Invest2 publishers2 min readPublished Updated
Suspected North Korean hackers have hidden about 1% of Bitget's $387.5 million loss in Zcash
Suspected North Korean hackers have moved $3.8 million of Bitget's $387.5 million into Zcash's shielded pool, about 1% of the haul. About $24 million of stolen ZEC remains in transparent addresses that exchanges and police can still freeze.
The Investor · Invest desk

What happened
- The attackers used a zero-day in a third-party security product Bitget had run for weeks to trick its approval process, without touching cold storage or private keys.
- XRP was the largest stolen asset at about $157 million, with ETH, USDT, USDC, ZEC, BNB, AVAX and TRX also taken across four networks.
- CEO Gracy Chen attributed the attack to North Korea-linked actors, citing behavioral patterns and IP addresses that match earlier DPRK hacks.
- Bitget suspended withdrawals soon after it detected the breach and began phasing them back in during late September.
Compiled by The InvestorSomething wrong?How this is made
Why it matters
- cost The loss is paid from Bitget's User Protection Fund, so customers are made whole and the exchange goes into any second incident with a smaller reserve.
- constraint Exchanges built their deposit screens to flag coins that touched Tornado Cash, sanctioned since 2022. Those screens have less to catch when the shielding is part of Zcash itself.
- exposure Any exchange running the same third-party security product is open to the same manipulation of its approval process until the zero-day is fixed.
On the coins taken so far, Zcash can hide at most the Zcash the attackers took. According to Crypto Briefing, they received about 18,900 ZEC from the exploit, worth roughly $28 million [7]. That is about 7% of the $387.5 million total [2]. The publication ranks the theft as the largest single crypto theft of 2026 [2]. The other 93% is in other tokens on other networks [5], and the account does not report where those coins have gone.
Inside the Zcash slice, the laundering is moving faster. About 2,700 of the 18,900 ZEC, roughly one coin in seven [3], was in the Ironwood pool by September 30, about six days after the breach [1]. Six days is the longest the move could have taken, so the rate was at least 450 ZEC a day [4]. At that minimum rate the remaining 16,200 ZEC would be in the pool within about five weeks [4]. Once the coins are shielded, only the sender's private viewing key can link them to the theft [8]. Until then they sit in transparent addresses, where exchanges and law enforcement can still freeze or blacklist them [10].
Bitget carries the cash cost. The exchange says its User Protection Fund held over $464 million at the time of the attack and is enough to repay customers in full [12]. Paying out $387.5 million would leave at least $76.5 million [5]. Against the first loss estimate of $351.6 million [4], the spare would have been at least $112.4 million. The review that added $35.9 million to the loss therefore took roughly a third off that cushion [6].
In my view, the Zcash laundering covers a $28 million slice of a $387.5 million theft [2]. Freezes on the transparent ZEC would keep the shielded share near the 1% already moved [1]. If the rest reaches Ironwood untouched, the share rises to about 7% [2]. The counter-case is that the attackers chose Zcash because it works for them [9], and that they can swap the other tokens into ZEC and shield those as well. On-chain evidence of that swap would prove this view wrong.
What to watch
- Freeze or blacklist notices on the transparent ZEC addresses before the rest of the coins reach the Ironwood pool.
- Whether the third-party security vendor is named, and whether other exchanges disclose that they ran the same product.
- A Bitget statement on how much the User Protection Fund actually paid out and what balance it holds afterwards.