Bitget Hackers Evade Detection with Zcash Route Change
The hackers behind the Bitget crypto hack have changed their methods to obscure their tracks. After an attempt to launder over $50 million via NEAR Intents failed, they sent approximately $3.9 million in Zcash into a protected Ironwood pool.
Ironwood is a private Zcash pool where transactions are made difficult to link back to the original funds. This change of route has added complexity for investigators tracking the stolen assets.
The hackers initially tried to launder money through THORChain, but Bitget had publicly requested that addresses linked to the theft be blocked. However, this attempt also failed as THORChain does not have a central authority to freeze accounts directly.
Bitget has reopened withdrawals after several days of suspension and claims customer balances remain intact. The exchange states that the attacker exploited a vulnerability in a third-party security product to obtain high-level internal credentials and send false withdrawal orders.