Bitget revises stolen-asset tally as investigators trace how North Korea-linked crypto thefts are laundered

Bitget revises stolen-asset tally as investigators trace how North Korea-linked crypto thefts are laundered

N
News Editor
2026-09-27 00:50:13
Bitget said on Sept. 25, 2026 that the amount transferred to attacker-controlled addresses in its security incident was revised from about $351.6 million to about $387.5 million after additional transfers involving Zcash and TRON were counted. The company said the change did not reflect a new theft, and that some of the assets had already been frozen with help from industry partners. On the same day, blockchain analytics firm Elliptic said the attack was “highly likely” linked to North Korea, based in part on connections between the funds and laundering addresses tied to earlier North Korea-related thefts, though Bitget has not yet released a full technical investigation report. The case has renewed attention on a broader question: how stolen crypto is turned into usable value. Reviews of the Bybit case and other incidents point to a layered process involving token swaps, cross-chain transfers, mixers, OTC settlement channels, and specialist intermediaries that may take control of funds early and assume the risk of freezes or seizures. Analysts also note that tracing funds on-chain does not by itself allow recovery, especially for native assets such as BTC and ETH that have no central issuer able to freeze balances.

Bitget said on Sept. 25, 2026 that it had revised the amount transferred to attacker-controlled addresses in its security incident from about $351.6 million to about $387.5 million. The company said the change came from additional accounting of related transfers involving Zcash and TRON, not from any new theft, and added that some of the assets had been frozen with assistance from industry partners.

Elliptic said the same day that the attack was “highly likely” linked to North Korea, citing connections between the funds involved and laundering addresses seen in earlier North Korea-related crypto theft cases. That remains an attribution judgment from a research firm, and Bitget has not published a full technical investigation report.

The update has brought back a familiar question. If stolen assets can be tracked on public blockchains and exchanges can flag suspicious addresses, how do attackers turn hundreds of millions of dollars in crypto into funds they can actually use?

Specialist intermediaries may take over stolen funds early

Follow-up investigations into cases including Bybit suggest that handling stolen crypto has become a specialized business. Attackers use swaps, cross-chain transfers and layered transactions to make tracing harder. Separate intermediaries then step in to provide conversion, fund substitution and off-chain settlement. Looking at the chain alone is not enough; investigators also need to identify who is receiving and paying on the other side.

In February 2025, Bybit lost about $1.5 billion in crypto assets. The U.S. Federal Bureau of Investigation later attributed the incident to North Korea and said the attackers had converted part of the proceeds into bitcoin and other crypto assets, dispersing them across thousands of addresses on multiple blockchains.

Security firm zeroShadow said in a July 2025 report that more than $1 billion from that case had been laundered between February and June. The estimate does not mean the same amount had already been converted into fiat currency, nor does it represent the attackers’ final net proceeds.

zeroShadow said professional laundering operators may have taken control of the funds at an early stage, paid the North Korean attackers after deducting fees, and then handled the stolen assets themselves. In an August 2025 half-year review, Elliptic also said a professional “money laundering as a service” network was likely involved from an early point.

Under that model, attackers may receive settlement before the original stolen funds finish moving through later stages. Once intermediaries take over, they still need to find channels for conversion and cash-out, while carrying the risk that the funds could be frozen, seized or blocked from moving.

That also means the funds being tracked on-chain may not remain under the control of the original attackers the whole time. Investigators need to do more than map the flow of funds. They also need to determine when control changed hands and what value was delivered back to the attackers.

Chainalysis offered another example in September 2026 through its investigation into the Xinbi merchant network. The firm said tens of millions of dollars in stolen funds from cases including Bybit and WazirX moved through the network. In some cases, specialist intermediaries accepted stolen assets that were easy to trace and delivered a different batch of stablecoins to clients, with the replacement pool also including proceeds from other fraud activity.

That kind of arrangement mixes funds from different criminal activity inside the same settlement network. Attackers reduce the amount of direct handling they need to do, while intermediaries earn fees. In this context, “clean” assets mainly means assets whose link to the original theft is harder to identify directly, not assets with a lawful origin.

