Edit | Wu Blockchain, ChatGPT

TL;DR

· Bitget increased the value of the involved assets to about $387.5 million, and the attribution to North Korea is still pending further confirmation. On September 25, 2026, Bitget said the figure was adjusted due to additional statistics, not new theft, and that some assets have already been frozen. Elliptic assessed that the attack is “highly likely” to be linked to North Korea, but the full technical investigation report has not yet been released.

· Professional intermediaries take over stolen funds; attackers may receive settlements earlier. zeroShadow says that between February and June 2025, more than $1 billion in stolen Bybit funds were laundered. The research suggests that intermediaries may take over the money sooner, pay the attacker the consideration after deducting fees, and bear the risk of subsequent freezes. This estimate does not mean that the equivalent amount has been fully cashed out, nor does it indicate the attacker’s net profit.

· Exchanging, cross-chain transfers, and tumbling increase tracking difficulty, buying time for subsequent transfers. Elliptic tracking found that Bybit stolen funds flowed through multiple wallets, exchange services, and cross-chain channels, with about $200 million passing through eXch. These actions may extend the investigation trail, but they do not automatically erase transaction records, nor do they indicate that all funds have been fully converted into fiat currency.

· Cashing out depends on over-the-counter (OTC) trading and settlement networks, and crypto assets can also be used directly for trade receivables and payments. Elliptic said that some Bybit stolen funds were transferred to Tron, exchanged for USDT, and then cashed out via a suspected China OTC trading service. MSMT also recorded a case in which North Korean personnel collected part of the proceeds from equipment sales in USDT, but the link to the specific crypto theft case still requires separate evidence.

· Tracing funds does not mean they can be frozen or recovered. Native BTC and ETH have no central issuer that can execute freezes directly; pursuing them typically requires platform cooperation, issuer actions, or law enforcement obtaining control of the assets. The U.S. Department of Justice previously disclosed the seizure of more than $15 million USDT related to North Korea-linked crypto theft cases, but from freezing and seizure to final return to victims still requires further procedures.

On September 25, 2026, Bitget updated its investigation progress into the security incident, revising the amount of assets sent to the attacker addresses from the initial estimate of about $351.6 million to about $387.5 million. The company said the change in amount came from additional statistics on related transfers such as Zcash and TRON, not from new thefts; some of the assets involved had been frozen with the assistance of industry partners.

On the same day, blockchain analytics firm Elliptic said the attack was “highly likely” linked to North Korea. Evidence includes links between the laundering addresses for funds involved and laundering addresses from previously identified North Korea-related crypto theft cases. However, this is still an attribution assessment by a research organization, and Bitget has not yet published a complete technical investigation report.

As tracking work unfolds, another question receives renewed attention: since the transfer records of stolen assets are publicly available and exchanges can identify suspicious addresses, how does the attacker turn hundreds of millions of dollars in crypto into usable funds?

Subsequent investigations into cases like Bybit show that the handling of stolen funds has already formed a professional division of labor. The attacker increases tracking difficulty by exchanging, cross-chain transfers, and multi-layer transfers, while professional intermediaries take over the assets and provide exchange, funds swapping, and off-chain settlement. To understand this network, you need to observe both the on-chain transaction paths and the people responsible for collecting and paying behind the transactions.

How professional money-laundering intermediaries take over stolen funds

In February 2025, Bybit had around $1.5 billion worth of crypto assets stolen. The U.S. Federal Bureau of Investigation later attributed the incident to North Korea and said the attacker had exchanged part of the stolen funds into bitcoin and other crypto assets, spreading them across thousands of addresses on multiple blockchains.

A report by the security company zeroShadow in July of the same year said that between February and June, more than $1 billion in stolen funds from the case had been laundered. This estimate does not mean the same amount had all been converted into fiat currency, nor does it indicate the attacker’s final net profit. The company’s analysis suggests that professional money launderers may have taken over the funds at an early stage, paid North Korean attackers the consideration after deducting fees, and then handled the stolen funds received. In its six-month recap published in August, Elliptic also believed that professional “laundering-as-a-service” networks likely became involved from early on.

In this model, the attacker may obtain settlement time earlier than when the original theft finishes its subsequent transfers. After intermediaries take over the assets, they need to keep finding exchange and cash-out channels and bear the risks that the funds are frozen, seized, or unable to be transferred out.

This also means that the continuously tracked funds on-chain are not necessarily always controlled by the original attacker. In addition to confirming the theft fund flows, investigators also need to identify when a transfer of control occurred and what the intermediary delivered to the attacker.

A Xinbi merchant network investigation disclosed by Chainalysis in September 2026 provides another example of funds swapping. The company said tens of millions of dollars in stolen funds from cases involving Bybit, WazirX, and others flowed through related merchant networks. Some professional intermediaries receive stolen assets that are easy to trace, then deliver another batch of stablecoins to clients; the replacement funds also include proceeds from other scams.

