Blockchain AcademicsBlockchain Academics
Chainalysis Traces $387M Bitget Hack to North Korea, Pushing 2026 DPRK Crypto Theft Past $1 Billion

Chainalysis Traces $387M Bitget Hack to North Korea, Pushing 2026 DPRK Crypto Theft Past $1 Billion

North Korea crossed a grim milestone this week. Chainalysis has formally attributed the $387 million breach of crypto exchange Bitget to DPRK-linked threat actors, pushing the regime's total cryptocurrency theft in 2026 above $1 billion.

Alejandro Silva RamírezEdited by Ibrahim RajabOctober 3, 20263 min read
Share

Chainalysis Traces $387M Bitget Hack to North Korea, Pushing 2026 DPRK Crypto Theft Past $1 Billion

North Korea crossed a grim milestone this week. Chainalysis has formally attributed the $387 million breach of crypto exchange Bitget, which occurred on September 24, to DPRK-linked threat actors, pushing the regime's total cryptocurrency theft in 2026 above $1 billion.

The forensics firm deployed in-house artificial intelligence to trace the stolen funds across four separate blockchains in what it described as a race against the attackers. This was not a static post-mortem but a live tracking operation, with Chainalysis analysts attempting to follow the money in real time as the hackers moved assets through layers of decentralized infrastructure designed to obscure their trail.

"The firm says the Sept. 24 breach pushed North Korea's 2026 crypto haul past $1 billion, and detailed how it used in-house AI to trace the stolen funds across four blockchains in a race against the attackers."

Chainalysis

The conversion path the attackers chose is instructive. Investigators traced stolen XRP through a cross-chain swap protocol into Bitcoin, a route that bypassed centralized exchange controls where compliance teams might freeze suspicious inflows. Cross-chain bridges and atomic swap protocols operate without custodians, making real-time intervention nearly impossible. But the strategy has a structural flaw that blockchain forensics firms have learned to exploit. The swaps "still left blockchain records," and those records, stitched together with AI-assisted pattern recognition across four chains, formed the evidentiary basis for the attribution. Drift and KelpDAO were among the protocols identified in connection with the affected asset flows.

The $1 billion threshold is significant not just as a headline number but as a structural signal. For context, the UN Panel of Experts estimated that DPRK-linked actors stole approximately $600 million in cryptocurrency across all of 2023. Reaching $1 billion with three months still remaining in 2026 represents a meaningful acceleration in both operational tempo and the scale of individual attacks. The $387 million Bitget breach alone dwarfs most prior single incidents; the 2018 Coincheck hack, often cited as a benchmark, totaled $530 million but unfolded across a simpler operational environment where exchange hot wallets were the primary vector. DPRK tactics have since evolved to target DeFi infrastructure directly, where the absence of a central operator makes incident response structurally harder.

Several caveats deserve attention. Chainalysis's attribution methodology is proprietary, and competing forensics firms have not independently verified the DPRK link. Sophisticated non-state actors have historically been capable of mimicking DPRK operational patterns, and blockchain analysis alone cannot rule out deliberate misdirection. The $1 billion figure for 2026 also warrants scrutiny: multi-chain tracking creates the risk of double-counting the same assets as they appear on successive ledgers. None of these caveats necessarily undermine the attribution, but they are reasons to treat it as a strong working conclusion rather than a settled fact pending corroboration from government agencies or independent forensic review.

The more pressing and perhaps underexplored question is what specific vulnerability in Bitget's infrastructure allowed a $387 million outflow to occur in the first place. Attribution tells us who; it does not yet fully answer how.

For the broader market, the $1 billion milestone reinforces a pattern that institutional participants and protocol developers can no longer treat as a tail risk. Exchanges and DeFi protocols operating with significant XRP or multi-chain treasury exposure face an adversary that has demonstrably upgraded its laundering playbook, moving from direct exchange withdrawals to cross-chain swap routes that are harder to intercept but, as this case shows, not impossible to trace. AI-assisted forensics is closing the gap between theft and attribution. Whether that gap closes fast enough to enable asset recovery, rather than merely historical accounting, remains the open question for the industry heading into 2027.

Discussion

Loading comments...