Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    Is ‘Paul Le Roux’ Really Satoshi Nakamoto What the Record Actually Shows
    Is ‘Paul Le Roux’ Really Satoshi Nakamoto? What the Record Actually Shows
    Bitget exchange coin token set in front of a blurred FTX building backdrop.
    Is Bitget the Next FTX? What the $351.6 Million Hack Does and Doesn’t Have in Common
    Gold Bitcoin BTC coin standing vertically in front of a rising green financial candlestick chart
    Inside Bitcoin’s September 2026 Rally: BTC Reclaiming $87K, $2B in ETF Inflows and a Short Squeeze
    CLARITY Act Fails 49-50 in US Senate as SEC & CFTC Move Ahead on Crypto Rules Within 48 Hours
    CLARITY Act Fails 49-50 in US Senate as SEC & CFTC Move Ahead on Crypto Rules Within 48 Hours
    Illustrated collage featuring diverse people surrounded by crypto symbols and a corporate boardroom backdrop.
    Quiet Racism in Crypto Gets “Obvious” During Circle’s Arc Mainnet Launch
  • Opinion
    OpinionShow More
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    The Architecture of Trust Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust: Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust What 4,000 Years of Trade Teach Us About RWA Tokenisation
    The Architecture of Trust: What 4,000 Years of Trade Teach Us About RWA Tokenisation
    One P2P Trade, Months of Limbo Why Innocent Indian Crypto Users Keep Paying the Price
    One P2P Trade, Months of Limbo: Why Innocent Indian Crypto Users Keep Paying the Price
    CLARITY Act The Bill Exists, the Deal Does Not, Trump Has to Wait
    CLARITY Act: The Bill Exists, the Deal Does Not, Trump Has to Wait
  • Learn
    • Explained
    • How To
    • Insights
  • IndicesNew
    • India USDT Premium Index
    • India USDC Premium Index
  • Videos
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • Daily Crypto Puzzles
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • IndicesNew
    • India USDT Premium Index
    • India USDC Premium Index
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
    • Daily Crypto Puzzles
  • Videos
  • Glossary
Follow US
© 2026 By Crypto Times. All Rights Reserved.
Industry

ZachXBT Exposes 5 Launderers Moving $387.5M Bitget Hack Funds for North Korea

Screenshots show the alleged operators seeking help over failed XRP-to-Bitcoin swaps and missing payouts as investigators followed the wallet trail.

Written By Dishita Malvania
Edited by Divya Mistry
Published 1 hour ago·Updated 22 minutes ago
Make The Crypto Times preferred on GoogleGoogle
ZachXBT Exposes 5 Launderers Moving $387.5M Bitget Hack Funds for North Korea
AI Summary
Show
North Korean-linked groups repeatedly launder crypto via THORChain, highlighting vulnerabilities in permissionless cross-chain protocols.
Bitget hack adds $387.5 million to a series of high‑profile thefts attributed to Lazarus Group, raising systemic risk concerns.
Public support requests on Discord/Telegram expose laundering tactics, giving investigators new on‑chain/off‑chain links for future tracking.

On-chain investigator ZachXBT on September 28 published the online identities of five people he says are laundering funds stolen in the $387.5 million Bitget hack. He described the operators as Chinese illicit actors working on behalf of the alleged North Korean attackers, and said they have been openly asking for help with stalled swaps and withdrawals in public support channels run by the services they use.

In his post on X, ZachXBT said the activity was being carried out “on behalf of the alleged DPRK attackers.” DPRK stands for the Democratic People’s Republic of Korea, the official name of North Korea. He added that he has closely tracked these groups across multiple exploits and plans to share more data in the coming weeks.

BREAKING: Chinese illicit actors laundering funds from the $387M Bitget exploit on behalf of the alleged DPRK attackers are openly asking for support with orders in public Discord servers and Telegram channels of services they use.

Notably, Alias 4 (below) was also seen… pic.twitter.com/KfdTo51M2o

— ZachXBT (@zachxbt) September 28, 2026

Five Aliases Named in the Post

The post lists five aliases alongside Discord or Telegram usernames, numeric account IDs, and on-chain transaction hashes. Discord is a group chat platform widely used by crypto projects to run community and support servers. A transaction hash is the unique identifier of a single blockchain transaction.

The aliases are:

  • Cc, using the Discord username cc02006.
  • jack, using the Discord username jack_34808.
  • Melon, using the Discord username under0346, linked to two transactions.
  • lolo / Marin, using the Telegram username pvpcz and the Discord username losern.
  • HELP ME, using the Discord username helpme031897.

