Bitget Hackers Move $4 Million Through Zcash as Exchange Grapples with Aftermath

Translucent Bitcoin symbol with glowing network filaments, smoke, light particles, and shadowy market candles in slate grey.

Hackers Funnel Millions Through Zcash Shield

On Wednesday, wallets tied to the $388 million Bitget hack shifted roughly $3.9 million in zcash (ZEC) into Zcash’s private pool, complicating efforts to trace the stolen assets.

The funds first passed through two intermediary addresses before reaching Ironwood, both funded by a wallet Bitget had previously identified as belonging to the attacker. While nearly 18,917 ZEC were received by this address during the initial theft, only a fraction has been laundered through privacy pools so far.

This latest maneuver follows earlier attempts to obscure funds: previous traces identified approximately $6.3 million in swaps from ether (ETH) to bitcoin (BTC) via THORChain, a decentralized cross-chain protocol. However, THORChain declined Bitget’s request to block the hacker’s transactions as another $6 million was converted to bitcoin—highlighting both the technical and ethical dilemmas facing DeFi infrastructure when dealing with criminal activity.


Blockchain investigator ZachXBT flagged three transfers totaling 2,746 ZEC into Ironwood between 08:15 and 08:46 UTC on Wednesday.

Early Clues Point to Zero-Day Flaw

Investigations have traced the origins of this attack back to August 31, when malicious actors exploited a zero-day vulnerability in a third-party security product integrated into Bitget’s infrastructure. According to cointelegraph.com, SlowMist’s probe revealed that attackers accessed “Product A” using its password—retrieved from an environment variable—to run a hidden script against its database. This early breach set the stage for the much larger theft that unfolded weeks later.

The breach was not detected until September 24, when funds began disappearing from Bitget’s hot wallets across several blockchains.

The following day, attackers escalated their efforts by leveraging an internal employee identity to penetrate the management platform of another security product (“Product B”). They attempted to inject system commands and upload malicious files, further compromising Bitget’s defenses. Forensic teams later recovered a deleted custom tool designed specifically to manipulate withdrawal controls and forge risk parameters within Bitget’s wallet system.

Massive Withdrawals and Shaken Confidence

When Bitget resumed withdrawals this week after freezing them in response to suspicious outflows, customer nerves were on full display. Over 4,000 bitcoins—valued at more than $334 million—left the exchange within just one hour of reopening withdrawals. Gracy Chen, Bitget’s CEO, reported that 9,585 orders totaling 4,098 bitcoins were processed in that brief window before activity stabilized.

This surge in withdrawals underscores a key tension: while Bitget managed to resume operations without further loss of private keys or cold wallet assets, its protection fund took a severe hit—dropping from $464 million before the hack to below $200 million afterward. The headline number is massive outflows, but beneath it lies a deeper erosion of customer trust that may take far longer to repair.

In response to the crisis, Bitget launched a bounty program offering 5% rewards on any frozen or recovered funds. Meanwhile, Tether and Circle blacklisted one attacker-linked wallet and froze over $318,000 in stablecoins; NEAR Intents also managed to block more than $50 million in assets tied to the exploit and freeze about $500,000.

Uncertain Recovery Prospects

Despite these quick countermeasures and partial asset freezes across multiple platforms, CEO Gracy Chen remains pessimistic about fully recovering all lost funds. She pointed out that in prior large-scale hacks—such as Bybit’s February 2025 incident—only a small fraction of stolen assets were ever retrieved: just $80 million out of $1.5 billion.

Bitget initially estimated its losses at $352 million but revised that figure upward after deeper analysis revealed additional compromised assets totaling $388 million. The exchange has since begun restoring withdrawal services in phases: Bitcoin withdrawals restarted Monday; Ethereum followed on Tuesday.

Whether further stolen crypto will be traced or returned remains uncertain.

The Wrap-Up

  • •On Wednesday, hackers moved about $3.9 million (2,746 ZEC) from the Bitget hack into Zcash’s Ironwood shielded pool.
  • •The Bitget breach originated from an Aug. 31 zero-day vulnerability in a third-party security product, leading to $388 million stolen.
  • •Over 4,000 BTC (worth $334 million) were withdrawn from Bitget in one hour after withdrawals resumed post-hack.

Key points still in play

If Bitget’s bounty program—offering 5% of funds frozen and 5% for those recovered—results in additional asset recovery or freezing beyond the $50 million already blocked by the NEAR Intents team and the $318,013 frozen by Tether and Circle, it would immediately increase the total amount secured from the $388 million breach; however, whether further recoveries will occur remains unclear.