Chainalysis AI tracing Bitget hack transactions through blockchain networks

Chainalysis AI Cuts Bitget’s $387M Hack Tracing From 20 Hours to 10 Minutes

Key insights

  • Chainalysis cut a twenty‑hour bridge matching task to, than ten minutes, which I find impressive.
  • Bitget lost three hundred eighty‑seven million dollars across Ethereum, XRP, Zcash and Tron which I see as a huge loss.
  • Faster transaction labeling could extend the window to freeze stolen crypto, which would help.

Chainalysis AI cut than 20 hours of manual bridge reconciliation to under 10 minutes during the investigation into Bitget’s $387 million hack. The speed allowed investigators to connect transactions across four blockchains while tracking funds that moved through cross-chain protocols.

Chainalysis reported the development on Oct. 1 after Bitget suffered the breach on Sept. 24. The analytics firm said its investigators directed the process while its in-house AI handled transaction matching. The firm also attributed the theft to Korean actors saying their crypto thefts, in 2026 have now exceeded $1 billion.

Investigators turned hours of tracing into minutes

Bitget detected unauthorized transfers at 18.31 UTC on Sept. 24 from parts of its hot and warm wallet infrastructure. Chainalysis later identified 23 transfers that moved roughly $387 million during the first three hours of the attack.

The funds were spread across Ethereum, XRP, Zcash and Tron. Ethereum made up 49.7% of the transfers. XRP accounted for 40.8%. Zcash contributed 7.6%. Tron made up the rest at 1.8%.

Chainalysis AI was used to match deposits on one network with payouts on another. Investigators set the matching rules. They reviewed the results. Decided which leads needed deeper look.

The firm said this process cut bridge reconciliation time from over 20 hours to, under 10 minutes. It also allowed new addresses to be labeled as receiving stolen funds within minutes. That quicker labeling gives exchanges, issuers and authorities time to detect suspicious transactions. It also increases the chance to freeze assets before they move further.

Stolen XRP created a complex cross-chain trail

Investigators followed stolen XRP through a cross-chain liquidity protocol that converted the assets into Bitcoin. According to Chainalysis, tens of millions of dollars passed through the route over roughly a day and a half.

The funds then moved through additional protocols before reaching Bitcoin addresses controlled by the attackers. Chainalysis said its team continues monitoring those destinations as the investigation progresses.

Meanwhile, Bitget revised its original loss estimate from $351.6 million to $387.5 million. The higher figure included additional Zcash and Tron transfers identified during the investigation.

Bitget later said attackers exploited a vulnerability involving a third-party security product. The exchange said the weakness allowed attackers to obtain credentials and forge withdrawal commands.

Mandiant and SlowMist assisted with the forensic investigation. Bitget maintained that its cold wallets and private keys remained secure.

Bitget pursued recovery as THORChain refused blocking

It offered separate 5% rewards for qualifying assistance that helped freeze stolen funds or recover them. Circle and Tether also froze about $318,000 in linked USDC and USDT by Sept. 26.

However, recovery efforts faced limits as the stolen assets moved through decentralized infrastructure. Bitget CEO Gracy Chen asked THORChain to block the addresses that were linked to the attackers after the funds entered the network.

THORChain said no to the request. It said its emergency controls are meant to protect the security of the network. The network does not freeze addresses selectively. GoPlus later questioned the comparisons made between THORChain and networks like Bitcoin and Ethereum.

The disagreement brought attention to a conflict between open, permissionless systems and the needs that arise during recovery after a security breach. Because of this investigators often have to depend on surveillance tracking efforts and help, from platforms.

Faster tracing raises the recovery stakes

While Chainalysis AI turned a significant manual process into minutes, the faster the tracing, the sooner the stolen assets are not restored. Instead, the technology provides investigators with a briefer lag between any suspicious transfers and identification of the industry.

It is useful when the attackers are transferring assets via bridges, instant swaps and several blockchain networks. Every extra transaction could make manual reconciliation slower and provide more funds leaving reachable services opportunities.

The findings also add another layer to the worries about North Korea’s crypto theft. The company attributed the Bitget hack to North Korean hackers and reported that the attacks have now cost more than $1 billion.

Withdrawals were gradually resumed on Bitget after the hack. Withdrawals in bitcoin were restarted on Sept. The 28th was followed by Ether on Sept. 29 and USDT on Sept. 30. The investigation is ongoing and Chainalysis is monitoring and investigating identified addresses and working with exchange and law enforcement partners.

Conclusion

The Bitget investigation illustrates the importance of cross-chain tracing in the context of crypto theft recovery. The Bitget investigation highlights the pivotal role of cross-chain tracing in the realm of crypto theft recovery. In addition to the features mentioned above, Chainalysis AI enhanced transaction matching capabilities, allowing human investigators to maintain control over the investigation and decisions made.

The technology is unable to regain the money on its own. But if hours of manual efforts are cut down to minutes, it will boost the reaction times when attackers quickly shift assets from one blockchain network to another.

Scroll to Top