Home News ZachXBT Links Chinese Actors to $387M Bitget Hack Laundering as NEAR Intent Prevented $50M in Flows

ZachXBT Links Chinese Actors to $387M Bitget Hack Laundering as NEAR Intent Prevented $50M in Flows

ZachXBT Links Chinese Actors to $387M Bitget Hack Laundering as NEAR Intent Prevented $50M in Flows

The $387.5 million Bitget exploit has quickly become more than another crypto exchange hack. It is now a case study in how stolen digital assets move through a fragmented, cross-chain financial system—and how blockchain investigators and decentralized infrastructure providers are attempting to disrupt that process in real time.

Bitget confirmed that approximately $387.5 million in assets were transferred to attacker-controlled addresses during the September 24 breach, revising its original estimate of $351.6 million after identifying additional losses involving Zcash and TRON.

The exchange said the incident was contained and that its User Protection Fund would cover affected users. The laundering trail has since attracted the attention of blockchain investigator ZachXBT.

He alleged that Chinese illicit actors are helping launder funds connected to the suspected North Korean attackers, with some of the alleged intermediaries openly seeking transaction assistance through Discord servers and Telegram channels associated with services they were using.

ZachXBT also linked one alleged operator to an earlier $292 million Kelp DAO exploit.  The attribution remains an allegation rather than a final judicial determination. Bitget has publicly pointed toward a North Korean connection, while investigations continue.

The important issue for the crypto industry, however, is the laundering infrastructure exposed by the investigation. According to reporting on ZachXBT’s findings, the stolen assets were moved between blockchains using bridges before being routed toward privacy-oriented services.

This strategy illustrates the fundamental challenge facing investigators: blockchain transactions are transparent, but liquidity is increasingly distributed across networks, bridges, decentralized exchanges, solvers and privacy tools.

That is where NEAR Intents enters the story. NEAR Intents said its SHIELD risk-intelligence system detected more than $50 million in attempted Bitget-linked flows. Most of those transactions were rejected before execution.

Approximately $503,000 was frozen during execution, while around $166,000 passed through the infrastructure, according to NEAR’s reported figures. The distinction matters. NEAR Intents did not seize $50 million.

Rather, its system prevented more than $50 million in attempted flows from being processed, while separately freezing funds that had already entered the execution process. The rejected transactions could then be redirected toward other venues.

NEAR’s response also highlights an emerging model for decentralized finance: permissionless networks do not necessarily require every application, liquidity provider or solver to process every transaction.

SHIELD can use intelligence from transaction-monitoring providers, researchers, exchanges and other industry participants to identify suspicious activity and refuse certain requests.

Perhaps more significant was NEAR Intents’ decision to waive its potential bounty share. Bitget had established a recovery program, but NEAR said it would not claim a reward for the intervention, allowing more potential recovery value to remain with the exchange and its users. Bitget CEO Gracy Chen publicly acknowledged the contribution.

The episode therefore exposes two sides of crypto’s architecture. The same interoperability that allows legitimate users to move capital rapidly across networks can also provide attackers with multiple routes for dispersing stolen assets.

Yet that infrastructure can simultaneously become a surveillance and intervention layer when transaction intelligence is embedded directly into execution systems.

For the industry, the Bitget incident demonstrates that recovering stolen cryptocurrency is no longer solely a matter of tracing wallets after the fact. It increasingly depends on whether bridges, solvers, exchanges and decentralized protocols can recognize illicit flows quickly enough to prevent them from becoming irreversible.

No posts to display

Post Comment

Please enter your comment!
Please enter your name here