ZachXBT said on Friday he has no current plans to track the $351.6 million Bitget incident that the exchange has linked to DPRK-linked activity.
The post, published early on September 25, 2026, answers a public question about why he had not issued a thread after Bitget disclosed a large hot-wallet event.
The wording is brief and direct. ZachXBT wrote that he stopped wasting my time helping industry parties that are not supporters of his work, naming donors, clients, longtime followers as the groups he still prioritizes.
The security researcher did not call the event unimportant and did not contest Bitget’s preliminary attribution but he said only that he does not intend to monitor it.
Investigator Draws a Line on Unpaid Work
The remark was a reply to a X user, who suggested ZachXBT may have stayed silent because he had previously warned Bitget. ZachXBT did not confirm that history. He framed the choice as a resource decision, not a verdict on Bitget’s operations or on the suspected actors.
That stance matters because ZachXBT is one of the most-followed independent on-chain investigators in crypto. Market participants often treat his threads as a parallel record when exchanges disclose thefts, especially cases tied to North Korea. His Friday note separates public demand for that work from the support he says he now requires before taking a case.
The denial does not settle attribution. It also does not change Bitget’s claim that customer balances remain intact. It records that a leading independent tracker will not run a public monitor on this file for now.
Why Markets Expected ZachXBT on Bitget
ZachXBT has built a substantial following and credible authority on cases that sit at the center of crypto security, not on commentary alone. The Crypto Times has documented his work on large thefts and suspected North Korea–linked flows, including his early attribution of the 2024 WazirX breach and his later claim that Garden Finance earned most of its recent fees from laundering tied to the $1.4 billion Bybit hack.
In 2026, ZachXBT also pressed Circle over the $285 million Drift exploit, arguing the issuer had hours to freeze stolen USDC as it moved across chains. Those files explain why the crypto community expected him to monitor Bitget after CEO Gracy Chen said the $351.6 million incident showed patterns consistent with DPRK-linked groups.
His docket is broader than exchange hacks. The investigator named alleged operators in social-engineering thefts, including a U.S. case he tied to about $19 million and a separate thread linking a caller to about $5 million in support-impersonation losses. He has also published trails he said produced a Tether freeze after linking an online handle to $667,000 from French robberies, and he spent months warning about LAB before that token collapsed.
This record is why his Bitget reply landed as a policy statement: he is choosing which high-profile security cases still get his time.
What Bitget Has Confirmed So Far
The surrounding facts come from Bitget’s own posts. CEO Gracy Chen published a SECURITY NOTICE on September 24 saying systems flagged unauthorized transfers from some hot wallets at 18:31 UTC. The notice put estimated funds affected at approximately $351.6 million.
Chen said cold wallets remain fully secure, that the loss sits inside a User Protection Fund holding more than $464 million, and that withdrawals were paused pending review while deposits and trading stayed open.
A later update said investigators had initial progress tracing the source to a critical backend system in wallet infrastructure. Chen said private key compromise has been ruled out and that loss containment is confirmed. After a multi-hour livestream, she summarized that affected assets included ETH, XRP, BNB, AVAX, USDT, USDC and other tokens across Ethereum, the XRP Ledger, Arbitrum, Avalanche, Optimism, BNB Chain and Base, and that XRP was the largest single chain loss. She added that IP and on-chain patterns were consistent with techniques used by DPRK-linked hacker groups, while saying authorities had been notified.
Those official details explain why observers expected a ZachXBT thread. His reply leaves the tracing work with Bitget, law enforcement, and any investigators the exchange has engaged. Further primary updates remain on Chen’s and ZachXBT’s X accounts as Bitget prepares the incident report promised after the first notice.
Also read: KelpDAO Sues LayerZero and CEO Bryan Pellegrino in Canada Over $292M rsETH Exploit
