Blockchain investigator ZachXBT has tracked $387.5 million in stolen funds from the Bitget hack actively moving across multiple chains and into privacy mixers. The on-chain evidence points to Chinese illicit actors facilitating the operation on behalf of suspected North Korean attackers.
The laundering flow is sophisticated and deliberate. Approximately four Bitcoin from the Bitget breach moved into a Wasabi CoinJoin round originating from a TRON wallet. The assets converted from TRX to USDT, bridged to Ethereum via USDT0, then swapped into roughly 145 ETH before hitting privacy services. The stolen funds have crossed THORChain, Ethereum, and Bitcoin networks—a deliberate cross-chain strategy to break the transaction trail.
Coordination is happening in the open. The actors are using Discord and Telegram to solicit order support and manage fund movement. ZachXBT linked the operation to an actor known as "Alias 4," who was also involved in the $292 million KelpDAO exploit earlier this year. The same operational patterns appear in attacks attributed to the TraderTraitor group, suggesting a coordinated network executing these large-scale thefts with recurring methodology.
ZachXBT plans to release additional findings in the coming weeks with deeper detail on the actors and their methods.

