Chainalysis has linked the Sept. 24 Bitget breach that stole $387 million to actors tied to North Korea, saying the theft helped push DPRK-linked crypto thefts past $1 billion in 2026. The stolen funds moved quickly in 23 transfers across Ethereum, XRP, Zcash and Tron and were routed through cross-chain liquidity protocols and privacy services. Chainalysis used in-house AI to reduce more than 20 hours of manual bridge reconciliation to under 10 minutes, while emphasizing human oversight. The findings align with statements from Bitget’s CEO and other forensics firms.
Chainalysis: AI-Backed Forensics Trace $387M Bitget Hack to North Korea

Blockchain analytics firm Chainalysis says it has traced last month’s $387 million breach of the Bitget exchange to actors linked to North Korea, strengthening a growing consensus that Pyongyang-connected hackers carried out one of 2026’s largest crypto thefts.
In a report published Wednesday, Chainalysis attributed the Sept. 24 intrusion to individuals associated with the Democratic People’s Republic of Korea (DPRK) and said the theft pushed the total value of crypto stolen by DPRK-linked groups in 2026 above $1 billion.
How the Heist Unfolded
The firm said it worked with Bitget and law enforcement agencies to follow the stolen funds across multiple blockchains. Chainalysis documented how quickly the assets moved: within three hours, the $387 million left Bitget in 23 transfers and was dispersed across four networks — Ethereum (49.7%), XRP (40.8%), Zcash (7.6%) and Tron (1.8%).
After exiting the exchange, the attackers routed funds through cross-chain liquidity and messaging protocols, executed instant swaps, and used laundering services and privacy pools to obscure the trail.
XRP Movement Highlighted
The movement of XRP received particular attention: rather than sending the tokens directly to an exchange, the attackers funneled XRP through a cross-chain liquidity protocol and withdrew Bitcoin on the other side. Tens of millions of dollars moved via that route over roughly a day and a half before arriving in Bitcoin addresses now under surveillance and believed to be controlled by the perpetrators.
AI Accelerated the Investigation
Notably, Chainalysis said it relied on in-house artificial intelligence and custom automation to keep pace with the fast-moving laundering activity. According to the report, the firm compressed what would have been more than 20 hours of manual bridge reconciliation into under 10 minutes. Chainalysis emphasized that AI accelerated analysts’ work rather than replacing human investigators, with people still directing and validating findings.
Context And Reactions
The attribution aligns with prior assessments: Bitget CEO Gracy Chen said the attack’s pattern was consistent with North Korea-linked operators, and the blockchain forensics company Elliptic described a DPRK connection as “highly likely.”
Observers tracked portions of the laundering publicly. The attacker hid funds in Zcash’s shielded pool; swap platforms reacted unevenly — Near Intents rejected more than $50 million in swaps tied to the attacker but was itself compromised days later for about $3.8 million, while Thorchain continued processing swaps. Stablecoin issuers Circle and Tether froze roughly $318,000 linked to the incident.
Takeaway: The Bitget incident underscores how sophisticated cross-chain tooling and privacy services enable fast, complex laundering, and how AI-assisted analytics are becoming essential to tracing and attributing large-scale crypto thefts.
Help us improve.




























