Bitget’s hackers turn to Zcash after $50 million laundering route gets blocked

Hackers behind the Bitget security breach are utilizing Zcash privacy features and THORChain to launder stolen cryptocurrency after cross-chain protocols blocked millions in illicit funds, while Bitget manages massive post-exploit user withdrawals.

Bitget’s hackers turn to Zcash after $50 million laundering route gets blocked

The cybercriminals responsible for the $387.5 million Bitget breach are leveraging Zcash’s privacy features to obscure the origin of the stolen capital, following increased resistance from traditional crypto escape routes.

On-chain analysis highlighted by investigator ZachXBT reveals that roughly 2,746 ZEC—valued at approximately $3.9 million—was deposited Wednesday into Zcash’s Ironwood shielded pool across three separate transactions. This sum accounts for about 15% of the 18,917 ZEC stolen from the platform.

These transfers complicate asset recovery efforts because transactions processed through Ironwood obscure sender identities, recipient addresses, and transfer amounts, thereby breaking the public transaction trail typically used by investigators to trace stolen funds. While deposits to the pool remain visible, any subsequent movements become significantly more difficult to connect back to their source.

This pivot toward Zcash’s privacy infrastructure comes after the perpetrators attempted to channel substantially larger amounts through cross-chain services, several of which have begun blocking the transactions.

According to NEAR Intents General Manager Alex Shevchenko, wallets associated with the Bitget heist sought to route more than $50 million through the protocol. The SHIELD risk system intercepted and rejected the majority of these transactions prior to execution, while approximately $503,000 was frozen after swaps had already commenced, and roughly $166,000 successfully cleared.

The blocked assets stayed under the hackers’ control, leaving them free to explore alternative pathways. The recent Zcash transactions illustrate how this dynamic is evolving as illicit funds face stricter screening measures across various sectors of the crypto ecosystem.

THORChain volume surges as hackers seek other routes

One alternative has been THORChain, an unpermissioned cross-chain exchange that has declined Bitget’s requests to blacklist addresses tied to the security breach.

Wallets linked to Bitget have repeatedly utilized the protocol to convert stolen crypto assets into native Bitcoin. Bitquery estimates that roughly 29,088 ETH—worth approximately $79 million at the time of its review—was routed into THORChain and exchanged for Bitcoin through Sept. 29.

Consequently, trading activity on the decentralized exchange has spiked dramatically since the exploit. THORChain processed over $1.5 billion in decentralized exchange volume in the days immediately following the attack, compared to roughly $146 million during the week leading up to the incident, according to DeFiLlama data evaluated by CryptoSlate.

This expansion coincided with hacker-associated flows, though total THORChain volume cannot be exclusively attributed to the attackers.

The stance taken by THORChain, contrasting with NEAR, underscores a growing divergence regarding how decentralized networks should react when encountering identified stolen assets.

NEAR has contended that permissionless access does not obligate its liquidity providers to process known illicit transactions. Conversely, THORChain has argued that selective censorship would compromise the core principles underpinning its network.

This disagreement creates tangible consequences for Bitget. Blocking one platform does not freeze funds held in self-custodied wallets; rather, it compels the perpetrator to seek out alternate liquidity sources, potentially steering assets toward permissionless exchanges or privacy tools that grant investigators fewer intervention avenues.

Bitget absorbs withdrawal rush as operations restart

Meanwhile, Bitget faces a different challenge from its user base as it gradually restores access to funds following a four-day withdrawal suspension.

DeFiLlama data reviewed by CryptoSlate indicates that over $700 million has left tracked Bitget wallets since withdrawal channels started reopening, pointing to immediate user demand to move assets off the platform. Because DeFiLlama tracks known exchange wallets, the metric mirrors on-chain movements rather than Bitget’s complete internal withdrawal ledger.

Bitcoin represented a major share of the initial wave. Bitget reported processing 9,585 withdrawal requests totaling 4,098 BTC as of Sept. 28, shortly after reopening Bitcoin withdrawals.

Outflows persisted as the exchange progressively restored support for other digital assets. Bitcoin withdrawals resumed Sunday, followed by Ethereum and subsequently USDT across the Ethereum, BNB Chain, Solana, and Tron networks. Bitget intends to reopen withdrawals for remaining cryptocurrencies alongside fiat and peer-to-peer services on Friday.

On Sept. 30, Bitget CEO Gracy Chen stated that the exchange’s Protection Fund had been replenished to exceed $300 million, reinstating a target the company pledged to hit after tapping the reserve in the wake of the breach.

She confirmed that BTC, ETH, and USDT withdrawals were functioning normally and characterized operations as “gradually back to usual.”

The exchange’s most recent proof-of-reserves audit offers another indicator of its capacity to absorb the withdrawals. Bitget disclosed an overall reserve ratio of 131% across 19 covered assets as of Sept. 29, meaning the assets detailed in its disclosure surpassed corresponding user balances by 31%.

Those metrics will undergo a broader stress test when Bitget lifts remaining withdrawal restrictions on Friday.

अक्सर पूछे जाने वाले प्रश्न

01What is the Bitget breach?

The Bitget breach refers to a major security incident involving the theft of $387.5 million in crypto assets from the exchange.

02How are the hackers laundering the stolen funds?

The attackers have attempted to route funds through cross-chain services like THORChain and NEAR Intents, and have recently turned to Zcash’s privacy-focused Ironwood shielded pool to hide the transaction trail.

03What is Zcash’s Ironwood pool?

Ironwood is a Zcash shielded pool that conceals senders, recipients, and transaction amounts, making it difficult for investigators to trace stolen assets.

04Has Bitget restored normal operations?

Bitget has been gradually restoring withdrawal services for assets like Bitcoin, Ethereum, and USDT, with remaining cryptocurrency, fiat, and P2P services scheduled to reopen on Friday.

शेयर करें

एक प्रतिक्रिया छोड़ें

आपका ईमेल पता प्रकाशित नहीं किया जाएगा। Required fields are marked *