Summary
- A hacker associated with the Bitget breach has started concealing around 2,700 ZEC, valued at approximately $3.8 million, in Zcash's Ironwood pool as of September 30.
- Near Intents reported rejecting over $50 million in transactions linked to the hack, while Thorchain declined to block the hacker's addresses.
- Bitget claims the total theft amounts to $387.5 million, with its CEO and Elliptic suggesting North Korean involvement, although this has not been confirmed by any government.
The individual responsible for the theft of $387.5 million from the Bitget cryptocurrency exchange has begun to obscure part of the stolen funds within Zcash's private pool. On-chain investigator ZachXBT reported on Wednesday that the hacker commenced the transfer of approximately 2,700 ZEC—about $3.8 million—into the Ironwood pool, a shielded section of the Zcash blockchain designed for privacy.
This shielded pool encrypts the sender, receiver, and transaction amount, making it impossible to trace the funds once deposited. Ironwood, which replaced the older Orchard pool on July 28, was introduced after a bug was discovered that could potentially allow for the creation of counterfeit coins.
The amount deposited represents roughly one-seventh of the total ZEC stolen in the hack, according to blockchain tracking. While investigators can monitor deposits and withdrawals from the pool, the transactions that occur in between remain hidden.
Bitget's CEO Gracy Chen indicated that the IP addresses and attack patterns align with those of North Korean hackers, a view echoed by blockchain analytics company Elliptic, which deems a North Korean connection "highly likely." Elliptic also categorized this incident as the largest suspected theft by North Korea in 2026, pushing the year's total over $1 billion.
Details of the Heist
The breach initiated on September 24, when Bitget detected unauthorized transactions from its hot wallets—wallets that are connected to the internet and used for daily operations. Chen stated that the hackers accessed backend systems to forge transaction data, circumventing the need to steal private keys. Bitget has asserted that its protection fund will cover the losses, ensuring that customer balances remain intact.
Following the theft, the laundering process began. According to TRM Labs, the hacker divided the stolen funds into new wallets with round figures, such as 10,000 ETH or 20 million XRP. Smaller amounts were then moved through cross-chain swapping services—mechanisms that exchange tokens across different blockchains, complicating the tracking process—like Thorchain, Across, Bridgers, Chainflip, and FixedFloat.
Near Intents, however, took a firm stance against these activities. General manager Alex Shevchenko announced on Tuesday that their screening system, named SHIELD, rejected over $50 million in swaps associated with the Bitget hacker. Approximately $503,000 was frozen during swap attempts, while around $166,000 managed to escape, he noted.
As for the frozen assets, Near intends to pursue legal and recovery actions. This situation has reignited the ongoing debate in the crypto community regarding the term "permissionless," which signifies that anyone can utilize a network without prior approval. Near cofounder Illia Polosukhin argued that this does not obligate every application to process all transactions.
Conversely, Thorchain took a different approach. After Chen publicly requested that it block the hacker's addresses, Thorchain responded on X, stating that a network halt is a protective measure for the protocol and not a tool for freezing specific transactions or funds. The network operates under independent node operators who vote on such halts, rather than being governed by a single entity, according to its developers.
A THORChain network halt is an emergency security mechanism designed to protect the protocol.
A halt is not a selective freeze of specific funds or an individual swap.
During the May 2026 exploit that resulted in $10.7M stolen from the liquidity pools, the attackers addresses… https://t.co/HrigTUbA4Q
— THORChain (@THORChain) September 28, 2026
It is worth noting that Thorchain has previously halted transactions. The network was paused for approximately five weeks following a $10.7 million exploit on May 15, according to its own report, and resumed operations on June 22.
Throughout this period, the hacker continued to execute swaps. On Monday, a series of transactions totaling around 2,390 ETH—approximately $6.3 million—were converted into 75.2 BTC via Thorchain, as evident from on-chain data.
In response to the incident, Bitget is offering a bounty of 5% on any frozen funds and an additional 5% on any recovered assets, excluding actions mandated by the courts or law enforcement.
