Chainalysis says artificial intelligence helped its investigators cut more than 20 hours of manual blockchain reconciliation down to under 10 minutes while tracing the 387 million USD stolen from crypto exchange Bitget — a glimpse of how fast the good guys are getting at following stolen money across chains.
By Priya Sharma | October 4, 2026
The firm laid out the details in an October 1 report on the Bitget hack, the September 24 breach that saw attackers drain roughly 387 million USD from the exchange’s hot and warm wallet infrastructure. For everyday DeFi users, the report matters for two reasons: it shows exchanges and investigators can respond to mega-thefts faster than ever, and it explains why some stolen funds get frozen quickly while other trails run cold. Bitcoin, meanwhile, continues to trade near 84,700 USD according to the batch price snapshot, holding its ground as the industry digests the aftermath.
The Hook: 20 Hours of Detective Work, Compressed to Minutes
- The Hook: 20 Hours of Detective Work, Compressed to Minutes
- On-Chain Evidence: 23 Transfers, Four Blockchains, 387 Million USD
- The Core Conflict: Attribution, THORChain, and Who Should Block What
- Market Implications: Faster Tracing Raises the Cost of Stealing
- The Verdict: AI Is Not the Detective — It Is the Assistant
When hackers move stolen crypto, they rarely keep it on one blockchain. They hop across networks — through cross-chain bridges, instant-swap services and mixing tools — precisely to make the trail hard to follow. Reconciling those hops by hand has traditionally been one of the slowest parts of any investigation.
Chainalysis says that for the Bitget case, its team built custom automation, with AI accelerating the process, that matched deposits on one network with payouts on another. A reconciliation task that previously took more than 20 hours of manual work was completed in under 10 minutes. Importantly, the firm stresses the AI did not run the show. As the report put it, “Our investigators still defined the logic, reviewed the outputs, and directed the investigation.”
On-Chain Evidence: 23 Transfers, Four Blockchains, 387 Million USD
The numbers from the attack itself remain staggering. Within the first three hours of the breach, Chainalysis recorded 23 transfers carrying about 387 million USD out of Bitget. The breakdown by blockchain, according to the firm:
- Ethereum — 49.7% of the stolen value
- XRP — 40.8% of the total
- Zcash — 7.6%
- Tron — 1.8%
Bitget’s systems detected the unauthorized transfers at 18:31 UTC on September 24. The exchange initially estimated its losses at 351.6 million USD, later raising the figure to 387.5 million USD after accounting for additional Zcash and Tron transfers. According to CEO Gracy Chen’s initial account, the attacker compromised a critical backend system, manipulated transaction data, and triggered the authorization process — while cold wallets and private keys stayed secure. The exchange’s follow-up investigation pointed to a vulnerability in a third-party security product that let attackers obtain credentials and forge withdrawal commands, with Mandiant and SlowMist assisting the forensic work.
One of the most revealing trails involved stolen XRP. Investigators tracked transfers through a cross-chain liquidity protocol that paid out Bitcoin instead of sending the XRP directly to an exchange — tens of millions of dollars passed through that route over roughly a day and a half before landing at attacker-controlled Bitcoin addresses. Newly identified addresses received stolen-fund labels within minutes, making the data immediately available to compliance teams worldwide.
The Core Conflict: Attribution, THORChain, and Who Should Block What
Chainalysis attributes the theft to North Korean actors, whose total crypto theft in 2026 it now puts above 1 billion USD. Chen’s own initial assessment was more cautious, citing IP behavior and VPN infrastructure consistent with known North Korean operations without confirming responsibility at that stage.
The case also reignited one of DeFi’s oldest arguments. After stolen funds began moving through THORChain, Chen pressed the protocol to block attacker addresses — and THORChain refused, arguing its emergency controls exist to protect network security, not to freeze individual wallets. Chen countered that decentralization should not shield services processing known stolen funds, while security firm GoPlus noted that THORChain’s validator-controlled vaults and signing system give its operators powers that ordinary blockchain validators do not have. On the issuer side, Circle and Tether had frozen a combined total of approximately 318,000 USD in USDC and USDT linked to the breach by September 26. Bitget has separately offered a 5% bounty for qualifying help freezing stolen funds and another 5% reward for successful recovery.
Market Implications: Faster Tracing Raises the Cost of Stealing
For regular investors, the practical takeaway is that the window in which thieves can quietly cash out is shrinking. When addresses linked to stolen funds get labeled within minutes rather than days, exchanges and compliance desks can refuse deposits before the money ever reaches an off-ramp. That does not recover funds on its own — much of the Bitget haul remains at large — but it systematically raises the cost and complexity of laundering large thefts.
It also strengthens the case for keeping assets on exchanges with visible reserve health. Bitget has restored withdrawals of major assets — Bitcoin on September 28, Ether on September 29, and USDT on September 30 — and says its Protection Fund has returned above 300 million USD. The exchange’s September 29 reserve snapshot reported a 131% overall ratio across 19 covered assets, each above 100%, while maintaining that customer balances were unaffected.
