**Chainalysis** officially analyzed that the $387 million Bitget hack was the work of a North Korea-linked attacker. The company specifically traced the on-chain flow of the stolen XRP as it was converted and laundered into Bitcoin (BTC) (BTC) via cross-chain liquidity routes.
Core content
Within 3 hours immediately after the September 24 attack, a total of $387 million was siphoned out from Bitget via 23 transactions.
The stolen XRP was converted to Bitcoin (BTC) through a cross-chain liquidity protocol without going through centralized exchanges.
In this incident, the amount of crypto stolen by North Korea-linked actors in 2026 exceeded $1 billion.
Bitget hacking fund flow
In its report, Chainalysis said that within the first three hours after the security breach on September 24, a total of 23 external transfers from Bitget led to $387 million being taken out.
The funds are analyzed as being first distributed across four blockchain networks, after which the attackers used cross-chain services and other on-chain routes to carry out additional laundering operations.
By share, 49.7% was the largest portion moved to Ethereum (ETH). Meanwhile, 40.8% flowed into the XRP Ledger. Zcash (ZEC) accounted for 7.6%, and Tron (TRX) for 1.8%.
The attackers did not use the usual pattern of sending the stolen XRP to exchanges. Instead, they first deposited it into a cross-chain liquidity protocol, then blurred the trail by withdrawing Bitcoin from another network. Chainalysis identified that, in the process, deposit-and-withdrawal transactions matched one-to-one, allowing them to track to specific Bitcoin addresses the movement of tens of millions of dollars from the attacker’s wallet over about 36 hours.
Bitget CEO Gracy Chen publicly raised the possibility of North Korean involvement immediately after the incident. At the time, she claimed that the IP used in the attack matched the pattern previously used when North Korea’s Reconnaissance General Bureau-linked organization accessed via a VPN. The $387 million hacking was recorded as the largest single incident among crypto hacks reported in 2026 so far.
Also to see: Polymarket Kyiv airstrike betting volume of $124,000… in reality, it was just two trades
Chainalysis warns about automated laundering tied to North Korea
Chainalysis emphasized the importance of rapid tracking, saying that North Korea-linked organizations are actively adopting automated tools for cross-chain movement of stolen assets and the laundering process. In the report, the company noted, “As North Korea increasingly uses sophisticated automation to move and conceal stolen funds, the ability to quickly identify and understand illegal fund flows has become more important than ever.”
Chainalysis built tailored tracking automation tools using its own developed AI. It is reported that this reduced manual work that previously took more than 20 hours to track bridge and cross-chain transactions to within 10 minutes. However, the company explained that the investigative team still designs the tracking logic, verifies the results, and leads the overall investigation.
As this Bitget hacking is attributed to North Korea, in 2026 alone the amount of cryptocurrency stolen by North Korea-linked groups has surpassed $1 billion. Earlier on April 1, $285 million was drained from the **Drift Protocol**, and on April 18, $292 million was siphoned off in an attack on the KelpDAO bridge vulnerability; both incidents were classified by researchers as North Korea-linked attacks.
TRM and **LayerZero** pointed to a North Korea-linked group, ‘TraderTraitor,’ as the culprit behind the KelpDAO attack. According to TRM, the two cases—Drift Protocol and KelpDAO—account for 76% of all crypto-hack losses compiled by the end of April. It is estimated that in just 2025 alone, North Korea-linked actors stole more than $2 billion from the global crypto industry.
Next read: AI agents beyond control—forced OpenAI to search its own 50 petabytes of records
