Bitget Hacker Moves $3.8M Into Zcash Privacy Pool

The hacker behind the $387.5 million Bitget exploit has moved part of the stolen funds into Zcash’s shielded pool, making the money significantly harder to trace.
On-chain investigator ZachXBT said Wednesday that the attacker transferred around 2,700 ZEC, worth approximately $3.8 million, into Ironwood, a privacy-focused pool on the Zcash network. The amount represents roughly one-seventh of the ZEC obtained from the theft.
Ironwood encrypts transaction details including the sender, recipient and amount. While blockchain observers can identify deposits into and withdrawals from the pool, the transactions taking place inside it are hidden from public view.
The pool launched on July 28 as a replacement for Zcash’s previous Orchard pool. Orchard was retired after researchers identified a vulnerability that could potentially have been used to create counterfeit coins.
The movement into Zcash is the latest step in a broader effort to obscure the stolen assets. Bitget CEO Gracy Chen has linked the attack to North Korean hackers, citing similarities in the attackers’ IP addresses and behavior. Blockchain analytics firm Elliptic has also described a North Korean connection as highly likely, saying the incident is the largest suspected North Korean crypto theft of 2026 and has pushed the group’s estimated yearly haul above $1 billion.
The Bitget attack began on Sept. 24 after the exchange detected unauthorized transfers from its hot wallets. Chen said the attackers compromised backend systems and manipulated transaction data without gaining access to private keys. Bitget has said its user protection fund will cover the losses, leaving customer balances unaffected.
Investigators have tracked the stolen funds through multiple wallets and blockchain networks. TRM Labs said the attacker divided the assets into newly created wallets containing large, round amounts, including roughly 10,000 ETH and 20 million XRP. Smaller portions were moved through cross-chain services such as THORChain, Across, Bridgers, Chainflip and FixedFloat.
Some platforms have blocked attempts to move the stolen assets. Near Intents general manager Alex Shevchenko said its SHIELD screening system rejected more than $50 million in swaps connected to the attacker. Around $503,000 was frozen during swaps, while approximately $166,000 passed through.
The incident has also renewed debate over whether decentralized networks should block transactions associated with hacks. Near co-founder Illia Polosukhin argued that operating as a permissionless network does not require every application to process every transaction.
THORChain, meanwhile, said halting its entire network is an emergency measure designed to protect the protocol rather than a mechanism for freezing individual addresses. The network is controlled by independent node operators who can vote on halts.
Despite the debate, the stolen funds have continued moving. On Monday, several transactions totaling about 2,390 ETH, worth around $6.3 million, were converted into roughly 75.2 BTC through THORChain, according to on-chain data.
THORChain previously halted its network for about five weeks following a $10.7 million exploit on May 15, with operations resuming on June 22.
Bitget is offering a bounty equal to 5% of funds that are frozen and another 5% of funds successfully recovered, excluding amounts recovered through court or law-enforcement orders.
