Chainalysis Links $387M Bitget Theft to North Korean Hackers
TREE NEWS reports: Chainalysis has attributed the $387 million Bitget theft to North Korean hackers, pushing the total value of crypto stolen by DPRK-linked actors this year above $1 billion. The attackers reportedly used a cross-chain swap to convert stolen XRP into Bitcoin and kept the tokens away from centralized exchanges, complicating tracing and seizure efforts.
How the Attack Unfolded
The Bitget incident fits a pattern that has become familiar: a large exchange breach, rapid on-chain laundering, and a deliberate pivot out of a traceable asset into Bitcoin. By swapping XRP for BTC through cross-chain infrastructure, the attackers reduced exposure to issuers and exchanges that can freeze assets. Keeping funds off exchanges also limits the effectiveness of blacklisting and seizure requests that regulators and law enforcement rely on.
Why XRP and Bitcoin Matter Here
The choice of assets is notable. XRP’s ledger offers issuers and exchanges limited ability to intervene once funds move, while Bitcoin’s liquidity and decentralized custody make it attractive for long-term holding. The cross-chain swap itself highlights a broader risk: bridges and swap protocols designed for legitimate interoperability can be abused to obscure the origin of stolen funds. For compliance teams, the lesson is that monitoring must extend beyond exchange deposits to cross-chain flows and self-custody movements.
The North Korean Playbook
DPRK-linked groups have spent years refining a playbook that combines technical exploits with disciplined laundering. The $1 billion-plus stolen this year underscores that sanctions and travel rules have not stopped the activity. The involvement of Drift, KelpDAO and other protocols in the broader ecosystem of traced flows suggests that North Korean actors are not limiting themselves to exchanges; they are probing DeFi infrastructure as well.
Implications for Exchanges and Regulators
- Exchanges: Expect tighter withdrawal controls, enhanced cross-chain monitoring, and faster freezing coordination.
- Regulators: The case strengthens arguments for stricter reporting on cross-chain transfers and for sanctions enforcement targeting mixers and bridges.
- Investors: Headline risk around exchange security remains elevated, particularly for platforms with large XRP and BTC reserves.
Forward Look
The Bitget hack is unlikely to be an isolated event. As long as cross-chain swaps and self-custody offer effective obfuscation, North Korean actors will keep using them. The coming year will test whether the industry can build faster, more coordinated responses — and whether regulators can close the gap between on-chain reality and enforcement reach.




