Bitget's $387.5M hack attacker moves $3.8M into Zcash's Ironwood privacy pool after NEAR Intents rejects swap attempts.
Security & Exploits ·
The person behind the $387.5 million theft from Bitget has begun depositing stolen funds into Zcash's Ironwood privacy pool after other platforms blocked the laundering attempts. Around 2,700 ZEC—valued at approximately $3.8 million—entered the shielded pool on September 30, according to on-chain tracking. This move came after Near Intents rejected more than $50 million in swap requests linked to the hack, freezing roughly $503,000 mid-transaction while approximately $166,000 escaped its screening system.
Shielded pools encrypt transaction details including sender, receiver, and amount, making fund movements untraceable once deposited, though transfers in and out remain visible. Ironwood replaced an earlier pool after researchers identified a vulnerability that could have enabled counterfeiting. The deposited amount represents roughly one-seventh of the ZEC stolen in the breach, which commenced September 24 when unauthorized transfers drained Bitget's internet-connected wallets. The attacker achieved this by accessing backend systems and falsifying transaction data rather than compromising private keys.
Bitget's CEO and blockchain analytics firm Elliptic have cited IP addresses and behavioral patterns suggesting North Korean involvement, though no government has confirmed attribution. The thefts across 2026 attributed to this suspected North Korean actor now exceed $1 billion. The broader laundering strategy split stolen assets across multiple wallets and routed portions through cross-chain swap platforms including Thorchain and Across, while Thorchain declined Bitget's public request to block the attacker's addresses, citing its decentralized structure and emergency-halt limitations.