Blockchain analytics firm Chainalysis has formally pinned the September 24 hack of Bitget on hackers tied to North Korea. The haul was $387 million, and the theft pushed North Korea's 2026 total past the $1 billion mark.
The report came out on Wednesday. The exchange's own first estimate of the loss was lower, $351.6 million, so the numbers in public still do not match. Below we go through what the Chainalysis team showed: how fast the money left, the routes, the role of AI in the investigation and which intermediaries managed to freeze anything at all.
Three hours, 23 transfers, four networks
According to Chainalysis, the first three hours after the breach were decisive. In that window $387 million left the exchange, split into 23 transfers. That is almost $17 million per transfer on average, so the hackers did not break the sum into thousands of small operations. They moved it in big chunks.
The money landed on four blockchains. From there the attackers used cross-chain liquidity and messaging protocols, instant swaps and laundering services. That mix makes life hard for investigators, since every step drops the funds into a new environment with its own transaction log.
The firm worked with Bitget and law enforcement from the start of the attack. For investigators it is a race where the attackers' head start is counted in hours.
Ethereum and XRP hold 90% of the loot
The split by network looks like this. Ethereum took 49.7%, roughly $192 million. XRP got 40.8%, about $158 million. Zcash received 7.6%, or $29 million, and Tron only 1.8%, around $7 million.
Together, Ethereum and XRP make up 90.5%.
Zcash showing up on this list is no accident. It is a coin with built-in privacy, and that is where, according to Decrypt on September 30, the attacker started hiding part of the funds, about $3.8 million in ZEC. That is roughly 1% of the total, but the direction of travel is clear.
The XRP that was turned into Bitcoin
The most interesting route involves XRP. The attackers did not cash it out through an exchange, where the tokens could have been stopped. They pushed it through a cross-chain liquidity protocol and pulled Bitcoin out on the other side.
Tens of millions of dollars moved this way over about a day and a half. The final stop is a set of addresses on the Bitcoin network, which Chainalysis is now watching.
Twenty hours of manual work in ten minutes
A separate part of the report is about AI. Chainalysis said it built its own automation to reconcile cross-chain bridges. By its estimate, doing this by hand would have taken more than 20 hours, and the system finished in under 10 minutes. That is a speedup of at least 120 times.
The company stressed that AI only speeds up analysts, and people still set the direction of the investigation. The statement is predictable, but the numbers back it up. When hackers moved $387 million in three hours, every hour of manual reconciliation meant a few more bridges crossed.
The conclusion matches what was said earlier. According to Bitget CEO Gracy Chen, the attack pattern matches North Korean hackers, and the analytics firm Elliptic called a link to the DPRK highly likely. Chainalysis added its own attribution and backed it with the fund routes.
Who refused and who let the money through
The intermediaries reacted differently. Near Intents turned down the hacker's swaps worth more than $50 million, about 13% of the stolen sum. A few days later the protocol itself lost $3.8 million to a withdrawal bug, which we covered separately. THORChain kept processing requests.
Circle and Tether froze about $318,000 in stablecoins. Against $387 million that is 0.08%. The level at which centralized issuers actually managed to step in is tiny, because most of the money went straight into assets with no issuer who can hit the stop button.
North Korea's billion and what to do about it
By Chainalysis's count, DPRK-linked groups have stolen more than $1 billion in 2026. The Bitget attack alone makes up up to 38.7% of that, and that is at the minimum threshold. The higher the real total, the smaller the Bitget share, but the order of magnitude stays the same: a few big hacks a year make up the bulk.
For regular users the takeaway is practical.
- Keep on an exchange only what you can afford to lose.
- Freezing after the fact works poorly, so do not count on it.
- Seed phrases should never be stored online.
Simple things, but they are the ones ignored most often. The next attack will almost certainly take the same path, through bridges and private pools, and the speed of analysts will once again race the speed of hackers.




Comments
Your email address will not be published. Required fields are marked *