0x23e816ea23e8…23e816e7

ConfirmedSecurity553 vB44 sat/vB3 min decode

Bitget $387M Exploit Funds Traced Through Bridges and Wasabi

ZachXBT has linked Chinese actors to the laundering of $387M from the Bitget exploit, tracing funds through cross-chain bridges and the Wasabi mixer. Investigators tie the activity to the $292M Kelp DAO exploit and TraderTraitor cluster.

Bitget Exploit: How Alleged DPRK-Linked Hackers Launder $387M Through Crypto Bridges and Mixers - Tekedia
WitnessBitget Exploit: How Alleged DPRK-Linked Hackers Launder $387M Through Crypto Bridges and Mixers - TekediaAI-generated

Outputs

  1. Bitget exploit totaled $387 million, with laundering traced by ZachXBT to Chinese illicit actors

  2. Stolen funds were chain-hopped through cross-chain bridges before reaching the Wasabi mixing service

  3. Laundering orders were solicited through public Discord servers and Telegram channels

  4. Actor 'Alias 4' is linked to both the Bitget laundering and the $292 million Kelp DAO exploit

  5. Laundering pattern matches prior TraderTraitor activity cluster, a North Korean-attributed intrusion group

Blockchain investigator ZachXBT has linked Chinese illicit actors to the laundering of funds from the reported $387 million Bitget exchange exploit, identifying a laundering pipeline that investigators say stretches across multiple intrusions attributed to North Korean-linked attackers.

According to ZachXBT, who has tracked the post-exploit activity on-chain, Chinese actors allegedly involved in laundering the Bitget proceeds have solicited assistance through public Discord servers and Telegram channels tied to services used in the money-laundering workflow. The visibility of those requests marks a notable operational choice: rather than operating entirely inside closed networks, some participants appear willing to advertise their services in communities where swapping tools and privacy infrastructure are openly traded.

What does the laundering pipeline look like?

Investigators currently observe the stolen funds moving across multiple blockchain networks through bridge transactions before reaching mixing services such as Wasabi. Chain-hopping — the practice of moving assets across different blockchain ecosystems — forces analysts to follow transaction trails across several networks rather than a single chain.

Mixing services then attempt to obscure the link between the original source wallets and downstream recipients. Each bridge hop, wallet interaction and mixer deposit produces additional forensic evidence. Timing, transaction amounts, wallet reuse and funding relationships can collectively reveal patterns that individual transactions are designed to conceal.

Which previous exploits share the same infrastructure?

The laundering footprint appears to extend beyond the Bitget case. One actor identified as "Alias 4" was reportedly observed laundering funds connected to the $292 million Kelp DAO exploit earlier in 2026. That overlap, if confirmed through further wallet-level correlation, would indicate that the same network is being redeployed across apparently unrelated attacks.

The pattern echoes behavior reported following multiple exploits attributed to the TraderTraitor activity cluster — a designation used by researchers to group intrusions tied to North Korean operators. Repeated use of the same or closely connected intermediaries would give investigators a clearer map of the supporting infrastructure behind these operations.

Why does the laundering infrastructure matter?

The infrastructure used to move stolen assets can be as significant as the original exploit itself. Once attackers extract funds, they must convert and conceal them without triggering widespread detection — a problem that has created sustained demand for intermediaries capable of moving money across chains while attempting to break the transaction trail.

Blockchain transactions remain permanently recorded, meaning that even when assets traverse multiple networks, the historical relationships between wallets, bridges and services remain available for forensic analysis. ZachXBT's findings indicate that investigators are now correlating wallet activity across the Bitget case, the Kelp DAO exploit and prior TraderTraitor-attributed incidents to identify overlapping addresses and service providers.

What are the operational implications for exchanges?

The wider concern is structural: successful laundering operations can become reusable infrastructure for future cyberattacks. If the same intermediaries repeatedly help monetize stolen cryptocurrency, they effectively function as standing capacity for persistent digital theft — a risk that falls first on centralized exchanges whose treasury controls and withdrawal monitoring systems remain the primary line of defense.

Further on-chain analysis of the Bitget-linked wallets, the Wasabi deposits and the TraderTraitor cluster's historic activity is expected to yield additional identified addresses in the coming weeks, sharpening the map of intermediaries available to future attackers and the timeline over which centralized venues must harden their off-ramp monitoring.

via tekedia.com (Original)

More from Elena Vasquez

Elena Vasquez

Show full bio

Staff writer covering marketplaces and e-commerce at Mempool Brief.

440 articles