Swaps, cross-chain transfers and mixers buy time

Even with specialist intermediaries involved, on-chain movement remains a core part of the laundering process.

Elliptic’s early tracing of the Bybit case showed attackers quickly swapping some stolen tokens into ETH and then moving the funds through multiple wallets, exchange services and cross-chain routes. Splitting funds across addresses, changing asset types and moving across networks all make it harder for investigators to reconnect the path. Mixers and privacy tools reduce the visible link between inputs and outputs even more.

Those steps raise the cost of tracing, but they do not erase the original transaction record. Their practical value for attackers is time: time to keep moving funds before they are identified, before counterparties are alerted, and before institutions act.

Some exchange services became key nodes in that process. In an April 2025 report, Elliptic estimated that about $200 million in stolen Bybit funds passed through eXch, an exchange service that did not require customer identification. That figure reflects the scale of funds processed through the service, not an equal amount already converted into fiat.

So even after funds pass through a mixer or a cross-chain service, they may still be identified. Whether they can ultimately be monetized depends on whether there are counterparties willing to take them and whether those counterparties can provide real-world settlement channels.

The exit point is not always a dollar transfer

In its six-month review of the Bybit incident, Elliptic said some of the stolen funds that remained traceable eventually reached the Tron network, were converted into USDT, and were then cashed out through suspected Chinese OTC services. That points to the continued role of OTC brokers in linking crypto assets with the fiat system after the on-chain transfers are done.

For platforms that carry out customer due diligence and transaction monitoring, receiving funds tied to a major theft creates compliance risk. Illegal intermediaries, though, are in the business of taking those assets and finding the next settlement channel.

A case published by the U.S. Treasury in 2020 showed that this division of labor was already in place years ago. Treasury alleged that two intermediaries received more than $100 million in stolen exchange funds from accounts controlled by North Korea. One of them moved more than $34 million in equivalent value through bank accounts linked to exchange accounts.

These intermediaries provide accounts, counterparties and liquidity. A blockchain may show assets entering an address, but the agreed exchange rate, the payment method on the other side and the final beneficiary often can only be confirmed through platform records and off-chain investigation.

Crypto assets are not used only to obtain fiat. They can also be used directly in trade settlement. In a 2025 report, the Multilateral Sanctions Monitoring Team, or MSMT, documented cases in which North Korean personnel used or planned to use USDT for trade settlement involving military equipment and raw materials. In one case, a North Korean procurement official sold equipment to a customer in Laos, and the buyer paid part of the amount in USDT.

The example shows that stablecoins have already been used in some trade payments. It does not, by itself, establish a direct link between such transactions and any specific crypto theft case. Separate fund evidence would still be needed.

Why visible funds are still hard to recover

Blockchain analysis can trace part of the path and identify related addresses, but public transaction records do not give investigators control over the assets.

Elliptic said some token issuers have the ability to freeze assets, while native BTC and ETH do not have a central issuer that can carry out the same kind of action. So even if an address is widely flagged, outside parties cannot move the assets back simply because the address has been identified.

Recovery usually requires a point where someone can actually control the funds: assets entering a custodial platform that cooperates with investigators, an issuer freezing tokens that support that function, or law enforcement legally obtaining control of accounts, devices or other assets. Identifying addresses, coordinating institutions and completing cross-border procedures all take time, and funds may keep moving while that happens.

Even frozen assets are not the same as returned assets. In November 2025, the U.S. Department of Justice said the FBI had seized more than $15 million in USDT in March that year in connection with four 2023 crypto platform thefts allegedly carried out by North Korea’s APT38. The department then filed a civil forfeiture action seeking the eventual return of the assets to their lawful owners.

Across these cases, the ability to monetize North Korea-linked stolen crypto appears to rest on a combination of on-chain movement and professional settlement networks. Swaps, cross-chain transfers and mixers make tracing harder. Intermediaries convert stolen assets into value the attackers can use. Recovery efforts, in turn, have to cover fund flows, service-provider accounts and the intermediary networks behind them.

The stolen amount reflects the loss at the time of the incident. How much attackers ultimately realize depends on later settlement, price changes, intermediary fees, and how much is frozen or recovered while the funds are still moving.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.