Advertise

Bitcoin

Chainalysis Pins $387M Bitget Theft on North Korea After XRP-to-Bitcoin Swap

Chainalysis attributes the $387 million Bitget theft to North Korean actors, tracing stolen XRP through cross-chain swaps into Bitcoin across 4 chains.

Be a creator
October 3, 2026, 02:33 PM UTC4 min read
AI SummaryAI
  • Attackers moved $387 million out of Bitget on September 24, later attributed to North Korean actors
  • Crypto stolen by DPRK-linked actors in 2026 now exceeds $1 billion
  • Ethereum received 49.7% of outflows, XRP Ledger 40.8%, Zcash 7.6%, Tron 1.8%
  • Drift lost $285 million on April 1 and KelpDAO $292 million on April 18
gate.com

Chainalysis Pins the Bitget Breach on North Korea

Attackers pulled $387 million out of Bitget on September 24, and on-chain analytics firm Chainalysis has now attributed the theft to North Korean operatives. The finding lifts the value of crypto taken by DPRK-linked actors in 2026 past $1 billion. It follows a 2025 in which North Korean actors took more than $2 billion from the industry, so the current year is running at a pace that could challenge that figure. The Bitget breach stands as the largest crypto hack of 2026 and pushed September's hack losses up by 462%. Suspicion reached Pyongyang almost immediately: Bitget CEO Gracy Chen cited IP addresses that matched the VPN choices of a group operating in North Korea. Chainalysis has published the full tracing of the stolen funds, and its authors frame the core problem as speed. The firm wrote that quick identification of illicit activity matters more now that North Korea deploys sophisticated automation to move and obscure stolen funds. The XRP price is not where this story lives; the stolen tokens are. The operators never sent the XRP to an exchange: they converted it into Bitcoin through a cross-chain route and kept it off trading venues entirely. That choice shapes the investigation, because conventional exchange deposits leave records and identity trails that an off-exchange liquidity protocol does not. The report documents the movement of the money rather than the point of entry: Bitget has not published a root-cause analysis of how the attackers obtained the funds in the first place. For custodial platforms, the case reads as a response test as much as a security one, since the money left the venue within hours of the exploit, before any freeze could take hold. Exchanges holding large XRP reserves now face the same question the report raises: whether their monitoring can keep pace with automated laundering.

XRP Turned to Bitcoin Without an Exchange

The mechanics are where the XRP Ledger enters the file. Chainalysis logged 23 outbound transfers within 3 hours of the September 24 exploit, scattering the $387 million across four blockchains. Ethereum absorbed nearly half of the outflows at 49.7%. The XRP Ledger captured 40.8%, privacy-focused Zcash 7.6%, and Tron the remaining 1.8%. Instead of pushing the stolen XRP toward a venue for spot trading, the attackers deposited it into a liquidity protocol running on cross-chain bridges, then withdrew Bitcoin on a different network. No exchange address appears in the deposit pattern, which is why the tracing team had to match deposits to payouts directly. That matching showed tens of millions of dollars moving this way across roughly 36 hours, and the trail ends at attacker-controlled crypto wallets holding Bitcoin, addresses the firm now monitors. The reconstruction relied on deposit-to-payout matching rather than any exchange KYC trail. Speed came from tooling: Chainalysis built custom automations with its in-house AI to accelerate cross-chain work, an effort it estimates cut reconciliation that would have taken over 20 hours by hand down to less than 10 minutes. Human analysts still define the logic and check the output. The theft also fits an established playbook. Bitget joins two April attacks already tied to North Korea. Attackers emptied Drift Protocol of $285 million on April 1, an operation the protocol said took months of social engineering, including face-to-face meetings. On April 18, they siphoned $292 million from the KelpDAO bridge, a breach both TRM and LayerZero tied to TraderTraitor, the Lazarus-affiliated unit. Those two incidents accounted for 76% of all crypto hack losses up to April.

The Endpoint: Monitored Bitcoin Wallets

Read together, the threads put the XRP Ledger in an uncomfortable position: not the target of 2026's largest hack, but the rail its proceeds traveled. Chainalysis's post-mortem stops short of a root cause for the Bitget breach itself, because the point of entry is not publicly documented. What the report does document is remediation on the tracing side, where automated cross-chain analysis now covers ground that once took a full working day. The state of the breach point is unchanged: the proceeds sit in Bitcoin wallets under active monitoring, with investigators still setting the logic and reviewing results. For anyone tracking XRP news, the lesson is that the ledger's liquidity now draws the industry's most capable thieves.

COINOTAG's editorial and research desk.

AI-Assisted

AI-generated, AI-reviewed, under COINOTAG editorial oversight.