-
Blockchain investigator ZachXBT says Chinese groups are helping move stolen crypto from the Bitget hack.
-
Bitget confirmed hackers stole $387.5 million after breaking into a backend wallet system.
-
Blockchain firm Elliptic says the attack matches North Korea’s usual pattern, and 2026 losses now top $1 billion.
A blockchain investigator says people are helping move stolen crypto from one of 2026’s biggest exchange hacks.
On September 28, researcher ZachXBT shared new findings online. He said suspected Chinese money launderers are working with the alleged North Korean attackers behind the theft. Some of them are asking for help inside public Discord and Telegram groups. Crypto-swapping services run these groups, according to his post, and users there often trade tips on moving funds quickly.
His report follows a security breach that Bitget confirmed days earlier. The exchange said hackers took a huge sum from its wallets on September 24. Crypto exchanges hold large amounts of digital cash for millions of users. That makes them a constant target for skilled attackers. Big hacks like this one shake trust in exchanges across the industry.
Bitget Confirms the $387.5 Million Breach
On September 24, attackers pulled funds from several Bitget hot and warm wallets. Hot and warm wallets stay connected to the internet, so exchanges can process trades fast. Bitget first put the loss at $351.6 million.
The initial figure was widely reported at the time, as covered in our story, Bitget gets hacked, reports $351 million crypto loss as stolen funds convert to ETH. The exchange later raised that number after tracking extra funds moved through Zcash and TRON.
Bitget said its cold wallets stayed safe during the attack. Cold wallets stay offline, which keeps them far harder to reach. According to CEO Gracy Chen, the hackers never got hold of Bitget’s private keys. Instead, they broke into a backend system inside the wallet setup. They then faked transaction data to slip past normal checks, allowing transfers to go through unnoticed. The trick worked because the backend system trusted the fake data as real.
Bitget says it found and fixed the security gap soon after the attack. The exchange is now working with cybersecurity firms Mandiant and SlowMist. Together, they are digging into exactly how the breach happened and who carried it out. Bitget said it will share more updates once the investigation moves forward. Decrypt also broke down the timeline of events shortly after the hack.
ZachXBT Tracks Where the Stolen Money Went
ZachXBT’s September 28 post named five online aliases tied to the laundering effort. These include CC, jack, Melon, lolo (also called Marin), and HELP ME. He shared transaction records and account details tied to each name.
Screenshots attached to the post show users complaining about failed crypto swaps. One account reportedly sent 277,724 XRP but only got back 431 XRP in return. That kind of mistake suggests the laundering process is not running smoothly for everyone involved. Even skilled criminal networks can run into technical trouble.
According to ZachXBT, the stolen funds moved across several blockchains before landing anywhere safe. Attackers reportedly used cross-chain bridges first. Then they sent the money through mixing tools such as Wasabi, which blend crypto from many users to hide where it came from.
He linked the alias lolo to an earlier hack. That earlier attack hit Kelp DAO and cost the platform $292 million. ZachXBT said the laundering pattern in that case looks a lot like this one.
He also compared the activity to past attacks tied to TraderTraitor. TokenPost reported that TraderTraitor is a hacking group experts often link to North Korea. The group has hit several exchanges and crypto platforms over the past few years. Investigators say its methods keep evolving with each new attack.
Elliptic Ties the Attack to North Korea
Blockchain analytics firm Elliptic backed up the North Korea theory in its own report. The firm said several clues make a North Korea link highly likely, based on wallet behavior and past attack patterns.
According to Elliptic, funds from the Bitget hack connect to wallet addresses used in past North Korea-linked thefts. The firm said this attack pushed its 2026 tracker for suspected North Korea crypto theft above $1 billion. Fortune also covered the scale of North Korea’s crypto theft operations this year.
Still, no law enforcement agency has confirmed North Korea’s role in this case. Reports keep describing the country as the suspected source. Meanwhile, Bitget and outside investigators continue tracing the stolen assets across different wallets and platforms. Recovering stolen crypto often takes months, and sometimes it never happens at all.
Some posts on X named two individuals, Wang Yicong and Xiao He, as members of a wider money-laundering network. These names have not been independently confirmed by reliable sources. Readers should treat them as claims, not confirmed facts, until more proof appears.
ZachXBT said his investigation is ongoing, and more names could surface soon. He expects to share additional details about the laundering networks in the coming weeks. For now, the stolen funds keep moving, and investigators keep watching every step. The case stands as one of the biggest crypto thefts recorded so far in 2026.