Chainalysis said it has traced last month’s $387 million hack of crypto exchange Bitget to actors tied to North Korea, adding another public attribution to one of the largest crypto thefts of the year.
In a report published Wednesday, the blockchain analytics firm said the Sept. 24 breach was carried out by parties linked to the Democratic People’s Republic of Korea. Chainalysis said the theft pushed the total amount of cryptocurrency stolen by North Korea-linked groups in 2026 above $1 billion.
The firm said it has been working with Bitget and law enforcement since the attack to trace the stolen assets across multiple blockchains.
Funds moved out in 23 transfers within three hours
Chainalysis detailed how quickly the funds left the exchange. In the first three hours, $387 million moved out of Bitget through 23 transfers and landed on four networks. Ethereum received 49.7% of the total, XRP took 40.8%, Zcash accounted for 7.6%, and Tron received 1.8%.
After that, the attackers moved the assets through cross-chain liquidity protocols, cross-chain messaging protocols, instant swap services, and laundering services in an effort to obscure the trail.
XRP route drew particular scrutiny
Chainalysis said the stolen XRP stood out. Instead of sending it to an exchange, the attackers routed it through a cross-chain liquidity protocol and withdrew Bitcoin on the other side. The report said tens of millions of dollars moved that way over roughly a day and a half before reaching attacker-controlled Bitcoin addresses that are now being monitored.
Chainalysis says in-house AI cut tracing time sharply
The company also said it relied on internal AI tools to keep up with the pace of the laundering activity. It built custom automation that reduced what it estimated would have been more than 20 hours of manual bridge reconciliation work to under 10 minutes.
Chainalysis said the technology accelerated investigators rather than replacing them, and that human analysts still directed the work.
Attribution matches earlier public assessments
The new attribution lines up with earlier statements from other parties. Bitget CEO Gracy Chen had said the attack’s patterns matched North Korean hackers. Blockchain analytics firm Elliptic had also described a DPRK link as 「highly likely」.
Laundering activity unfolded in public
The laundering process has continued to play out on public blockchains, with on-chain sleuths following the movements. The attacker first hid funds in Zcash’s shielded pool. Swap services responded differently: Near Intents rejected more than $50 million in swaps tied to the hacker, but was itself hacked days later for $3.8 million, while Thorchain continued processing the transactions.
Circle and Tether, meanwhile, froze about $318,000 in stablecoins.