The Crypto Times has not independently verified that these accounts belong to the people ZachXBT describes, or that each account matches the transactions listed. Independent confirmation from other blockchain tracing firms is still pending. The full account IDs and transaction hashes are available in ZachXBT’s original post.

Screenshots attached to the thread show the operators contacting support staff for THORChain-linked services about stalled XRP-to-Bitcoin (BTC) swaps, refunded transactions, and missing Bitcoin payouts.

A flow chart in the thread, carrying a TRM Labs watermark, maps wallets from the Bitget exploit into clusters tagged with the same aliases and onward into THORChain. 

TRM Labs is a blockchain intelligence firm. THORChain is a cross-chain protocol that lets users swap native assets, such as XRP and Bitcoin, directly between different blockchains.

A Link to the Kelp DAO Exploit

ZachXBT said the fourth alias, lolo / Marin, was also seen laundering funds from the Kelp DAO exploit earlier this year. Kelp DAO is a liquid restaking protocol that issues rsETH, a token representing restaked Ether (ETH).

On April 18, 2026, attackers drained about 116,500 rsETH, worth roughly $292 million, from Kelp DAO’s bridge built on LayerZero, a cross-chain messaging protocol. Blockchain analytics firm Chainalysis and LayerZero itself later linked the attack to TraderTraitor, a North Korean hacking cluster within the wider Lazarus Group. LayerZero’s post-mortem attributed the incident to TraderTraitor, also tracked as UNC4899, citing research from Mandiant and CrowdStrike.

The Federal Bureau of Investigation (FBI) had earlier named TraderTraitor as the actor behind the February 2025 theft of roughly $1.5 billion from crypto exchange Bybit. ZachXBT said he has seen the same laundering pattern after multiple TraderTraitor-attributed exploits.

In the Kelp DAO case, the attacker routed stolen ETH to Bitcoin through THORChain, sharply lifting the protocol’s trading volume.

How the Bitget Funds Are Moving

ZachXBT said the stolen funds are being “chain-hopped,” or moved across several blockchains through bridges, before being deposited into mixing services such as Wasabi. Wasabi Wallet is a privacy-focused Bitcoin wallet that uses CoinJoin, a technique that combines coins from many users into a single transaction so that individual payments become harder to trace.

That account matches an earlier finding from blockchain compliance firm AMLBot. On September 27, AMLBot reported that about 4 BTC traced to a Bitget TRON wallet had entered a Wasabi CoinJoin round. According to its trace, the funds moved from TRON (TRX) into Tether (USDT), were bridged to Ethereum, swapped for about 145 ETH, and converted through THORChain into roughly 4.59 BTC before being split into the mixer.

The latest disclosure adds a human layer to that on-chain picture. Rather than relying only on private over-the-counter (OTC) trading desks, the operators named by ZachXBT appear to have posted support requests in public channels, shared transaction hashes, and asked staff to complete or troubleshoot swaps. That activity leaves a record of usernames, timing, and service use that investigators can match against blockchain data.

What Bitget Has Confirmed

Bitget’s security systems detected unauthorized transfers from parts of its hot and warm wallet infrastructure at 18:31 Coordinated Universal Time (UTC) on September 24. Hot wallets stay connected to the internet to process routine withdrawals, while warm wallets sit between hot wallets and offline cold storage.

The exchange first put the loss at $351.6 million. On September 25, it raised the figure to about $387.5 million after tracing additional Zcash (ZEC) and TRON transfers from the original attack window, and said the revision did not reflect a second breach. Affected assets included XRP, ETH, USDT, ZEC, USD Coin (USDC), USDT0, Tether Gold (XAUt), BNB, Avalanche (AVAX), and TRX. XRP was the largest single asset taken in the breach, at about 103 million tokens.

Bitget Chief Executive Officer (CEO) Gracy Chen said the attacker compromised a critical backend system, spoofed transaction data, and caused the exchange’s own authorization process to sign the outgoing transfers. Private keys were not stolen, and cold wallets and the separate Bitget Wallet product were not affected. Blockchain security firm GoPlus Security later estimated that about $185 million moved in a single minute during the attack.

On September 28, Bitget gave a more specific account, saying the attacker exploited a vulnerability in a third-party security product to obtain high-level internal credentials and then sent fraudulent withdrawal commands to its wallet system.

