Advertise

Hack

Bitget Hackers Shield 2,700 ZEC Worth $3.8M in Zcash's Ironwood Pool

Bitget attackers shielded about 2,700 ZEC, worth $3.8 million, into Zcash's Ironwood privacy pool, one in seven of the 18,900 ZEC stolen on September 24.

Be a creator
October 1, 2026, 01:32 AM UTC4 min read
AI SummaryAI
  • Bitget attackers shielded about 2,700 ZEC, worth roughly $3.8 million, into Ironwood on September 30.
  • The September 24 Bitget breach drained about 18,900 ZEC, then valued near $28.3 million.
  • Bitget revised incident losses to about $387.5 million from an initial $351.6 million.
  • NEAR Intents' SHIELD screening rejected more than $50 million in attacker swap requests.
binance.com

ZachXBT Flags Shielding Into Ironwood

Six days after attackers drained the hot wallets of Bitget, a major crypto exchange, the trail went dark on September 30, when on-chain investigator ZachXBT reported that addresses tied to the hackers had begun shielding roughly 2,700 ZEC into Ironwood, the newest privacy pool on Zcash (ZEC). At the prevailing Zcash price near $1,407, the batch is worth about $3.8 million to $3.9 million. The significance sits in the destination rather than the size. Zcash settles both transparent and shielded transfers, and once coins cross into Ironwood, the sender, receiver and amount of every pool-internal payment disappear behind zero-knowledge proofs. Investigators can still see which transparent addresses deposited coins, with amounts and timing visible, but the public record stops at the pool boundary: splitting, internal routing and later withdrawals no longer leave an open trail. ZachXBT posted three deposit transactions alongside the source addresses behind the stolen funds, and the flow matches t1WgMdtND8NF7NDUuYmq8MpMj1NTCXkMDVG, the attacker address Bitget itself published. The September 24 theft in total moved about 18,900 ZEC off the platform, then worth close to $28.3 million, which puts the shielded share at roughly one in seven stolen coins, or 14% to 15%. His wording that the group had only “begun” shielding frames the 2,700 ZEC as a likely first tranche, with about 16,000 ZEC still sitting on identified transparent addresses. He attributes the operation to a suspected North Korean group, and Bitget CEO Gracy Chen has described IP and VPN infrastructure consistent with past North Korean intrusions, though no government has completed a formal public attribution. The laundering step lands while ZEC trades near its recent peaks: the coin touched about $1,587 on September 27, within reach of the $1,590 peak it set after a 36% weekly rally, and it remains one of the strongest performers in the altcoin market, though it still trades far from its all-time high.

NEAR Intents Blocked $50M First

Before the coins reached the pool, screening systems had already pushed back. The attackers first fragmented the haul across chains, converting into more liquid assets, and cross-chain swap service NEAR Intents reported that its SHIELD screening rejected more than $50 million in swap requests connected to the breach, froze about $503,000 mid-conversion and let roughly $166,000 slip through. THORChain took the opposite position. After Gracy Chen publicly asked the network to refuse the attacker's addresses, THORChain replied that its chain halt is an emergency mechanism to protect the protocol, not a tool for freezing specific funds, and its own explorer data shows the attackers converted about 2,390 ETH, roughly $6.3 million, into 75.2 BTC in batches on September 28. Bitget, meanwhile, has reworked its accounting of the damage. On September 25 the platform revised the total impact to about $387.5 million, up from the initially disclosed $351.6 million, with the increase mainly covering Zcash and Tron holdings that had not been fully counted at first. In its official announcement, Bitget said its protection fund will absorb the financial impact of the incident and that user funds are unaffected, and it put up a recovery bounty worth 5% of any funds frozen or returned through outside assistance. The latest proof of reserves, snapshotted at 17:00 (UTC+8) on September 29, shows an overall reserve ratio of 131% across 19 assets, with BTC at 142%, ETH at 110% and USDT and XRP each at 107%, all above the 1:1 coverage line. Blockchain analytics firm Elliptic assesses North Korean involvement as highly likely, but the label stays unofficial until a government agency confirms it. The exploited vulnerability has been patched, and the platform says its focus now sits on tracking and recovering what remains.

Six Days On, 16,000 ZEC in the Open

COINOTAG's reading: the evidence trail here is unusually clean. Three Ironwood deposit transactions are published and verifiable on-chain, and the pool the attackers picked is the protocol's newest construction. Ironwood went live on July 28, 2026, at block height 3,428,143 through the NU6.3 upgrade, after researchers found a soundness flaw in the older Orchard circuit that could theoretically mint extra ZEC undetected. Orchard now permits outflows only, a turnstile mechanism keeps the pool's tokenomics verifiable, and tracking put about 3.99 million ZEC inside as of September 26, with 89.4% of Orchard funds migrated. Six days on from the breach, roughly 16,000 ZEC still sit on known transparent addresses, and whether they follow the first 2,700 into the pool is the figure to watch. Self-custody is adapting too: Ledger now supports private ZEC balances on desktop, while ZEC's 68.3% climb over the past month keeps it inside a broader bull market.

COINOTAG's editorial and research desk.

AI-Assisted

AI-generated, AI-reviewed, under COINOTAG editorial oversight.