Summary
- Since $387 million was stolen from Bitget on September 24, Chainalysis investigators have been working with the exchange and law enforcement partners to trace the stolen funds across multiple blockchains and protocols.
- Our team quickly built custom tooling and automation for the investigation using our in-house AI. This helped investigators reduce tracing time, connect seemingly fragmented on-chain activity, and uncover new links across the investigation.
- The DPRK-attributed attack pushes the total value of crypto stolen by North Korea actors in 2026 past $1 billion. In the coming weeks, our team will continue to monitor the stolen funds, label linked addresses, and share intelligence with counterparts.
When Chainalysis began tracing the $387 million stolen from Bitget last week, we knew the actors behind the exploit would move quickly. So our investigators leveraged in-house AI to create custom automations that matched their speed.
In a round-the-clock war room, our Customer Outcomes team kept Bitget and law enforcement partners updated with the latest insights Chainalysis derived while following the money. We boosted our efforts by building custom automation tools to move fast, cutting out manual tracing of complex transactions across multiple blockchains and reconciling activity at each step. We estimate that more than 20 hours of manual bridge reconciliation was compressed to under 10 minutes.
As can be seen in the graph below, which shows a portion of the transfers, hundreds of transfers have been carried out since the attack began. The funds were transferred between different networks, such as from Ethereum to Bitcoin.
This wasn’t simply an AI-assisted tool to help our investigators build graphs. Our agentic platform gives our experts the ability to interrogate Chainalysis and other data sources to quickly develop custom solutions tailored to the specific investigation.
Importantly, this did not replace our investigative expertise. Rather, it accelerated it. Our investigators still defined the logic, reviewed the outputs, and directed the investigation.
The ability to quickly identify and understand illicit activity is increasingly important as DPRK and other threat actors use sophisticated automation to move and obscure stolen funds. Investigators must keep pace with these tactics while applying the judgment and expertise needed to make sense of complex on-chain activity.
That makes speed a critical part of the investigative process. Within minutes of identification, labels flagging stolen funds were live in our data platform, giving compliance teams and law enforcement the data they needed to act.
Reconstructing the path of stolen funds
In the first three hours after the exploit, $387 million left Bitget across 23 transfers, landing on four chains: Ethereum (49.7%), XRP (40.8%), Zcash (7.6%), and Tron (1.8%), as shown below. From there, we identified distinct laundering mechanisms used by the threat actors, from cross-chain liquidity and messaging protocols to instant swaps. We also identified links to laundering services.
Our investigators’ ability to reconstruct the movements of funds across pathways using the custom tooling was particularly important for the stolen XRP. Rather than sending the XRP to an exchange, the attackers pushed it through a cross-chain liquidity protocol and took Bitcoin out the other side.
In simple terms, such protocols let someone deposit one asset on one chain and receive a different asset on another without an account or intermediary connecting the two sides. But each swap still leaves an on-chain record.
Our investigators matched deposits to their corresponding payouts, bridging the gap between blockchains and extending the trail.
Tens of millions of dollars moved through this mechanism over roughly a day and a half. We traced those funds to their destinations and continued following them through subsequent transactions, including through several on-chain protocols, before reaching attacker-controlled Bitcoin addresses now being monitored. This tracing was possible because the automation operated on top of the cross-chain attribution data Chainalysis has built over more than a decade — connecting activity across protocols that would otherwise appear unrelated.
The visual below is a condensed version of part of the transfers made after the attack and the use of various services, such as bridges, mixers, and decentralized exchanges.
What comes next
The work is not done. In the coming weeks, we’ll continue using our custom tooling to monitor the stolen funds and label newly identified destination addresses, while working with exchanges, issuers, and law enforcement partners to trace the funds and support efforts to disrupt their movement.
This work also offers a glimpse of what’s possible with the next generation of our investigative capabilities. Tune in on November 19 to learn more.
FAQ
What happened in the Bitget Exploit?
On September 24, 2026, DPRK-attributed threat actors stole $387 million from cryptocurrency exchange Bitget. Within three hours, the stolen funds had moved across four blockchains: Ethereum (49.7%), XRP (40.8%), Zcash (7.6%), and Tron (1.8%). The attackers then used cross-chain liquidity and messaging protocols, instant swaps, and laundering services to move and obscure the funds.
How did Chainalysis use AI to trace the stolen funds?
Chainalysis investigators used in-house AI to build custom automations that accelerated complex, cross-chain tracing. In one example, more than 20 hours of manual bridge reconciliation was compressed to under 10 minutes. Investigators also used cross-chain attribution data built over more than a decade to match deposits and payouts across protocols and extend the trail across blockchains.
Did AI replace human investigators?
No. Our investigators still defined the logic, reviewed outputs, and directed the investigation. AI automated time-consuming manual work and helped investigators interrogate complex on-chain activity more quickly, while human judgment and expertise remained central to interpreting the results and deciding where to investigate next.
How does this tracing help exchanges and law enforcement?
Chainalysis labels flagging stolen funds were added to our platform, giving exchanges and law enforcement visibility into the movement of the assets. This intelligence can support efforts to identify, freeze, or block stolen funds. Chainalysis will continue monitoring the funds, labeling newly identified addresses, and sharing intelligence with exchanges, issuers, and law enforcement partners.
How does this attack fit into broader North Korean crypto theft activity?
The theft brings the total value of crypto stolen by North Korea-attributed actors in 2026 to more than $1 billion. Moreover, the ability to quickly identify and understand illicit activity is increasingly important as North Korea increasingly uses sophisticated automation to move and obscure stolen funds. Investigators must keep pace with these tactics while applying the judgment and expertise needed to make sense of complex on-chain activity.
This website contains links to third-party sites that are not under the control of Chainalysis, Inc. or its affiliates (collectively “Chainalysis”). Access to such information does not imply association with, endorsement of, approval of, or recommendation by Chainalysis of the site or its operators, and Chainalysis is not responsible for the products, services, or other content hosted therein.
This material is for informational purposes only, and is not intended to provide legal, tax, financial, or investment advice. Recipients should consult their own advisors before making these types of decisions. Chainalysis has no responsibility or liability for any decision made or any other acts or omissions in connection with Recipient’s use of this material.
Chainalysis does not guarantee or warrant the accuracy, completeness, timeliness, suitability or validity of the information in this report and will not be responsible for any claim attributable to errors, omissions, or other inaccuracies of any part of such material.









Be the first to comment