Skip to content
Tech

Bitget’s hackers turn to Zcash after $50 million laundering route gets blocked

Hackers behind the Bitget security breach are utilizing Zcash privacy tools and THORChain to launder stolen cryptocurrency after cross-chain platforms blocked millions in illicit transactions.

Satoshi Queen3 min read
Bitget’s hackers turn to Zcash after $50 million laundering route gets blocked

The perpetrators behind the massive $387.5 million Bitget security breach are utilizing Zcash’s privacy functions to obscure their illicitly obtained capital as cryptocurrency companies tighten blocks on alternative laundering channels. On-chain data highlighted by blockchain investigator ZachXBT reveals that approximately 2,746 ZEC—valued at nearly $3.9 million—was moved into the Ironwood shielded pool of Zcash across three separate transactions on Wednesday. This sum accounts for about 15% of the 18,917 ZEC plundered from the trading platform.

These movements present significant hurdles for Bitget’s asset recovery initiatives, as transactions processed within the Ironwood pool mask senders, recipients, and transaction volumes, thereby disrupting the public ledger trail relied upon by investigators. While initial deposits into the pool stay visible, tracking any subsequent transfers back to their original source becomes exceedingly difficult.

This pivot to Zcash privacy tools comes after the culprits attempted to channel significantly greater amounts through cross-chain platforms, several of which have started declining the transactions. Alex Shevchenko, General Manager of NEAR Intents, disclosed that wallets tied to the Bitget breach tried to route over $50 million via the protocol. The platform’s SHIELD risk management mechanism blocked the vast majority of these requests prior to completion, successfully froze approximately $503,000 mid-swap, and allowed roughly $166,000 to slip through. Although blocked assets stayed in the hackers’ possession, it forced them to look for alternative channels.

These recent Zcash transactions highlight an evolving cat-and-mouse game as stolen capital faces stricter surveillance throughout the digital asset ecosystem.

THORChain volume surges as hackers seek other routes

A primary alternative utilized by the thieves is THORChain, a decentralized cross-chain liquidity protocol that has declined Bitget requests to blacklist addresses associated with the exploit. Wallets connected to the Bitget incident have consistently leveraged the platform to convert stolen cryptocurrencies into native Bitcoin. According to estimates from Bitquery, roughly 29,088 ETH—approximate to $79 million at the time of the review—was routed into THORChain and exchanged for Bitcoin.

Frequently Asked Questions

5 questions
01How much was stolen in the Bitget breach?

The hackers stole a total of $387.5 million from the exchange.

02Why are the hackers using Zcash?

The attackers are turning to Zcash’s Ironwood shielded pool to hide the stolen funds and break the public blockchain trail, making it much harder for investigators to track the assets.

03How much Zcash has been moved into the shielded pool?

Approximately 2,746 ZEC, valued at roughly $3.9 million, has been transferred into the pool through three transactions.

04What happened when the hackers tried to use NEAR Intents?

Wallets linked to the theft attempted to process over $50 million through the protocol. The platform’s SHIELD risk system rejected most of the transactions, froze about $503,000, and let roughly $166,000 pass through successfully.

05Which cross-chain exchange has seen a surge in volume from the hackers?

THORChain has seen significant volume because it is a permissionless exchange that has resisted requests to block the addresses tied to the hack, allowing the perpetrators to swap stolen Ethereum for native Bitcoin.

Leave a Reply

Your email address will not be published. Required fields are marked *