On September 30, the hacker responsible for draining $387.5 million from crypto exchange Bitget started moving approximately 2,700 ZEC, valued at roughly $3.8 million, into Ironwood, a shielded pool on the Zcash blockchain. This development follows the refusal by Near Intents to process more than $50 million in swaps linked to the attack. General manager Alex Shevchenko stated that Near’s SHIELD screening system rejected these transactions, freezing about $503,000 mid-swap while allowing roughly $166,000 to slip through. Meanwhile, Thorchain declined Bitget CEO Gracy Chen’s request to block the attacker’s addresses, asserting that network halts are emergency tools for protocol protection rather than mechanisms for selective fund freezes.
The initial breach occurred on September 24 when unauthorized transfers were flagged from Bitget’s hot wallets. Chen indicated that attackers accessed backend systems and falsified transaction data rather than stealing private keys, noting that customer balances remain unaffected due to Bitget’s protection fund. Blockchain analytics firm Elliptic has identified the theft as the largest suspected North Korean cybercrime of 2026, pushing the annual total past $1 billion, though no government has confirmed this attribution. TRM Labs observed that the attacker split funds into fresh wallets holding round amounts, such as 10,000 ETH or 20 million XRP, before routing smaller chunks through cross-chain swap services including Across, Bridgers, Chainflip, and FixedFloat. Despite Thorchain’s stance, on-chain data shows batches totaling roughly 2,390 ETH were converted into 75.2 BTC via the platform on Monday.
The migration of stolen assets into Zcash’s Ironwood pool marks a critical escalation in the laundering phase of the Bitget hack, leveraging privacy technology to obscure transaction trails after public blockchains became increasingly hostile to illicit flows. The decision by Near Intents to reject significant swap volumes demonstrates that centralized intent-based protocols can effectively act as chokepoints against sanctioned or criminal actors, contrasting sharply with Thorchain’s adherence to a permissionless model where network halts are reserved for systemic emergencies rather than individual address blocking. This divergence highlights a growing tension within decentralized finance between operational compliance and ideological neutrality, particularly when facing state-sponsored threats attributed to North Korea.
Market structure implications arise from the varying responses of infrastructure providers to high-profile exploits. While Bitget offers a bounty for recovered funds, the inability of certain cross-chain bridges to selectively freeze assets allows hackers to continue converting tokens like ETH into BTC, albeit at reduced efficiency compared to earlier stages. The use of Ironwood specifically underscores the limitations of current on-chain surveillance; investigators can track entry and exit points but cannot monitor internal movements, creating blind spots that may persist until regulatory frameworks for privacy coins evolve. Stakeholders must watch whether other major exchanges or bridge operators adopt stricter screening protocols similar to Near’s SHIELD, potentially fragmenting liquidity pools based on compliance standards rather than technical capability.


