Chainalysis Links $387 Million Bitget Hack to North Korea

Blockchain analytics firm Chainalysis attributed a $387 million hack of Bitget to North Korea-linked actors, saying the incident raises the total value of North Korea-associated crypto thefts in 2026 above $1 billion. On-chain records indicate some of the stolen XRP was moved and swapped through THORChain.

By AI Newsroom· Reviewed by Pranav, Founder & Editor-in-ChiefPublished 2 minutes agoUpdated 2 minutes ago0 views
Chainalysis Links $387 Million Bitget Hack to North Korea

Why It Matters

Attributing a large exchange theft to a state-linked actor highlights persistent use of crypto for illicit finance and the challenges of tracing and recovering stolen assets. The routing of stolen tokens through cross-chain services such as THORChain shows how attackers exploit decentralized liquidity protocols to obfuscate proceeds.

Key Facts

  • Victim: Bitget
  • Amount stolen: $387 million
  • Attribution: Chainalysis linked the theft to North Korea
  • Impact on 2026 totals: Pushes North Korea-linked crypto thefts above $1 billion in 2026
  • On-chain movement: Stolen XRP was swapped through THORChain

Blockchain intelligence firm Chainalysis has linked a $387 million hack of the crypto exchange Bitget to actors associated with North Korea. According to Chainalysis, adding this theft to previously identified incidents raises the aggregate value of North Korea-linked cryptocurrency thefts for 2026 above $1 billion.

Chainalysis flagged movement of the stolen funds on public ledgers and reported that some of the pilfered XRP was routed through THORChain, a cross-chain liquidity protocol, where the tokens were swapped. The firm's analysis suggests the use of decentralized swapping services to launder or obscure the origin of stolen crypto assets.

The Bitget incident is one of several sizeable thefts in 2026 that Chainalysis attributes to actors linked to North Korea, and it underscores how state-linked groups continue to target centralized platforms and exploit decentralized infrastructure. The public on-chain records cited by Chainalysis provide traceable links between the original theft and subsequent token swaps but do not imply recovery of the funds.

Chainalysis's findings add to ongoing industry and regulatory attention on how illicit actors use a mix of centralized exchanges and decentralized protocols to move and convert stolen crypto. The company’s attribution and transaction tracing illustrate typical analytical methods used to connect on-chain activity to identified threat actors.

Keep Reading