Alleged Bitget fund launderers sought help in public chats after swaps stalled, ZachXBT says

Alleged Bitget fund launderers sought help in public chats after swaps stalled, ZachXBT says

N
News Editor
2026-10-02 04:29:06
Blockchain investigator ZachXBT said people allegedly laundering funds from the Sept. 24 Bitget exploit for suspected North Korean attackers openly asked for help in public Discord servers and Telegram channels after swap orders ran into problems. The post described several users, including aliases such as jack, Cc, Melon, and lolo, who said they used THORChain-related services to swap XRP into BTC but could not verify the expected BTC on-chain. In one exchange highlighted in the report, a staff member carrying a SwapKit tag replied with a photo of Kim Jong Un and comments mocking the user’s concern. The article also cited a TRM flow chart showing how funds moved from the XRP Ledger through intermediary wallets into THORChain, then through cross-chain bridges, and eventually to Wasabi. Bitget had asked THORChain to block hacker-linked addresses, while THORChain said a network pause on Sept. 28 was an emergency safety measure for the protocol rather than a selective freeze aimed at a specific set of funds or swaps.

Blockchain investigator ZachXBT said people allegedly laundering funds from the Sept. 24 Bitget hack for suspected Democratic People’s Republic of Korea, or DPRK, attackers were openly asking for order support in public Discord servers and Telegram channels used by the services they relied on.

In a post on X, ZachXBT said the activity was tied to the Bitget exploit, which he described at about $387 million. He wrote that Chinese illicit actors handling the stolen funds on behalf of the alleged DPRK attackers were seeking help publicly after swaps became stuck.

Users posted support requests in public channels

One user using the alias jack asked on Sept. 27, 「GM! Where do I submit a ticket?」 He then said he had used “Thorium” to swap XRP into BTC and still had not received the BTC after nearly a full day. The report noted that he wrote THORChain as “Thorium.” THORChain is a decentralized cross-chain swap protocol that does not require account registration.

The exchange then turned sarcastic. A staff member carrying a SwapKit label first replied with a photo of Kim Jong Un smiling and waving. jack said he was 「very worried」 and added that losing the assets would 「bring a lot of trouble to my life.」 The staff member followed with: 「Will Kim Jong Un be angry?」 and 「Bro, you picked the wrong job.」

Another user, under the alias Cc, sounded more urgent. He asked, 「Are my funds safe?」 and said the issue was a technical error. According to his message, he only received refunded XRP while the webpage showed no BTC information at all. A screenshot he shared said a 431.08696 XRP swap had been refunded because the network had already completed that swap and the repeated attempt was returned.

Cc also said he had sent 277,724 XRP and received back only 431 XRP, while the interface still showed the swap as completed. He then tagged support and wrote: 「Please help me check, I’m begging you.」

A user identified as Melon said on Sept. 28 that the BTC network had paused during withdrawal processing, which appeared to cause two BTC swaps to be canceled. Staff replied that 「both swaps have been completed,」 but Melon pressed again, saying he could not find either withdrawal on-chain.

Another user, lolo, said several hours had passed since the swap was initiated but the funds still had not arrived, even though the app showed success. A staff member asked whether he was the same person active on Telegram. He posted a hash and answered 「yes,」 acknowledging that both accounts belonged to him. ZachXBT said this alias had also laundered funds from the $292 million Kelp DAO theft in April this year.

The report says this does not show the service kept the funds

The article made a separate point here: the chat logs do not show that the service provider swallowed the illicit funds. In Cc’s screenshot, the system marked the swap as completed, and the 431 XRP was described as a refund for a duplicate submission. The reason these users were asking for help was that they could not verify the incoming BTC.

The original report did not say whether the BTC ultimately arrived.

Fund flow moved from XRPL to THORChain and then to Wasabi

ZachXBT also attached a fund-flow chart prepared by TRM.

The first stage was the XRP Ledger, or XRPL. The report said about 103 million XRP from a Bitget hot wallet was first moved into the hacker’s main wallet. On Sept. 24, the funds were split into multiple transfers and sent to at least eight intermediary wallets. Those wallets then moved funds among themselves before the assets were distributed across five aliases. The article said XRPL does not support freezing, leaving Ripple unable to stop the movement.

The second stage was THORChain. Funds tied to all five alias wallets then flowed there. The report said THORChain requires no registration and no KYC, allowing direct swaps from XRP and ETH into native BTC.

The inflow amounts marked on the chart were:

  • Melon: 200,000 XRP across two transfers
  • Cc: 178,470 XRP
  • HELP ME: 60,000 XRP plus 30,000 XRP
  • jack: 55,555 XRP
  • lolo: 45,737 XRP

Those six transfers totaled about 570,000 XRP, only a small fraction of the roughly 103 million XRP that had moved out, according to the report.

After the swaps into BTC, ZachXBT said the funds moved again through cross-chain bridges. The report described those bridges as tools that move assets from one chain to another. The final destination cited was Wasabi, a Bitcoin mixing wallet that combines BTC from multiple users and redistributes it, making source and destination harder to match.

THORChain responded to blocking request

The article said Bitget had asked THORChain to block addresses linked to the hacker. Bitget CEO Gracy Chen said, 「Decentralization is a design principle, not a shield for stolen funds.」

THORChain responded on Sept. 28 that the network pause was an emergency safety mechanism intended to protect the protocol, 「not a selective freeze targeting specific funds or a single swap,」 and described itself as a permissionless, non-censoring neutral public tool.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
300

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.