
Please Follow us on Gab, Minds, Telegram, Rumble, Truth Social, GETTR, X, Youtube, Instagram
In a recent blog post, blockchain analytics firm Chainalysis attributed the $387 million theft from cryptocurrency exchange Bitget to North Korean state-sponsored hackers. The firm used a combination of its’ AI-powered cryptocurrency analysis and its’ traditional investigative methods to track the stolen funds, moving them across multiple blockchains. Importantly, although the firm used technology to enhance the analysis of the data, it was human investigators who ultimately attributed the theft and controlled the output of their analysis.
After the breach, the attackers had been using more sophisticated techniques for laundering the stolen assets, spreading them through cross-chain liquidity protocols, messaging platforms, instant swap services, as well as specialized laundering infrastructure. The scale of such attempts highlights the attackers’ high level of experience in managing a large-scale cybercrime operation and in evading detection by blockchain forensics experts, writes Decrypt.
Stolen XRP was handled differently by the hackers and after some time it was converted into Bitcoin through cross-chain liquidity protocol and then extracted from the pool on the other side of the trade. This cross-chain arbitrage was used by hackers not only to convert very traceable asset into something else but also to make it as anonymous as possible by hopping from one protocol to another. The activity of extracting tens of millions of dollars in assets through this method took approximately 36 hours.
We previously highlighted that the attack bore similarities to past attacks conducted by DPRK cyber crime operators, as identified by Bitget CEO Gracy Chen. Blockchain analytics firm Elliptic also assessed the involvement of North Korean cyber crime operators in the theft to be “highly likely”.
The money laundering activity is very transparent and is being carried out on public blockchains. The attacker moved parts of the funds to Zcash’s shielded pool in order to use the privacy features. However, how swap services react to these transactions varies greatly. Near Intents for example rejected over $50m in hacker-linked transactions. They got hacked days later though. Thorchain on the other hand continued to process the suspect transactions.
However, stablecoin issuers such as Circle and Tether were able to prevent $318,000 in stablecoins that were siphoned off in the hack from entering circulation. The move highlights the power of centralized control of widely held stablecoins even as the broader decentralized trading environment continues to facilitate hacker activity.


















