Chainalysis reported that its in-house artificial intelligence significantly accelerated the investigation into the $387 million theft from Bitget, cutting more than 20 hours of manual cross-chain bridge reconciliation down to under 10 minutes. The firm attributes the September 24 breach to North Korean actors, noting that this incident brings their total 2026 thefts above $1 billion. Investigators utilized custom automation tools to track stolen XRP through cross-chain swaps to Bitcoin addresses controlled by the attackers, with human investigators directing the logic and reviewing outputs.
The attack involved 23 transfers moving approximately $387 million out of Bitget within the first three hours, distributed across Ethereum (49.7%), XRP (40.8%), Zcash (7.6%), and Tron (1.8%). Bitget CEO Gracy Chen stated that cold wallets remained secure, but a vulnerability in a third-party security product allowed attackers to forge withdrawal commands. While Chainalysis labeled new addresses within minutes for compliance teams, THORChain rejected Bitget’s request to block attacker addresses, citing network neutrality principles. Bitget has offered separate 5% rewards for assistance in freezing or recovering funds and restored major asset withdrawals by late September.
This development highlights the evolving role of artificial intelligence in cryptocurrency forensics, demonstrating how automated tools can drastically reduce the latency between an exploit and actionable intelligence. By compressing complex cross-chain matching tasks from hours to minutes, Chainalysis enables faster identification of illicit flows, which is critical given the rapid movement of stolen assets through liquidity protocols. However, the case underscores that AI serves as an accelerator rather than a replacement for human expertise; investigators still define the matching rules and strategic direction, ensuring that technological speed does not compromise analytical accuracy or attribution reliability.
The incident also exposes structural tensions between centralized exchange recovery efforts and decentralized protocol governance. Bitget’s attempt to leverage THORChain’s emergency controls to freeze specific addresses was rejected on grounds of network neutrality, illustrating the limitations exchanges face when tracing funds through decentralized infrastructure. This friction suggests that future regulatory frameworks may need to address how decentralized protocols interact with law enforcement and victim recovery mechanisms, particularly as institutional adoption grows and the scale of losses increases.


