AI Speeds Up Tracing of $387 Million Bitget Exploit Linked to North Korea
Chainalysis deployed in-house AI to compress 20 hours of manual cross-chain tracing into under 10 minutes, following funds across seven blockchains after the massive September 24 exchange breach.
At a glance
- What happened
- Attackers compromised a Bitget backend system on Sept. 24, 2026, stealing up to $387 million by spoofing transaction data to bypass withdrawal controls.
- Why it matters
- The exploit represents the largest crypto theft of 2026 and showcases how advanced threat actors are bypassing private key security by targeting authorization software.
- Who is affected
- Bitget and its users are directly affected, though losses are covered by the exchange's $464 million User Protection Fund.
- What's next
- Chainalysis will present a detailed look at its next-generation AI investigative capabilities on Nov. 19, 2026, as investigators monitor the stolen funds.
- Primary source
- Chainalysis Blog: How AI Helped Chainalysis Investigators Trace the $387 Million North Korea Stole from Bitget
Key points
- Attackers stole $387 million from Bitget on Sept. 24, 2026, by manipulating a backend system to approve unauthorized hot and warm wallet transfers.
- Chainalysis used in-house AI to compress over 20 hours of manual cross-chain bridge reconciliation into under 10 minutes to trace the stolen funds.
- On-chain links to previous Bybit and AFX Bridge hacks strongly suggest the involvement of North Korean threat actors, pushing DPRK's 2026 haul past $1 billion.
A massive security breach at cryptocurrency exchange Bitget on Sept. 24, 2026, resulted in the theft of hundreds of millions of dollars, triggering an intense, AI-assisted tracing effort by blockchain analytics firm Chainalysis 1. The exploit, which targeted Bitget's hot and warm wallets, represents the largest cryptocurrency theft of 2026 by value 4.
While early on-chain estimates placed the loss between $170 million and $190 million by looking only at Ethereum Virtual Machine (EVM) chains, subsequent data revealed a much larger footprint 4. According to Chainalysis, the attackers made off with $387 million 1, while Bitget and TRM Labs identified approximately $351.6 million in losses after accounting for outflows across the XRP Ledger and TRON 4. The incident has pushed the total value of cryptocurrency stolen by North Korean actors in 2026 past the $1 billion mark 1.
The Anatomy of the Exploit
Unlike traditional hacks that rely on compromised private keys, the Bitget exploit targeted the exchange's transaction authorization infrastructure 4. According to Bitget CEO Gracy Chen, the attacker gained access to a backend system connected to the exchange's wallet infrastructure 4. The attacker then spoofed transaction data, manipulating what the authorization systems saw and tricking the exchange's withdrawal controls into approving the transfers 4. Bitget confirmed that its private keys were not stolen and its cold wallets remained unaffected 4.
This attack methodology closely mirrors the February 2025 Bybit exploit, where attackers similarly manipulated the authorization interface to trick signers into approving a transfer 4. In the first three hours after the Bitget breach, $387 million left the exchange across 23 transfers, landing on four primary blockchains: Ethereum ($ETH) (49.7%), XRP ($XRP) (40.8%), Zcash ($ZEC) (7.6%), and TRON ($TRX) (1.8%) 1.
Once the funds left Bitget, the attackers executed a rapid fragmentation strategy 4. On Ethereum, the stolen assets were quickly split among new wallets, many holding round amounts of roughly 10,000 ETH 4. On the XRP Ledger, the funds passed through smaller relay accounts before arriving in separate wallets holding round amounts of 20 million XRP 4.
Accelerating the Chase with AI
To keep pace with the attackers' automated laundering techniques, Chainalysis deployed its in-house AI platform to build custom automation tools for its investigators 1. This agentic platform allowed analysts to interrogate data sources and construct custom solutions tailored to the specific flow of funds 1.
According to Chainalysis, the AI-driven tools compressed more than 20 hours of manual cross-chain bridge reconciliation into under 10 minutes 1. This speed allowed investigators to quickly match deposits to corresponding payouts across decentralized protocols, bridging the gap between disparate blockchains 1. Within minutes of identifying the destination addresses, Chainalysis pushed live labels to its data platform to alert compliance teams and law enforcement agencies 1.
Human investigators remained central to the operation, defining the logic, reviewing the AI's outputs, and directing the overall tracing strategy 1. The automation operated on top of Chainalysis's decade-long database of cross-chain attribution data, allowing investigators to link transactions that would otherwise appear unrelated 1.
