Three threads in the investigation of the September 24 Bitget breach — the largest crypto theft of the year at approximately $387.5 million — came into sharper view last week: an attribution assessment from Chainalysis, a granular fund-flow trace from BitOK, and a preliminary incident-response report from Mandiant describing how the attackers reached the exchange's wallet infrastructure.
Each is an investigative assessment rather than a final verdict, and none has yet converted into significant confirmed recoveries.
Attribution: North Korean Actors, Suspected Lazarus
In an October 1 analysis, Chainalysis described the attack as DPRK-attributed and said it pushed the value of crypto stolen by North Korean-linked actors during 2026 past $1 billion, tracing the stolen funds across four blockchains. Scorechain separately attributed attacker wallets to the Lazarus Group, the North Korean unit behind several previous exchange thefts.
The attribution remains an investigative assessment, not a government finding. BitOK's fund-flow report does not identify the people behind the intrusion, and the Mandiant preliminary report reviewed by Brave New Coin does not name a responsible state or group. For precedent, the FBI formally attributed the February 2025 Bybit theft — about $1.5 billion — to North Korea; no equivalent official statement exists for Bitget.
Blockchain investigator ZachXBT added laundering allegations on September 28, claiming that Chinese intermediaries moving Bitget proceeds for suspected North Korean attackers were requesting transaction support in public Discord and Telegram channels, with funds moving through bridges and into mixing services including Wasabi. Those claims are unverified allegations.
How the Attackers Got In
Mandiant's preliminary incident-response report said the attacker gained privileged access to third-party security appliances, established persistent access, and moved into Bitget's production wallet job server, where malicious packages were deployed. Mandiant described its investigation as ongoing.
Bitget's September 30 update said investigations by Mandiant and SlowMist broadly supported the previously disclosed attack path: compromised credentials enabled fraudulent withdrawal commands that bypassed risk controls. The exchange says private-key compromise was ruled out, cold wallets were unaffected and user balances were unchanged. Per Bitget's timeline, the first unauthorized transfers occurred around 18:31 UTC on September 24.
Where the Money Is
BitOK's October 1 update, published by Brave New Coin, gives investigators their most concrete target: 31 THORChain payouts delivered 87.823 BTC, consolidated into ten Bitcoin outputs that remained unspent as of 11:23 UTC on October 1. The outputs hold 101.78 BTC in total, but two consolidations mixed in funds from other sources — reporting the full amount as stolen would overstate what the trace establishes, BitOK cautioned.
Elsewhere the trail is darkening. BitOK recorded nine direct inputs totaling 14.61 BTC entering six Wasabi CoinJoin rounds on September 28 and 30, and 13 Tornado Cash deposits totaling 9.4 ETH on September 30. Eight storage wallets that held 50,163.84 ETH on September 28 contained essentially nothing at the October 1 check. The wider investigation maps 1,425 Bitcoin payouts totaling roughly 1,259 BTC across Ethereum-to-THORChain routes — gross flow figures that cannot be read as recoverable balances.
"The best opportunity to intervene is when stolen funds reach a centralized exchange or another service able to freeze withdrawals and identify the receiving account," BitOK analyst Alexander Manev said.
Recovery Posture
Slightly over $1 million of the stolen funds had been frozen as of late last week, by AMBCrypto's accounting. Bitget, for its part, has completed its restoration: Bitcoin withdrawals resumed September 28, Ethereum September 29, and on October 2 the exchange announced that withdrawals for all remaining tokens, along with fiat and customer-to-customer services, had resumed.
The nearest comparison for how this ends is the Liquid Network exploit: attackers there returned 3,400 BTC — roughly 85% of the bitcoin withdrawn — after exploiting a flaw in transaction-validation software. Whether the Bitget trace produces anything similar now depends on where those ten unspent outputs move next.
TrustGrade tracks the security posture of platforms and protocols in digital assets. Verified trust data: trustgrade.ai.