People allegedly laundering money from the $387 million Bitget hack have been asking for customer support in public chat rooms, according to blockchain investigator ZachXBT.
He said the group are Chinese money launderers working for the suspected North Korean attackers. They posted openly in the Discord servers and Telegram channels of services they use to move the funds.
What the Bitget Hack Suspects Posted
Bitget lost $387.5 million on September 24. CEO Gracy Chen said attackers tricked the exchange’s internal approval system into signing the transfers, and that North Korea was “very likely” behind it. BeInCrypto’s Bitget hack timeline lays out how it happened.
ZachXBT named five accounts and matched each one to a transaction. His screenshots show them complaining to staff at THORChain, a network that swaps coins between blockchains without an account, that XRP-to-Bitcoin swaps never arrived.
One user, “Cc,” wrote that 277,724 XRP went in but only 431 came back. Another, “jack,” said losing the assets “would cause a lot of trouble in my life.” A moderator for the swap service SwapKit answered with a photo of Kim Jong Un.
Kelp DAO Link and the North Korean Pattern
ZachXBT said one account, “lolo,” also laundered money from the $292 million Kelp DAO exploit in April. In the chat, lolo confirmed going by “Marin” on Telegram.
“I’ve observed the same pattern after multiple TraderTraitor attributed exploits, and I’ve closely tracked these groups,” the on-chain sleuth wrote.
TraderTraitor is the FBI‘s name for a North Korean hacking group. The bureau blamed it for the $308 million theft from Japanese exchange DMM Bitcoin in 2024.
The funds are now hopping between blockchains through bridges and landing in mixers such as Wasabi, a wallet that blends coins to hide their trail, he said.
THORChain has refused to block wallets tied to the attackers. Bitget said withdrawals reopen Monday. ZachXBT plans to release more data on the groups in the coming weeks.
Source: BeInCrypto