Blockchain analytics firm Chainalysis has attributed the $387 million Bitget hack to North Korea-linked actors, saying the breach pushed Pyongyang's 2026 crypto theft total past $1 billion. Bitget, meanwhile, has criticized DeFi protocols for refusing to help trace the stolen funds, crediting NEAR Intents as the exception.
Chainalysis has pinned the Sept. 24 $387 million Bitget hack on actors tied to the Democratic People's Republic of Korea, adding its weight to a growing consensus around one of the year's largest crypto thefts. The firm said the heist pushed the total value of crypto stolen by North Korea-linked groups in 2026 past $1 billion.
AI traces $387 million across four chains
Chainalysis laid out how fast the money moved: in the first three hours, $387 million left Bitget across 23 transfers, landing on Ethereum (49.7%), XRP (40.8%), Zcash (7.6%) and Tron (1.8%). From there, the attackers ran the funds through cross-chain liquidity and messaging protocols, instant swaps, and laundering services to obscure the trail.
The firm said it used in-house AI to keep pace, building automation that it estimated compressed more than 20 hours of manual work into under 10 minutes. Bitget CEO Gracy Chen had already said the attack's patterns matched North Korean hackers, and Elliptic called a DPRK link "highly likely." The attribution therefore builds on assessments made before Chainalysis published its report.
Bitget criticizes DeFi protocols' refusal to help
Bitget has argued that some permissionless protocols refused to help trace the stolen funds, singling out NEAR Intents as the exception. The entry point for the breach was a zero-day vulnerability in third-party security software that let attackers obtain high-level credentials and issue fraudulent withdrawal commands.
CEO Gracy Chen said the exchange's cold wallets and private keys stayed protected throughout the incident, and Bitget has told users losses will be covered by its User Protection Fund, valued at over $464 million before the breach. Withdrawals have been resuming gradually since Sept. 28.
Recovery stays minimal
NEAR Intents said its SHIELD system identified over $50 million in attempted laundering tied to the hack, but actual freezes were far smaller: the system froze $503,000 while transactions were still executing, and roughly $166,000 slipped through before it caught on. Bitget had offered a 5% bounty on recovered funds; NEAR Intents waived it.
Overall recovery is estimated at just 0.2% of total losses. NEAR Intents itself later suspended service after an attacker drained about $3.8 million from it, a separate incident the team attributed to a bug in how its deposit and withdrawal infrastructure talks to its main smart contract.
Sources: Decrypt, Crypto Briefing
Trading involves risk.