Electric Coin Company / Wikimedia Commons (Public domain)
Bitget funds reportedly shielded through Zcash after breach
Alleged North Korean hackers are funneling stolen crypto into Zcash's privacy pool to cover their tracks after a $387.5 million exchange exploit
Roughly $3.8 million worth of Zcash stolen from cryptocurrency exchange Bitget has already disappeared into a shielded transaction pool, making it effectively untraceable on the public ledger. The move is the latest chapter in a breach that ranks as the largest single crypto theft of 2026.
Attackers linked to North Korea are reportedly using Zcash’s Ironwood shielded pool, a privacy feature designed to hide sender, receiver, and amount data, to launder a portion of the approximately $387.5 million they siphoned from the Seychelles-based exchange on September 24.
Inside the breach
Bitget’s security team first flagged the unauthorized activity at around 18:31 UTC. The initial damage estimate came in at $351.6 million, but a subsequent review bumped that figure to $387.5 million once the full scope of compromised wallets became clear.
The stolen assets spanned a surprisingly wide menu. XRP accounted for the single largest chunk at roughly $157 million. The rest included ETH, USDT, USDC, ZEC, BNB, AVAX, and TRX, spread across networks including Ethereum, the XRP Ledger, Zcash, and TRON.
What makes this breach particularly unsettling is how it happened. Investigators traced the root cause to a zero-day exploit buried inside a third-party security product that Bitget had been using for several weeks. The vulnerability allowed attackers to manipulate transaction data and trick the exchange’s internal approval process, all without ever touching cold storage or private keys.
Bitget CEO Gracy Chen attributed the attack to actors associated with the DPRK, citing behavioral patterns and IP addresses consistent with previous North Korea-linked hacks. If the attribution holds, it pushes the total value of suspected North Korean crypto thefts above $1 billion for 2026 alone.
The news moving money, markets, and the world—before your day starts.
Daily. Free. Join 34,000+ readers across crypto, finance, and policy.
The Zcash laundering playbook
By September 30, roughly six days after the breach, on-chain observers noticed movement. Attackers had received approximately 18,900 ZEC from the exploit, valued at around $28 million. Of that, about 2,700 ZEC worth $3.8 million had already been routed into Zcash’s Ironwood shielded pool.
For the uninitiated: Zcash operates two types of transactions. Transparent ones work a lot like Bitcoin, visible to anyone with a block explorer. Shielded transactions encrypt everything. Once funds enter a shielded pool, linking them to their origin becomes, for all practical purposes, impossible without the sender’s private viewing key.
The choice of Zcash over more commonly used laundering routes like Tornado Cash on Ethereum suggests the attackers are adapting. Tornado Cash has faced sanctions from the US Treasury’s OFAC since 2022, and many exchanges now flag deposits that touch it. Zcash’s native shielding, by contrast, is built into the protocol itself rather than layered on top.
Bitget’s response and what comes next
Bitget suspended withdrawals shortly after detecting the breach but began phasing them back in during late September. The exchange pointed to its User Protection Fund, which held over $464 million at the time of the incident, as sufficient to cover customer losses in full.
The roughly $24 million in ZEC still sitting in transparent addresses represents a race against time. If the attackers manage to funnel the remainder into shielded pools before exchanges and law enforcement can freeze or blacklist those coins, recovery becomes extraordinarily difficult.