Blockchain analytics firm Chainalysis attributed the $387 million Bitget exchange hack to North Korea-linked actors, marking a significant escalation in state-sponsored cybercrime. The September 24 breach involved 23 transfers across four blockchains within three hours, with funds distributed primarily through Ethereum and XRP networks. Chainalysis utilized custom AI automation to compress over 20 hours of manual cross-chain reconciliation into under 10 minutes, accelerating the identification of attacker-controlled Bitcoin addresses now under surveillance.
Bitget CEO Gracy Chen confirmed that the attack patterns matched known North Korean hacker methodologies, while Elliptic assessed the DPRK link as highly likely. The exchange raised its loss estimate from $351.6 million to $387.5 million after accounting for additional Zcash and Tron transfers. Recovery efforts included restoring major asset withdrawals by late September and reporting a 131% reserve ratio. Meanwhile, laundering attempts faced resistance; Near Intents rejected swaps tied to the hacker, though THORChain declined selective blocking, citing network security protocols.
The rapid attribution of the Bitget breach underscores the evolving role of artificial intelligence in forensic blockchain analysis. By drastically reducing the time required to reconcile cross-chain movements, Chainalysis demonstrated how automated tools can outpace the speed at which sophisticated attackers move stolen assets. This capability is critical for exchanges and law enforcement, as the window for freezing funds often closes within hours of an exploit. The case highlights that while human investigators still define logic and review outputs, AI-driven efficiency is becoming indispensable for effective incident response in multi-chain environments.
From a market structure perspective, the divergent responses of decentralized protocols like THORChain and Near Intents reveal ongoing tensions between censorship resistance and compliance pressures. While some services actively blocked transactions linked to the hack, others maintained neutrality, arguing that selective freezing undermines network integrity. This fragmentation complicates recovery efforts for victims and raises questions about the liability of infrastructure providers facilitating illicit flows. As North Korea’s 2026 theft total surpasses $1 billion, the industry must grapple with whether decentralized finance protocols should adopt more flexible emergency controls to support institutional adoption and regulatory alignment.


