
ZachXBT Bitget hack laundering investigation links five alleged facilitators to THORChain swaps after the $387.5M theft.
Author: Kritika Gupta
28th September 2026- Crypto investigator ZachXBT says Chinese actors are laundering funds from the $387 million Bitget hack.
High Signal Summary For A Quick Glance
smart
@smartmovezz
@zachxbt Hackers are already shopping mixers in public Discords Users are still waiting on a livestream and a withdrawal timetable That gap is the whole story.
BREAKING: Chinese illicit actors laundering funds from the $387M Bitget exploit on behalf of the alleged DPRK attackers are openly asking for support with orders in public Discord servers and Telegram channels of services they use. Notably, Alias 4 (below) was also seen https://t.co/KfdTo51M2o
11:47 AM·Sep 28, 2026
CPH2691
@cph2691
@zachxbt What people of skill should do is steal money from Exchanges and send it to Burner addresses. Some exchanges deserve this
BREAKING: Chinese illicit actors laundering funds from the $387M Bitget exploit on behalf of the alleged DPRK attackers are openly asking for support with orders in public Discord servers and Telegram channels of services they use. Notably, Alias 4 (below) was also seen https://t.co/KfdTo51M2o
11:44 AM·Sep 28, 2026
Evas
@DasEvas1
@zachxbt Doxxing the exact Discord IDs and transaction hashes on the timeline is absolute god-tier OSINT work. These facilitators ran state-sponsored laundering ops and left a clear breadcrumb trail right back to their Telegram handles. Once major CEXs load these transaction hashes into
BREAKING: Chinese illicit actors laundering funds from the $387M Bitget exploit on behalf of the alleged DPRK attackers are openly asking for support with orders in public Discord servers and Telegram channels of services they use. Notably, Alias 4 (below) was also seen https://t.co/KfdTo51M2o
11:31 AM·Sep 28, 2026
Steady attention without excessive speculation.
According to ZachXBT, these facilitators work on behalf of the alleged DPRK attackers behind the theft. Strikingly, he says they asked for help in public Discord servers and Telegram channels. He named five aliases and shared their handles, IDs, and on-chain swap hashes.
ZachXBT laid out the evidence in a breaking thread on X. The post drew about 68,000 views within hours.
He named five aliases: Cc, jack, Melon, lolo (also Marin), and HELP ME. For each one, he published Discord or Telegram IDs plus THORChain swap hashes.
His screenshots show these users inside what looks like a THORChain and SwapKit support Discord. There, they ask staff to check “stuck” XRP-to-BTC swaps and open support tickets.
One jack thread even includes a Kim Jong Un meme. A support handle replies with the line, “Will Kim get mad?” So the alleged laundering happened in the open, not a private room.
Those public logs matter. As a result, investigators now hold rare human identifiers, such as Discord snowflake IDs and Telegram IDs. Platforms and exchanges can screen deposits against them.
The Bitget hack laundering trail shows stolen funds moving across addresses and chains. Investigators have traced XRP through THORChain swaps toward Bitcoin. Separately, AMLBot flagged a route carrying about four BTC into Wasabi CoinJoin. These are observed portions of the trail; how much of the total loss has passed through each route remains unclear.
ZachXBT says the activity resembles patterns he has seen after other exploits attributed to TraderTraitor. He also alleges that one of the five handles he identified, lolo/Marin (“Alias 4”), helped launder funds from the roughly $292 million Kelp DAO exploit in April 2026. That cross-case link has not yet been independently confirmed.
Bitget exploit and laundering investigation
Unauthorized transfers hit hot and warm wallets. Bitget revised its initial $351.6M estimate after accounting for more transfers from the same incident.
Bitget’s CEO, Elliptic, and TRM Labs describe a likely North Korean connection. No government agency has publicly attributed this exploit.
Investigators track assets through multiple chains and THORChain swaps. AMLBot reports a path carrying about 4 BTC into Wasabi CoinJoin.
He says Chinese actors sought swap support in public Discord and Telegram channels. He also links one handle, “Alias 4,” to laundering tied to the Kelp DAO exploit. Those claims remain unconfirmed by a second primary source.
Watch for additional exchange freezes, a formal government attribution, or sanctions action. None has been announced in response to ZachXBT’s findings.
Bitget’s security notice dates the breach to 18:31 UTC on 24 September 2026. CEO Gracy Chen said systems flagged unauthorized transfers from parts of its hot and warm wallets.
Cold wallets and the separate Bitget Wallet product were not hit. According to Bitget, attackers did not steal private keys. Instead, the company says they compromised a backend system, spoofed transaction data, and triggered its signing process. A real signer thus approved a forged transfer, a failure class seen in the 2025 Bybit theft.
The first loss estimate was about $351.6 million. Bitget later revised it to about $387.5 million after adding Zcash and TRON transfers from the same incident. XRP was the largest slice, at roughly 103 million tokens. The ZachXBT Bitget hack laundering findings concern what happened to those stolen funds after the exploit.
Bitget says the incident is contained and the vulnerability is patched. Accordingly, withdrawals are reopening in phases.
BTC withdrawals reopened first, from 08:00 UTC on 28 September. Bitget said the first batch processed thousands of requests. Meanwhile, The Block reported ETH, USDT, and other assets follow through 2 October.
The company says a User Protection Fund covers user balances. It puts that fund at more than $464 million, or about 5,500 BTC.
Still, recovery remains small. So far, Circle and Tether froze only about $318,000 to $339,000 in stablecoins. Most stolen value keeps moving, so Bitget also launched a 5% freeze and 5% recover bounty.
Attribution to North Korea remains alleged, not official. No FBI, OFAC, or Mandiant report has named Bitget’s attackers as of this writing.
Even so, several firms lean that way. Elliptic calls the exploit “highly likely” linked to the DPRK. TRM Labs says “likely” but has not definitively attributed it.
Chen pointed to VPN IP addresses that, according to her, match a certain DPRK group. Reuters, by contrast, stayed descriptive and did not attribute the theft.
Context also matters here. ZachXBT had said on 25 September that he would not monitor the case. Moreover, he clashed with Bitget earlier in 2026 over token market-making. Yet that history does not falsify the checkable screenshots and hashes.
Bitget has promised a full incident report but has not published it yet. Investigators will also watch whether platforms act on ZachXBT’s aliases.
The rails story stays live too. Chen asked THORChain to refuse the addresses, and THORChain declined. Separately, Ripple cannot freeze stolen XRP the way issuers freeze ERC-20 tokens, per CoinDesk.
Markets, meanwhile, stayed calm. BGB slipped a few percent around disclosure, to about $1.97, and has chopped since. So far, the laundering thread has not shown up as a distinct price event.
This article is not financial advice. For now, the Bitget hack laundering trail remains public, and each new swap adds fresh identifiers investigators can trace.
Our Crypto Talk is committed to unbiased, transparent, and true reporting to the best of our knowledge. This news article aims to provide accurate information in a timely manner. However, we advise the readers to verify facts independently and consult a professional before making any decisions based on the content since our sources could be wrong too. Check our Terms and conditions for more info.
ZachXBT Exposes Bitget Hack Laundering in Discords
KelpDAO LayerZero Lawsuit Targets CEO Over $292M Hack
Bitget Hack Drains $351.6M, Fake Account Targets Users
DCENT Wallet Users Urged to Move Funds After Alert
ZachXBT Exposes Bitget Hack Laundering in Discords
KelpDAO LayerZero Lawsuit Targets CEO Over $292M Hack
Bitget Hack Drains $351.6M, Fake Account Targets Users
DCENT Wallet Users Urged to Move Funds After Alert