0x0f0393d80f03…0f0393db

ConfirmedSecurity587 vB146 sat/vB3 min decode

Bitget Hacker Moves $3.8M Into Zcash's Ironwood Shielded Pool

The Bitget attacker moved 2,700 ZEC into Zcash's Ironwood shielded pool. Near Intents rejected $50M in swaps; Thorchain declined to block the hacker's addresses.

Outputs

  1. The Bitget attacker moved ~2,700 ZEC (~$3.8 million), roughly one-seventh of stolen ZEC, into Zcash's Ironwood shielded pool on Sept. 30, per ZachXBT.

  2. Near Intents' SHIELD screening system rejected over $50 million in swaps tied to the attacker, freezing ~$503,000 mid-swap, while ~$166,000 slipped through.

  3. Bitget puts the theft at $387.5 million; CEO Gracy Chen and Elliptic point to North Korea, which no government has confirmed. Bitget offers a 5% bounty on frozen funds and 5% on recovered funds.

The attacker who drained $387.5 million from crypto exchange Bitget has begun shielding loot inside Zcash's Ironwood pool, complicating recovery efforts already hampered by cross-chain swap services that refuse to block the hacker's addresses.

On-chain investigator ZachXBT reported Wednesday that the attacker moved roughly 2,700 ZEC — about $3.8 million — into Ironwood, a shielded pool on the privacy-focused Zcash blockchain. A shielded pool encrypts the sender, the receiver and the transaction amount, meaning investigators can see coins enter and exit but cannot trace what happens in between.

The deposit represents roughly one-seventh of the ZEC stolen in the hack, according to on-chain tracking. Ironwood launched on July 28 to replace an older pool, Orchard, after a researcher discovered a bug that could have allowed the creation of counterfeit coins.

Attribution points to North Korea, without confirmation

Bitget CEO Gracy Chen has said the attack's IP addresses and patterns match North Korean hackers, and blockchain analytics firm Elliptic assesses a North Korean link as "highly likely." No government has confirmed the attribution. Elliptic ranks the incident as the largest suspected North Korean theft of 2026, pushing the year's attributed total past $1 billion.

The heist began on Sept. 24, when Bitget's systems flagged unauthorized transfers out of its hot wallets — the internet-connected wallets that hold an exchange's day-to-day funds. Chen said the attackers compromised backend systems and faked transaction data rather than stealing private keys. Bitget says its protection fund covers the damage and customer balances remain unaffected.

The laundering pipeline

TRM Labs found the attacker split the funds into fresh wallets holding round amounts — roughly 10,000 ETH or 20 million XRP each. Smaller chunks moved through cross-chain swap services, which trade one coin for another on a different blockchain and muddy the trail. The services used include Thorchain, Across, Bridgers, Chainflip and FixedFloat.

Near Intents took a different path. General manager Alex Shevchenko said Tuesday that its screening system, SHIELD, rejected more than $50 million in swaps tied to the Bitget attacker. About $503,000 was frozen mid-swap, and roughly $166,000 slipped through, he said. Near says the frozen funds will go through legal and recovery proceedings.

The move reignited a familiar debate over "permissionless" networks. Near co-founder Illia Polosukhin argued that permissionlessness does not oblige every application to process every transaction.

Thorchain declines to intervene

Thorchain went the other way. After Chen publicly asked the protocol to refuse service to the attacker's addresses, Thorchain posted on X that a network halt is an emergency tool to protect the protocol, not a mechanism to freeze specific funds or swaps. Independent node operators vote on halts; no company runs the network, according to its developers.

The protocol has stopped transactions before, though. Thorchain halted its entire network for roughly five weeks following a $10.7 million exploit on May 15, resuming on June 22, according to its own post-incident report.

The attacker's swaps kept flowing regardless. On Monday, on-chain data show, several batches totalling roughly 2,390 ETH — about $6.3 million — were converted into 75.2 BTC through Thorchain.

Bitget is now offering a bounty of 5% of any frozen funds and another 5% of any recovered funds, excluding recoveries ordered by courts or law enforcement. As more stolen ZEC migrates into Ironwood and swap services continue processing the attacker's conversions, the exchange's recovery window narrows with each passing block.

via trmlabs.com (Original)

More from Elena Vasquez

Elena Vasquez

Show full bio

Staff writer covering marketplaces and e-commerce at Mempool Brief.

440 articles