymity of cryptocurrencies is an illusion, explaining that all transactions leave traceable traces via fiat-crypto exchanges and IP addresses, and cites the Bitfinex affair as proof, while banning the use of Bitcoin on its territory despite tolerance of detention.

On-chain analyst Wazz claims to have identified a coordinated operation linked to 53 memecoin launches on Robinhood Chain, which extracted at least $18.43 million between July 10 and September 21, by exploiting a loophole in the Pons V2 anti-sniping tax to concentrate the supply and immediately resell to investors.

The UNCTAD statistics portal (UNCTADstat) underwent a massive automated collection of 16,000 requests between April and June 2026. IP addresses and identifiers suggest a link to OpenAI agents, although the site only contains public data.

Solana is testing Alpenglow, an overhaul of its consensus replacing TowerBFT and Proof of History. This protocol aims to reduce transaction finality from 12.8 seconds to 150 milliseconds, improving efficiency for payments and bridges.