Community Trust ScoreLikely Real
North Korea did it again. Chainalysis has tied the $387 million theft from Bitget directly to North Korean-linked hackers, and the hit pushed the total crypto stolen by those actors in 2026 past $1 billion.
Why It Matters
The increasing frequency and scale of cyberattacks attributed to North Korean hackers underscore the ongoing vulnerability of cryptocurrency exchanges and the broader crypto ecosystem. The surpassing of $1 billion in theft for 2026 highlights not only the financial implications for affected platforms but also raises concerns over regulatory responses and security measures within the industry. This trend could further erode investor confidence and impact the overall market stability, prompting calls for enhanced cybersecurity protocols across the sector.
The Bitget breach, which happened on September 24, is now the single largest crypto hack of 2026. It’s a brutal number on its own — but it landed on top of an already ugly year. Back in April, the same cluster of North Korean-linked groups pulled $285 million out of Drift Protocol on April 1, then followed that with a $292 million exploit from KelpDAO on April 18. Together, those April attacks alone accounted for 76% of total crypto hack losses in the first stretch of the year. Bitget’s September incident then raised that month’s losses by 462%. So yeah — the pace isn’t slowing.
Bitget’s CEO, Gracy Chen, spoke up shortly after the breach and said the IP addresses involved matched patterns common to North Korean hacker groups. That’s a pretty fast attribution, but Chainalysis backed it up.
How the Attackers Moved $387 Million Without Touching an Exchange
Right after the exploit, Chainalysis tracked 23 outbound transfers moving the stolen funds across four networks: Ethereum, the XRP Ledger, Zcash, and Tron. Spreading funds that fast across that many chains isn’t accidental — it’s a deliberate strategy to fragment the trail and slow down anyone trying to follow the money.
But the most striking part of the operation was what they did with the XRP. Instead of running it through a traditional exchange — where compliance teams and automated flags would likely catch large, suspicious inflows — the attackers deposited the stolen XRP directly into a cross-chain liquidity protocol. From there, they converted it to Bitcoin on a separate network. No exchange. No KYC checkpoint. Clean swap.
Zcash’s involvement adds another layer of difficulty. It’s a privacy-focused chain, and mixing privacy coins into a laundering route is basically a way of throwing a blanket over part of the trail. Chainalysis is still monitoring the Bitcoin addresses the attackers now control, and the investigation is ongoing. No final destination confirmed yet.
Chainalysis Builds AI Tools to Keep Up
Cross-chain tracing used to be painfully slow. Following money across Ethereum, then XRP Ledger, then Bitcoin manually would take days — and by then, the funds are long gone through another hop. Chainalysis said it built custom automations specifically to cut that time down. The firm developed in-house AI tools that drastically reduced the manual reconciliation work required to piece together cross-chain transactions.
It’s not a solved problem, though. The attackers are clearly aware of where the friction points in blockchain analytics are, and they’re routing funds through the gaps. The use of decentralized, cross-chain liquidity protocols instead of centralized exchanges is a direct response to how much better exchanges have gotten at flagging suspicious flows. Basically, if the exchange is the checkpoint, you skip the exchange.
Chainalysis keeps stressing that speed matters here. The faster a theft gets flagged and traced, the better the odds of freezing funds somewhere down the chain — especially if the stolen assets pass through a more centralized chokepoint later. That’s why the automation investment matters. Slower tracing means more time for the hackers to layer and obscure.
The $1 billion figure for 2026 is already alarming on its own. And it comes after North Korean-linked actors reportedly stole over $2 billion in 2025. The scale here isn’t random opportunism — it’s a sustained, state-linked operation that seems to be getting more technically capable, not less.
What’s probably most unsettling for the broader crypto industry is how cleanly the Bitget attackers executed this. Twenty-three outbound transfers in the immediate aftermath. Four blockchains. A cross-chain swap that bypassed every traditional exchange mechanism. Privacy coins layered in. The operational tempo was fast, and the routing was sophisticated.
And the funds are still moving. Chainalysis is watching the Bitcoin addresses, but the firm hasn’t said those funds are frozen or recovered. Further updates are expected as the tracing effort continues, though no timeline has been given. Gracy Chen hasn’t made additional public statements beyond the initial IP address comment, and Bitget hasn’t released further detail on how the breach happened internally.
The Drift Protocol and KelpDAO hacks earlier this year — $285 million and $292 million respectively — were never fully resolved either, at least not publicly. So the pattern is: fast attack, cross-chain obfuscation, and a long, grinding investigation that may or may not surface the funds.
Chainalysis continues to monitor the Bitcoin addresses tied to the Bitget theft.
Hub: Bitcoin price, news, and analysis
Frequently Asked Questions
How much did North Korean hackers steal from Bitget?
North Korean-linked hackers stole $387 million from Bitget in a September 24 exploit, making it the largest single crypto hack of 2026, per Chainalysis.
How did the attackers convert stolen XRP to Bitcoin without using an exchange?
They deposited the stolen XRP into a cross-chain liquidity protocol and converted it to Bitcoin on a separate network, bypassing traditional exchanges entirely.





