Latest News

Bitget Hack Wallets Move $3.9 Million in Zcash Into…

Why Did The Hacker Move ZEC Into Zcash’s Private Pool?

Wallets linked to Bitget’s $387.5 million security breach moved about $3.9 million in Zcash into the network’s private payment system on Wednesday, making part of the stolen funds substantially harder to trace.

Three transactions sent a combined 2,746 ZEC into Ironwood, Zcash’s newest shielded pool, between 08:15 and 08:46 UTC. The transfers represent roughly 15% of the ZEC taken during the Sept. 24 attack.

Blockchain investigator ZachXBT first flagged the movements. The ZEC passed through two intermediary addresses funded by a wallet Bitget has identified as attacker-controlled. That original address received nearly 18,917 ZEC during the breach.

The move adds another stage to the laundering process following an attack that exploited a third-party security product and Bitget’s transaction-signing infrastructure, rather than compromising the exchange’s private keys.

Bitget has said the Sept. 24 incident affected assets across Ethereum and other EVM networks, XRP Ledger, Zcash and Tron. Its final estimate of $387.5 million was higher than the initial $351.6 million figure partly because Zcash and Tron assets were added during the reconciliation process.

What Happens When Stolen ZEC Enters Ironwood?

Zcash supports both transparent transactions, where blockchain observers can see addresses and amounts, and shielded transactions designed to conceal payment information.

Investigators can see the 2,746 ZEC entering Ironwood, but once the coins are inside the shielded pool, the blockchain no longer publicly reveals the sender, recipient or transaction amount for subsequent shielded transfers.

If ZEC later leaves the pool for a transparent address, the amount exiting becomes visible again. Analysts can attempt to compare deposits and withdrawals using timing, values and other metadata, but the protocol does not expose a direct transaction trail connecting an Ironwood deposit with a later withdrawal.

Ironwood was introduced after Zcash developers designed a new shielded pool following a critical issue involving the older Orchard system. Privacy is central to the architecture, and shielded usage has been rising sharply. Zcash recently recorded its highest weekly number of shielded transactions since 2022, with more than 62,000 shielded transactions in a single week.

Investor Takeaway

The important change is not that the stolen ZEC disappeared from the blockchain. Investigators can still see assets entering and leaving Zcash’s transparent layer. The problem is that Ironwood breaks the publicly visible link between those points, reducing the effectiveness of straightforward wallet-to-wallet tracing.

How Does The Zcash Route Compare With Other Bitget Fund Movements?

The attacker has been moving proceeds through multiple networks and cross-chain services, producing very different outcomes depending on the infrastructure involved.

One attacker-linked wallet previously converted roughly $6.3 million of Ether into Bitcoin through THORChain. Those swaps remained publicly traceable at the blockchain level because observers could identify the incoming ETH and corresponding outgoing BTC, even though the assets crossed between networks.

Other routes have been less successful. A broker recently rejected an attempt by the Bitget exploiter to route stolen assets through Chainflip before the transaction entered the protocol.

NEAR Intents separately said its monitoring systems blocked attempts to move more than $50 million in Bitget-linked assets and froze another $503,000 that had already entered its infrastructure.

Zcash presents a different challenge because privacy is provided at the protocol level rather than by an intermediary that can simply reject a transaction before settlement.

Why Does The ZEC Movement Matter For Bitget’s Recovery Effort?

Bitget has been working with security firms, exchanges and other crypto infrastructure providers to identify, freeze and recover assets since the breach. The exchange has also launched a recovery bounty programme and published addresses linked to the attacker.

Those efforts work best while stolen funds remain in transparent wallets or pass through centralized services capable of freezing assets. Movement into a shielded pool removes much of that visibility.

That does not necessarily mean the 2,746 ZEC is permanently beyond recovery. The attacker may eventually need to move the coins back into transparent addresses, exchanges or other services to convert or spend them, potentially creating new points for investigators to follow.

For now, however, the transfer shows how the recovery effort is becoming more difficult as the stolen portfolio fragments across networks. Bitget can continue tracking public addresses, but the ZEC entering Ironwood has moved into an environment where the blockchain itself no longer provides investigators with a complete transaction path.

You may also like