Chen has said investigators found IP addresses matching virtual private network (VPN) patterns used by a North Korea-linked group. Blockchain analytics firm Elliptic separately assessed the attack as highly likely to be linked to North Korea, citing on-chain connections to earlier DPRK-attributed thefts, including the Bybit exploit. No government has issued a formal attribution for the Bitget hack. Mandiant and SlowMist are assisting the investigation.

Bitget says the full loss is covered by its User Protection Fund, which held more than $464 million at the time of the incident, according to TRM Labs. The exchange has also offered a 5% bounty on funds frozen or recovered with outside help.

Why the Timing Matters

On September 25, ZachXBT said he had no current plans to monitor the Bitget exploit, adding that he now prioritizes donors, clients, and longtime followers over industry parties that do not support his work.

The September 28 thread does not fully reverse that position. It is a targeted disclosure of alleged laundering intermediaries, not a full reconstruction of the attack.

The post also lands in the middle of a public dispute over THORChain’s role. On September 26, Chen formally asked THORChain to refuse service to the published attacker addresses, writing that decentralization “is a design principle, not a shield for facilitating known stolen funds.” THORChain replied the same day that it is decentralized and permissionless like Bitcoin, Ethereum, and BNB Chain, and has since declined to block the wallets. Stolen XRP continued to swap into Bitcoin through the protocol after that exchange.

The dispute echoes the Bybit case, when the attacker laundered most of the stolen ETH through THORChain within about 10 days.

Withdrawals Restart in Phases

Bitget reopened Bitcoin withdrawals at 08:00 UTC on September 28, the first stage of a phased restart. Under its published schedule, ETH withdrawals are due on September 29, USDT on September 30, and remaining tokens, fiat services and peer-to-peer (P2P) transactions on October 2.

ZachXBT’s post remains the primary public record of the handles, account IDs and transaction hashes. Neither Bitget nor THORChain had publicly responded to the named aliases at the time of writing.

Also Read: Fake GIWA Chain Drained 766 ETH After 1,335 Addresses Bridged Into It

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News

Daily Crypto Puzzles
Tickerdle Tickerdle Crypto Connections Crypto Connections Crypto Crossword Crypto Crossword
TAGGED:BitGetCrypto HackNorth Korea
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link

Daily Crypto Puzzles

Tickerdle crypto game Tickerdle Crypto Connections game Crypto Connections Crypto Crossword game Crypto Crossword

Latest News

A hooded figure working on a laptop in front of an illuminated MEXC logo on a dark wall.
MEXC User Says He Lost $340,000 Through Hacker’s Unrevoked API Key
Michael Saylor speaking in front of a Strategy brand backdrop with an integrated Bitcoin logo.
1,665 BTC Added: Strategy’s Bitcoin Treasury Reaches 847,666 Coins with Latest Purchase
India's ED Expands Crypto & Cyber Tracing Under Renewed NFSU Pact
India’s ED Expands Crypto & Cyber Tracing Under Renewed NFSU Pact
Is ‘Paul Le Roux’ Really Satoshi Nakamoto What the Record Actually Shows
Is ‘Paul Le Roux’ Really Satoshi Nakamoto? What the Record Actually Shows
A gloved hand holding a smartphone displaying the Bitget logo in front of a hooded, shadowed figure.
Bitget Resumes BTC Withdrawals Four Days Following $387.5M Hack

Find Us on Socials

You may also like

Circle Co-Founder Sean Neville and Chief Financial Officer (CFO) Jeremy Fox-Geen

Circle’s CFO and a Co-Founder Depart, With $1.05M Exit Package for the CFO

BlackRock Says AI Agents Could Become Crypto's Next Demand Engine

BlackRock Says AI Agents Could Become Crypto’s Next Demand Engine

An illuminated 3D THORChain logo mounted on a dark wall under spotlights.

THORChain Rejects Bitget CEO’s Request to Block $387.5M Hacker Wallets

Analyst Exposes $18.43M Robinhood Chain Memecoin Rug Pull Ring

Analyst Exposes $18.43M Robinhood Chain Memecoin Rug Pull Ring

The Crypto Times Logo PNG

News

All News
Market News
Bitcoin News
Ethereum News
Altcoin News
Regulations & Policies
DeFi News
Blockchain News
Industry News

Sections

Exclusive
Opinions
Learn
Insights
Videos
Glossary

India Premium Indices

Stablecoins
USDT
USDC

Play

Daily Crypto Puzzles
Tickerdle
Crypto Connections
Crypto Crossword

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy
Contact Us
Career

Follow Us

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information