Bitget $387M hack AI tracing

Chainalysis says it used in-house artificial intelligence to cut a bridge reconciliation task that would normally take investigators more than 20 hours down to under 10 minutes while tracing the $387 million drained from crypto exchange Bitget.

The breakdown comes from a Chainalysis report dated Oct. 1, as crypto.news reported. The blockchain analytics firm said its investigators built custom automation specifically for the case after Bitget detected unauthorized transfers on Sept. 24, and the tool helped connect fragmented transaction trails that would otherwise look unrelated when viewed on separate networks.

Key takeaways

  • Chainalysis says its AI shrank a 20-hour bridge-matching task to under 10 minutes during the Bitget probe.

  • Roughly $387 million left Bitget across Ethereum, XRP, Zcash and Tron in 23 transfers.

  • Chainalysis links the theft to North Korean actors, whose 2026 crypto thefts now top $1 billion.

  • Circle and Tether froze about $318,000 in linked USDC and USDT by Sept. 26.

How AI Tracing Accelerated the Bitget Hack Investigation

Chainalysis investigators set the matching logic themselves, then let the AI handle the repetitive cross-chain legwork of pairing deposits on one network with payouts on another. โ€œOur investigators still defined the logic, reviewed the outputs, and directed the investigation,โ€ the firm said in its report. Newly flagged addresses tied to the stolen funds received labels within minutes, feeding directly into the compliance data platform used by exchanges and law enforcement partners.

Inside the $387 Million Theft Across Four Blockchains

Within the attackโ€™s first three hours, Chainalysis tracked 23 separate transfers that drained roughly $387 million from Bitget. According to its analysis, 49.7% went to Ethereum, 40.8% to XRP, 7.6% to Zcash and 1.8% to Tron.

Investigators traced the stolen XRP through a cross-chain liquidity protocol that paid out Bitcoin rather than routing the tokens straight to an exchange, with tens of millions of dollars passing through that route over roughly a day and a half. From there, the funds moved through several more protocols to attacker-controlled Bitcoin addresses that Chainalysis said it continues to monitor.

Bitgetโ€™s own investigation traced the breach to a vulnerability in a third-party security product that let attackers obtain credentials and forge withdrawal commands. Mandiant and SlowMist assisted with the forensic work. According to Chainalysis, North Korean actors were behind the attack, pushing the groupโ€™s cumulative 2026 crypto theft past $1 billion, whereas Bitget CEO Gracy Chen initially pointed only to IP patterns and VPN infrastructure resembling known North Korean tactics, stopping short of a definitive attribution.

Bitgetโ€™s Response: Detection, Rewards and Restored Withdrawals

According to Bitget, its systems detected unauthorized transfers at 18:31 UTC on Sept. 24 originating from segments of its hot and warm wallet infrastructure. The exchange subsequently revised its estimated losses upward, moving from $351.6 million to $387.5 million once further Zcash and Tron transfers were accounted for.

To claw back funds, Bitget offered separate 5% rewards for information leading to frozen assets and for successful recovery. Circle and Tether froze about $318,000 in linked USDC and USDT by Sept. 26. In its update on Sept. 30, Bitget verified that withdrawal functions had come back online in phases โ€” Bitcoin on Sept. 28, followed by Ether on Sept. 29 and USDT on Sept. 30 โ€” while reiterating that user funds remained untouched and that more than $300 million had already flowed back into its Protection Fund.

THORChainโ€™s Response and a Separate North Korea Case

Chen sought to have THORChain block the attackerโ€™s addresses once stolen funds began moving through the protocol, but THORChain declined. The network argued its emergency controls exist to protect overall network security rather than to freeze individual wallets, a distinction it said differs fundamentally from selective address blocking. GoPlus, a security firm, disputed THORChainโ€™s comparison to Bitcoin and Ethereum, noting that its vaults rely on validator control and a distinct signing mechanism that grants operators capabilities beyond what base-layer validators possess.

Separately, a U.S. federal court case reported Sept. 8 ordered forfeiture of roughly $212,700 in stablecoins tied to North Korean IT workers. According to the Justice Departmentโ€™s June 2025 complaint, prosecutors claimed the workers concealed their true identities to land jobs abroadโ€”some at blockchain firmsโ€”typically receiving payment in USDC or USDT before laundering it via token swaps, cross-chain transfers and accounts set up under fake identities. While Judge Rudolph Contreras approved forfeiture of the single identified wallet, he rejected the wider request without prejudice, finding that the public notice had not adequately specified the remaining assets.

Article produced with the assistance of artificial intelligence and reviewed by the editorial team.