The Verdict: AI Is Not the Detective — It Is the Assistant
The most important sentence in the Chainalysis report is the one stressing that human investigators still defined the logic and directed the case. AI compressed the grunt work of matching cross-chain transfers; it did not decide who to chase. For an industry that loses billions a year to theft, that combination — machine speed with human judgment — is becoming the standard playbook. Watch for labeled-address lists to grow in the coming weeks as the remaining funds move, and for the freeze-versus-permissionless debate that THORChain sparked to return the next time a major protocol sits in a laundering path.
The cryptocurrency market remains highly volatile. This article is for informational purposes only and does not constitute financial advice.
ten minutes to map what used to take a team two days of bridge hopping by hand. the hackers respond by laundering through more chains, so now its an automation arms race
The frozen-versus-lost split in the Bitget case is the detail worth keeping. Speed only saves funds that touch a counterparty willing to freeze. Anything pure peer to peer is gone.
tracing 387M across chains in 10 minutes while the hackers are still hopping bridges. the gap between attack speed and chase speed is finally closing
10 minutes to trace, months to freeze anything. chase speed is closing for the tracing side, the freeze side still runs on lawyer hours
lawyer hours until the flagged addresses hit a compliance terminal, then its one click to reject the deposit. the bottleneck moved from tracing to getting smaller venues to actually run the feed
one click assumes the venue even runs the feed. half the places 387m can wash through have no compliance terminal at all
lawyer hours is generous, try never. my withdrawal ticket from the 2022 exploit era is still technically open
Chen asking THORChain to freeze attacker addresses and getting refused is the part that should worry people. the tech to trace is clearly here, the will to stop it halfway isnt
thorchain saying no is the system working as designed, permissionless cuts both ways. the freeze button everyone wants already exists, its called a bank
thorchain refusing is kind of the point though. you freeze one address today, tomorrow every regulator wants a button
kinda disagree, thorchain refusing the freeze is why it works at all. fix it at the exit ramps with exchange screening, a dex kill switch would get abused within a year
20 hours down to 10 minutes is great but onionrout has a point, the freeze debate got settled on ramps years ago. chainalysis feeds kraken and binance already, that is the actual recovery mechanism here
chen asking a dex to freeze is asking a protocol to grow a compliance department overnight. the refusal was predictable, deposit screening at the exit ramps is the actual lever
imagine building the perfect bridge hop laundering stack and a cluster of gpus reconstructs it before your second transfer confirms. rough week to be a hacker
20 hours down to 10 min is impressive but the 387M still left the building on sept 24. tracing fast and recovering funds are two different sports
Fast tracing still matters even without recovery. Once those addresses got flagged, every major exchange could refuse the deposits. That is how most frozen funds actually get frozen.
the 387m was always gone the minute it hit those bridges. but flagged addresses in 10 minutes means the launderers get a shrinking menu of venues every hour, that compounds
true, but the 387m left in pieces, not one bag. every hop after the 10 minute flag lands on a smaller venue willing to take it, thats where the trail actually dies
which is exactly why the bounty math works, pieces get sloppy. someone bridges a fragment to a kyc exchange eventually
exactly, 10 minutes to flag while the 387m is already hopping bridges. trace speed only pays when exchanges pre-screen against the feed, otherwise its forensics for a lawsuit
the part people miss about the 10 minute trace is exchanges can screen deposits against it in real time now. the hack still pays for the lawyers, just not for the cashout
the bitget drains bridged through instant swaps within hours on sept 24. 10 minute tracing only matters if the flagged list reaches small exchanges fast, thats where the laundering actually finishes
chainalysis pinned the cluster fast but the instant swap hops mean dozens of downstream venues each need the list pushed manually. 10 minutes becomes 10 hours of outreach
the outreach bottleneck is real but flagged clusters propagate through shared compliance feeds now. venues plugged into the feed get it within the hour, the ones that dont are where the trail goes to hide
20 hours of manual reconciliation compressed to 10 minutes changes the tracing economics. smaller thefts used to be too cheap to chase, now nothing is below the floor
ingrid is right on the economics. the 387m made headlines, the real shift is every 40k drainer wallet now costs more to trace than it did to rob
10 minutes is a nice flex for the report but the sept 24 drains hit instant swaps within hours. tracing won the sprint, the laundering runs a marathon
read the oct 1 report, the AI flagged the bridge hops but a human still had to sign off on each cluster merge. faster pipeline, same bottleneck
the human gate is the point though. a false cluster merge poisons the shared feed for every venue plugged into it, a slow signoff beats 10 minutes of wrong flags rippling everywhere
23 transfers in 3 hours across 4 chains, reconciled in 10 minutes. the speed advantage only existed because tracing stayed manual for a decade after the hackers automated
10 minutes to map 23 hops across 4 chains and the money still moved anyway. tracing is basically solved, custody obviously isnt, thats the actual bitget takeaway