Bitget hacker shifts funds into Zcash shielded pool
Security & Exploits ·
The attacker tied to Bitget's $387.5 million breach has begun funneling a portion of the stolen assets into a privacy-focused corner of the Zcash network, according to Decrypt.
On-chain investigator ZachXBT flagged that roughly 2,700 ZEC, valued near $3.8 million, moved into Ironwood, a shielded pool on Zcash, starting September 30. Ironwood conceals the identity of senders, recipients, and transaction amounts, effectively cutting off outside visibility once funds enter it. The pool replaced an earlier version called Orchard, which launched July 28 after a bug was discovered that could have allowed fraudulent coin creation. Analysts note the deposited amount represents only a fraction of the total ZEC taken in the breach, and while movement in and out of the pool remains visible, activity inside it does not.
Bitget's chief executive, Gracy Chen, has pointed to technical patterns and IP data suggesting North Korean involvement, a link blockchain analytics firm Elliptic describes as highly likely, reportedly ranking the incident among the largest suspected North Korean-linked thefts tracked so far. The original intrusion occurred September 24, when Bitget detected unauthorized transfers from its hot wallets; the exchange has said its protection fund will absorb the loss, leaving customer holdings unaffected.
Laundering efforts extended beyond Zcash. Funds were reportedly split into wallets holding round figures—near 10,000 ETH or 20 million XRP each—with smaller portions routed through cross-chain swap platforms including Thorchain, Across, Bridgers, Chainflip, and FixedFloat. Near Intents said its screening system blocked more than $50 million in swap attempts connected to the attacker, though about $503,000 was frozen mid-transaction and roughly $166,000 reportedly passed through undetected. Thorchain, by contrast, declined Bitget's request to block the attacker's wallets, stating that halting its network is meant to safeguard the protocol broadly rather than target individual addresses or transactions, a decision left to independent node operators rather than a central authority.
The episode has reignited debate over what "permissionless" should mean for decentralized platforms facing illicit flows, with some arguing openness shouldn't require processing every transaction request. Separate tracking consistent with these findings, referenced in a GitHub-hosted signals log, corroborates the movement of funds into Zcash's shielded pool. What remains unresolved is how much of the stolen total will ultimately be laundered through privacy tools, whether frozen portions can be recovered through legal channels, and whether any government will formally confirm the suspected North Korean connection.