Bitget Hacker Moves $3.8 Million Into Zcash Shielded Pool as Near Rejects $50 Million in Swaps
Key Takeaways
- •The attacker moved roughly 2,700 ZEC, valued at about $3.8 million and equal to around one-seventh of the stolen ZEC, into Zcash's Ironwood shielded pool starting Sept. 30, according to investigator ZachXBT.
- •Bitget says its protection fund covers the $387.5 million loss, leaving customer balances unaffected, after attackers infiltrated backend systems and falsified transaction data rather than stealing private keys beginning Sept. 24.
- •Near Intents' SHIELD screening system rejected more than $50 million in swaps tied to the hacker and froze about $503,000 mid-swap, while roughly $166,000 slipped through.
- •Thorchain refused Bitget's request to block the attacker's addresses, arguing halts are emergency protocol protections rather than selective freezes, and on-chain data show it converted roughly 2,390 ETH, about $6.3 million, into 75.2 BTC for the hacker.
- •Bitget CEO Gracy Chen linked the attack's IP addresses and pattern to North Korean hackers, and Elliptic calls the connection highly likely, ranking it the largest suspected North Korean theft of 2026 and pushing the year's total past $1 billion, though no government has confirmed the attribution.

The hacker behind the $387.5 million theft from crypto exchange Bitget has started hiding part of the loot inside a privacy pool on Zcash, the latest step in a laundering operation that has drawn sharply different responses from the cross-chain platforms in the money's path.
On-chain investigator ZachXBT said Wednesday that the attacker began moving about 2,700 ZEC, Zcash's native token—roughly $3.8 million—into Ironwood, a shielded pool on the privacy-focused Zcash blockchain, with the activity starting on Sept. 30.
A shielded pool is a part of the Zcash network that encrypts the sender, the receiver, and the amount, so nobody can follow the money once it goes in. Ironwood launched July 28 to replace an older pool, Orchard, after a researcher found a bug that could have let someone print counterfeit coins.
According to on-chain tracking, the deposit amounts to roughly one-seventh of the ZEC stolen in the hack. Investigators can still observe coins entering and leaving the pool, but the shielded design means they cannot see what happens in between. The remaining roughly six-sevenths of the stolen ZEC had not been observed entering the pool in the cited tracking, leaving those balances visible to investigators until the moment any portion crosses into shielding.
The development caps a week in which the attacker met starkly different treatment from the services involved: Near Intents says it rejected more than $50 million in swaps tied to the hack, while Thorchain declined Bitget's request to block the attacker's addresses.
Bitget puts the theft at $387.5 million. CEO Gracy Chen has said the attack's IP addresses and pattern match North Korean hackers, and blockchain analytics firm Elliptic calls a North Korean link "highly likely." Elliptic also ranks it the largest suspected North Korean theft of 2026, pushing the year's total past $1 billion. No government has confirmed the attribution.
How the money got here
The heist began Sept. 24, when Bitget's systems flagged unauthorized transfers out of its hot wallets—the internet-connected wallets that hold an exchange's day-to-day funds. Chen said the attackers got into backend systems and faked transaction data rather than stealing private keys. Bitget says its protection fund covers the damage, so customer balances are unaffected.
Then came the laundering. TRM Labs found the attacker split the funds into fresh wallets holding round amounts, roughly 10,000 ETH or 20 million XRP each. Smaller chunks went through cross-chain swap services—tools that trade one coin for another on a different blockchain, which muddies the trail—including Thorchain, Across, Bridgers, Chainflip, and FixedFloat.
Near Intents, meanwhile, said no. General manager Alex Shevchenko said Tuesday that its screening system, called SHIELD, rejected more than $50 million in swaps tied to the Bitget attacker. About $503,000 got frozen mid-swap, and roughly $166,000 slipped through, he said. Near says the frozen funds will go through legal and recovery proceedings.
The decision set off a familiar crypto fight over the word "permissionless," which means anyone can use a network without approval. Near cofounder Illia Polosukhin argued that it doesn't oblige every app to process every transaction. Between them, the two platforms put crypto's competing playbooks on display in a single week: screening at the application layer, as Near chose, or keeping the protocol neutral, as Thorchain maintains it must.
Thorchain went the other way. After Chen publicly asked it to refuse service to the attacker's addresses, Thorchain said in a post on X that a network halt is an emergency tool to protect the protocol, not a way to freeze specific funds or swaps. It is run by independent node operators who vote on halts, not by a company, according to its developers.
A THORChain network halt is an emergency security mechanism designed to protect the protocol.
A halt is not a selective freeze of specific funds or an individual swap.
During the May 2026 exploit that resulted in $10.7M stolen from the liquidity pools, the attackers addresses…
— THORChain (@THORChain) September 28, 2026
The obvious objection is that Thorchain has stopped transactions before. It halted its entire network for about five weeks after a $10.7 million exploit on May 15, according to its own report, and did not resume operations until June 22.
The hacker's swaps kept flowing in the meantime. On Monday, several batches totalling roughly 2,390 ETH—about $6.3 million—were converted into 75.2 BTC through Thorchain, on-chain data show.
From here, the observable markers are concrete: whether additional ZEC crosses into Ironwood, whether the bounty draws results, and whether Near's promised legal and recovery proceedings produce outcomes on the frozen $503,000. Bitget is offering a bounty of 5% of any funds frozen and another 5% of any funds recovered, excluding actions ordered by courts or law enforcement.