NEWS
Chainalysis AI Traced the Bitget Hack in 10 Minutes
Chainalysis cut Bitget’s $387.5 million bridge trace to under 10 minutes, then freeze refusals left about $840,000 locked as 2026 DPRK theft passed $1 billion.
Chainalysis says its in-house AI cut more than 20 hours of Bitget hack bridge work to under 10 minutes after the September 24 theft of $387.5 million. The firm tied the breach to North Korea-linked actors and said that haul pushed 2026 DPRK-attributed crypto theft past $1 billion.
Labels on the stolen coins went live in minutes. Publicly visible freezes, as of September 29, still sat at about $840,000.
Twenty-Three Transfers in Three Hours
Bitget detected unauthorized transfers from hot and warm wallets at 18:31 UTC on September 24, 2026. Cold wallets were not hit. Chief executive Gracy Chen later said the attacker broke into a critical backend system in the wallet stack, spoofed the data shown to the approval process, and got Bitget’s own signing path to move the money. Private keys, she said, were not stolen.
The first two sends were tiny: 0.84 ETH on Ethereum and 93 TRX on Tron. Large outflows started at 18:58. At 19:05 the exchange’s own checks spotted a gap and blocked customer withdrawals, but forged commands kept hitting the wallet system. The last successful send was at 21:23, 2 hours and 52 minutes after the tests. Bitget shut the signing machines at 21:44.
THE DRAIN ON SEPTEMBER 24
- 18:31 UTC: First unauthorized sends, 0.84 ETH and 93 TRX, both under the risk threshold.
- 18:58 UTC: Large outflows begin from hot and warm wallets.
- 19:05 UTC: Reconciliation flags a discrepancy and blocks user-initiated withdrawals.
- 21:23 UTC: Last transfer out; the window from the tests is 2 hours and 52 minutes.
- 21:44 UTC: Bitget shuts signing machines and other wallet withdrawal services.
Bitget first put the loss at $351.6 million, then raised it to $387.5 million on September 25 after adding Zcash and TRON balances from the same window. The revision was a fuller count, the exchange said, not a second breach. Affected coins included XRP, ETH, USDT, ZEC, USDC, USDT0, XAUt, BNB, AVAX and TRX. Mandiant and SlowMist were brought in on the forensics.
Chainalysis reconstructed the first three hours as 23 transfers onto four chains: Ethereum 49.7%, XRP 40.8%, Zcash 7.6% and Tron 1.8%. XRP was the largest single slice, over $157 million. Stolen stablecoins, about $75.48 million in USDT, USDC and USDT0 plus 3,000 XAUt, were swapped into native tokens within 41 minutes, before Chen’s first public post at 21:30.
Chainalysis Compressed Bridge Work to Under 10 Minutes
Chainalysis published its account on October 1. Investigators already knew DPRK-linked crews move coins fast, so the Customer Outcomes team ran a round-the-clock war room with Bitget and law-enforcement partners and used in-house AI to create custom automations that matched deposits to payouts across bridges and swap protocols.
The firm estimated that more than 20 hours of manual bridge reconciliation was compressed to under 10 minutes. The model did not pick the case. Investigators set the logic, checked the output, and steered the trail. The automation sat on more than a decade of cross-chain attribution data, which is what made hops that look unrelated on two ledgers line up as one swap.
Within minutes of identification, labels flagging stolen funds were live in our data platform, giving compliance teams and law enforcement the data they needed to act.
Chainalysis Team, October 1 investigation note
That speed showed up most clearly on XRP. Instead of parking the tokens at a centralized exchange, the attackers pushed them through a cross-chain liquidity protocol and took Bitcoin on the other side. Tens of millions of dollars moved that way over roughly a day and a half, then through later hops, before landing on attacker-controlled Bitcoin addresses that Chainalysis said it is still watching.
A 10-minute match is a labeling window, not a recovery. Circle and Tether can freeze a balance they issue. A permissionless swap network can keep paying Bitcoin to whoever names an address. The second job is where this case stalled.
