Bitget Hack Attributed to North Korea as Stolen XRP Converted Into Bitcoin
Key Takeaways
- •Chainalysis attributed the September 24 Bitget hack, with losses revised to approximately $387.5 million, to North Korea-linked actors, pushing DPRK-affiliated crypto theft above $1 billion in 2026.
- •Attackers converted stolen XRP into Bitcoin through the decentralized cross-chain protocol THORChain, bypassing centralized exchanges, with Bitquery reporting 90.5% of the stolen XRP converted as of September 29.
- •Bitget joined Drift Protocol and KelpDAO as major North Korea-linked targets this year, following two April attacks that cost approximately $577 million combined.
- •Bitget raised its loss estimate by incorporating previously uncounted Zcash and Tron transfers, fixed the vulnerability, and offers bounties worth 5% of frozen funds plus 5% of recovered funds.
- •Chainalysis used in-house AI tracing tools that cut more than 20 hours of manual bridge reconciliation to under 10 minutes while following funds to attacker-controlled Bitcoin addresses.

Chainalysis has attributed the roughly $387 million hack of cryptocurrency exchange Bitget to North Korea-linked actors, saying the September 24 breach pushed digital assets stolen by DPRK-affiliated groups above $1 billion in 2026. In an October 1 report, the blockchain analytics firm detailed how attackers moved stolen XRP across multiple blockchains and converted it into Bitcoin without routing the funds through a centralized exchange.
Bitget separately confirmed losses of approximately $387.5 million after revising its initial estimate. The updated attribution follows earlier suspicions raised by Bitget CEO Gracy Chen and adds further evidence to the exchange's ongoing security investigation.
North Korea-Linked Theft Tops $1 Billion in 2026
With the Bitget breach, the exchange joins Drift Protocol and KelpDAO among the major platforms hit by attacks tied to North Korea this year. The Bitget incident follows two April episodes that together cost approximately $577 million.
On April 1, attackers drained $285 million from Drift Protocol. Blockchain intelligence firm TRM described months of social engineering, including meetings with staff, before the attackers compromised the approval process and obtained the authorizations needed to execute unauthorized withdrawals.
KelpDAO suffered a separate $292 million bridge exploit on April 18. LayerZero linked that operation to TraderTraitor, a North Korean threat group associated with Lazarus. According to TRM, the two April attacks accounted for 76% of crypto hack losses through that month, though that figure covers an earlier reporting period rather than the annual total now including Bitget.
Chainalysis estimated that North Korean hackers stole more than $2 billion during 2025. The latest attribution places another major exchange breach within that continuing pattern of theft, which has included some of the largest crypto exploits of recent years. United Nations experts and U.S. Treasury actions have long tied North Korea's cryptocurrency theft campaigns to state revenue, including weapons funding, and the 2026 figure — already more than half of last year's full-year estimate — underscores the scale of an operation that has persisted across multiple years.
Chen had pointed to North Korea shortly after the Bitget theft, citing suspicious IP addresses connected to VPN services previously used by a DPRK-linked hacking group.
September was also costly for the wider industry. PeckShield recorded $766.49 million in losses across 55 major hacks, approximately 462% above August, with Bitget the largest single incident.
Bitget Revises Loss Estimate and Publishes Attacker Addresses
Bitget said its higher loss estimate incorporated previously uncounted Zcash and Tron transfers, describing the revision as fuller accounting rather than a new wave of unauthorized withdrawals. The exchange said investigators had identified and fixed the underlying vulnerability, and it published the attacker's addresses to help other platforms monitor affected assets.
The Bitget investigation includes cybersecurity firms Mandiant and SlowMist. According to the exchange, industry coordination has already frozen some affected assets. Its recovery program offers eligible contributors bounties worth 5% of successfully frozen funds and 5% of recovered funds — a structure that gives exchanges and security researchers a direct financial stake in flagging stolen assets as they move.
How Stolen XRP Became Bitcoin Through a Cross-Chain Protocol
Chainalysis identified 23 outbound transfers during the first three hours after the hack, grouping their destinations into Ethereum, the XRP Ledger, Zcash, and Tron. Ethereum accounted for 49.7% of the outflows, followed by the XRP Ledger at 40.8%. Zcash, a privacy-focused network, received 7.6%, while Tron represented 1.8% of the traced transfers.
The attackers then moved XRP into a cross-chain liquidity protocol and received Bitcoin on another network. The route bypassed a centralized exchange account while still leaving transaction records for investigators to examine. The distinction matters because centralized venues can be served with account records and freeze requests, whereas fully on-chain swaps leave only transaction data for investigators to correlate. Chainalysis matched deposits with corresponding payouts and followed tens of millions of dollars over roughly 36 hours, tracking subsequent transfers until the trail reached attacker-controlled Bitcoin addresses.
Independent analysis from Bitquery identified THORChain, a decentralized liquidity network that settles swaps of native assets across blockchains, as a route used to convert the stolen XRP. Its September 29 accounting found that 90.5% of the stolen XRP had been converted into Bitcoin. Swap records named destination assets and recipient addresses, helping connect payments across otherwise separate networks.
Chainalysis said its team used in-house AI to build custom tracing tools, estimating that automation cut more than 20 hours of manual bridge reconciliation to under 10 minutes. Investigators continued to define the tracing logic and review the results. The firm is monitoring linked Bitcoin addresses and sharing intelligence with exchanges, issuers, and law enforcement partners — and with roughly 9.5% of the stolen XRP still unconverted as of Bitquery's September 29 accounting, that address-level monitoring, the ongoing tracing review, and Bitget's bounty-driven freeze program are the concrete items to watch as the investigation develops.