Crypto

AI Helps Chainalysis Trace $387M Bitget Hack to North Korea in Minutes, Not Hours

Published

on

A massive cryptocurrency hack that drained $387 million from exchange Bitget has been traced to North Korean state-linked actors, according to blockchain analytics firm Chainalysis, which says it used in-house artificial intelligence to compress weeks of forensic work into a matter of minutes.

The breach, discovered on September 24, is now one of the largest crypto heists of the year and has pushed the total value of digital assets stolen by North Korean operatives in 2026 past the $1 billion mark, Chainalysis said in a report published October 1. The firm’s findings underscore just how quickly stolen funds can vanish across blockchains — and how investigators are racing to keep pace using the same kind of automation increasingly deployed by the attackers themselves.

A cryptocurrency hack unfolds in hours, not days

Bitget said its systems flagged unauthorized transfers at 18:31 UTC on September 24, originating from parts of its hot and warm wallet infrastructure. Within the first three hours of the attack, 23 separate transfers moved roughly $387 million out of the exchange and across four different blockchains: Ethereum (49.7%), XRP (40.8%), Zcash (7.6%) and Tron (1.8%).

Bitget initially estimated losses at $351.6 million before revising the figure upward to $387.5 million after accounting for additional Zcash and Tron movements. CEO Gracy Chen said the attacker compromised a critical backend system, manipulated transaction data and triggered the platform’s withdrawal-authorization process, while cold wallets and private keys remained untouched. A later investigation, supported by forensic firms Mandiant and SlowMist, traced the breach to a vulnerability in a third-party security product that let attackers harvest credentials and forge withdrawal commands.

Advertisement

Chen’s early public statements pointed to IP behavior and VPN infrastructure consistent with known North Korean hacking patterns, though she stopped short of formal attribution at the time. Chainalysis has since gone further, directly attributing the exploit to Democratic People’s Republic of Korea-linked actors — a now-familiar signature in a string of high-profile crypto thefts tied to Pyongyang’s efforts to fund its weapons programs through cybercrime.

How AI reshaped the investigation

What set this case apart, according to Chainalysis, was the speed at which its investigators could reconstruct the flow of stolen money across disparate blockchains. The firm said its team built custom automation tools powered by its in-house AI within a round-the-clock “war room,” coordinating directly with Bitget and law enforcement partners as the attackers moved funds.

The headline figure: more than 20 hours of manual work reconciling cross-chain bridge transactions was reduced to under 10 minutes. That kind of acceleration mattered because the thieves were using sophisticated, automated techniques of their own to fragment and obscure the money trail — swapping assets between networks, routing funds through liquidity protocols, and funneling proceeds toward laundering services.

Chainalysis was careful to frame the AI’s role as a force multiplier rather than a replacement for human judgment. “Our investigators still defined the logic, reviewed the outputs, and directed the investigation,” the firm said in its report, emphasizing that analysts set the matching rules and reviewed every automated output before acting on it. Newly identified wallet addresses tied to the stolen funds were labeled within minutes inside Chainalysis’s data platform, giving compliance teams at exchanges and law enforcement agencies real-time intelligence to act on.

Advertisement

One notable thread involved stolen XRP. Investigators discovered that tens of millions of dollars in XRP passed through a cross-chain liquidity protocol over roughly a day and a half, emerging on the other side as Bitcoin rather than landing directly on an exchange. By matching deposits on one network with payouts on another — a process Chainalysis says its AI dramatically sped up — investigators followed the funds through several additional protocols until they reached Bitcoin addresses believed to be under the attackers’ control.

Fallout across the industry

The Bitget cryptocurrency hack also triggered friction between the exchange and decentralized protocols caught in the middle of the laundering trail. Chen publicly pressed THORChain, a cross-chain liquidity network through which stolen funds passed, to block the attacker’s addresses. THORChain declined, arguing that its emergency controls exist to protect overall network security rather than to freeze individual wallets — a distinction Chen rejected, arguing that decentralization shouldn’t provide cover for facilitating known stolen funds.

Security firm GoPlus weighed in on the dispute, noting that THORChain’s validator-controlled vaults and signing architecture give its operators a degree of control that differs meaningfully from the way validators function on base-layer blockchains like Bitcoin or Ethereum — complicating THORChain’s comparison of itself to fully permissionless networks.

Meanwhile, stablecoin issuers Circle and Tether have reportedly frozen a combined set of addresses linked to the stolen funds, and Bitget has offered a 5% bounty for information leading to the freezing or recovery of the missing assets. Chainalysis said its team will continue monitoring the attacker-controlled wallets and sharing intelligence with partners as the funds continue to move.

Advertisement

The episode adds to a growing body of evidence that North Korea’s cyber units remain among the most prolific and effective threats in the crypto industry, repeatedly exploiting weaknesses in exchange infrastructure and third-party security tools. For an industry still grappling with how to secure increasingly complex, multi-chain systems, the Bitget case is also something of a proof of concept for defenders: AI-assisted tracing may be narrowing the head start that attackers have traditionally enjoyed once a cryptocurrency hack goes live.

Related reading:
Sources:

You must be logged in to post a comment Login

Leave a Reply

Cancel reply

Trending

Exit mobile version