On September 24, hackers drained $387 million from centralized cryptocurrency exchange Bitget through 23 separate transactions completed within three hours. The funds were distributed across four networks: Ethereum accounted for 49.7%, XRP for 40.8%, Zcash for 7.6%, and Tron for 1.8%. Chainalysis identified the perpetrators as North Korean-linked groups, noting that this single incident represents a major share of the more than $1 billion in crypto assets stolen by these entities so far in 2026.
The stolen assets were routed through cross-chain liquidity protocols and converted into Bitcoin before being moved to attacker-controlled addresses. Chainalysis utilized internal AI technology to accelerate the investigation, reducing manual reconciliation time from over 20 hours to under 10 minutes. While stablecoin issuers Circle and Tether froze approximately $318,000 linked to the theft, Near Intents blocked over $50 million in related swaps but subsequently suffered its own hack. Thorchain continued processing transactions without interruption during the breach.
This incident underscores the persistent vulnerability of centralized exchanges to state-sponsored cyber operations, particularly when attackers leverage sophisticated cross-chain laundering techniques. The rapid movement of funds across multiple networks within a narrow timeframe demonstrates a high level of pre-planning and operational capability. The attribution by Chainalysis, supported by Elliptic and Bitget CEO Gracy Chen, highlights the growing consensus on the role of North Korean hacking groups in financing their regime through digital asset theft. The scale of the loss, contributing significantly to the annual total exceeding $1 billion, signals an escalating threat landscape that challenges existing security infrastructures.
From a market structure perspective, the fragmented response among platforms reveals critical gaps in coordinated industry defense mechanisms. While some entities like Near Intents acted swiftly to block swaps, others such as Thorchain maintained standard operations, illustrating divergent risk management philosophies. The use of privacy tools like Zcash’s shielded pool complicates tracing efforts, yet public blockchain transparency allowed real-time monitoring of most movements. This duality suggests that while regulatory scrutiny may increase following such breaches, the technical arms race between attackers and defenders continues to evolve, with AI-driven analytics becoming essential for timely intervention.