Why THORChain Would Not Freeze the Bitget Wallets
THORChain said it is permissionless like Bitcoin and would not refuse service to the published attacker addresses. Chen asked on September 26 at 11:44 UTC. The protocol answered at 18:17 UTC the same day. It had already paused its whole network after its own May 2026 loss of about $10.7 million, which it treated as a protocol emergency rather than a freeze of someone else’s coins. Stolen Bitget funds kept swapping toward Bitcoin.
Chen put the ask in public, with the attacker addresses already listed and tracked:
Our attacker addresses are publicly listed and actively tracked. We are formally asking @THORChain to refuse service to these addresses. Decentralization is a design principle, not a shield for facilitating known stolen funds.
The industry is watching. https://t.co/rOzV9kpu0F— Gracy Chen @Bitget (@GracyBitget) September 26, 2026
THORChain’s reply compared itself to base-layer chains and asked what duty those chains have when they carry known stolen coins:
We are devasted to hear about the recent exploit and can imagine how difficult this must be for everyone involved.
THORChain is decentralized and permissionless like Bitcoin, Ethereum, and BNB Chain.
What responsibility should Bitcoin, Ethereum, and BNB Chain bear when… https://t.co/ArvP6N1w3F
— THORChain (@THORChain) September 26, 2026
The distinction the protocol drew is real in its own terms. A full halt stops every swap to protect THORChain. A selective block of Bitget-linked wallets would have been a targeted freeze, which it said it will not do. After that answer, Blocksec’s read of Bitget’s tracing dashboard still showed THORChain as the main cross-chain path, about $269 million sent in 7,804 transactions as of September 29. Those are pass-through amounts, not a second theft total, and the same coins can touch more than one bridge.
A three-hour drain plus 41-minute stablecoin swaps already leaves issuers a gap measured in minutes. Cutting bridge matching to under 10 minutes only changes the recovery math if a party with freeze power is waiting on the label. THORChain was the largest pipe and it was not waiting.
$840,000 Frozen, 0.2% of the Haul
Blocksec, working from the public dashboard and issuer freeze records, said publicly visible freezes total about $840,000 as of September 29, about 0.2% of $387.5 million. Tether and Circle locked about $340,000 in stablecoins that sat idle on attacker addresses. NEAR Intents said it froze about $503,000 mid-swap after its SHIELD risk layer flagged the flow.
FREEZES VERSUS THE MAIN SWAP PIPE
| Party | Action | Amount |
|---|---|---|
| THORChain | Pass-through swaps, no address freeze | About $269 million |
| USDT0 / LayerZero | Pass-through | About $55.13 million |
| Circle CCTP | Pass-through | About $49.33 million |
| Chainflip | Pass-through | About $37.27 million |
| Tether and Circle | Frozen idle stablecoins | About $340,000 |
| NEAR Intents | Frozen mid-execution | About $503,000 |
NEAR Intents said the attacker tried to move more than $50 million through it, about $166,000 got through, and the frozen slice is its own figure, which it warned could be off by up to 10%. The Tether and Circle locks were leftovers: delayed bridge arrivals and a THORChain refund that landed after the attacker had already left the address. One later USDT pile of 425,959 tokens sat only 1 hour and 14 minutes, shorter than the fastest freeze Blocksec timed at about 5 hours and 24 minutes, and it was not frozen.
By September 29 the attacker still controlled about $342 million, 88.3% of the stolen total. Bitcoin was about 83.7% of that remainder, about 3,386 BTC, with Zcash about 8.5% and ETH about 7.3%, about 9,357 ETH. About $3.94 million had gone into Bitcoin CoinJoin, still small next to the BTC pile. About $3.78 million had been lost to swap and bridge slippage as of September 25.
