Investigator ZachXBT says the group behind the $387.5 million Bitget breach is moving stolen funds through public Discord and Telegram channels rather than hidden forums. He has also linked one of the actors to an earlier $292 million Kelp DAO exploit and to North Korea-affiliated hacking groups.
Nearly $400 million stolen from Bitget is being laundered in plain sight, through some of the internet's most public gathering spots rather than dark web forums or encrypted drops. Blockchain investigator ZachXBT has identified actors coordinating the movement of the stolen funds through public Discord and Telegram channels, using bridging services and mixers, including Wasabi, to obscure the trail.
A pattern, not a one-off
ZachXBT flagged specific usernames tied to the operation, including handles cc02006 and jack_34808. At least one identified actor has been linked to the earlier $292 million Kelp DAO exploit, which also occurred in 2026, suggesting a systematic, coordinated laundering network rather than an isolated incident.
The actors have been linked to North Korea-affiliated groups operating under aliases like TraderTraitor and Lazarus. Two breaches potentially linked to the same network, totaling nearly $680 million in a single year, form what investigators describe as a pattern rather than a coincidence.
How the breach happened
The September 24 attack wasn't a brute-force key theft. Instead, attackers compromised a third-party backend system Bitget relied on, spoofing transaction data to bypass internal authorization checks and drain roughly $387.5 million from the exchange's hot and warm wallets — now the largest digital asset theft of 2026. Private keys were never compromised, so cold wallets stayed secure.
The exchange suspended withdrawals immediately and began resuming them in phases starting September 28. It confirmed its User Protection Fund, which exceeds $464 million, would cover user losses.
It is also offering a 5% bounty for recovery of the lost assets, roughly $19.4 million at $387.5 million. Bitget has brought in Mandiant and SlowMist to investigate the breach, and law enforcement agencies are also involved.
Source: Crypto Briefing
Trading involves risk.