Bitget Hack Tied to North Korea as Stolen XRP Flows Into Bitcoin

4 hours ago 9

TLDR:

  • The Bitget hack is linked to North Korean hackers. Chainalysis says the theft lifts their 2026 crypto total above $1 billion.
  • Investigators traced stolen XRP through a cross-chain protocol into Bitcoin. The swaps bypassed an exchange but still left blockchain records.
  • Drift and KelpDAO lost a combined $577 million in April. TRM said those attacks represented 76% of crypto hack losses through that month.
  • Chainalysis estimates automation cut over 20 hours of bridge reconciliation to under 10 minutes. Investigators defined logic and reviewed results.

The Bitget hack involved North Korean hackers, Chainalysis said, attributing the $387 million theft to DPRK-linked actors. The firm said the September 24 breach pushed crypto stolen by North Korea-linked groups above $1 billion in 2026. Investigators followed stolen XRP through a cross-chain protocol into Bitcoin addresses controlled by the attackers.

The October 1 report details how the funds moved between blockchains without passing through an exchange. Bitget separately confirmed losses of approximately $387.5 million after revising its initial estimate. The updated attribution follows earlier suspicions raised by CEO Gracy Chen and provides further evidence for the ongoing security investigation.

Bitget Hack Expands North Korean Theft Total Beyond $1 Billion

Bitget joins Drift Protocol and KelpDAO, among major platforms hit by attacks linked to North Korea this year. The Bitget hack follows two April incidents that together cost approximately $577 million.

On April 1, attackers drained $285 million from Drift Protocol. TRM described months of social engineering, including meetings with staff, before attackers compromised the approval process. Attackers obtained approvals before executing the unauthorized withdrawals.

KelpDAO suffered a separate $292 million bridge exploit on April 18. LayerZero linked that operation to TraderTraitor, a North Korean threat group associated with Lazarus. 

TRM said those two attacks represented 76% of crypto hack losses through April. That figure covers an earlier reporting period, rather than the latest annual total following the Bitget hack. 

Chainalysis estimated that North Korean hackers stole more than $2 billion during 2025. The latest attribution places another major exchange breach within that continuing pattern. 

Chen had pointed to North Korea shortly after the theft. She cited suspicious IP addresses connected to VPN services previously used by a DPRK-linked hacking group. 

September losses also rose sharply across the industry. PeckShield recorded $766.49 million across 55 major hacks, approximately 462% above August, with Bitget the largest incident.

Bitget said its higher loss estimate included previously uncounted Zcash and Tron transfers. The exchange said the revision reflected fuller accounting rather than another wave of unauthorized withdrawals.

Bitget said investigators had identified and fixed the underlying vulnerability. The exchange published attacker addresses to help other platforms monitor affected assets. 

How Stolen XRP Became Bitcoin Through a Cross-chain Protocol

Chainalysis identified 23 outbound transfers during the first three hours after the Bitget hack. It grouped their destinations into Ethereum, XRP Ledger, Zcash, and Tron.

Ethereum accounted for 49.7% of the outflows, followed by XRP Ledger at 40.8%. Zcash received 7.6%, while Tron represented 1.8% of the traced transfers.

The attackers moved XRP into a cross-chain liquidity protocol and received Bitcoin on another network. This route bypassed a centralized exchange account while leaving transaction records for investigators to examine.

Chainalysis matched deposits with corresponding payouts and followed tens of millions of dollars over roughly 36 hours. Its investigators tracked subsequent transfers until the trail reached attacker-controlled Bitcoin addresses.

Independent analysis from Bitquery identified THORChain as a route used to convert stolen XRP. Its September 29 accounting found that 90.5% of the stolen XRP had become Bitcoin.

That analysis adds detail to the Bitget hack money trail. Swap records named destination assets and recipient addresses, helping connect payments across otherwise separate networks. 

The Bitget hack investigation includes cybersecurity firms Mandiant and SlowMist. Bitget said industry coordination had already frozen some affected assets. Its recovery program offers eligible contributors bounties worth 5% of successfully frozen funds and 5% of recovered funds.

Chainalysis said its team used in-house AI to build custom tracing tools. It estimated that over 20 hours of manual bridge reconciliation took under 10 minutes with automation.

Investigators continued to define the tracing logic and review the results. Chainalysis is monitoring linked Bitcoin addresses and sharing intelligence with exchanges, issuers, and law enforcement partners.

The post Bitget Hack Tied to North Korea as Stolen XRP Flows Into Bitcoin appeared first on Blockonomi.

Read Entire Article