Buy
Market
🔥
Prediction Market

Bitget Hack Suspects Seek Help in Public Chats, Investigator Says

Blockchain sleuth ZachXBT says money launderers tied to the $387M Bitget hack sought help in public chats.

28/09/2026 12:568 min read

People believed to be cleaning the proceeds of the $387 million Bitget hack have been requesting assistance in public online forums, blockchain sleuth ZachXBT said.

He described the individuals as Chinese money launderers acting for suspected North Korean hackers. They posted openly in Discord servers and Telegram channels belonging to the platforms they rely on to transfer the funds.

What the Bitget Hack Suspects Posted

The crypto exchange lost $387.5 million on September 24. CEO Gracy Chen said attackers tricked the exchange's internal approval system into authorizing the transfers, and that North Korea was “very likely” behind the heist.

ZachXBT identified five accounts and connected each one to a specific transaction. His screen captures show them complaining to THORChain staff that XRP-to-Bitcoin swaps never went through. THORChain is a network that exchanges tokens across blockchains without requiring an account.

BREAKING: Chinese illicit actors laundering funds from the $387M Bitget exploit on behalf of the alleged DPRK attackers are openly asking for support with orders in public Discord servers and Telegram channels of services they use.

Notably, Alias 4 (below) was also seen… pic.twitter.com/KfdTo51M2o

— ZachXBT (@zachxbt) September 28, 2026

A user named “Cc” reported sending 277,724 XRP but receiving only 431 back. Another, “jack,” said the loss “would cause a lot of trouble in my life.” A SwapKit moderator, the service for swapping, replied with a picture of Kim Jong Un.

Kelp DAO Link and the North Korean Pattern

According to ZachXBT, an account called “lolo” also cleaned money from the $292 million Kelp DAO exploit in April. In the chat, lolo confirmed using the name “Marin” on Telegram.

“I’ve observed the same pattern after multiple TraderTraitor attributed exploits, and I’ve closely tracked these groups,” the on-chain sleuth wrote.

TraderTraitor is the FBI's designation for a North Korean hacking collective. The bureau linked it to the $308 million theft from Japanese exchange DMM Bitcoin in 2024.

The funds are now moving across blockchains via bridges and ending up in mixers like Wasabi, a wallet that obscures coin trails, ZachXBT said.

THORChain has declined to block wallets tied to the attackers. Bitget stated that withdrawals will resume on Monday. ZachXBT intends to publish further information on the groups in the coming weeks.

Share to

Disclaimer: this article comes from third-party media and is provided for reference only. It does not constitute investment advice. Crypto and other financial products carry significant price volatility risk, so please make your own decisions carefully.

Related articles