Blockchain analytics firm Chainalysis has attributed last month's $387 million Bitget exchange hack to actors tied to North Korea. According to a report published Wednesday, the breach has pushed the total value of cryptocurrency stolen by North Korea-linked groups in 2026 past $1 billion.
Chainalysis stated it collaborated with Bitget and law enforcement to track the stolen funds following the September 24 attack. Within the first three hours of the breach, the $387 million moved across 23 transfers into four different blockchain networks: Ethereum accounted for 49.7%, XRP for 40.8%, Zcash for 7.6%, and Tron for 1.8%.
Following the initial transfers, the attackers utilized cross-chain liquidity and messaging protocols, instant swaps, and laundering services to obfuscate the trail. The stolen XRP was routed through a cross-chain liquidity protocol to convert into Bitcoin over approximately a day and a half, eventually landing in attacker-controlled Bitcoin addresses.
To keep pace with the complex cross-chain movements, Chainalysis employed in-house artificial intelligence. The firm reported that custom automation compressed more than 20 hours of manual bridge reconciliation work into under 10 minutes, though human investigators continued to direct the process.
This attribution aligns with previous assessments from Bitget CEO Gracy Chen, who noted the attack patterns matched North Korean hackers, and blockchain analytics firm Elliptic, which previously deemed a North Korean link highly likely.
As laundering activities continued publicly, Zcash's shielded pool was used to hide funds. Swap services responded differently to the situation: Near Intents rejected more than $50 million in swaps connected to the hacker before being hacked itself days later, while Thorchain continued processing transactions. Additionally, Circle and Tether froze approximately $318,000 in stablecoins.


