The attackers behind the $387.5 million Bitget breach have started moving part of their loot into Zcash’s private payment system. The move makes the stolen funds harder to follow and shows how laundering tactics are shifting as some protocols refuse to cooperate.
What moved on Wednesday
On-chain investigator ZachXBT flagged the activity on September 30. Wallets linked to the exchange hack sent 2,746 ZEC, worth about $3.9 million, into Ironwood, Zcash’s newest shielded pool. The deposits came in three transfers over 31 minutes. They passed through two intermediary addresses funded by a wallet that Bitget had already identified as belonging to the attacker.
That amount is only a slice of the stolen ZEC. ZachXBT puts the total taken from Bitget’s hot wallet at roughly 18,900 ZEC, worth about $28.3 million, so the Ironwood deposits represent around 14% to 15%. The remaining ZEC, close to $24 million, still sits on transparent addresses where it can be monitored. ZachXBT has alleged that North Korean-linked actors are responsible. That attribution has not been independently confirmed.
Why shielding matters
Zcash supports two kinds of addresses. Transparent ones work like Bitcoin, with every movement visible on the ledger. Shielded pools encrypt the sender, the recipient and the amount. Deposits into Ironwood can still be seen, so investigators know exactly how much entered. Once the coins are inside, outgoing transfers cannot be reliably linked back to the original theft.
Shielding the funds does not make them counterfeit, and it does not change the loss Bitget disclosed. It does make recovery harder. Exchanges and law enforcement usually rely on following funds to a point where they can be frozen. A privacy pool breaks that chain.
The route that failed first
The Zcash move follows a failed attempt to launder far larger sums. NEAR Intents general manager Alex Shevchenko said wallets associated with the theft tried to push more than $50 million through the protocol’s cross-chain swaps. NEAR refused to process the transactions.
THORChain, another cross-chain venue, has reportedly continued to allow transactions linked to the incident, citing its decentralised design. That has drawn criticism from people who argue that protocols should block activity tied to confirmed thefts. The split highlights a growing divide between networks willing to police flows and those treating neutrality as a principle.
How the breach unfolded
The attack began on September 24, when Bitget’s systems flagged unauthorised outgoing transactions from a hot wallet. That is an internet-connected wallet used for an exchange’s day-to-day liquidity. Bitget said its protection fund covered the losses, so customer balances were not affected. Withdrawals were suspended for several days and have since been gradually reopened.
The company is continuing its recovery efforts, but the Ironwood deposits make that harder for the portion of funds now shielded.
What to watch next
The main unknown is how much of the remaining transparent ZEC will follow into the shielded pool. The untouched balance is now the figure that matters, since any further deposits can be measured against it. Investigators will also watch for the attackers using other privacy tools or swap services.
For the wider industry, the episode raises awkward questions. Privacy features that protect ordinary users also give thieves a place to hide. Cross-chain protocols face growing pressure to decide what they will and will not process. Regulators in several jurisdictions are already weighing how to treat privacy-focused assets, and a high-profile laundering case could add fuel to that debate.
The takeaway
The shielded deposits are a relatively small share of the haul, but they signal where the attackers are heading. With one major swap route closed and another contested, privacy pools offer a way to cut the trail. For Bitget, the next phase is likely to be a race between its recovery team and the people trying to disappear with the funds.

