A new report has confirmed suspicions held by on-chain analysts. Blockchain analytics firm Chainalysis published findings on Wednesday linking the $387 million hack of exchange Bitget on September 24 to North Korean hacker groups. The confirmation adds to their track record while pushing the total value of assets stolen by state-linked entities in 2026 past $1 billion.
Chainalysis’s findings align with initial suspicions across the industry. Shortly after the incident occurred, Bitget CEO Gracy Chen stated that the attack pattern matched hallmarks of North Korean hacker operations. Another security firm, Elliptic, had also provided an early assessment that the involvement of state-backed hackers was highly likely, before tracing evidence confirmed the attribution.
Cross-Chain Escape Routes
The forensic investigation highlights how the perpetrators split the stolen assets. Within the first three hours of the attack, the hackers moved the $387 million out of Bitget wallets through 23 consecutive transfers. The stolen funds were dispersed across four different networks: Ethereum received the majority share of 49.7%, the XRP network 40.8%, privacy coin Zcash 7.6%, and the Tron network took 1.8%.
The hackers deployed specific laundering tactics for the looted XRP. Rather than sending the coins to centralized exchanges, they rotated them through cross-chain liquidity protocols. The XRP funds were then withdrawn as Bitcoin, with billions of dollars moving through this channel over roughly 1.5 days. All fund flows led to Bitcoin addresses that are now under surveillance.
This report complements previous findings uncovering the perpetrators’ maneuvers to conceal tracks using Zcash. The complexity of escape routes spanning multiple networks typically demands hours of manual data reconciliation. Chainalysis broke through that bottleneck using its internal artificial intelligence, compressing an analysis process of 20 hours down to under 10 minutes.
Some Funds Blocked at Exit Points
The movement of these funds triggered mixed responses from infrastructure providers. The Near Intents protocol responded to the activity by rejecting swap transactions worth over $50 million originating from the perpetrators’ wallets. In contrast, the Thorchain protocol continued processing exchange transactions entering its network.
Among dollar-pegged coins, issuers Circle and Tether froze roughly $318,000 in stablecoins. While intercepting hundreds of thousands of dollars, this figure is merely a tiny fraction compared to the $387 million principal loss. Artificial intelligence technology has accelerated tracking the path of fleeing funds, but executing absolute interception on decentralized infrastructure remains a real obstacle.
Via Decrypt.
Previously: Chainalysis AI Traces $387M Stolen Bitget Funds in 10 Minutes - Here Is the Escape Route
Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.




