Abstract cross-chain forensic tracing of funds stolen from Bitget

Chainalysis Says AI Traced the $387 Million Bitget Hack in Under 10 Minutes

• October 3, 2026 3:10 pm • Comments

Chainalysis says its investigators used in-house artificial intelligence to follow the $387 million stolen from Bitget across four blockchains, cutting one of the most labor-intensive parts of the job from more than 20 hours to less than 10 minutes.

That is the striking number. But the more important point for the crypto market is what happened around it: human investigators defined the logic, checked the results, and used automation to keep up with an attacker moving assets across chains at machine speed.

The first three hours were a cross-chain sprint.

In its account of the investigation, Chainalysis said $387 million left Bitget in 23 transfers during the first three hours after the September 24 breach. Ethereum received 49.7% of the outflow, while 40.8% landed on the XRP Ledger.

Zcash accounted for 7.6% and Tron for 1.8%, giving investigators four separate ledgers to reconcile before they could follow the later swaps and protocol hops as one connected movement of funds.

Those initial transfers were only the start. The stolen assets then moved through cross-chain liquidity systems, messaging protocols, instant swaps, and services used to blur the trail.

A transaction graph confined to one blockchain would have shown only fragments of the larger route, leaving the deposits on one network disconnected from the payouts that appeared elsewhere.

Chainalysis said its team operated a round-the-clock war room with Bitget and law-enforcement partners. Labels for identified stolen funds were added to its data platform within minutes so compliance teams could respond while the assets were still moving.

The firm said the custom tools worked on top of cross-chain mapping data built over more than a decade. That historical record let investigators connect protocol activity that would otherwise look unrelated.

Bitget said the investigation found malicious activity involving a third-party security product:

Why the XRP trail mattered.

The stolen XRP created a particularly difficult leg of the investigation. The attackers avoided a direct deposit at a centralized exchange.

They sent XRP into a cross-chain liquidity protocol and received Bitcoin on the other side.

That route can make two connected transactions look unrelated. Chainalysis matched deposits to payouts and extended the trail across blockchains.

The firm followed tens of millions of dollars through subsequent protocols to Bitcoin addresses it identified as attacker-controlled. Those addresses remain under monitoring.

The company said its AI did not decide who was responsible or replace investigators. It helped build custom automation on top of Chainalysis’ existing cross-chain data.

Investigators still chose the questions, reviewed the output, and decided where to follow the money.

That distinction matters. This was not a chatbot guessing at wallet ownership.

It was automation reducing repetitive reconciliation work while experienced analysts stayed responsible for the conclusions.

Bitget restored service while the tracing continued.

Bitget temporarily paused withdrawals after the attack and later restored them in phases. Chief executive Gracy Chen said in a September 28 recap that Bitcoin withdrawals were live and that Ethereum, USDT, and other assets would follow.

She also said the exchange had completed a trace-back and identified the exploited backend path.

Decrypt’s reporting noted that the Chainalysis finding reinforced earlier assessments from Chen and blockchain analytics firm Elliptic. Chainalysis said the theft pushed the value stolen by North Korea-linked actors in 2026 above $1 billion.

The report also described a split response from services that encountered the funds. Near Intents rejected more than $50 million in swaps tied to the attacker, while other routes continued processing transactions.

Stablecoin issuers Circle and Tether froze roughly $318,000, a small share of the overall theft and far below the amount routed across the four chains. Most of the value had already moved into assets and pathways that cannot be frozen by a centralized issuer.

The real race is now speed against speed.

Crypto investigators have always had transparent ledgers working in their favor. Their disadvantage is that transparency can be scattered across many networks, bridges, and swap services.

Attackers need only move quickly enough to stay ahead of the teams labeling addresses and warning exchanges.

Compressing hours of cross-chain reconciliation into minutes changes that contest. It gives exchanges, stablecoin issuers, compliance teams, and law enforcement a better chance to act while the trail is still hot.

It does not guarantee recovery, and Chainalysis did not claim that it did. The funds are still being monitored and the investigation is continuing.

What this episode demonstrates is narrower but important: investigators can now automate the connective work between chains without outsourcing the judgment that makes the evidence useful.

Join the conversation!

We have no tolerance for comments containing violence, racism, profanity, vulgarity, doxing, or discourteous behavior. If a comment is spam, instead of replying to it please click the icon below and to the right of that comment. Thank you for partnering with us to maintain fruitful conversation.