Wallets linked to the $387.5 million hack of cryptocurrency exchange Bitget have started moving stolen Zcash (ZEC) into the network’s Ironwood shielded pool, on-chain investigator ZachXBT said on Wednesday, September 30.
He said the operators behind the transfers, whom he described as alleged Democratic People’s Republic of Korea (DPRK) attackers, had shielded about 2,700 ZEC, worth roughly $3.8 million. DPRK is the official name of North Korea.
In a post on his Investigations Telegram channel, ZachXBT wrote that the operators “have just begun shielding ~2.7K ZEC ($3.8M) total from the Bitget exploit into the Ironwood pool.” He listed six Ironwood deposit transactions and a transparent source address, t1WgMdtND8NF7NDUuYmq8MpMj1NTCXkMDVG.
The shielded amount is only part of the Zcash taken in the breach. ZachXBT put the ZEC stolen from Bitget’s hot wallet at about 18,900 ZEC, worth roughly $28.3 million, which means the first Ironwood deposits account for about one-seventh of the stolen ZEC.
What Shielding Into Ironwood Means
Zcash supports two kinds of payments. Transparent transactions work like Bitcoin transfers, with sender, recipient, and amount visible on the public ledger. Shielded transactions use zero-knowledge proofs, a cryptographic method that confirms a transaction is valid without revealing its details.
Ironwood is Zcash’s newest shielded pool. It went live with the Network Upgrade 6.3 (NU6.3) at block height 3,428,143 on July 28, 2026, under the rules set out in Zcash Improvement Proposal (ZIP) 258. The upgrade followed the discovery in late May of a soundness flaw in the older Orchard pool, a bug that could in theory have allowed counterfeit ZEC to be created without detection.
New shielded payments now go to Ironwood, and Orchard no longer accepts new deposits. Funds leaving Orchard must pass through a protocol “turnstile” that records how much exits, so the circulating supply can still be checked.
For investigators, the practical effect is limited but real. Anyone can see how much ZEC enters Ironwood from a transparent address. Once inside, transfers hide the sender, recipient, and amount. The coins are not erased, but the public trail stops until funds leave the pool and reach a transparent address again.
Shielding stolen ZEC does not suggest the coins were counterfeit, and it does not change Bitget’s disclosed loss figure. It does raise the cost of tracing the next move. Any stolen ZEC that remains in transparent addresses can still be watched.
ZachXBT also noted that competing privacy projects have argued that threat actors do not use ZEC. The Ironwood deposits run against that claim, at least for this portion of the Bitget funds.
How the Bitget Hack Unfolded
Bitget, a Seychelles-registered centralized exchange, detected unauthorized transfers from parts of its hot and warm wallet infrastructure at 18:31 Coordinated Universal Time (UTC) on September 24. Hot wallets stay connected to the internet to process routine withdrawals, while warm wallets sit between hot and offline storage. The exchange has said its cold wallets and its separately operated self-custody product, Bitget Wallet, were not affected.
Bitget Chief Executive Officer (CEO) Gracy Chen said the attackers did not steal private keys. Instead, they compromised backend systems and spoofed transaction data, so that Bitget’s own authorization process signed the outgoing transfers. Blockchain security firm GoPlus Security later reconstructed a one-minute wave at 19:16 UTC that moved about $185 million, including large Ether (ETH), XRP, and TRON (TRX) transfers. XRP was the largest single asset taken, at about 103 million tokens.
On September 30, blockchain security firm SlowMist and cybersecurity firm Mandiant, both hired by Bitget after the breach, released interim forensic findings showing the attacker had a foothold weeks before any funds moved. SlowMist dated the first malicious activity on a third-party product to August 31 and said a custom withdrawal tool later forged orders that Bitget’s wallet system accepted as valid.
Mandiant said the intruder gained access to third-party security appliances, in one case through a zero-day vulnerability, a flaw unknown to the vendor, before moving into Bitget’s wallet environment. Neither firm named the vendors involved.
The North Korea Attribution
Chen has said IP address and virtual private network (VPN) patterns in the attack resembled earlier DPRK-linked operations. Elliptic has described a North Korea link as highly likely, citing on-chain ties to previous thefts, including activity connected to the February 2025 Bybit hack. Bitget has not released the technical evidence behind its assessment, and no government has formally attributed the attack.
ZachXBT has referred to the incident as a DPRK exploit. On September 25, he said he had no current plans to monitor the case unless supporters backed the work, but he later published the aliases of alleged launderers anyway.
The Laundering Trail Before Ironwood
On September 28, ZachXBT identified what he described as Chinese illicit actors moving Bitget proceeds for the alleged DPRK attackers. He named Discord and Telegram aliases including Cc, Jack, Melon and lolo / Marin, and said they had asked for help in public channels after failed XRP-to-Bitcoin swaps. He added that the Marin alias had also appeared in laundering tied to April’s Kelp DAO exploit, a separate theft researchers have linked to North Korea. The Crypto Times has not independently verified those account-to-person matches.
Cross-chain swap services have been central to the trail. THORChain, a network that lets users swap native assets across blockchains without a central operator, declined Chen’s formal request to refuse service to published attacker addresses, citing its permissionless design.
NEAR Intents, a cross-chain swap protocol, said the attackers tried to route more than $50 million through its network. Only about $669,000 actually reached its rails. Of that, $503,000 was frozen mid-swap and about $166,000 went through.
The Ironwood deposits are the first major ZEC-specific concealment step reported since the theft.
Bitget’s Response on September 30
On the same day as the Ironwood transfers, Bitget said it had restored its User Protection Fund to above $300 million, with an on-chain balance of 3,705 Bitcoin (BTC). The fund, a reserve Bitget set up to cover user losses, held 5,500 BTC, worth about $464 million, when the breach was disclosed and was used to absorb the loss.
Bitget’s 47th proof-of-reserves (PoR) report, based on a snapshot taken at 09:00 UTC on September 29, put its overall reserve ratio at 131% across 19 assets.
Withdrawals are returning in phases. Bitget reopened BTC withdrawals at 08:00 UTC on September 28 and ETH withdrawals on September 29. Tether (USDT) was scheduled for September 30, with remaining assets and peer-to-peer (P2P) services due on October 2. The exchange has also offered a 5% bounty on frozen or recovered funds.
What Remains Open
Several questions are unresolved. The SlowMist and Mandiant findings are interim and do not name the compromised third-party products. It is not clear how much of the roughly 18,900 stolen ZEC remains in transparent addresses, or how much will follow the first 2,700 ZEC into Ironwood. Bitget has not disclosed how much of the $387.5 million has been frozen compared with how much has been swapped into Bitcoin. No state has formally attributed the hack.
ZachXBT framed the Ironwood deposits as the start of the shielding process, not the end of it. The public record still shows the source address, the deposit transactions, and the amount that entered the pool. What happens next is, by design, harder to see.
Also Read: Coinbase Accused of Hiding Hack Losses and $25M in Unrepaid Client Funds
