Chinese laundering network moves $387M in Bitget exploit funds
Security & Exploits ·
Researchers say Chinese-linked actors are actively soliciting cash-out routes on Discord and Telegram for hundreds of millions in stolen crypto tied to alleged North Korean hackers.
Roughly $387M tied to a Bitget exploit is being funneled through cross-chain bridges and the Wasabi mixer, with the laundering handled by Chinese actors who researchers link to alleged DPRK attackers, according to reporting from wublockchain.xyz. Investigators tracking the funds say the same network has also been connected to an earlier exploit of Kelp DAO, suggesting a recurring set of intermediaries rather than a one-off cash-out operation. The pattern described—open solicitation on mainstream chat platforms paired with mixer use—illustrates how laundering for state-linked crypto theft has moved partly into public-facing channels even as the underlying flows still rely on established obfuscation tools like bridges and mixers.
The alleged DPRK connection situates the Bitget case within a broader pattern of North Korea-linked crypto theft that has drawn sustained attention from researchers, exchanges, and governments. Wider coverage of the DPRK crypto threat has documented North Korean developers embedded for months inside DeFi teams before major heists, covert IT worker networks earning steady monthly income while posing as legitimate contributors, and malware campaigns that fingerprint wallets before deploying through compromised Telegram accounts and fake video calls. Separately, industry and law enforcement responses have included recovery plans from exploited protocols and new training arrangements between blockchain analytics firms and national police agencies aimed at building capacity against these networks.
What remains unclear in the Bitget case is the identity and scale of the specific Chinese laundering actors involved, how much of the $387M has already moved beyond tracked mixers and bridges, and whether any funds will be frozen or recovered. It is also not established what direct operational link, if any, exists between this laundering network and the broader DPRK IT-worker infrastructure documented elsewhere, beyond the alleged connection researchers have drawn. Continued tracing of the funds, and whether exchanges or bridge operators intervene to halt further movement, will determine how much of the exploit proceeds ultimately reach North Korea-linked wallets.