Newsroom
1 October, 2026 / News / AI / Tags: bitget, thorchain, zcash, ironwood, pool

Attackers linked to the $387.5 million theft from Bitget have begun concealing about 2,700 Zcash tokens inside the blockchain’s Ironwood pool, obscuring their origins and reducing traceability on the network
Security teams at the crypto exchange Bitget have confirmed that approximately $3.9 million in Zcash was transferred into its shielded Ironwood pool on September 30, marking a significant step in laundering the proceeds of a major breach that occurred nearly a week earlier.
Bitget detected unauthorized transfers out of its hot wallets on September 24, with the initial loss estimate standing at $351.6 million before the company revised the figure to $387.5 million. The exchange stated that its protection fund will cover the full impact, leaving customer balances untouched. CEO Gracy Chen attributed the attack to actors whose IP addresses and transaction patterns closely match those of North Korean operators, calling it the year’s largest suspected North Korean cryptocurrency theft and pushing the total over $1 billion for 2026.
On-chain analysts identified the initial haul as roughly 18,900 ZEC, of which more than 2,700 were moved into Ironwood. The shielded pool conceals the sender, recipient, and amount of any internal transfers while still allowing external observers to track deposits and withdrawals.
Attempts to move the stolen assets through major decentralized swap platforms met resistance. NEAR Intents’ SHIELD screening system rejected over $50 million in transactions tied to the Bitget attacker, freezing roughly $503,000 mid-process and allowing about $166,000 to complete. Thorchain, after being directly approached by Bitget, refused to halt service to the attacker’s addresses, citing its decentralized structure where independent node operators—not a central authority—decide on emergency network pauses.
Despite the blocks, some funds continued circulating. Multiple batches totaling roughly 2,390 ETH, equivalent to about $6.3 million, were swapped into 75.2 BTC through Thorchain in the days following the initial breach.
Ironwood, which replaced the earlier Orchard pool on July 28, was activated precisely to address earlier concerns over potential counterfeit issuance in shielded transactions. Once the 2,700 ZEC entered the pool on September 30, the funds became significantly harder to follow, as any subsequent internal movements remain encrypted.
Blockchain investigator ZachXBT publicly identified the transfer, noting that it represented roughly one-seventh of the total ZEC taken in the heist. The move occurred after repeated attempts to launder the assets via permissionless swap services had encountered security filters.
| Service | Action | Funds Affected (USD) |
|---|---|---|
| NEAR Intents | Rejected $50M+ in swaps | $503,000 frozen; $166,000 passed |
| Thorchain | No service halt requested | 2,390 ETH (~$6.3M) converted to BTC |
Bitget has offered a public bounty of 5 percent of any funds frozen and another 5 percent of any recovered, excluding court-ordered or law-enforcement actions. The exchange continues to work with investigators to recover the assets and has already stated that its protection fund will be replenished to over $300 million within a week.
Thorchain’s position underscored ongoing debates within the decentralized finance sector about the balance between network neutrality and proactive fraud prevention. The protocol, which had previously halted operations for five weeks following a May exploit, drew criticism for allowing the attacker’s funds to keep moving despite the known origin.
Elliptic, the blockchain analytics firm, described the North Korean connection as highly likely, further cementing the attack’s place among the largest state-linked cryptocurrency incidents of the year.
The incident highlights the persistent challenges in tracing funds once they enter privacy-focused protocols. While Zcash’s shielded pool offers strong protection for users once inside, the entry point itself remains visible to on-chain observers, prompting questions about how exchanges and services should best balance security with user privacy rights.









