Hackers behind the $387.5 million Bitget exchange breach have moved 2,746 ZEC, valued at roughly $3.9 million, into Zcash's Ironwood shielded pool. This transfer represents about 15 percent of the 18,917 ZEC stolen from the exchange.
Transactions within the shielded pool conceal senders, recipients, and specific amounts, breaking the public transaction trail that blockchain investigators use to track illicit asset movements. While deposits into the pool remain visible, subsequent transfers become difficult to link to their origin.
This shift to Zcash's privacy infrastructure follows failed attempts by the attackers to move substantially larger sums through other cross-chain services. Several services have begun refusing transactions linked to the theft, indicating tightening on-chain screening protocols.
NEAR Intents General Manager Alex Shevchenko said wallets associated with the Bitget theft tried to process more than $50 million through the protocol. NEAR's SHIELD risk system rejected the majority of these transactions before execution. Approximately $503,000 was frozen after swaps had already commenced, while only about $166,000 successfully passed through.
The rejected assets prompted the attackers to seek alternative liquidity routes. These latest Zcash transfers demonstrate how the contest between hackers and recovery efforts is evolving as stolen funds encounter increased scrutiny across the crypto market.
Hackers have also utilized THORChain, a permissionless cross-chain exchange. THORChain has resisted requests from Bitget to block addresses connected to the theft, creating a divide in how decentralized infrastructure responds to identified illicit assets.
Bitget-linked wallets have repeatedly used THORChain to convert stolen assets into native Bitcoin. Bitquery estimated that approximately 29,088 ETH, valued at about $79 million at the time of analysis, was sent into THORChain and swapped for Bitcoin through Sept. 29.
THORChain's volume surged following the breach. The decentralized exchange processed over $1.5 billion in volume in the days immediately after the incident, compared to roughly $146 million in volume during the week preceding the attack, according to DeFiLlama data.
THORChain's position contrasts with NEAR's. THORChain maintains that selective censorship would undermine its network's core principles. NEAR argues that permissionless access does not obligate its liquidity providers to execute known illicit transactions.