Blockchain analytics firm Chainalysis attributed the $387 million Bitget exchange hack to North Korea-linked actors, marking a significant escalation in state-sponsored cybercrime. The September 24 breach involved 23 transfers across four blockchains within three hours, with funds distributed primarily through Ethereum and XRP networks. Chainalysis utilized custom AI automation to compress over 20 hours of manual cross-chain reconciliation into under 10 minutes, accelerating the identification of attacker-controlled Bitcoin addresses now under surveillance.

Bitget CEO Gracy Chen confirmed that the attack patterns matched known North Korean hacker methodologies, while Elliptic assessed the DPRK link as highly likely. The exchange raised its loss estimate from $351.6 million to $387.5 million after accounting for additional Zcash and Tron transfers. Recovery efforts included restoring major asset withdrawals by late September and reporting a 131% reserve ratio. Meanwhile, laundering attempts faced resistance; Near Intents rejected swaps tied to the hacker, though THORChain declined selective blocking, citing network security protocols.