Bitget Hacker Turns to Zcash Privacy Pool After Near Rejects $50M in Swaps
The actor behind the $387.5 million Bitget breach has begun moving part of the proceeds into Zcash's shielded Ironwood pool, depositing about 2,700 ZEC (around $3.8 million) on Sept. 30. Near Intents says its screening system blocked more than $50 million in swaps tied to the theft, while Thorchain declined requests to selectively freeze the attacker's addresses.

Why It Matters
The use of Zcash's privacy pool marks an escalation in laundering tactics that reduce on-chain transparency for investigators, while the split responses from cross-chain services underscore tensions over whether decentralized protocols should or can block illicit funds. The incident also forms part of a larger attribution debate and recovery effort following one of 2026's largest crypto heists.
Key Facts
- Date of Ironwood deposit: Sept. 30, 2026
- Amount moved into Ironwood: About 2,700 ZEC (~$3.8 million)
- Total Bitget theft: $387.5 million
- Near Intents rejections: More than $50 million in swaps blocked; about $503,000 frozen mid-swap; ~$166,000 processed
- Thorchain swaps noted: Roughly 2,390 ETH (~$6.3 million) converted into 75.2 BTC via Thorchain
On Sept. 30, on-chain investigator ZachXBT reported that the address tied to the Bitget breach deposited roughly 2,700 ZEC — about $3.8 million — into Ironwood, the shielded pool on the privacy-focused Zcash network. Ironwood encrypts sender, recipient and amount details for shielded transactions; investigators can see coins enter and exit the pool but not transactions that happen inside. Ironwood replaced Zcash's prior pool, Orchard, after a July security fix addressing a potential counterfeit-coin vulnerability.
The Bitget exploit, which the exchange values at $387.5 million, began Sept. 24 when unauthorized transfers left hot wallets. Bitget said attackers falsified backend transaction data rather than extracting private keys, and the exchange has said its protection fund will cover customer balances. Bitget CEO Gracy Chen has linked the attack's IP addresses and patterns to North Korean actors; analytics firm Elliptic described a North Korean connection as "highly likely" and characterized the theft as the largest suspected North Korean theft of 2026, pushing that year's suspected total above $1 billion.
After the breach, analysts at TRM Labs observed the attacker splitting funds into new addresses holding round amounts (about 10,000 ETH or 20 million XRP each) and routing smaller sums through cross-chain swap services such as Thorchain, Across, Bridgers, Chainflip and FixedFloat. Near Intents said its screening tool SHIELD blocked more than $50 million in swaps linked to the attacker, freezing roughly $503,000 mid-swap while about $166,000 was processed. Near said frozen funds will enter legal and recovery procedures.
Not all services followed Near's approach. Thorchain declined to freeze specific addresses at Bitget's request, reiterating that its emergency halt mechanism is intended to protect the protocol as a whole rather than to selectively freeze particular funds or swaps. Despite that stance, on-chain data show several batches totaling about 2,390 ETH (roughly $6.3 million) were converted into 75.2 BTC through Thorchain.
Bitget has offered a bounty equal to 5% of any funds frozen and an additional 5% of funds recovered, excluding recoveries ordered by courts or law enforcement. Investigators continue to track movements on-chain, but the use of Zcash's Ironwood shielded pool reduces visibility into the attacker's subsequent handling of the deposited ZEC.
Keep Reading
Daines Unveils Crypto Tax Bill Pairing Payment Relief With Wash-Sale Rules

Introducing The Information Exchange on Solana, Powered by Decrypt and MYR

California Bans Public Officials From Issuing Meme Coins Under New Newsom Law

Morning Minute: SEC Clears Token Buybacks for Crypto Networks
Original source: Decrypt