Chinese launderers seek help in public channels to move funds from $387M Bitget hack: ZachXBT
Blockchain investigators trace $387.5 million in stolen funds through public messaging channels and mixing services in what's become the largest digital asset theft of 2026
Nearly $400 million stolen from Bitget is being laundered through some of the internet’s most public gathering spots. Not dark web forums or encrypted dead drops. Discord servers and Telegram groups.
The September 24 breach, which saw approximately $387.5 million drained from Bitget’s hot and warm wallets, now holds the dubious title of largest digital asset theft of 2026. And the cleanup operation is playing out in plain sight.
The laundering playbook
Blockchain investigator ZachXBT has identified actors coordinating the movement of stolen funds through public Discord and Telegram channels. The individuals are using bridging services and mixers, including Wasabi, to obscure the transaction trail.
ZachXBT flagged specific usernames involved in the operation, including handles cc02006 and jack_34808. At least one identified actor has been linked to the earlier $292 million Kelp DAO exploit that also occurred in 2026, suggesting this isn’t a one-off operation but part of a systematic, well-coordinated laundering network.
The actors have been linked to North Korea-affiliated groups operating under aliases like TraderTraitor and Lazarus.
The news moving money, markets, and the world—before your day starts.
Daily. Free. Join 34,000+ readers across crypto, finance, and policy.
How the breach happened
The attack vector wasn’t a brute-force key theft. Instead, the attackers compromised a third-party backend system that Bitget relied on, allowing them to spoof transaction data and bypass internal authorization processes. Private keys were never compromised, which meant cold wallets stayed secure.
Bitget suspended withdrawals immediately following the breach and began resuming them in phases starting September 28. The exchange confirmed that its User Protection Fund, which exceeds $464 million, would cover user losses.
The exchange is also offering a 5% bounty for recovery of the lost assets. At $387.5 million, that works out to roughly $19.4 million.
The investigation and its wider implications
Bitget has brought in Mandiant and SlowMist, two of the more respected names in blockchain forensics and cybersecurity, to investigate the breach. Law enforcement agencies are also involved.
The Kelp DAO connection is particularly concerning. Two breaches totaling nearly $680 million, potentially linked to the same network, in a single year is not a coincidence. It’s a pattern.