Newsroom

Bitget Hackers Shield $3.9 Million Loot in Zcash Privacy Pool After Blocked Swaps

1 October, 2026   /   News   /  AI   /   Tags:  bitget, thorchain, zcash, ironwood, pool

Bitget Hackers Shield $3.9 Million Loot in Zcash Privacy Pool After Blocked Swaps

Attackers linked to the $387.5 million theft from Bitget have begun concealing about 2,700 Zcash tokens inside the blockchain’s Ironwood pool, obscuring their origins and reducing traceability on the network

Security teams at the crypto exchange Bitget have confirmed that approximately $3.9 million in Zcash was transferred into its shielded Ironwood pool on September 30, marking a significant step in laundering the proceeds of a major breach that occurred nearly a week earlier.

Details of the September 24 Heist

Bitget detected unauthorized transfers out of its hot wallets on September 24, with the initial loss estimate standing at $351.6 million before the company revised the figure to $387.5 million. The exchange stated that its protection fund will cover the full impact, leaving customer balances untouched. CEO Gracy Chen attributed the attack to actors whose IP addresses and transaction patterns closely match those of North Korean operators, calling it the year’s largest suspected North Korean cryptocurrency theft and pushing the total over $1 billion for 2026.

The breach exploited backend systems to generate fake internal transaction data rather than directly stealing private keys.
Bitget CEO Gracy Chen

On-chain analysts identified the initial haul as roughly 18,900 ZEC, of which more than 2,700 were moved into Ironwood. The shielded pool conceals the sender, recipient, and amount of any internal transfers while still allowing external observers to track deposits and withdrawals.

Failure of Cross-Chain Swap Services

Attempts to move the stolen assets through major decentralized swap platforms met resistance. NEAR Intents’ SHIELD screening system rejected over $50 million in transactions tied to the Bitget attacker, freezing roughly $503,000 mid-process and allowing about $166,000 to complete. Thorchain, after being directly approached by Bitget, refused to halt service to the attacker’s addresses, citing its decentralized structure where independent node operators—not a central authority—decide on emergency network pauses.

Despite the blocks, some funds continued circulating. Multiple batches totaling roughly 2,390 ETH, equivalent to about $6.3 million, were swapped into 75.2 BTC through Thorchain in the days following the initial breach.

The Zcash Privacy Solution

Ironwood, which replaced the earlier Orchard pool on July 28, was activated precisely to address earlier concerns over potential counterfeit issuance in shielded transactions. Once the 2,700 ZEC entered the pool on September 30, the funds became significantly harder to follow, as any subsequent internal movements remain encrypted.

Blockchain investigator ZachXBT publicly identified the transfer, noting that it represented roughly one-seventh of the total ZEC taken in the heist. The move occurred after repeated attempts to launder the assets via permissionless swap services had encountered security filters.

ServiceActionFunds Affected (USD)
NEAR IntentsRejected $50M+ in swaps$503,000 frozen; $166,000 passed
ThorchainNo service halt requested2,390 ETH (~$6.3M) converted to BTC

Bitget has offered a public bounty of 5 percent of any funds frozen and another 5 percent of any recovered, excluding court-ordered or law-enforcement actions. The exchange continues to work with investigators to recover the assets and has already stated that its protection fund will be replenished to over $300 million within a week.

Regulatory and Industry Response

Thorchain’s position underscored ongoing debates within the decentralized finance sector about the balance between network neutrality and proactive fraud prevention. The protocol, which had previously halted operations for five weeks following a May exploit, drew criticism for allowing the attacker’s funds to keep moving despite the known origin.

Elliptic, the blockchain analytics firm, described the North Korean connection as highly likely, further cementing the attack’s place among the largest state-linked cryptocurrency incidents of the year.

The incident highlights the persistent challenges in tracing funds once they enter privacy-focused protocols. While Zcash’s shielded pool offers strong protection for users once inside, the entry point itself remains visible to on-chain observers, prompting questions about how exchanges and services should best balance security with user privacy rights.

Associated cryptocurrencies
Disclaimer
This article was generated by AI using information from multiple industry sources. It has not been reviewed or verified by a human editor and may contain inaccuracies, omissions, or misinformation. Readers are encouraged to independently verify any information before making decisions based on its content.
This article is for informational purposes only and does not constitute financial, legal, or investment advice. Cryptocurrency and related investments involve substantial risk, and past performance does not guarantee future results.