0x395e6e4a395e…395e6e4d

ConfirmedSecurity555 vB94 sat/vB3 min decode

Chainalysis Attributes $387 Million Bitget Hack to North Korea

Chainalysis attributes the $387 million Bitget breach to North Korean actors, with over 90% of stolen XRP already swapped into bitcoin via THORChain.

Outputs

  1. Chainalysis attributed the Sept. 24 theft of roughly $387 million from Bitget to DPRK-attributed threat actors in an Oct. 1 report.

  2. 93.22 million XRP — 90.5% of the ~102.98 million XRP stolen — was swapped for bitcoin through THORChain as of Sept. 29, per Bitquery.

  3. The theft pushed Chainalysis's tally of North Korea-linked crypto thefts in 2026 past $1 billion.

Chainalysis has attributed the Sept. 24 theft of roughly $387 million from crypto exchange Bitget to North Korean actors, pushing its tally of crypto stolen by Pyongyang-linked groups in 2026 past $1 billion.

In an Oct. 1 report, the blockchain-analytics firm labeled the attackers "DPRK-attributed threat actors" and said investigators traced tens of millions of dollars in stolen XRP into bitcoin through cross-chain swaps. The report describes Chainalysis's fund-tracing methods but does not disclose the specific evidence underpinning the North Korean attribution.

The findings follow Bitget's expanded accounting of the breach, which raised the exchange's loss estimate to about $387.5 million after adding previously omitted Zcash and Tron assets to the original tally.

23 withdrawals across nine networks

Chainalysis counted 23 transfers out of Bitget in the first three hours of the incident. A separate transaction-by-transaction reconstruction by blockchain data provider Bitquery also lists 23 withdrawals, spread across nine networks: Ethereum, Arbitrum, Optimism, Base, BNB Chain, Avalanche, the XRP Ledger, Zcash and Tron. Bitquery traced subsequent bridging activity from Arbitrum, Avalanche, Optimism and Base into Ethereum.

For the stolen XRP, Chainalysis said investigators matched deposits into a cross-chain liquidity protocol with corresponding bitcoin payouts. Tens of millions of dollars moved through that mechanism over roughly a day and a half, the firm said, before further transactions reached attacker-controlled bitcoin addresses that Chainalysis is now monitoring.

Bitquery identified THORChain as the conversion route. Its XRP accounting snapshot, as of Sept. 29, showed that 93.22 million XRP — 90.5% of the approximately 102.98 million XRP stolen — had already been swapped for bitcoin through the protocol.

One swap, two on-chain records

Individual transactions show how the route operates. On Sept. 27, an address on Bitget's public attacker list sent 87,230 XRP in a swap that THORChain's transaction index marks as successful. The corresponding bitcoin transaction paid out 1.54315516 BTC to the destination named in the XRP payment's memo field. The bitcoin transaction also embeds a reference back to the XRP transaction hash, preserving a verifiable link between the two chains.

That on-chain linkage matters for recovery efforts. Unlike funds parked on a single chain, assets laundered through a cross-chain protocol leave split records across networks, complicating freezes and exchange-level blacklisting. The scale is significant: with more than 90% of the stolen XRP already converted within days of the breach, the window for interception at the protocol level has effectively closed.

The route has already produced a governance dispute. THORChain invoked its permissionless design after Bitget demanded that the protocol refuse service to identified attacker addresses, as The Defiant previously reported. The standoff underscores a structural gap in post-hack response: decentralized liquidity protocols operate without a central operator capable of unilaterally blocking transactions, leaving exchanges and investigators to work at the edges of the flow rather than at its source.

Chainalysis said it is working with Bitget and law enforcement partners and will continue monitoring the funds, labeling newly identified addresses and sharing intelligence to disrupt further movement. The remaining question for investigators is where the converted bitcoin lands next — attacker-controlled addresses under surveillance are the primary chokepoint for any freeze or seizure action before the funds reach mixing services or opaque custody.

via chainalysis.com (Original)

More from Tom Whitfield

Tom Whitfield

Show full bio

News editor covering media and advertising at Mempool Brief.

419 articles