These transactions mix funds from different criminal activities within the same settlement network. Attackers can reduce the work required to handle stolen proceeds directly, while intermediaries profit through fees. “Clean assets” here mainly means assets that are harder to directly trace back to the original theft, not that their origin is already legitimate.

Exchanging, cross-chain transfers, and tumbling mainly serve to buy time

Apart from professional intermediaries, on-chain transfers remain an important part of the money-laundering process.

Elliptic’s early tracking of the Bybit case showed that the attacker quickly exchanged part of the stolen tokens into ETH, and then continued transferring them through multiple wallets, exchange services, and cross-chain channels. Spreading addresses, changing asset types, and crossing different networks increase the workload for investigators to re-connect the funding paths. Mixing and privacy tools further reduce how directly associated the sources of funds are with their outputs.

These actions can increase tracking costs, but they do not automatically delete existing transaction records. For attackers, the key role of complex paths is to buy time to continue transferring before the funds are identified, relevant institutions are notified, and measures are taken.

Some exchange services are also key nodes. In its April 2025 report, Elliptic estimated that about $200 million in Bybit stolen funds flowed through eXch, an exchange service that does not require customer identity verification. This figure reflects the scale of funds handled by the service, and does not mean that the same amount has already been fully converted into fiat currency.

Therefore, a theft that passes through a tumbler or cross-chain service may still be identifiable. Whether it can ultimately be cashed out depends on whether there are counterparties willing to take over later transactions, and whether those counterparties can provide real-world settlement channels.

An outflow of funds is not necessarily a single dollar loss

In its six-month recap of the Bybit incident, Elliptic said that some of the stolen funds that could continue to be tracked ultimately reached the Tron network, were exchanged for USDT, and then were cashed out through a suspected China OTC service. This indicates that after on-chain transfers, OTC traders connecting crypto assets with the fiat system still play an important role.

For platforms that conduct customer due diligence and transaction monitoring, receiving funds connected to major crypto theft cases can trigger compliance risks. But the business of illegal intermediaries itself includes taking over these assets and finding subsequent settlement channels.

A case published by the U.S. Department of the Treasury in 2020 shows that this division of labor has long existed. The Treasury alleged that two intermediaries received a combined total of more than $100 million in exchange-hacked proceeds from accounts controlled by North Korea. One of them transferred an equivalent amount of more than $34 million in related funds through bank accounts associated with the exchange.

The services provided by such intermediaries include accounts, counterparties, and the ability to rotate funds. On-chain, you can see assets entering a certain address, but the exchange price agreed by both parties, the payment method on the other end, and the ultimate beneficiary often require combining platform records and off-chain investigations to confirm.

The role of crypto assets is not limited to converting into fiat currency; they can also be used for trade receivables and payments. In a report released in 2025, the Multilateral Sanctions Monitoring Team (MSMT) documented cases in which North Korean personnel used, or planned to use, USDT for trade settlement, involving transactions such as military equipment and raw materials. In one case, a North Korean procurement officer sold equipment to a customer in Laos, and the buyer paid part of the amount in USDT.

This case shows that stablecoins have been used for part of trade receivables. However, whether there is a direct link between such transactions and a specific crypto theft incident still requires separate financial evidence.

Why you can see the money, but it’s hard to get it back

Blockchain analytics can track parts of the funding paths and identify related addresses, but publicly available transaction records do not grant investigators permission to control assets.

Elliptic noted that some token issuers have the ability to freeze, while native BTC and ETH do not have a central issuer that can directly carry out comparable freezing actions. Therefore, even if an address is widely flagged, external entities cannot simply reverse the assets in it based on the label alone.

Pursuit usually requires a stage where someone can actually control the funds—for example, assets entering a custodial platform that cooperates with investigations, issuer actions on tokens with freezing capabilities, or law enforcement obtaining control of relevant accounts, devices, and assets by law. Identifying addresses, coordinating agencies, and completing cross-border procedures all take time, yet the funds may continue moving during that period.

Frozen assets do not necessarily mean they have already been returned to victims. In November 2025, the U.S. Department of Justice disclosed that the FBI seized more than $15 million USDT in March that year. The related funds were tied to four 2023 crypto platform thefts allegedly carried out by North Korea’s APT38. The DOJ then filed a civil forfeiture request seeking the final return of the assets to lawful owners.

From these cases, the ability of North Korea-linked crypto theft activity to monetize depends on the combination of on-chain transfers and professional settlement networks. Exchanging, cross-chain transfers, and tumbling increase tracking difficulty, while intermediaries convert the stolen funds into value the attacker can control. Pursuit efforts therefore need to cover the funding paths, service-provider accounts, and intermediary networks at the same time.

The amount stolen reflects the asset loss at the time the incident occurred. How much profit the attacker ultimately obtains also depends on later settlements, changes in coin prices, intermediary fees, and how much capital is frozen or recovered while moving through the process.