Hackers behind the $387.5 million Bitget security breach moved approximately 2,746 ZEC, about $3.9 million, into Ironwood, Zcash’s newly activated shielded pool, according to blockchain transaction records reviewed by CoinDesk.
The transfer, representing roughly 15% of the ZEC stolen in the September 24 attack, marks one of the first major tests of the privacy feature since its July 28 launch.
Bitget hackers shift stolen ZEC into Ironwood
The Bitget hackers initially obtained nearly 18,917 ZEC during the September 24 attack, according to blockchain investigator ZachXBT, as reported in the linked story.
The latest transactions involved two intermediary addresses that were funded by an address previously identified as being controlled by the attackers.
On Wednesday, those intermediary wallets sent a combined 2,746 ZEC into Ironwood, the newest shielded pool on the Zcash network.
The transactions are visible at the point where funds enter the shielded system. However, activity occurring within the shielded pool is designed to conceal important transaction details, including the sender, recipient and transferred amount.
Bitget has confirmed that the overall amount affected by its September security incident is approximately $387.5 million. The exchange said the revised figure includes assets on Zcash and TRON that were not part of its initial $351.6 million estimate.
Why Ironwood matters for tracking stolen funds
The Bitget hackers’ use of Ironwood is particularly relevant because Zcash recently introduced the pool as part of its NU6.3 network upgrade.
According to Zcash’s official documentation, Ironwood activated on the mainnet on July 28, 2026. The upgrade introduced a new shielded pool intended to strengthen the network’s supply integrity following the remediation of an issue involving the previous Orchard pool.
Zcash’s architecture allows users to make shielded transactions in which transaction information is protected from public disclosure. Ironwood therefore provides a mechanism through which funds can move without exposing the same level of transaction detail available on a transparent blockchain.
For investigators following the Bitget hackers, that distinction matters. The amount entering Ironwood can be observed, but activity after the funds enter the shielded environment does not provide the same public transaction trail.
If some of the ZEC later exits the pool into a transparent address, investigators could potentially compare the entry and exit information using factors such as timing, transaction amounts and other publicly observable metadata. However, the underlying shielded activity is not exposed as a conventional transaction history.
Bitget hackers have already used cross-chain routes
The move into Zcash is not the first attempt by the Bitget hackers to make tracing more complicated.
The linked report notes that approximately $6.3 million in ether was previously converted into bitcoin through THORChain from an attacker-linked wallet.
Unlike the Ironwood transfers, those swaps leave visible blockchain records showing assets entering and leaving the relevant system.
The broader Bitget investigation has involved multiple networks and assets. Bitget says affected assets included XRP, ETH, USDT, ZEC, USDC, USDT0, XAUt, BNB, AVAX and TRX. The exchange has also said the incident involved certain hot and warm wallet infrastructure, while its cold wallets remained unaffected.
Bitget’s official account says the attackers exploited a vulnerability in a third-party security product to obtain internal credentials and then used forged withdrawal commands to trigger unauthorized transfers.
The company says the vulnerability has been remediated and that Mandiant and SlowMist are assisting with the investigation.
The Bitget hackers’ continuing movement of assets across different networks illustrates the difficulty of recovering funds once they leave an exchange-controlled environment.
Every additional conversion, bridge or privacy mechanism can introduce another layer between investigators and the original stolen assets.
Recovery effort faces a more complex tracing challenge
The latest ZEC transfers do not necessarily mean the funds have disappeared permanently. Public blockchain records can still provide useful information about movements into and out of shielded systems, and investigators can continue monitoring known attacker-controlled addresses.
However, the Bitget hackers’ use of Ironwood demonstrates how privacy-focused infrastructure can alter the mechanics of blockchain investigations.
Zcash itself describes Ironwood as a new shielded pool introduced through NU6.3, with formal verification designed to strengthen supply integrity.
For Bitget, the focus remains on identifying the stolen assets, tracing their movement and recovering funds where possible. The exchange has stated that its Protection Fund exceeds $464 million and is intended to cover the financial impact of the incident.
Meanwhile, the Bitget hackers continue to move portions of the stolen assets. The transfer of approximately $3.9 million worth of ZEC into Ironwood represents another development investigators will need to monitor as they attempt to reconstruct the flow of funds from the September 24 breach.
The incident remains a developing investigation, and additional movements could provide further information about the attackers’ strategy or complicate efforts to identify the final destinations of the stolen cryptocurrency.