ZachXBT Tracks 277,724 XRP Stuck in $387M Bitget Hack Laundering

ZachXBT says Chinese launderers moving the $387M Bitget hack funds sought help in public chats, with 277,724 XRP stuck in failed XRP-to-Bitcoin swaps.

(02:55 PM UTC)
4 min read
AI SummaryAI
  • One launderer reported 277,724 XRP deposited with only 431 returned from a failed swap.
  • Bitget lost $387.5 million on September 24 after attackers tricked its internal approval system.
  • Account 'lolo' also laundered funds from the $292 million Kelp DAO exploit in April.
  • The FBI ties the TraderTraitor group to the $308 million DMM Bitcoin theft in 2024.
v3xn8bwc

Launderers Seek Help in Public Chats

The crew moving stolen funds out of Bitget has been asking customer support for help in fully public chat rooms, exposing its own laundering operation in the process. Rather than operating quietly, they posted inside the Discord servers and Telegram channels of the very services they use to shift the money, requesting assistance with stuck orders. On-chain investigator ZachXBT documented the behavior on Sunday, naming five accounts and matching each alias to a specific transaction. He assesses the group as Chinese money launderers working on behalf of the suspected North Korean perpetrators behind the September 24 breach, in which attackers tricked the exchange's internal approval system into signing $387.5 million in outgoing transfers. Bitget CEO Gracy Chen characterized the incident as a manipulation of that multi-step approval workflow and said North Korean involvement was very likely. The screenshots ZachXBT published show the accounts complaining to staff at THORChain — a network that swaps assets between blockchains without user accounts, an alternative to spot trading on centralized venues — because their XRP-to-Bitcoin conversions never arrived. One user, going by “Cc,” reported that 277,724 XRP went in but only 431 came back. Another, “jack,” wrote that losing the assets “would cause a lot of trouble in my life.” A moderator for the swap service SwapKit answered with a photograph of Kim Jong Un. The investigator's on-chain thread lays out the full alias-to-transaction mapping.

Kelp DAO Link and TraderTraitor

The laundering crew is not new to large-scale theft. ZachXBT reported that one of the five accounts, operating under the handle “lolo,” also moved funds from the $292 million Kelp DAO exploit in April, and that the same account confirmed in chat that it goes by “Marin” on Telegram. That overlap matters: it suggests a small, repeat specialist workforce rather than a crew assembled for a single job. The investigator wrote that he has observed the same behavioral pattern after multiple exploits attributed to TraderTraitor and has tracked these groups closely for some time. TraderTraitor is the Federal Bureau of Investigation's designation for a North Korean cyber outfit, one the bureau holds responsible for the $308 million theft from Japanese exchange DMM Bitcoin in 2024 — making the Bitget breach the latest entry in a series of state-directed exchange raids. Per ZachXBT's tracing, the stolen funds are now hopping between blockchains through bridges before reaching mixers such as Wasabi, a wallet that blends coins from many users to obscure the trail — a CoinJoin-style approach that differs from ledger-level privacy designs like Mimblewimble. The $387.5 million haul is large enough that, set against the market cap of most mid-tier tokens, it could not be offloaded without leaving traces. THORChain, for its part, has declined to freeze the wallets tied to the attackers, while Bitget says withdrawals will reopen on Monday. The investigator plans to publish further data on the groups in the coming weeks. Readers tracking the market in real time can follow live spot and futures prices on Bitget.

For COINOTAG, the episode underscores that even industrial-scale laundering leaves operational fingerprints. The primary evidence here — the alias-to-transaction matches in the investigator's thread and the exchange's own account of a deceived approval system — points to a social-engineering root cause, with remediation centered on re-securing internal signing and reopening withdrawals Monday. As long as THORChain keeps servicing attacker-linked swaps and bridges keep feeding mixers, tracing will trail the money. The demand side is structural: unlike economies piloting a central bank digital currency, Pyongyang cannot print hard currency, which is why state-directed exchange raids persist. Additional disclosures are likely within weeks.

COINOTAG News Desk

COINOTAG News Desk

COINOTAG's editorial and research desk.

How our News Desk works
AI-Assisted

AI-generated, AI-reviewed, under COINOTAG editorial oversight.