Key points
- Chainalysis says $387 million left Bitget in 23 transfers during the first three hours of the September 24 incident.
- The firm mapped the initial funds to Ethereum, XRP, Zcash and Tron, then followed cross-chain swaps and laundering services.
- Chainalysis attributes the attack to North Korea-linked actors, but the reviewed sources do not establish an official public adjudication.
A new map of the Bitget theft
Chainalysis has published a detailed account of how its investigators followed the $387 million taken from Bitget on September 24 across multiple blockchains. The October 1 report says the firm worked with the exchange and law-enforcement partners while the stolen assets moved through hundreds of transactions. Decrypt highlighted the findings on October 3, making the tracing methodology and the firm’s North Korea attribution a fresh development in the continuing investigation rather than a new breach or additional loss.
Four chains received the initial transfers
According to Chainalysis, the funds left Bitget in 23 transfers during the first three hours. Ethereum received 49.7% of the value, XRP accounted for 40.8%, Zcash received 7.6% and Tron took 1.8%. Those percentages describe the first destinations identified by the firm, not the assets’ final locations. The attackers later used cross-chain liquidity and messaging protocols, instant swaps and services associated with laundering to split and obscure the trail.
Related reporting: Bitget sets phased withdrawal restart after security breach
XRP was converted into Bitcoin across chains
The XRP portion created a particularly difficult tracing problem. Chainalysis says the attackers did not simply send the XRP to a centralized exchange. Instead, they used a cross-chain liquidity protocol, depositing one asset and receiving Bitcoin on another network. Investigators matched deposits with corresponding payouts and followed tens of millions of dollars through additional onchain services over roughly a day and a half. The resulting Bitcoin addresses are now being monitored, according to the company.
AI accelerated reconciliation, not judgment
Chainalysis says its investigators used in-house AI to build custom automations for bridge reconciliation and transaction matching. In one example, the company estimated that a task requiring more than 20 hours of manual reconciliation was compressed to under 10 minutes. It stressed that investigators still defined the logic, reviewed the outputs and directed the work. The distinction matters because faster graph construction does not remove the need to validate address labels, interpret cross-chain activity or decide whether a connection is meaningful.
The North Korea link remains an attribution
The firm attributes the theft to actors linked to the Democratic People’s Republic of Korea and says the incident pushed the value stolen by North Korea-attributed groups in 2026 above $1 billion. Decrypt reported that the assessment aligns with earlier comments from Bitget chief executive Gracy Chen and a separate Elliptic assessment describing a DPRK connection as highly likely. Those are private-sector analyses. The reviewed materials do not identify a public court finding or final government determination assigning responsibility for the theft.
Tracing can support freezes without guaranteeing recovery
Chainalysis says labels for identified stolen funds were added to its platform within minutes, giving exchanges, compliance teams and law enforcement a way to screen later movements. Such intelligence can help services block transactions, preserve evidence or respond to legal requests. It does not mean all traced assets are recoverable. Funds can move into privacy tools, decentralized protocols or jurisdictions where intervention is difficult, and transaction visibility alone does not confer control over the assets.
Root cause and recovery remain separate questions
The report focuses on movements after the assets left Bitget. It does not provide a complete public forensic explanation of how the attackers gained access to the exchange’s wallets. Bitget previously said user balances would be covered and began a phased withdrawal restart, but those operational assurances are separate from attribution and asset recovery. The next verifiable milestones will be newly frozen funds, law-enforcement action, recovered assets or a fuller incident postmortem from the exchange.
Sources
- Chainalysis: How AI helped trace the $387 million Bitget theft
- Decrypt: Chainalysis traces the Bitget hack to North Korea-linked actors
AI-generated editorial image; not a photograph of the reported event. Prepared with AI assistance and source verification.
