Chainalysis Used AI to Trace $387 Million Bitget Hack to North Korea
Key Takeaways
- •Blockchain firm Chainalysis published a report Wednesday attributing the $387 million Bitget breach of Sept. 24 to North Korea-linked actors, a conclusion matching earlier statements from Bitget CEO Gracy Chen and analytics firm Elliptic.
- •According to Chainalysis, the heist pushed the total value of cryptocurrency stolen by North Korea-linked groups in 2026 past $1 billion.
- •The stolen funds left Bitget within three hours across 23 transfers, splitting among Ethereum (49.7%), XRP (40.8%), Zcash (7.6%), and Tron (1.8%).
- •The attackers converted much of the stolen XRP into Bitcoin through a cross-chain liquidity protocol and concealed funds in Zcash's shielded pool, while Circle and Tether froze only about $318,000 in linked stablecoins.
- •Chainalysis used in-house AI automation to compress an estimated 20-plus hours of manual bridge reconciliation into under 10 minutes, with human analysts still directing the investigation.

Blockchain analytics firm Chainalysis has attributed last month's $387 million hack of crypto exchange Bitget to North Korea-linked actors, adding its weight to a growing consensus that Pyongyang's hackers carried out one of the year's largest cryptocurrency thefts.
In a report published Wednesday, Chainalysis tied the Sept. 24 breach to actors connected to the Democratic People's Republic of Korea, saying the heist pushed the total value of crypto stolen by North Korea-linked groups in 2026 past $1 billion. The firm said it has been working alongside Bitget and law enforcement to trace the funds across multiple blockchains since the attack. The milestone underscores the scale at which North Korea-linked groups now operate, and why tracing efforts like this one span analytics firms, exchanges, and law enforcement.
Chainalysis laid out how quickly the money moved. In the first three hours, $387 million left Bitget across 23 transfers and landed on four networks: Ethereum took nearly half at 49.7%, followed by XRP at 40.8%, Zcash at 7.6%, and Tron at 1.8%. The speed of the dispersal illustrates the challenge facing investigators working to follow the funds.
From there, the attackers ran the money through cross-chain liquidity and messaging protocols, instant swaps, and laundering services in an effort to obscure the trail and frustrate tracking efforts. Every hop between chains and assets means more bridges and swaps to reconcile, multiplying the work back at the analytics desk.
The stolen XRP drew particular attention. Rather than routing the tokens to an exchange, the attackers pushed them through a cross-chain liquidity protocol and pulled Bitcoin out the other side. Tens of millions of dollars moved that way over roughly a day and a half before reaching attacker-controlled Bitcoin addresses that investigators are now monitoring.
Notably, Chainalysis said it leaned on in-house artificial intelligence to keep pace, building custom automation that compressed what it estimated as more than 20 hours of manual bridge reconciliation into under 10 minutes. The firm stressed that the technology served to accelerate its investigators rather than replace them, with human analysts still directing the work. The speed gap explains the appeal: the attackers finished dispersing the funds within three hours, while the manual equivalent of even a single slice of the tracing work would have consumed most of a day.
The attribution echoes earlier assessments made in the days after the breach. Bitget CEO Gracy Chen said the attack's patterns matched those of North Korean hackers, and blockchain analytics firm Elliptic called a DPRK link "highly likely."
The laundering operation has played out in public, with eagle-eyed on-chain sleuths tracking the attacker's every move. Early in the process, the attacker began hiding funds in Zcash's shielded pool, a privacy feature that conceals transaction details. Swap services split in their response: Near Intents rejected more than $50 million in swap requests tied to the hacker, only to suffer its own hack days later, while Thorchain kept processing transactions. The split highlighted how much of a laundering trail's visibility depends on the choices of individual services.
Circle and Tether, meanwhile, froze roughly $318,000 in stablecoins tied to the stolen funds, according to the report — a small fraction of the $387 million taken. With investigators monitoring the attacker-controlled Bitcoin addresses and part of the haul sitting in Zcash's shielded pool, how much of the fund ultimately surfaces at the watched addresses remains the open question in the case.