On September 30, the hacker responsible for draining $387.5 million from crypto exchange Bitget started moving approximately 2,700 ZEC, valued at roughly $3.8 million, into Ironwood, a shielded pool on the Zcash blockchain. This development follows the refusal by Near Intents to process more than $50 million in swaps linked to the attack. General manager Alex Shevchenko stated that Near’s SHIELD screening system rejected these transactions, freezing about $503,000 mid-swap while allowing roughly $166,000 to slip through. Meanwhile, Thorchain declined Bitget CEO Gracy Chen’s request to block the attacker’s addresses, asserting that network halts are emergency tools for protocol protection rather than mechanisms for selective fund freezes.

The initial breach occurred on September 24 when unauthorized transfers were flagged from Bitget’s hot wallets. Chen indicated that attackers accessed backend systems and falsified transaction data rather than stealing private keys, noting that customer balances remain unaffected due to Bitget’s protection fund. Blockchain analytics firm Elliptic has identified the theft as the largest suspected North Korean cybercrime of 2026, pushing the annual total past $1 billion, though no government has confirmed this attribution. TRM Labs observed that the attacker split funds into fresh wallets holding round amounts, such as 10,000 ETH or 20 million XRP, before routing smaller chunks through cross-chain swap services including Across, Bridgers, Chainflip, and FixedFloat. Despite Thorchain’s stance, on-chain data shows batches totaling roughly 2,390 ETH were converted into 75.2 BTC via the platform on Monday.