On September 24, 2026, cryptocurrency exchange Bitget suffered an exploit that resulted in the theft of $387 million. Chainalysis attributed the attack to threat actors linked to the Democratic People's Republic of Korea (DPRK).

The incident pushes total crypto stolen by DPRK-linked entities in 2026 past $1 billion. Bitget partnered with security firms Mandiant and SlowMist to investigate the breach.

Within three hours of the exploit, the $387 million left Bitget through 23 transfers across four blockchains. Ethereum received 49.7 percent of the stolen assets, XRP Ledger 40.8 percent, Zcash 7.6 percent and Tron 1.8 percent.

Chainalysis identified multiple laundering mechanisms, including cross-chain liquidity protocols, cross-chain messaging protocols and instant swap services. The analysis revealed links to established laundering services.

Chainalysis's AI-powered automation tools compressed over 20 hours of manual bridge reconciliation into less than 10 minutes. An agentic platform allowed investigators to interrogate data sources and develop custom solutions for the Bitget case. Investigators retained control over logic, output review and investigative direction.

A key challenge involved tracking stolen XRP. Attackers routed it through a cross-chain liquidity protocol such as THORChain to acquire Bitcoin on the other side, rather than sending XRP directly to an exchange. Chainalysis matched the initial XRP deposits to their corresponding Bitcoin payouts, extending the fund trail across blockchains. Labels flagging the stolen funds went live on Chainalysis's platform within minutes, providing compliance teams and law enforcement with real-time data.

DPRK-linked threat actors increasingly use automation to obscure and move stolen funds. Chainalysis noted that DPRK groups often target large crypto firms by placing IT workers inside companies, posing as recruiters to steal credentials and approaching executives with fabricated investor pitches.