Blockchain analytics firm Chainalysis has attributed the $387 million hack of the Bitget exchange on September 24 to actors linked to North Korea. This incident pushes the total value of cryptocurrency stolen by Pyongyang-affiliated groups in 2026 past $1 billion. The report details how the stolen assets moved rapidly across four networks within three hours: Ethereum accounted for 49.7% of the transfers, XRP for 40.8%, Zcash for 7.6%, and Tron for 1.8%. Attackers utilized cross-chain liquidity protocols, instant swaps, and laundering services to obscure the trail, notably converting XRP into Bitcoin through a cross-chain protocol before moving it to monitored addresses.
To manage the complexity of tracking these multi-chain movements, Chainalysis employed in-house artificial intelligence. The firm stated that custom automation compressed over 20 hours of manual bridge reconciliation work into less than 10 minutes, though human investigators continued to direct the analysis. This attribution aligns with earlier assessments from Bitget CEO Gracy Chen and analytics firm Elliptic, both of which identified patterns consistent with North Korean hacking groups. Concurrently, stablecoin issuers Circle and Tether froze approximately $318,000 related to the theft, while swap service Near Intents rejected over $50 million in hacker-linked transactions before suffering its own security breach days later.
The rapid deployment of AI-driven tracing tools highlights a shifting operational dynamic in crypto forensics, where speed is becoming as critical as accuracy in mitigating large-scale thefts. By reducing the time required to map complex cross-chain movements from hours to minutes, firms like Chainalysis are attempting to keep pace with sophisticated laundering techniques that exploit decentralized finance infrastructure. This efficiency gain suggests that future regulatory and compliance frameworks may increasingly rely on automated surveillance capabilities to detect illicit flows in real-time, rather than depending solely on post-incident manual audits.
However, the persistence of North Korean cyber operations despite improved detection methods underscores the limitations of current defensive measures. The fact that attackers successfully moved hundreds of millions across multiple chains using privacy coins and cross-chain bridges indicates that existing compliance barriers remain porous. While freezing small amounts of stablecoins demonstrates some level of centralized control, the bulk of the assets likely entered circulation through decentralized channels. This disparity between the scale of theft and the limited success of asset recovery points to an ongoing structural vulnerability in the global crypto market, where institutional adoption outpaces the development of robust, unified enforcement mechanisms.


