On-chain investigator ZachXBT has published screenshots on X pointing to Chinese intermediaries laundering funds from the $387.5 million Bitget hack, allegedly on behalf of suspected North Korean attackers. The material, posted on September 28, centres on Discord and Telegram support tickets tied to stuck THORChain swaps between XRP and bitcoin.
Bitget first detected the intrusion on September 24 at 18:31 UTC, initially reporting losses of $351.6 million before revising the figure upward to $387.5 million. The exchange has said the breach stemmed from a compromised backend service rather than a leaked private key, and has described North Korea as a "very likely" lead in the investigation. Bitget maintains a protection fund of $464 million.
ZachXBT wrote that the operation involved "acteurs illicites chinois" acting "pour le compte des attaquants présumés de la RPDC." His findings identify five aliases involved in moving the funds: Cc, jack, Melon, lolo/Marin and HELP ME.
Stuck swaps and mixer deposits
According to the investigator, roughly 103 million XRP transited through a series of wallets before reaching THORChain. One alias, Cc, reported sending 277,724 XRP through the protocol and receiving only 431 XRP back, a discrepancy cited as evidence of funds becoming stuck mid-swap. Another alias, Melon, told support staff the delay was "parce que le réseau BTC était en pause," referring to the bitcoin network being paused during the transaction.
ZachXBT's screenshots also link the alias lolo/Marin to the $292 million Kelp DAO exploit. Funds were reportedly moved across bridges before being deposited into mixing services, including Wasabi.
THORChain declines to act
Bitget CEO Gracy Chen asked THORChain to block the addresses flagged in the investigation. The protocol has not done so. THORChain has its own history with theft: a vault was drained of $10.7 million in May 2026, after which the network suspended operations for approximately five weeks.
The Bitget case follows a pattern of large-scale thefts attributed to North Korean-linked actors, including the $1.5 billion theft from Bybit in February 2025. THORChain has repeatedly featured in laundering routes following such incidents, drawing scrutiny from exchanges and investigators over its refusal to intervene against flagged wallets even when requested directly by victim platforms.




