BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
Policy

Zcash Becomes New Destination For Bitget Hacker

The attacker behind the $387.5 million Bitget exploit has turned to Zcash's privacy infrastructure as a new tool for obscuring stolen funds. Wallets linked to the hack have started moving sto

AnonymousCryptoCompass newsroom
October 1, 2026
3 min read
NEWS
Zcash Becomes New Destination For Bitget Hacker
CryptoCompass editorial visual for policy coverage.

The attacker behind the $387.5 million Bitget exploit has turned to Zcash's privacy infrastructure as a new tool for obscuring stolen funds. Wallets linked to the hack have started moving stolen $ZEC into the network's Ironwood shielded pool, on-chain investigator @zachxbt flagged on Wednesday, September 30.

Into the Ironwood Pool

Transaction records show that 2,746 ZEC entered Ironwood, Zcash's newest shielded pool, in three transfers between 08:15 and 08:46 UTC.At midday prices, that amounts to roughly $3.9 million and represents about 15 percent of the ZEC that left the exchange on September 24.

@zachxbt identified the movements and noted that the funds passed through two intermediary addresses before entering the private pool.Investigators can see the amount crossing into Ironwood, but transfers inside the shielded pool hide the sender, recipient and amount.Shielded transactions use zero-knowledge cryptography to keep transaction details private while allowing the network to verify that transactions are valid.

ZachXBT put the total ZEC stolen from Bitget's hot wallet at about 18,900 ZEC, worth roughly $28.3 million, meaning the Ironwood deposits represent only a portion of those holdings, with around 16,200 ZEC still outside the pool.The operators behind the transfers have been described by ZachXBT as alleged Democratic People's Republic of Korea (DPRK) attackers.

Bitget CEO Gracy Chen has said attackers exploited a vulnerability in a third-party security product to obtain high-level internal credentials, then sent fraudulent withdrawal instructions directly into Bitget's wallet systems.Private keys were not stolen, and cold wallets were unaffected.

NEAR Intents SHIELD Blocks $50 Million in Swap Attempts

Before pivoting to Zcash, the attacker had attempted to move stolen assets through several cross-chain swap services. NEAR Intents blocked more than $50 million in attempted cross-chain transfers that it linked to wallets involved in the breach.The $50 million figure does not represent funds recovered. Most of the rejected transactions never entered the protocol's execution process and were subsequently routed toward other service providers.

The cross-chain protocol froze about $503,000 during execution and allowed roughly $166,000 in suspected stolen funds to pass through, according to Alex Shevchenko, general manager of NEAR Intents.NEAR Intents said it will forgo Bitget's bounty and return the frozen funds through legal proceedings.

The intervention has intensified debate over whether NEAR Intents can remain permissionless while using SHIELD compliance controls to halt cross-chain transactions and hold funds pending legal review.

Sources:CoinDesk: Bitget hackers move $4 million into Zcash's private poolCoinDesk: $50 million in Bitget hacker swaps puts NEAR Intents' permissionless claim to the testCrypto.news: NEAR Intents says it stopped $50M Bitget laundering bid