The plot thickens in the massive $387 million Bitget exchange hack from late September. Blockchain analytics heavyweight Chainalysis dropped a report this Wednesday confirming what many suspected: the breach is the work of North Korea-linked actors.

The Breakdown

On September 24, hackers drained $387 million from Bitget in just three hours. The funds were split across four networks: Ethereum (49.7%), XRP (40.8%), Zcash (7.6%), and Tron (1.8%). To keep their bags hidden, the attackers used a mix of cross-chain liquidity protocols, instant swaps, and laundering services.

One wild detail: the attackers moved tens of millions in XRP through a cross-chain protocol, swapping it directly for Bitcoin over the course of a day and a half.

AI to the Rescue

Chainalysis revealed they used custom AI automation to keep up with the hackers. By automating bridge reconciliation, they cut down what would have been 20 hours of manual labor to under 10 minutes. Real talk: they clarified that the AI didn't do the thinking—it just helped the human investigators move faster.

Market Impact

This isn't a total shocker. Bitget CEO Gracy Chen previously pointed to North Korean patterns, and analytics firm Elliptic also suggested the link was "highly likely." With this heist included, North Korea-linked groups have now cleared over $1 billion in stolen crypto for 2026 alone. Meanwhile, Circle and Tether managed to freeze about $318,000 in stablecoins, and some protocols like Near Intents blocked swaps, though they faced their own security issues shortly after.

Why it matters

This heist is a reminder that the space is still high-stakes. While tracking tech is getting smarter, the ability to launder funds across chains remains a major issue. Always do your own research (DYOR) and remember—keeping your assets on a centralized exchange carries inherent risks. This is not financial advice.