Bitget Exploiter Moves $3.8M in ZEC Into Zcash's Ironwood Shielded Pool
Key Takeaways
- •Wallets tied to the Bitget exploiter transferred roughly 2,700 ZEC, valued at $3.8 million, into Zcash's Ironwood shielded pool, accounting for about 14% of the 18,900 ZEC stolen in the breach.
- •On-chain investigator ZachXBT described the wallets as belonging to alleged North Korea-linked attackers, but Bitget has not issued a formal attribution while Mandiant and SlowMist conduct the ongoing forensic investigation.
- •The September 24 breach is now estimated at approximately $388 million, up from the initially identified $351.6 million, after additional Zcash and TRON transfers were classified as part of the incident.
- •Once ZEC enters Ironwood, addresses and amounts are encrypted, so public blockchain analysis cannot follow the coins beyond the three identified deposits unless a participant discloses viewing keys.
- •Bitget is offering a 5% bounty for help freezing or returning stolen assets, and its Protection Fund, which held more than $464 million, is designated to absorb user losses as withdrawals resume through October 2.

Addresses linked to the Bitget exploiter have started moving approximately 2,700 ZEC, valued at $3.8 million, into Zcash's Ironwood shielded pool, wrapping funds stolen in the exchange's September 24 breach in an additional layer of privacy.
The transfers account for roughly 14% of the 18,900 ZEC taken from Bitget's hot-wallet infrastructure. Investigators identified three Ironwood deposits as the funds began leaving the transparent address published in connection with the attack.
On-chain investigator ZachXBT described the wallets as belonging to alleged North Korea-linked attackers. Bitget has not formally attributed the breach to North Korea, and the forensic investigation remains ongoing with Mandiant and SlowMist involved. North Korea-linked hacking units have been implicated by researchers and authorities in a string of major cryptocurrency thefts in recent years, though formal attribution in active cases generally follows completed forensic work.
The ZEC forms part of a breach estimated at roughly $388 million, which affected hot and warm wallets across Zcash, Ethereum and several EVM networks, the XRP Ledger, and TRON. The final figure rose from the $351.6 million initially identified after additional Zcash and TRON transfers were classified as part of the incident.
Ironwood Obscures the Trail Beyond the Deposit
Zcash activated Ironwood on July 28 as part of its NU6.3 network upgrade. The pool replaced Orchard as the network's primary shielded pool after a soundness vulnerability was discovered earlier this year.
Shielded Zcash transactions encrypt the addresses and transaction amounts that would otherwise be publicly visible. Once ZEC enters the shielded pool, the public blockchain no longer carries enough information to reconstruct the subsequent payment path unless a participant provides additional disclosure — a step Zcash facilitates through viewing keys, which let transaction participants share read-only visibility into shielded activity with auditors or investigators.
The three identified deposits therefore confirm that the stolen ZEC entered Ironwood, but public chain analysis alone cannot follow the same coins through later shielded transfers the way it can track transparent Zcash addresses.
Approximately 16,200 ZEC from the original 18,900 ZEC remains outside the 2,700 ZEC identified in the latest shielding activity, although additional movements could change that balance.
Recovery Effort Spans Multiple Networks
The Zcash movement comes as Bitget continues efforts to freeze or recover funds across multiple chains and liquidity routes. The exchange has offered a 5% bounty for voluntary assistance that directly results in stolen assets being frozen or returned.
Attempts to stop other portions of the funds have already exposed the limits of cross-chain recovery. THORChain rejected requests to restrict addresses connected to the theft, triggering a broader decentralization dispute over whether validator-operated protocols should intervene when publicly identified stolen assets pass through their infrastructure.
Bitget's Protection Fund held more than $464 million when the breach occurred and has been designated to absorb the financial impact for users. BTC and ETH withdrawals have already resumed, USDT withdrawals reopened on September 30, and remaining token, fiat, and P2P withdrawals are scheduled to resume on October 2.
The latest Ironwood transactions leave approximately 16,200 ZEC of the original stolen Zcash balance outside the identified shielded deposits, while tracing and recovery work continues across the other assets taken in the breach. Whether Bitget moves to formal attribution once the Mandiant and SlowMist findings are in remains one of the case's open questions.