Chainalysis Used AI to Trace the $387M Bitget Hack Back to North Korea

Blockchain analytics firm Chainalysis attributed a Sept. 24 $387 million hack of crypto exchange Bitget to actors linked to North Korea, saying the theft pushed Pyongyang-linked crypto takings in 2026 past $1 billion. The company described rapid fund movements across four blockchains and said it used in-house AI tools to accelerate tracing work for investigators.

By AI Newsroom· Reviewed by Pranav, Founder & Editor-in-ChiefPublished less than a minute agoUpdated less than a minute ago0 views
Chainalysis Used AI to Trace the $387M Bitget Hack Back to North Korea

Why It Matters

If correct, the attribution adds another large heist to a series of DPRK-linked crypto thefts this year and highlights how state-linked cybercrime continues to target centralized exchanges. Chainalysis' use of AI to speed cross-chain tracing also illustrates evolving investigative techniques in response to fast, multi-chain laundering operations.

Key Facts

  • Date of breach: Sept. 24, 2026 (reported as last month in source)
  • Amount stolen: $387 million
  • Attribution: Actors tied to the Democratic People's Republic of Korea (North Korea)
  • 2026 total for DPRK-linked crypto thefts: Surpassed $1 billion, per Chainalysis
  • First three hours: number of transfers: 23 transfers out of Bitget in first three hours

Chainalysis concluded in a published report that the Sept. 24 theft of $387 million from Bitget was carried out by actors connected to the Democratic People's Republic of Korea, and that the incident pushed the year-to-date value of crypto stolen by DPRK-linked groups in 2026 past $1 billion. The firm said it collaborated with Bitget and law enforcement in tracing the flows across multiple blockchains.

According to Chainalysis, the stolen funds moved quickly: within three hours the $387 million left Bitget in 23 transfers and was distributed across four networks — Ethereum (49.7% of the funds), XRP (40.8%), Zcash (7.6%) and Tron (1.8%). After the initial moves, attackers used cross-chain liquidity and messaging protocols, instant swaps, and other laundering services to obfuscate the trail.

Chainalysis highlighted that the XRP portion was routed through a cross-chain liquidity protocol and converted into Bitcoin on the other side, with tens of millions of dollars moved that way over roughly a day and a half before arriving at attacker-controlled Bitcoin addresses that are now being monitored. The report also notes activity in Zcash's shielded pool as part of the laundering chain.

To keep pace with those rapid, multi-chain flows, Chainalysis said it employed custom in-house AI automation to compress what it estimated would have been more than 20 hours of manual bridge reconciliation into under 10 minutes, accelerating investigators' work while maintaining human direction of the analysis. The firm's attribution aligns with prior assessments from Bitget's CEO Gracy Chen and the analytics firm Elliptic, both of which flagged a DPRK link as likely.

Keep Reading