The recent hack of the Bitget platform, which resulted in the theft of nearly $387.5 million, continues to generate significant headlines. Renowned on-chain investigator ZachXBT recently uncovered a network of China-based intermediaries allegedly laundering stolen assets on behalf of North Korean hackers. This money-laundering operation heavily leverages the THORChain protocol to convert massive volumes of XRP into Bitcoin. Even more startling is the brazen audacity of these actors, who do not hesitate to publicly request technical support on the protocol's Discord and Telegram channels whenever their automated transactions encounter technical hurdles.
On-chain analysis reveals a sophisticated modus operandi involving five identified aliases, whose activities have been linked to wallets associated with the Bitget attack. These individuals, employing methods previously observed in incidents like the Kelp DAO exploit, funnel stolen funds through mixers such as Wasabi after routing them through various cross-chain bridges. The evidence provided by the investigator is backed by explicit screenshots: customer support tickets where these intermediaries share transaction IDs and demand that their swaps be processed, confirming that the money-laundering process relies not just on algorithms, but on constant human intervention.
This situation has sparked significant tension between Bitget and THORChain. The exchange's leadership, while assuring that its $464 million reserve fund will cover user compensation, has formally requested that the implicated addresses be frozen. However, THORChain has refused, reaffirming its permissionless nature. According to the protocol's developers, blacklisting specific addresses would contradict the fundamental decentralization principles governing their infrastructure—much like those of Bitcoin. While technically consistent with the philosophy of open networks, this stance raises major ethical and security concerns in an ecosystem where the freezing of illicit funds has become a critical regulatory issue.
This case once again illustrates the complexity of combating cybercrime in the digital asset sector, particularly when state-sponsored actors are suspected. As Bitget attempts to contain the fallout from the intrusion, the inability—or refusal—of intermediary protocols to cooperate with victims undermines global security. The industry now faces a persistent dilemma: how to preserve the immutability and total openness of blockchains while preventing organized criminal entities from using these very tools to convert their spoils into untraceable funds.