Chainalysis Says AI-Assisted Automation Matched Bitget Hack Transfers in Under 10 Minutes

Daily Feed
Chainalysis Says AI-Assisted Automation Matched Bitget Hack Transfers in Under 10 Minutes

Chainalysis says custom automation cut Bitget cross-chain matching to under 10 minutes

Chainalysis says custom, AI-assisted automation cut one cross-chain matching task in its Bitget breach investigation from more than 20 hours to under 10 minutes. The speedup applied to matching deposits with payouts, not tracing the entire theft. Investigators remained in control.

  • Chainalysis counted 23 transfers carrying about $387 million out of Bitget in the first three hours.
  • Investigators set the matching rules, reviewed the results and chose which leads to pursue.
  • Bitget later estimated its loss at $387.5 million.
  • The breach also exposed a dispute over whether cross-chain protocols should block suspected attackers.

What the automation did and did not do

Blockchains keep separate transaction records. When funds move between networks, investigators may need to match a deposit on one chain with a corresponding payout on another. This work, known as cross-chain reconciliation, gets harder when funds pass through multiple services or change assets along the way.

In an Oct. 1 report, Chainalysis said it built custom, AI-assisted automation after the Sept. 24 Bitget breach to match cross-chain deposits and payouts. The task took under 10 minutes, compared with more than 20 hours of manual reconciliation, the firm said.

Chainalysis did not say AI solved the case on its own. “Our investigators still defined the logic, reviewed the outputs, and directed the investigation, ” the firm said. It did not identify the specific models or technical methods used.

The firm also said newly identified addresses received stolen-fund labels within minutes. Compliance teams could then access those labels through its platform. The labels can help services spot suspicious funds, but they do not freeze or recover assets by themselves.

From XRP to Bitcoin

Chainalysis said investigators traced stolen XRP through a cross-chain liquidity protocol that paid out Bitcoin rather than sending XRP directly to an exchange. Tens of millions of dollars reportedly passed through that route over roughly a day and a half. Chainalysis said later transfers through several protocols led to Bitcoin addresses it attributed to the attackers.

The firm said it would keep monitoring those destinations and labeling additional addresses as funds moved. It did not identify every service in the reported route, so the tracing details remain Chainalysis’s account, not a complete, independently verifiable transaction map.

For the initial transfers, Chainalysis reported an asset breakdown of 49.7% Ethereum, 40.8% XRP, 7.6% Zcash and 1.8% Tron. The percentages add up to 99.9%, likely because of rounding. Chainalysis counted about $387 million moved in 23 transfers during the first three hours. Bitget later raised its estimate from $351.6 million to $387.5 million after accounting for additional Zcash and Tron transfers.

Bitget’s account of the breach

Bitget said its systems detected unauthorized transfers at 18:31 UTC on Sept. 24 from parts of its hot and warm wallet infrastructure. CEO Gracy Chen initially said a critical backend system had been compromised, transaction data manipulated and the authorization process triggered. Bitget said its cold wallets and private keys remained secure.

The exchange later said its investigation found a vulnerability in an unnamed third-party security product that allegedly let attackers obtain high-level internal credentials. Bitget named Mandiant and SlowMist among the firms helping with forensic work and tracing. The available information does not identify the product or establish the full technical sequence.

Chainalysis attributed the theft to North Korean actors. Chen’s initial assessment was more cautious. She cited IP behavior and VPN infrastructure consistent with known North Korean hacking operations, but did not confirm responsibility at that point. The attribution matters, but Chainalysis has not provided enough detail here to independently assess the evidence behind its conclusion.

Tracing is not recovery

Following funds across chains can help investigators identify addresses and services. It does not guarantee anyone can freeze or return the assets. That depends partly on where the funds go and whether a service has the ability and willingness to intervene. The available information does not establish how much of Bitget’s reported loss was ultimately recovered.

Bitget said major withdrawals resumed in stages: Bitcoin on Sept. 28, Ether on Sept. 29 and USDT on Sept. 30. In a Sept. 30 update, it scheduled the return of remaining token, fiat and peer-to-peer withdrawals for Oct. 2 at 08:00 UTC. That schedule does not confirm that every service resumed as planned.

THORChain and the limits of intervention

Bitget’s CEO sought to block attacker-linked addresses from using THORChain, a cross-chain liquidity protocol. THORChain rejected selective blocking, saying its emergency controls were intended to protect the network, not freeze individual wallets.

GoPlus challenged comparisons between THORChain and Bitcoin or Ethereum, pointing to THORChain’s vaults and threshold-signing system. Threshold signing lets a required group of participants authorize a transaction instead of relying on one keyholder. Michael Perklin, a THORChain supporter, argued that the process is automated and that shutting down the infrastructure would interrupt legitimate activity along with suspicious transactions.

The disagreement goes beyond whether a protocol can stop activity. A network-wide halt and a targeted block on particular addresses are different interventions. They carry different consequences for users and raise different questions about who exercises control. The competing claims do not, on their own, settle how decentralized THORChain is or what responsibilities its operators should accept.

Key questions and answers

  • How much was taken from Bitget?

    Chainalysis counted about $387 million in 23 transfers during the first three hours. Bitget later estimated its loss at $387.5 million.

  • What did the automation speed up?

    It helped match deposits and payouts across blockchains, cutting that task from more than 20 hours to under 10 minutes. It did not complete the entire investigation.

  • Did the automation recover the funds?

    No. It helped investigators trace transactions and identify addresses. Tracing can support recovery efforts, but it cannot freeze or return funds on its own.

  • Who did Chainalysis say was responsible?

    Chainalysis attributed the theft to North Korean actors. Chen initially described indicators consistent with North Korean hacking operations but did not confirm responsibility at that stage.

  • Why did THORChain refuse to block the addresses?

    THORChain said its emergency controls were meant to protect the network, not selectively freeze individual wallets. Critics questioned how its vault and signing arrangements fit with claims of decentralization.

Faster matching can give investigators and compliance teams an earlier lead. It cannot replace sound evidence, force a service to act or guarantee that stolen funds will come home.

Share this article

Powered by ADBYTES

Advertise smarter.

Adbytes.Media is a transparent advertising network where advertisers reach real audiences and publishers, affiliates & everyday members earn ADBYTES tokens. Join the community and start earning today.

Back to Blog