Blockchain investigator ZachXBT reported that attackers behind the recent Bitget exchange hack have transferred stolen funds into Zcash’s Ironwood shielded pool. Approximately 2,746 ZEC, valued at around $3.9 million, entered the privacy feature between 08:15 and 08:46 UTC on Wednesday. This amount represents about 15% of the total ZEC stolen during the September 24 breach, which drained $387.5 million from the platform.
The transfers originated from wallets identified by Bitget as belonging to the attacker, specifically passing through two intermediary addresses funded by a wallet holding nearly 18,917 ZEC. Once inside the Ironwood pool, sender, recipient, and amount details become hidden from public ledgers. While external observers can see deposits entering the pool, internal movements are obscured until funds exit to a public address. This action contrasts with earlier attempts where hackers swapped ether for bitcoin via THORChain, leaving visible records for investigators.
The migration of stolen assets into Zcash’s Ironwood shielded pool marks a significant escalation in the obfuscation tactics employed by the actors behind the Bitget breach. By leveraging privacy technology, the attackers effectively remove transaction visibility from public blockchain explorers, creating a substantial barrier for on-chain tracking and asset recovery efforts. Unlike previous swaps through THORChain, which left an audit trail, the shielded pool conceals the flow of funds entirely while they remain inside, complicating the ability of investigators to trace the destination or timing of subsequent withdrawals.
This development highlights the growing tension between regulatory compliance expectations and the technical capabilities of privacy-enhancing cryptocurrencies. For exchanges and law enforcement, the inability to monitor these transactions undermines standard forensic methods used to recover stolen digital assets. The situation underscores the operational risks associated with institutional adoption of crypto infrastructure, particularly when malicious actors utilize advanced privacy tools to evade detection. Future investigations will depend on whether any portion of the funds exits the shielded pool to a traceable address, allowing analysts to correlate timing and volume data to reconstruct the movement.


