Cross-chain hack investigations typically take days to map out the escape routes of stolen assets. Chainalysis cut down this lengthy process using in-house artificial intelligence (AI). The analytics firm reduced bridge reconciliation time from over 20 hours to less than 10 minutes while investigating the $387 million Bitget exploit.
The breach occurred on September 24, 2026. Bitget detected unauthorized transfers at 18:31 UTC originating from its hot and warm wallets. Within the first three hours of the attack, Chainalysis systems recorded 23 transfers moving roughly $387 million in crypto assets out of the exchange. Bitget management initially estimated losses at $351.6 million, later revising the figure up to $387.5 million after factoring in additional Zcash and Tron outflows detected later.
The majority of the stolen funds were in Ethereum, accounting for 49.7%, and XRP at 40.8%. The remainder consisted of 7.6% Zcash and 1.8% Tron.
Tracing the XRP Conversion Path
Investigators discovered that a portion of the XRP was converted into Bitcoin using cross-chain liquidity protocols. Tens of millions of dollars moved through this exchange route in just about a day and a half. AI helped investigators build custom automation tools to link transactions across different blockchains. The machine processed raw data, while human analysts retained control over logic and final decisions.
Newly identified recipient wallet addresses were labeled as ‘stolen funds’ within minutes. That data was fed directly into compliance systems for immediate action, eliminating the information lags that typically plague manual tracking.
Attribution and Asset Freezes
Chainalysis linked the heist to North Korean hacking groups. Bitget CEO Gracy Chen offered a more cautious assessment, noting that the IP address patterns and VPN infrastructure used by the perpetrators were consistent with North Korean cyber operations, without naming a specific entity. Bitget also named Mandiant and SlowMist as two external security firms assisting with their forensic investigation.
Circle and Tether took early action by freezing roughly $318,000 in USDC and USDT tied to the incident as of September 26. Bitget supplemented these efforts by offering a 5% bounty for information leading to fund freezes, along with a separate 5% reward for successful asset recovery.
Exchange Service Recovery
Exchange inflows and outflows gradually returned to normal toward the end of September. Bitget confirmed the reopening of withdrawals for major assets: Bitcoin on September 28, Ether on September 29, and USDT on September 30. The exchange’s operational reserve, the Protection Fund, was also reported back above the $300 million mark. A reserve snapshot on September 29 showed the total fund coverage ratio reached 131%. While AI’s speed in tracing the flow of funds has not yet recovered all the missing assets, the tooling ensures law enforcement can respond far faster than before.
Reported by crypto.news.
Also read: Microsoft’s X Account Hijacked for 30 Minutes for CLIPPY Token - Fake Promo Tactic Repeats
Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.




