The hacker behind the Bitget heist has found a new hiding spot. On Sept. 30, the attacker began shielding about 2,700 ZEC, roughly $3.8 million, in Zcash’s Ironwood privacy pool. That move comes after Near Intents rejected more than $50 million in swaps tied to the hack, while Thorchain declined Bitget’s request to block the attacker’s addresses.
Bitget states the theft amounts to $387.5 million. The company’s CEO and Elliptic both point toward North Korea, although no government has confirmed it. Elliptic describes a North Korean connection as “highly likely”, and ranks it the biggest suspected North Korean theft of 2026, which pushes the year’s total past $1 billion.
Ironwood Launches
The Ironwood pool for Zcash encrypts the sender, the receiver, and the amount, keeping the trail hidden from anyone who might try to track the funds once they enter. It took over from Orchard, which was exposed by a researcher finding a flaw that could have allowed counterfeit coins to be created. The pool went live July 28, and the amount set aside works out to about one-seventh of the ZEC lost in the hack, per on-chain data.
The pool keeps a record of coins moving in and out, while what happens inside stays secret. That secrecy is the whole idea behind a privacy pool: a record of movement without a record of who owns it.
On Sept. 24, Bitget’s systems first flagged unauthorized transfers out of its hot wallets. The attackers got into backend systems and faked transaction data rather than stealing private keys, according to Chen.
Near’s Screening System
Near Intents says it turned down more than $50 million in swaps linked to the hack. Around $503,000 got caught up and frozen mid-swap, while some $166,000 managed to get through instead.
Tuesday brought word from general manager Alex Shevchenko that its SHIELD screening system turned down over $50 million in swaps linked to the Bitget attacker. Near cofounder Illia Polosukhin responded by saying that “permissionless” does not require every app to handle every transaction.
Near has said that the frozen assets will be processed through legal and recovery procedures.
Thorchain’s Stand
In a post on X, Thorchain said that a network halt serves as an emergency tool meant to safeguard the protocol. The company made clear that halts are not used as a means to freeze specific funds or individual swaps.
The attack that took place in May involved the theft of $10.7M from the liquidity pools, with the attackers’ addresses being exposed through the exploit known as 2026.
Thorchain halted its entire network for about five weeks after a $10.7 million exploit on May 15, and resumed June 22. Several batches totalling roughly 2,390 ETH—about $6.3 million—were converted into 75.2 BTC through Thorchain.
The Money’s Path
The attacker divided the funds among new wallets containing round amounts, roughly 10,000 ETH or 20 million XRP each. The smaller pieces were moved through cross-chain swap services, including:
- Thorchain
- Across
- Bridgers
- Chainflip
- FixedFloat
Bitget has set aside a reward of 5% for any funds frozen, along with an additional 5%, for any funds recovered, except where action is ordered by courts or law enforcement.
What Bitget Says
The protection fund at Bitget is covering the loss, which means customer balances are not affected.
No government has confirmed the North Korea connection, and Elliptic’s judgment holds no official authority.
Recovery So Far
The Ironwood deposit serves as a declaration. The thief placed roughly one-seventh of the taken ZEC into a pool where the trail stops — not forever, but long enough to hinder anyone attempting to trace it back.
The fact that Near rejected $50 million in swaps demonstrates how well screening works. Of those swaps, about $503,000 were frozen mid-swap, while roughly $166,000 managed to slip through.
The remaining $387.5 million minus the Ironwood deposit is still exposed.
The Ironwood pool buys time.
The Case So Far
- Bitget puts the theft at $387.5 million
- Elliptic points to North Korea, calling the link “highly likely”
- Elliptic ranks it the largest suspected North Korean theft of 2026, pushing the year’s total past $1 billion
- Near rejected more than $50 million in swaps tied to the hack
- Thorchain declined Bitget’s request to block the attacker’s addresses
- The Ironwood deposit holds roughly 2,700 ZEC, or $3.8 million
One response is to keep the trail concealed until the heat subsides; that is the Ironwood pool. A second approach is to intercept the swaps before they are completed; that is what the screening systems do.
The adversary has selected both options, and the remainder of the field is waiting to see which approach performs better.
Where the paper stands
The paper backs the small business against both the agency and the giant, and against broad new rulebooks that would raise the cost of entry for all. Here the thief has found a new hiding spot in Zcash’s Ironwood privacy pool, and the question turns on whether screening systems like Near’s SHIELD can stop the swaps before they land. The $387.5 million theft is a warning to all businesses handling crypto, not a call for new regulation that would raise the price of entry for everyone else.
The thief’s move into Ironwood is a statement, not a surrender. It shows the danger of a privacy feature that lets funds vanish from sight. The screening systems, by contrast, show what works when firms actually look at the money before it moves. The paper would prefer that firms keep looking, and that the big firms do not use the fear of crime to build rulebooks that punish the small ones.
Readers should watch whether the screening systems hold. Near’s rejection of over $50 million in swaps shows what works, and the Ironwood deposit shows what the thief is willing to risk. The $387.5 million balance remains exposed, and the case has yet to reach its end.
Source material: “Bitget Hacker Turns to Zcash Privacy Pool After Near Rejects $50M in Swaps,” Decrypt.
Get the Notebook.
The day's best stories and every fresh verdict, in plain English, in your inbox by seven. One email a day, no more.

