The perpetrators behind the $387.5 million Bitget exploit have found a new hiding place, transferring 2,700 ZEC, worth approximately $3.8 million, to Ironwood, a private pool on the Zcash network.
Ironwood is Zcash’s newly shielded system launched on July 28 to replace the Orchard pool, which was retired due to bug vulnerabilities. The system operates by encrypting sender, recipient, and transaction amounts. Once inside, any trace of the funds disappears from public view. The $3.8 million sent to the pool accounts for about one-seventh of the total ZEC stolen since the attack began on September 24.
Rather than stealing private keys, the attackers targeted the exchange’s hot wallet directly by forging transaction data. TRM Labs reported that the hackers immediately split the stolen funds into several new wallets, each containing 10,000 ETH or 20 million XRP. From there, they laundered the assets across various cross-chain protocols, including Across, Bridgers, Chainflip, FixedFloat, and THORChain.
Traces of a North Korean Syndicate
Bitget and forensic analytics firms have reached a unified conclusion regarding the culprits. Bitget CEO Gracy Chen stated that the IP addresses and attack patterns align with the profile of North Korean hackers. Elliptic also deemed the isolated nation’s syndicate highly likely to be involved, noting Bitget as their largest heist in 2026. The breach pushed the total crypto stolen by North Korean hackers past $1 billion in a single year.
Two Divergent Responses to the Hackers
Despite strong early traces of money laundering, industry players responded in starkly opposing ways. NEAR Intents took an aggressive step by freezing $50 million in assets and turning down bounty offers. On the other hand, THORChain allowed the hacker’s funds to flow through and refused to block them, with protocol developers arguing their platform is a purely decentralized network that cannot halt user assets.
To restrict the hacker’s ability to cash out remaining assets, Bitget is maintaining an open bounty. The exchange is offering a 5% reward to anyone willing to freeze the hacker’s funds, plus an additional 5% commission if the stolen assets are returned intact to the exchange.
The Bitget theft and subsequent fund transfers to Ironwood illustrate the double-edged nature of crypto privacy. Anonymity features designed to protect ordinary users’ transactions have now become tools for organized syndicates to obscure the trail of hundreds of millions of dollars in customer funds.
Reported via Decrypt.
Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.




