0x22bffc6222bf…22bffc65
Bitget's $387.5M Hack: Launderers Unmasked by Their Own Chat Logs
Bitget lost $387.5M on Sept. 24 after attackers tricked its approval system. ZachXBT traced launderers via public chats, tying them to Kelp DAO and TraderTraitor.

Outputs
Bitget lost $387.5 million on September 24, 2026, via a compromised internal approval system; no private keys were stolen.
CEO Gracy Chen said North Korea was "very likely" behind the attack.
ZachXBT tied suspect account "lolo" to the $292 million Kelp DAO exploit and the FBI-designated TraderTraitor group.
THORChain refused Bitget's September 26 request to block attacker wallets, citing its permissionless design.
Withdrawals resume in phases: BTC Sept. 28, ETH Sept. 29, USDT Sept. 30, other tokens Oct. 2.
Bitget lost $387.5 million on September 24, 2026, after attackers tricked the exchange's internal approval system into authorizing transfers — without ever compromising a private key — and CEO Gracy Chen said North Korea was "very likely" behind the operation.
The breach, one of the largest crypto exchange thefts of 2026, hit a backend system inside Bitget's wallet infrastructure across Ethereum and other EVM networks, the XRP Ledger, Zcash and TRON. Bitget first estimated damages at $351.6 million, then raised the figure to roughly $387.5 million after identifying additional Zcash and TRON transactions tied to the same attack. The exchange said cold wallets and the separate Bitget Wallet product were unaffected.
Who is moving the stolen funds?
Blockchain investigator ZachXBT says Chinese money launderers working on behalf of the suspected North Korean attackers exposed themselves by asking for customer support in public channels. He named five accounts, matched each to a specific transaction and published supporting screenshots.
The suspects complained openly in Discord servers and Telegram channels after XRP-to-Bitcoin swaps failed. One account, "Cc," wrote that 277,724 XRP went into a swap but only 431 came back. Another, "jack," said losing the assets "would cause a lot of trouble in my life." In one exchange, a moderator for swap service SwapKit replied to the complaints with a photo of Kim Jong Un.
How far does the network reach?
One flagged account, "lolo," also laundered proceeds from the $292 million Kelp DAO exploit in April, according to ZachXBT. In chat logs, lolo confirmed operating under the Telegram alias "Marin," linking two multi-hundred-million-dollar thefts to the same infrastructure.
ZachXBT said he has "observed the same pattern after multiple TraderTraitor attributed exploits." TraderTraitor is the FBI's designation for a North Korean hacking group the bureau previously blamed for the $308 million theft from Japan's DMM Bitcoin in 2024. The repeated fingerprints across Kelp DAO, DMM Bitcoin and Bitget point to a single network, or a closely linked one, operating across platforms rather than running one-off jobs.
Why won't THORChain freeze the wallets?
Tracing the funds shows a familiar laundering pipeline: bridges, then mixers. Security firm AMLBot found roughly 4 BTC linked to the breach moved from TRON through USDT0, then Ethereum and THORChain, before reaching Bitcoin and entering a Wasabi CoinJoin round, according to crypto.news.
Chen formally asked THORChain on September 26 to refuse service to the attacker's publicly tracked addresses, arguing that "decentralization is a design principle, not a shield for facilitating known stolen funds" and that "the industry is watching." THORChain refused, saying its emergency halt mechanisms protect the protocol itself, not a tool for selectively freezing addresses.
GoPlus Security pushed back, arguing THORChain's validator set collectively controls vaults through threshold signatures and can pause activity through documented mechanisms. Security executive Michael Perklin rejected that comparison, likening THORChain nodes to Bitcoin miners. "In all 3, there is no active choice to sign, only an active choice to turn off the machine," he said, warning that halting infrastructure would also block legitimate transfers.
The dispute has precedent. During the 2025 Bybit hack, attacker funds routed through THORChain generated $2.91 billion in volume and about $3 million in fees, and a core developer left after a proposal to block the attacker's transactions failed to win node operator support.
What happens next?
Bitget is rebuilding operations in stages. Bitcoin withdrawals resumed September 28, Ethereum on September 29 and USDT on September 30, with remaining tokens plus fiat and P2P services scheduled for October 2. The exchange brought in Mandiant and SlowMist to trace funds and probe the breach, and launched a bounty paying 5% for frozen assets and another 5% for recovered funds. By September 26, Circle and Tether had frozen about $318,000 in USDC and USDT connected to the case.
ZachXBT says he will release more data on the laundering network in the coming weeks, keeping pressure on the same cross-chain escape routes investigators say North Korean-linked groups have relied on since the Bybit hack.
via cointelegraph.com (Original)