0x320d97d9320d…320d97dc
North Korea-Linked Bitget Hackers Move $3.8M Into Zcash Shielded Pool
Hackers tied to North Korea have shielded $3.8 million in ZEC after stealing $387.5 million from Bitget on September 24, the largest crypto theft of 2026.
Outputs
Bitget lost $387.5 million in a September 24 breach, the largest crypto theft of 2026.
Attackers shielded roughly 2,700 ZEC worth $3.8 million in Zcash's Ironwood pool by September 30.
XRP accounted for about $157 million of the stolen assets.
Bitget CEO Gracy Chen attributed the attack to DPRK-linked actors.
The exchange's User Protection Fund held over $464 million at the time of the incident.
Attackers linked to North Korea have routed approximately $3.8 million worth of Zcash into the protocol's Ironwood shielded pool, according to on-chain records, obscuring a portion of the $387.5 million stolen from Bitget in the largest single crypto theft of 2026.
The Seychelles-based exchange detected the unauthorized activity at roughly 18:31 UTC on September 24. Bitget's initial damage assessment put losses at $351.6 million; a subsequent review raised the figure to $387.5 million once investigators mapped the full scope of compromised wallets.
What was stolen and how?
The stolen assets spanned multiple chains and token standards. XRP accounted for the single largest share at roughly $157 million. The remainder included ETH, USDT, USDC, ZEC, BNB, AVAX and TRX, distributed across Ethereum, the XRP Ledger, Zcash and TRON.
Investigators traced the breach to a zero-day exploit inside a third-party security product Bitget had used for several weeks. The vulnerability let attackers manipulate transaction data and deceive the exchange's internal approval process. Critically, the attackers never touched cold storage or private keys.
Bitget CEO Gracy Chen attributed the attack to actors associated with the DPRK, citing behavioral patterns and IP addresses consistent with previous North Korea-linked hacks. If the attribution holds, suspected North Korean crypto thefts would surpass $1 billion for 2026 alone.
How is the Zcash laundering working?
By September 30, roughly six days after the breach, on-chain observers recorded the attackers holding approximately 18,900 ZEC from the exploit, valued around $28 million. Of that, about 2,700 ZEC worth $3.8 million had already entered Zcash's Ironwood shielded pool.
Zcash supports two transaction types. Transparent transactions resemble Bitcoin's model, with sender, receiver and amounts visible to anyone through a block explorer. Shielded transactions encrypt all of that data. Once funds enter a shielded pool, linking them to their origin becomes practically impossible without the sender's private viewing key.
The routing choice signals adaptation by the attackers. Tornado Cash, the Ethereum-based mixer frequently used in prior laundering operations, has been sanctioned by the US Treasury's Office of Foreign Assets Control since 2022, and many exchanges now flag deposits with exposure to it. Zcash's shielding is native to the protocol rather than an overlay service, complicating blacklist enforcement at the point of deposit.
What is Bitget doing?
Bitget suspended withdrawals shortly after detecting the breach and began phasing them back in during late September. The exchange pointed to its User Protection Fund, which held over $464 million at the time of the incident, as sufficient to cover customer losses in full.
Roughly $24 million in ZEC remains in transparent addresses. That balance now defines the enforcement window: if attackers move the remainder into shielded pools before exchanges and law enforcement can freeze or blacklist those coins, recovery becomes extraordinarily difficult. The outcome of that race will test how effectively asset-recovery teams can operate against protocol-level privacy at scale.
via Crypto Briefing (Source)