North Korea’s 2026 Crypto Theft Crosses $1 Billion
Chainalysis calls the Bitget actors DPRK-attributed. Elliptic, writing on September 25 before the AI note, said multiple indicators make a North Korea link highly likely and that the case pushed its tracked 2026 total past the $1 billion mark. It had already counted more than 51 DPRK-linked incidents in 2026 and treated Bitget as the year’s largest single theft in that set.
THE ATTRIBUTION FILE
- Elliptic: Shared laundering rails with earlier DPRK-attributed jobs, including Bybit in 2025, plus a fast exit from stablecoins into each chain’s native asset.
- Chen: IP and VPN patterns she said match a known DPRK group, called a North Korean crew “very likely,” and stopped short of a full technical dump.
- Chainalysis: Same attribution in the October 1 note, with labels pushed to compliance teams while the coins were still moving.
- Blocksec: On-chain overlaps point more cleanly to shared launderers than to proof that the same operators ran every prior job.
Elliptic also flagged a tell from an earlier case: stolen coins on Arbitrum were bridged to Ethereum quickly, a move that fits a lesson from KelpDAO, where the Arbitrum Security Council froze 30,766 ETH. That is not a courtroom finding. It is why exchanges and analytics firms treated the Bitget wallets as a live DPRK-style laundering problem from the first night.
A 5% Bounty on Funds That Are Already Bitcoin
Bitget said its User Protection Fund covers customer losses and that the incident stayed contained after the signers went dark. Recovery, though, is a hunt for coins that are already being peeled into Bitcoin mixers. On September 25 the exchange opened a Recovery Bounty Program and published a live tracing dashboard, an address API, and a report form for anyone who can freeze or return funds.
THE OPEN RECOVERY LEVERS
- Freeze bounty: 5% of successfully frozen funds for the party whose voluntary work caused the freeze.
- Recovery bounty: 5% of funds actually recovered, on the same voluntary terms.
- LazarusBounty: Bitget said it will also use Bybit’s LazarusBounty channel as a core path for tips and claims.
- Court path: Actions taken under court orders or law-enforcement requests are excluded from bounty pay.
Chainalysis said it will keep the custom tooling on the destination addresses, push new labels, and share them with exchanges, issuers, and police. It also said it will show more of that investigative stack on November 19. Monitoring of the identified wallets is still the job. The 10-minute bridge match already happened. The coins that matter now are the ones sitting in Bitcoin, where a freeze looks like a mixer input, a court order, or a voluntary return against a 5% cheque.
Bitget listed primary attacker addresses on Ethereum, the XRP Ledger, Zcash and Tron the day after the theft. Those addresses are still the map. What changed on October 1 is how fast the next hop on that map can be labelled. What did not change is who has to say yes before a labelled coin actually stops.
Disclaimer: This article is news reporting and analysis of a cryptocurrency theft, on-chain tracing, and related freeze and bounty programs. It is for information only and is not investment advice, legal advice, or a recommendation to buy, sell, hold, or claim any digital asset or bounty. Readers who hold exchange balances, consider a recovery claim, or face a related legal question should consult a licensed financial adviser, a qualified attorney, or both before acting. Figures, freeze totals, attribution judgments, and program terms reflect the cited company notices and research notes as of the dates given in the story and can change as tracing continues.
-
AUTO3 years agoBMW’s Heated Seat Retreat Taught Automakers Which Fees Survive
-
ENTERTAINMENT1 month agoDolly Parton Laid to Rest as the Public Funeral Began
-
NEWS4 weeks agoJohn Ternus Debuts a $2,099 Foldable and Holds iPhone 18
-
NEWS4 weeks agoTesla Burns AI Cash While SpaceX Sends the Invoices
-
NEWS3 years agoCopilot’s Election Problem Shifted From Errors to Silence
-
TECHNOLOGY3 years agoTwitter Search Not Showing All Results: How to Fix it?
-
AUTO3 years agoAlberta Still Charges EV Owners $200 After Fuel Tax Pause
-
NEWS4 weeks agoThe Book on China’s Car Brain Still Stars Infineon