The Laundering Trail and the DPRK Connection
While TRM Labs has not definitively attributed the attack, Bitget's preliminary investigation linked the IP addresses used in the exploit to VPN services associated with a North Korean hacking group 4. Furthermore, on-chain tracing has revealed multiple overlaps with wallets used to launder previous North Korean hacks, including the Bybit breach and the AFX Bridge exploit 4. These links run through a specific laundering network that has not been observed working with any other cybercriminal group 4.
To obscure the trail, the attackers pushed the stolen XRP through a cross-chain liquidity protocol, taking Bitcoin ($BTC) out on the other side without needing an intermediary account 1. Other portions of the stolen funds on BNB Chain and Ethereum were swapped through THORChain and split across Bitcoin addresses using peel chains 4. Stolen TRX was swapped for $USDT on SunSwap, moved to Ethereum, and routed through THORChain to be converted into Bitcoin 4.
This highly structured laundering pattern is characteristic of the Democratic People's Republic of Korea (DPRK) 2. Historically, North Korean hackers structure on-chain payments in smaller tranches, with over 60% of their laundering volume concentrated below a $500,000 transfer value 2. They also show a strong preference for cross-chain bridges, mixing services, and Chinese-language money movement and guarantee networks 2.
Implications for Exchange Security
The Bitget exploit highlights a growing vulnerability for centralized exchanges: the susceptibility of backend authorization systems to data manipulation 4. As exchanges implement robust cold-storage solutions to protect private keys, highly sophisticated threat actors are shifting their focus toward the software and systems that control withdrawal approvals 2, 4.
For Bitget, the financial blow was mitigated by its $464 million User Protection Fund, which the exchange stated would cover the entire loss 4. However, the incident underscores the escalating scale of individual breaches 2. In 2025, the ratio between the largest hack and the median of all incidents crossed the 1,000x threshold for the first time, concentrating losses heavily among a few catastrophic events 2.
What to Watch
- Movement of Dormant Funds: As of late September, large portions of the stolen ETH and XRP remained stationary in the initial round-number holding wallets 4. Observers are monitoring these addresses to see when and how they enter the next stage of the laundering cycle 4.
- Bitget's Incident Report: The exchange has promised a detailed incident report, which is expected to clarify how the backend system was compromised and provide further technical evidence regarding North Korean attribution 4.
- Chainalysis Product Reveal: Chainalysis has announced it will showcase the next generation of its AI-assisted investigative capabilities during a public presentation on Nov. 19, 2026 1.
Questions this story raises
- How did the attackers compromise Bitget without stealing private keys?
- The attackers compromised a backend system connected to Bitget's wallet infrastructure. They manipulated the transaction data shown to the exchange's authorization process, tricking the system into approving the transfers from hot and warm wallets automatically.
- What role did artificial intelligence play in the investigation?
- Chainalysis investigators used an in-house AI platform to build custom automation tools. This allowed them to automate the reconciliation of complex cross-chain transactions, reducing a process that normally takes over 20 hours of manual labor down to under 10 minutes.
- Are Bitget user funds safe?
- Yes. Bitget paused withdrawals immediately after detecting the exploit and stated that its $464 million User Protection Fund is sufficient to cover the entirety of the stolen assets. Cold wallets were not affected by the breach.
Sources
- [1] How AI Helped Chainalysis Investigators Trace the $387 Million North Korea Stole from Bitget — Chainalysis Blog, October 1, 2026
- [2] North Korea Drives Record $2 Billion Crypto Theft Year, Pushing All-Time Total to $6.75 Billion — chainalysis.com, October 6, 2026
- [3] 💵 Arche Capital Insights: The debasement trade survives higher rates — archecapital.substack.com, October 5, 2026
- [4] Bitget Loses USD 351.6 Million in Hot Wallet Breach in Likely North Korea Attack — trmlabs.com, September 30, 2026
Written by Basis Desk's newsroom system from the primary sources above and machine-verified against them before publication. Market figures marked "at the time of writing" come from live exchange data. Report an error: corrections@basisdesk.news · corrections policy.
The Daily Brief, in your inbox at 07:00 ET
Five stories, the numbers that moved, what to watch. Three minutes. No hype, no advice, unsubscribe in one click.
Get the big crypto stories first
A few alerts a day at most: major breaking news and the morning brief. Switch off anytime.
Not financial advice. Basis Desk publishes information, not recommendations. Crypto assets are volatile and you can lose what you invest.