ZachXBT names five aliases laundering Bitget’s $387.5 million hack for North Korea, and they’re doing it on Discord
On-chain investigator ZachXBT says suspected money launderers tied to the $387.5 million Bitget exploit are openly seeking help through Discord and Telegram.
On-chain sleuth ZachXBT has named five aliases he says are laundering the $387.5 million Bitget hack for North Korean attackers, and some were asking for help in public Discord and Telegram channels.
In a post on X, ZachXBT said the actors are laundering funds “on behalf of the alleged DPRK attackers” and described the activity as a pattern he has observed following multiple exploits attributed to the TraderTraitor hacking operation.
Source; ZachXBT
The claims come days after Bitget confirmed that approximately $387.5 million in digital assets were transferred to attacker-controlled addresses during a Sept. 24 security incident.
The exchange initially estimated the affected amount at $351.6 million before revising the figure after accounting for additional assets on Zcash and TRON. Bitget said the increase represented a more complete accounting of the original transfers, rather than additional theft.
ZachXBT identifies five alleged laundering aliases
ZachXBT listed five aliases that he says are connected to the laundering activity: “Cc,” “jack,” “Melon,” “lolo / Marin” and “HELP ME.”
The investigator attached Discord or Telegram identifiers and blockchain transaction references to each alias. He also highlighted one account, identified as “lolo / Marin,” as having previously appeared in the laundering of funds from the $292 million Kelp DAO exploit earlier this year.
ZachXBT did not present the aliases as confirmed identities. Instead, the post connects the online accounts to specific blockchain transactions that he says form part of the laundering trail.
The disclosure provides another look at the infrastructure that can emerge after a major crypto exploit. Rather than relying solely on a single wallet or service, stolen assets can be moved between networks and routed through different intermediaries in an attempt to make their origins harder to follow.
According to ZachXBT, the Bitget-linked funds are currently being chain-hopped through bridges before being deposited into mixing services, including Wasabi.
The technique involves moving assets between different blockchain networks, creating additional transactions and addresses between the original theft and eventual attempts to convert or obscure the funds.
Funds move through bridges and mixing services
The laundering activity is taking place as investigators continue tracking the assets across multiple networks.
Bitget said the Sept. 24 incident affected assets across Ethereum and several EVM networks, XRP Ledger, Zcash and TRON. Its investigation identified multiple attacker-controlled addresses across those networks.
The exchange has said its investigation identified the attack path and that the underlying vulnerability has been remediated. Mandiant and SlowMist are assisting with forensic analysis and fund tracing.
ZachXBT’s latest findings suggest that the challenge has now extended beyond identifying the original attacker. Investigators must also follow the network of intermediaries and services through which the stolen assets are being moved.
The investigator said the individuals he identified were not operating entirely in private. Instead, they were allegedly asking for help with orders in public communities operated by services they use.
One user asked ZachXBT why the alleged actors would use Discord rather than Telegram or other private messaging platforms. ZachXBT responded that they ask for help with orders on both Telegram and Discord.
Another commenter questioned why the actors were not using privacy-focused cryptocurrencies such as Zcash or Monero. ZachXBT replied with one word: “Liquidity.”
That exchange points to a central challenge for illicit crypto operators: privacy features may offer greater transaction obfuscation, but the ability to move large amounts of value into liquid markets can be equally important.
Investigator says more data is coming
ZachXBT said the activity follows a pattern he has seen after multiple exploits attributed to TraderTraitor, a name used in the cybersecurity industry for activity associated with North Korean state-linked cryptocurrency theft.
Independent blockchain-intelligence firm Elliptic has also assessed that the Bitget attack is highly likely to be connected to DPRK-linked activity, citing similarities with previously observed techniques. Elliptic said the incident pushed the amount of crypto theft it tracks as DPRK-linked in 2026 above $1 billion.
However, the attribution remains an investigative conclusion rather than a publicly established identification of the individuals behind the Bitget attack.
Bitget CEO Gracy Chen has previously said the attack showed similarities to techniques associated with North Korean hackers. The exchange said the attacker compromised a critical backend system in its wallet infrastructure and used it to spoof transaction information and trigger unauthorized transfers through the authorization process.
ZachXBT said he has closely tracked the groups involved and plans to release more of his data in the coming weeks.
The disclosure could provide investigators and exchanges with additional information about the people and services allegedly involved in moving the stolen assets. It also illustrates how the investigation of a major crypto exploit can continue long after the initial wallet transfers, with investigators following not only the stolen coins but the intermediaries helping move them through the wider digital-asset ecosystem.
Meanwhile, Bitget says the underlying vulnerability has been fixed and that the incident remains contained. The exchange has also launched a recovery effort while continuing its investigation with external cybersecurity firms.
Moses Edozie is a writer and storyteller with a deep interest in cryptocurrency, blockchain innovation, and Web3 culture. Passionate about DeFi, NFTs, and the societal impact of decentralized systems, he creates clear, engaging narratives that connect complex technologies to everyday life.