Newsroom
3 October, 2026 / News / AI / Tags: bitget, chainalysis, thorchain, september, minutes

Blockchain analytics firm applied custom AI tools to match cross-chain bridge activity during the September 24 Bitget breach investigation, reducing a multi-hour task to minutes while attributing the attack to North Korean actors
Blockchain analytics firm Chainalysis reported that its in-house artificial intelligence reduced more than 20 hours of manual bridge reconciliation work to under 10 minutes while tracing funds stolen in the September 24, 2026, Bitget exchange breach. The firm estimated the total at approximately $387 million after the exchange revised its initial figure upward.
Bitget systems detected unauthorized transfers at 18:31 UTC on September 24 from segments of its hot and warm wallet infrastructure. Cold wallets and private keys remained secure, according to the exchange. CEO Gracy Chen stated that an attacker compromised a critical backend system, manipulated transaction data, and triggered the authorization process. Later findings pointed to a vulnerability in a third-party security product that allowed credential theft and forged withdrawal commands. Forensic assistance came from Mandiant and SlowMist.
Within the first three hours, Chainalysis recorded 23 transfers totaling about $387 million. The breakdown showed 49.7 percent directed to Ethereum, 40.8 percent to XRP, 7.6 percent to Zcash, and 1.8 percent to Tron. Bitget initially reported losses of $351.6 million before adjusting the estimate to $387.5 million to include additional Zcash and Tron transfers. The exchange stated the revision did not involve further outflows after containment.
Investigators followed stolen XRP through a cross-chain liquidity protocol that paid out Bitcoin rather than routing the tokens directly to an exchange. Tens of millions of dollars moved along this path over roughly a day and a half. Subsequent transfers passed through additional protocols to Bitcoin addresses controlled by the attackers. Chainalysis continues to monitor those destinations and plans to apply further labels as funds move.
The AI-supported automation drew on more than a decade of cross-chain attribution data to connect deposits on one network with payouts on another. Newly identified addresses received stolen-fund labels within minutes and became available to compliance teams through the firm’s data platform. Investigators set the matching rules, checked results, and decided which leads to pursue.
Chainalysis attributed the theft to North Korean actors, stating that the incident pushed the group’s cumulative cryptocurrency thefts in 2026 above $1 billion. Chen initially described IP behavior and VPN infrastructure consistent with known North Korean operations without confirming responsibility at that stage.
Bitget requested that THORChain block attacker addresses after funds began moving through the protocol. THORChain declined, stating that its emergency controls protect overall network security rather than freeze individual wallets. Security firm GoPlus noted differences between THORChain’s validator-controlled vaults and base-layer blockchain validators.
By September 26, Circle and Tether had frozen approximately $318,000 in linked USDC and USDT. Bitget offered separate 5 percent rewards for qualifying assistance that results in frozen assets and for successful recovery. The exchange restored major withdrawals in phases: Bitcoin on September 28, Ether on September 29, and USDT on September 30. Remaining token, fiat, and peer-to-peer withdrawals were scheduled for October 2. Bitget reported that its Protection Fund had returned above $300 million and that a September 29 reserve snapshot showed a 131 percent overall ratio across covered assets, with customer balances unaffected.
Chainalysis said the AI tools accelerated one component of a broader investigation conducted with Bitget and law enforcement partners. The firm continues to track identified addresses as recovery efforts proceed.









