Chainalysis AI traces $387M Bitget hack in under 10 minutes

Chainalysis AI traces $387M Bitget hack in under 10 minutes - 1



Chainalysis has used its in-house AI to cut more than 20 hours of manual bridge reconciliation to under 10 minutes while investigating the $387 million stolen from Bitget.

Summary

Chainalysis says AI accelerated cross-chain matching while investigators directed the work and reviewed results.

The firm attributes the attack to North Korean actors, putting their 2026 theft above $1 billion.

okex

Investigators tracked stolen XRP through cross-chain swaps to Bitcoin addresses controlled by the attackers.

Bitget has offered separate 5% rewards for qualifying help freezing and recovering stolen funds.

Chainalysis said in its Oct. 1 report that investigators built custom automation to connect transactions across blockchains after the Sept. 24 breach. The reported time saving concerned matching bridge deposits with payouts, one part of an investigation involving Bitget and law enforcement partners.

Working around the clock, the firm’s investigation team used the tools to follow fragmented transaction trails and share findings with the exchange and authorities. According to the report, newly identified addresses received stolen-fund labels within minutes, making the information available to compliance teams through its data platform.

Chainalysis AI matched transfers while investigators directed the case

Under the process described by the firm, investigators set the matching rules, checked the results, and decided which leads to pursue. Its AI helped them build tools for the specific case rather than taking control of the investigation.

As the report put it:

“Our investigators still defined the logic, reviewed the outputs, and directed the investigation.”

Drawing on more than a decade of cross-chain attribution data, the automation connected deposits on one network with payments on another. The firm said the approach helped reconstruct activity that could otherwise appear unrelated when viewed on separate blockchains.

In the stolen XRP trail, investigators identified transfers through a cross-chain liquidity protocol that paid out Bitcoin instead of sending the XRP directly to an exchange. According to the report, tens of millions of dollars passed through that route over roughly a day and a half.

After matching the deposits and payouts, investigators followed subsequent transactions through several protocols to attacker-controlled Bitcoin addresses, the firm said. Its team continues to monitor the identified destinations and plans to label additional addresses as the funds move.

The Bitget hack sent $387m across four chains

Within the first three hours of the attack, Chainalysis recorded 23 transfers carrying about $387 million out of Bitget. Its breakdown assigned 49.7% to Ethereum, 40.8% to XRP, 7.6% to Zcash and 1.8% to Tron.

Beyond the initial withdrawals, the firm identified cross-chain liquidity and messaging protocols, instant-swap services and links to laundering services. Its published transaction graphs show portions of the hundreds of transfers made after the breach.

Bitget said its systems detected unauthorized transfers at 18:31 UTC on Sept. 24 from parts of its hot and warm wallet infrastructure. The exchange later raised its loss estimate from $351.6 million to $387.5 million after including additional Zcash and Tron transfers.

According to CEO Gracy Chen’s initial account, the attacker compromised a critical backend system, manipulated transaction data, and triggered the authorization process. Bitget said cold wallets and private keys remained secure.

The exchange’s subsequent investigation identified a vulnerability in a third-party security product that allowed attackers to obtain credentials and forge withdrawal commands, according to its reported findings. Bitget named Mandiant and SlowMist among the firms assisting with forensic work and tracing.

While Chainalysis attributes the theft to North Korean actors, Chen’s initial assessment was more cautious. She cited IP behavior and VPN infrastructure consistent with known North Korean hacking operations without confirming responsibility at that stage.

THORChain rejected Bitget’s request to block attacker addresses

As crypto.news previously reported, Chen sought to block attacker addresses from using THORChain after stolen funds began moving through the protocol. THORChain rejected selective blocking, arguing that its emergency controls protect network security rather than freeze individual wallets.

Chen argued that decentralization should not shield services facilitating known stolen funds. THORChain maintained that pausing its network during a security incident differs from denying service to particular addresses.

Security firm GoPlus challenged the protocol’s comparison with Bitcoin and Ethereum, pointing to its validator-controlled vaults and signing system. According to GoPlus, those features give THORChain’s operators powers that differ from validators on the underlying blockchains.

On the issuer side, earlier reporting put Circle and Tether’s combined freezes at approximately $318,000 in USDC and USDT linked to the breach by Sept. 26.

According to Bitget’s recovery terms, qualifying assistance that results in funds being frozen can earn a 5% bounty, while successful recovery carries a separate 5% reward.

Bitget restored withdrawals as U.S. authorities pursued separate DPRK proceeds

In its Sept. 30 update, Bitget confirmed it had restored major asset withdrawals, with Bitcoin returning on Sept. 28, Ether on Sept. 29 and USDT on Sept. 30. Its timetable scheduled remaining token, fiat and P2P withdrawals for Oct. 2 at 08:00 UTC.

Chen also said the Protection Fund had returned above $300 million. Bitget’s Sept. 29 reserve snapshot reported a 131% overall ratio across 19 covered assets, with each above 100%, while the exchange maintained that customer balances were unaffected.

In a separate U.S. case reported Sept. 8, a federal court ordered stablecoin forfeiture of approximately $212,700 linked to wages earned by North Korean IT workers. Prosecutors alleged that workers concealed their identities, obtained overseas jobs, and routed earnings through cryptocurrency.

The Justice Department’s June 2025 complaint alleged that unwitting employers, including blockchain companies, often paid the workers in USDC or USDT. Prosecutors described laundering through token swaps, transfers between blockchains, false-identity accounts, and smaller transactions.

Judge Rudolph Contreras granted forfeiture for the identified wallet but denied the request covering the remaining property without prejudice because prosecutors had not adequately identified those assets in their public notice.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *

Pin It on Pinterest