Chainalysis Links $387M Bitget Hack to DPRK-Linked Actors After 23 Transfers

Last Updated:
Scammers Amassed $241 Million Via Pump-and-Dump Scheme, Says Analyst
Google News

Get our latest news first. Add us as your Preferred Source on Google and tap "Star" to prioritize our updates.

Chainalysis has linked the $387 million Bitget hack to DPRK-linked actors after attackers moved funds across four blockchains. The firm said transfers began after the exploit and involved 23 transactions within three hours.

Ethereum carried 49.7% of the funds, while XRP accounted for 40.8%. Zcash represented 7.6%, and Tron handled 1.8%. Chainalysis tracked hundreds of transfers as the attackers moved assets between networks.

Cross-Chain Tracking

Chainalysis said investigators used custom automation to reconstruct transactions across multiple blockchains. The tools reduced more than 20 hours of bridge reconciliation work to under 10 minutes.

Source: Chainalysis

The stolen XRP presented a tracing challenge. Attackers routed the tokens through a cross-chain liquidity protocol rather than an exchange. They received Bitcoin on another network through the process.

Related: NEAR Intents $3.8 Million Exploit: What Users Should Know and Do

Funds Continue Moving

Each swap created an on-chain record that investigators could match across networks. Tens of millions of dollars moved through the mechanism for roughly 36 hours.

Chainalysis also identified instant swaps, cross-chain messaging protocols and laundering services. Investigators traced the funds into Bitcoin addresses controlled by the attackers.

The firm said it will continue tracking the identified addresses and coordinating with exchanges, issuers and law enforcement.

Related: U.S. Treasury Targets A7 Network Over Iran Sanctions Evasion

Disclaimer: The information presented in this article is for informational and educational purposes only. The article does not constitute financial advice or advice of any kind. Coin Edition is not responsible for any losses incurred as a result of the utilization of content, products, or services mentioned. Readers are advised to exercise caution before taking any action related to the company.