On-chain investigator ZachXBT on September 28 published the online identities of five people he says are laundering funds stolen in the $387.5 million Bitget hack. He described the operators as Chinese illicit actors working on behalf of the alleged North Korean attackers, and said they have been openly asking for help with stalled swaps and withdrawals in public support channels run by the services they use.
In his post on X, ZachXBT said the activity was being carried out “on behalf of the alleged DPRK attackers.” DPRK stands for the Democratic People’s Republic of Korea, the official name of North Korea. He added that he has closely tracked these groups across multiple exploits and plans to share more data in the coming weeks.
Five Aliases Named in the Post
The post lists five aliases alongside Discord or Telegram usernames, numeric account IDs, and on-chain transaction hashes. Discord is a group chat platform widely used by crypto projects to run community and support servers. A transaction hash is the unique identifier of a single blockchain transaction.
The aliases are:
- Cc, using the Discord username cc02006.
- jack, using the Discord username jack_34808.
- Melon, using the Discord username under0346, linked to two transactions.
- lolo / Marin, using the Telegram username pvpcz and the Discord username losern.
- HELP ME, using the Discord username helpme031897.
The Crypto Times has not independently verified that these accounts belong to the people ZachXBT describes, or that each account matches the transactions listed. Independent confirmation from other blockchain tracing firms is still pending. The full account IDs and transaction hashes are available in ZachXBT’s original post.
Screenshots attached to the thread show the operators contacting support staff for THORChain-linked services about stalled XRP-to-Bitcoin (BTC) swaps, refunded transactions, and missing Bitcoin payouts.
A flow chart in the thread, carrying a TRM Labs watermark, maps wallets from the Bitget exploit into clusters tagged with the same aliases and onward into THORChain.
TRM Labs is a blockchain intelligence firm. THORChain is a cross-chain protocol that lets users swap native assets, such as XRP and Bitcoin, directly between different blockchains.
A Link to the Kelp DAO Exploit
ZachXBT said the fourth alias, lolo / Marin, was also seen laundering funds from the Kelp DAO exploit earlier this year. Kelp DAO is a liquid restaking protocol that issues rsETH, a token representing restaked Ether (ETH).
On April 18, 2026, attackers drained about 116,500 rsETH, worth roughly $292 million, from Kelp DAO’s bridge built on LayerZero, a cross-chain messaging protocol. Blockchain analytics firm Chainalysis and LayerZero itself later linked the attack to TraderTraitor, a North Korean hacking cluster within the wider Lazarus Group. LayerZero’s post-mortem attributed the incident to TraderTraitor, also tracked as UNC4899, citing research from Mandiant and CrowdStrike.
The Federal Bureau of Investigation (FBI) had earlier named TraderTraitor as the actor behind the February 2025 theft of roughly $1.5 billion from crypto exchange Bybit. ZachXBT said he has seen the same laundering pattern after multiple TraderTraitor-attributed exploits.
In the Kelp DAO case, the attacker routed stolen ETH to Bitcoin through THORChain, sharply lifting the protocol’s trading volume.
How the Bitget Funds Are Moving
ZachXBT said the stolen funds are being “chain-hopped,” or moved across several blockchains through bridges, before being deposited into mixing services such as Wasabi. Wasabi Wallet is a privacy-focused Bitcoin wallet that uses CoinJoin, a technique that combines coins from many users into a single transaction so that individual payments become harder to trace.
That account matches an earlier finding from blockchain compliance firm AMLBot. On September 27, AMLBot reported that about 4 BTC traced to a Bitget TRON wallet had entered a Wasabi CoinJoin round. According to its trace, the funds moved from TRON (TRX) into Tether (USDT), were bridged to Ethereum, swapped for about 145 ETH, and converted through THORChain into roughly 4.59 BTC before being split into the mixer.
The latest disclosure adds a human layer to that on-chain picture. Rather than relying only on private over-the-counter (OTC) trading desks, the operators named by ZachXBT appear to have posted support requests in public channels, shared transaction hashes, and asked staff to complete or troubleshoot swaps. That activity leaves a record of usernames, timing, and service use that investigators can match against blockchain data.
What Bitget Has Confirmed
Bitget’s security systems detected unauthorized transfers from parts of its hot and warm wallet infrastructure at 18:31 Coordinated Universal Time (UTC) on September 24. Hot wallets stay connected to the internet to process routine withdrawals, while warm wallets sit between hot wallets and offline cold storage.
The exchange first put the loss at $351.6 million. On September 25, it raised the figure to about $387.5 million after tracing additional Zcash (ZEC) and TRON transfers from the original attack window, and said the revision did not reflect a second breach. Affected assets included XRP, ETH, USDT, ZEC, USD Coin (USDC), USDT0, Tether Gold (XAUt), BNB, Avalanche (AVAX), and TRX. XRP was the largest single asset taken in the breach, at about 103 million tokens.
Bitget Chief Executive Officer (CEO) Gracy Chen said the attacker compromised a critical backend system, spoofed transaction data, and caused the exchange’s own authorization process to sign the outgoing transfers. Private keys were not stolen, and cold wallets and the separate Bitget Wallet product were not affected. Blockchain security firm GoPlus Security later estimated that about $185 million moved in a single minute during the attack.
On September 28, Bitget gave a more specific account, saying the attacker exploited a vulnerability in a third-party security product to obtain high-level internal credentials and then sent fraudulent withdrawal commands to its wallet system.
Chen has said investigators found IP addresses matching virtual private network (VPN) patterns used by a North Korea-linked group. Blockchain analytics firm Elliptic separately assessed the attack as highly likely to be linked to North Korea, citing on-chain connections to earlier DPRK-attributed thefts, including the Bybit exploit. No government has issued a formal attribution for the Bitget hack. Mandiant and SlowMist are assisting the investigation.
Bitget says the full loss is covered by its User Protection Fund, which held more than $464 million at the time of the incident, according to TRM Labs. The exchange has also offered a 5% bounty on funds frozen or recovered with outside help.
Why the Timing Matters
On September 25, ZachXBT said he had no current plans to monitor the Bitget exploit, adding that he now prioritizes donors, clients, and longtime followers over industry parties that do not support his work.
The September 28 thread does not fully reverse that position. It is a targeted disclosure of alleged laundering intermediaries, not a full reconstruction of the attack.
The post also lands in the middle of a public dispute over THORChain’s role. On September 26, Chen formally asked THORChain to refuse service to the published attacker addresses, writing that decentralization “is a design principle, not a shield for facilitating known stolen funds.” THORChain replied the same day that it is decentralized and permissionless like Bitcoin, Ethereum, and BNB Chain, and has since declined to block the wallets. Stolen XRP continued to swap into Bitcoin through the protocol after that exchange.
The dispute echoes the Bybit case, when the attacker laundered most of the stolen ETH through THORChain within about 10 days.
Withdrawals Restart in Phases
Bitget reopened Bitcoin withdrawals at 08:00 UTC on September 28, the first stage of a phased restart. Under its published schedule, ETH withdrawals are due on September 29, USDT on September 30, and remaining tokens, fiat services and peer-to-peer (P2P) transactions on October 2.
ZachXBT’s post remains the primary public record of the handles, account IDs and transaction hashes. Neither Bitget nor THORChain had publicly responded to the named aliases at the time of writing.
Also Read: Fake GIWA Chain Drained 766 ETH After 1,335 Addresses Bridged Into It
