1. The theft
Bitget's systems detected unauthorised transfers from some of its hot wallets at 18:31 UTC on 24 September. The attackers did not steal private keys. According to CEO Gracy Chen, they compromised a backend system used to process wallet transactions and tricked the exchange's internal approval process into signing off on fraudulent withdrawals. The losses, first put at $351.6 million, were revised to $387.5 million once transactions on Zcash and TRON were added.
The largest single piece of the haul is about 103 million XRP, worth roughly $157 million. Funds left across at least five networks, including Ethereum and other EVM chains, the XRP Ledger, Zcash and TRON. Bitget says its cold storage was untouched and that its $464 million user protection fund covers customer balances. Withdrawals were due to resume in phases from 28 September.

Why North Korea
Bitget's CEO said North Korea was "very likely" behind the attack, citing IP addresses and on-chain patterns matching techniques used by Pyongyang's hackers.
TRM Labs found multiple overlaps with wallets used to launder earlier North Korean thefts, including Bybit and AFX Bridge, pointing to TraderTraitor.
No official attribution yet. Bitget says law enforcement is investigating. Le Détroit found no FBI statement confirming the attribution at the time of writing, unlike for Bybit.

2. Who is TraderTraitor
TraderTraitor is the name the FBI gives to a North Korean hacking group, also tracked as UNC4899 and considered part of the broader Lazarus Group, which is generally attributed to the intelligence services of the Korean People's Army. It has been blamed for the largest thefts in the history of crypto.

If the Bitget theft is confirmed as North Korean, TRM Labs estimates North Korea's crypto thefts in 2026 would reach $1.04 billion, the second-largest year on record after 2025. TRM puts North Korean groups behind nearly three-quarters of all stolen crypto this year. "North Korea keeps stealing from this ecosystem at alarming speed and scale," said Ari Redbord, TRM's global head of policy.

3. How the money is washed
Stealing is the easy part. Turning $387 million of flagged crypto into money a sanctioned state can spend takes a supply chain. ZachXBT's findings, and the transaction graph built with TRM Labs, show one link of that chain in unusual detail.



What the screenshots show
The messages published by ZachXBT come from support channels of services the launderers were using. On 28 September, the account "Melon" asked for help with two bitcoin swaps, saying the bitcoin network had been paused during the outbound process and that he could not find the withdrawals on the blockchain. A support member replied that both swaps were completed. An account called "HELP ME" posted a THORChain transaction link. Two days earlier, "lolo" complained that his funds had not arrived hours after the app showed the exchange as successful, and confirmed he was "Marin" on Telegram when asked.

The same people moving hundreds of millions in stolen funds were filing support tickets like any other user.
4. Is this known? Yes, for years
The division of labour, North Korean hackers stealing and Chinese-speaking brokers laundering, is one of the best-documented patterns in crypto crime.
2020, the first charges. The US Justice Department charged two Chinese nationals, Tian Yinyin and Li Jiadong, with laundering more than $100 million stolen by North Korean hackers between December 2017 and April 2019. The Treasury sanctioned them the same day. The indictment says part of the laundered funds paid for infrastructure used in North Korea's hacking campaigns. The Treasury noted that proceeds of North Korean cyber activity "often end up at Chinese financial institutions".
2025, a nexus. TRM Labs described North Korea, Chinese underground banking and parts of Russian organised crime as an interconnected system, each bringing a different capability: hackers, laundering networks, cash.
2026, an industry. Chainalysis documented a Chinese-language underground laundering ecosystem serving many types of criminals, as US and UK authorities designated networks such as the Prince Group and Huione.
5. The THORChain question
THORChain lets users swap assets between blockchains without an intermediary holding the funds, and without identity checks. It has repeatedly been criticised for not blocking funds from North Korean thefts. After the Kelp DAO exploit, its daily swap volume jumped to $394 million, against a usual level under $35 million, according to The Block. The protocol has held its line: there is no admin key and no single entity in control, so the protocol, in its own words, is "neutral because the code is neutral". According to reports on the Bitget case, it has again declined to block wallets tied to the attackers.


