>_ nokycswap.me ENRU
btc→xmr 15.43 fixedfloatxmr→btc 0.0641 fixedfloateth→xmr 4.96 fixedfloatbtc→usdt 8 327 exolixltc→xmr 1.24 exolix best offer per pair · our rates worker · tick 60s

home › blog › bitget-hack-387m-cross-chain

Bitget hack: how $387.5M moved through cross-chain swaps — and what it means if you swap without KYC

by Milan Voss · published

Key takeaways

What happened at Bitget

Bitget is a large centralized exchange that requires KYC — it is not a service we review. We cover this breach because of where the stolen funds went next: through the same cross-chain swap infrastructure our readers use every day.

date (UTC)event
Sept 24, 2026Unauthorized transfers run for about three hours; the first one at 02:31 and the last at 05:23 (UTC+8), according to SlowMist. Bitget halts withdrawals and reports $351.6 million affected.
Sept 25Bitget revises the total to about $387.5 million after counting Zcash and TRON transfers, launches a recovery bounty and a live tracking dashboard. ZachXBT says he has no plans to monitor the case.
Sept 26–28THORChain declines Bitget’s request to refuse the attacker’s addresses; NEAR Intents reports blocking over $50 million in attempted transfers.
Sept 28ZachXBT publishes five accounts he says are laundering the funds. Bitget restarts Bitcoin withdrawals.
Sept 30Bitget restores BTC, ETH and USDT withdrawals and publishes a proof of reserves showing a 131% reserve ratio across 19 assets.

The affected assets included ETH, XRP, BNB, AVAX, USDT and USDC on Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BNB Chain and Base, CEO Gracy Chen said.

How the attackers got in

This was not a stolen-key hack. According to Bitget’s own account, relayed by Fortune and BleepingComputer:

  1. The attackers exploited a zero-day vulnerability in third-party security software used by the exchange.
  2. With it they obtained internal credentials and reached a backend system that processes wallet transactions.
  3. They forged transfer data so that fraudulent withdrawals looked legitimate, and Bitget’s approval process signed them.
  4. The transfers came only from hot and warm wallets. Bitget says its cold wallets and the separate Bitget Wallet product were not affected.

Bitget says the flaw is fixed. It is investigating with Mandiant and SlowMist.

The lesson is uncomfortable for every custodial service: an approval system is only as strong as the software it trusts. The keys were never touched — the process that decides when to use them was.

Who was behind it?

Bitget says it suspects North Korean attackers. No government has formally attributed the attack.

What has been published concerns the laundering, not the breach itself. On September 28, ZachXBT named five accounts he says are moving the stolen funds on behalf of the suspected attackers, and matched each to a transaction. He says they asked for help with stuck transactions in the public Discord and Telegram channels of services they were using. One of them — known as “lolo”, also referred to as “Alias 4” — also laundered funds from the $292 million Kelp DAO exploit in April. ZachXBT says he has seen the same pattern after several exploits attributed to the North Korea-linked group known as TraderTraitor, and plans to publish more data.

As one analysis notes, this evidence does not by itself prove who carried out the breach.

Where the money went

The stolen funds were split across chains and services. ZachXBT and others report movement through cross-chain bridges and swap protocols, including THORChain, and into the bitcoin mixer Wasabi.

Two kinds of freezes have happened so far:

That is less than 0.3% of the total. Gracy Chen has said she is not very optimistic about recovery: once funds have crossed chains, freezing gets hard.

NEAR Intents vs THORChain: two answers to the same question

The Bitget hack turned a long-running debate into a live test. What should a cross-chain protocol do when stolen money arrives?

NEAR IntentsTHORChain
What it didIts screening layer SHIELD flagged and rejected more than $50 million in attempted transfers; froze about $503,000 during execution; about $166,000 passed throughDeclined Bitget’s request to refuse service to the attacker’s addresses
Stated positionWill actively fight the laundering of hacked funds; frozen funds to be returned through a legal process; waived Bitget’s 5% + 5% bountyIt is “decentralized and permissionless like Bitcoin, Ethereum, and BNB Chain”
Where screening sitsOn integrated quote flows, before the swap; its documentation says coverage can vary by flowNot at protocol level; interfaces built on top may screen
SourcesCointelegraph, NEAR Intents docsCointelegraph Magazine

Note what happened to the money NEAR Intents rejected: it moved to other providers. Screening at one door does not stop the money; it changes which door it uses.

THORChain has been here before. It was used to swap a large share of the funds from the $1.46 billion Bybit hack in 2025. Lawyers now argue over whether “decentralized” is a defense, and over whether NEAR’s blocking shows that its system can be made to block in other situations too.

What our own data shows

We label screening for every service in our catalog: what is checked, when, and by whom, quoted from each service’s own terms or documentation. As of October 1, 2026:

In other words, “no KYC” rarely means “no checks”. The checks have moved: from your identity to your coins. See the catalog — each service shows its screening label, with the full quote and source on its review page.

If you swap without KYC: how to avoid tainted coins

After a hack of this size, stolen coins spread. Most of them will never touch you, but here is how to keep it that way.

Before you swap

If your swap is held

  1. Do not send more funds to “unlock” it.
  2. Ask support in writing which clause of their terms they rely on.
  3. Keep your order ID, deposit and payout transaction hashes, and screenshots of the quote.
  4. Read what the service’s own terms say about holds and refunds — we quote them, with paragraph numbers, in our frozen-funds guide.
  5. If you do not want to publish your evidence, you can still prove later that you had it today: submit only its sha256 hash in the comment form of the service’s review — we timestamp it in Bitcoin.

Will Bitget users get their money back?

Bitget says its user protection fund covers the loss. The fund held about $465 million when the incident was disclosed; Bitget says it will top it back above $300 million from its own capital. Withdrawals have been restored in stages, and users can check whether their balances are included in the reserves through Bitget’s Merkle-tree tool.

Recovering the stolen funds themselves is another matter. Bitget’s recovery bounty pays 5% for helping freeze funds and another 5% for recovering them. So far the frozen amounts are small.

Frequently asked questions

How much was stolen in the Bitget hack? About $387.5 million. Bitget first reported $351.6 million and raised the figure after counting Zcash and TRON transfers; it says the increase reflects fuller accounting, not a second theft.

Were Bitget users’ funds lost? Bitget says its protection fund covers the loss. The fund held about $465 million when the incident was disclosed, and withdrawals have been restored in stages since September 28.

Was North Korea behind the Bitget hack? Bitget says it suspects North Korean attackers. No government has made a formal attribution yet. ZachXBT’s published evidence concerns the people laundering the funds, not the people who carried out the breach.

Why did NEAR Intents block the funds while THORChain did not? NEAR Intents runs a screening layer called SHIELD on its quote flows and rejected more than $50 million in attempted transfers. THORChain says it is decentralized and permissionless and does not selectively refuse transactions.

Could I receive stolen Bitget coins in a no-KYC swap? It is possible if you swap with someone who received them. Most instant exchanges we track risk-score incoming coins after your deposit, so tainted funds can lead to a hold or a request for source-of-funds information.

What should I do if my swap is held after a big hack? Do not send more funds to unlock it. Ask support in writing which clause they rely on, keep your order ID and transaction hashes, and read what that service’s own terms say about holds and refunds.

Sources

This article is updated as the investigation continues. We do not review Bitget and have no commercial relationship with it, THORChain or NEAR Intents.