AI Tracks North Korea’s $387 Million Bitget Hack in Minutes
North Korea’s crypto thefts in 2026 have surpassed $1 billion, with the latest breach targeting the Bitget exchange. On September 24 at 18:31 UTC, unauthorized transfers drained cryptoassets including ETH, XRP, BNB, AVAX, USDT, and USDC from Bitget’s hot and warm wallets. The initial estimated loss was $351.6 million, but further investigation revealed additional stolen assets on Zcash and Tron, bringing the total to $387.5 million. Bitget CEO Gracy Chen noted that the attack resembled techniques used by DPRK-linked hacking groups, citing IP addresses tied to previously used VPN infrastructure.
The thieves acted swiftly, moving the stolen funds across 23 transfers within three hours. The assets were distributed across four blockchains: Ethereum (49.7%), XRP (40.8%), Zcash (7.6%), and Tron (1.8%). Instead of sending XRP to centralized exchanges where it could be frozen, the attackers used a cross-chain liquidity protocol to convert it into Bitcoin. Chen described the breach as a backend compromise in Bitget’s wallet infrastructure, which allowed the spoofing of transaction data without stealing private keys.
What sets this incident apart is the speed at which Chainalysis traced the stolen funds. Historically, tracking funds across multiple blockchains manually could take over 20 hours. However, Chainalysis developed custom AI automation that reduced this process to under 10 minutes. While investigators defined the matching logic and reviewed every output, the AI handled the repetitive cross-chain legwork, ensuring the trail remained traceable while the thieves were still moving the funds.
Chainalysis’s findings were independently confirmed by Elliptic, which also attributed the attack to North Korean hackers. Elliptic reported that this breach pushed the total suspected North Korean crypto theft in 2026 past $1 billion, spanning over 51 incidents this year. In 2025, Elliptic had tracked more than $2 billion stolen by DPRK-linked actors. The incident highlights the evolving tactics of North Korean hackers, who rely on breaching backends, moving funds across multiple chains, and using privacy coins to obscure the trail. The rapid response by Chainalysis demonstrates the growing importance of automation in crypto forensics to keep pace with these sophisticated threats.