The wallets linked to Bitget's $387.5 million theft have begun moving stolen funds into Zcash's Ironwood shielded pool, according to on-chain activity flagged by blockchain investigator ZachXBT — a shift that comes as cross-chain services increasingly refuse to process the attacker's larger swaps.

Three transactions on Wednesday pushed 2,746 ZEC, roughly $3.9 million, into Ironwood, CryptoSlate reported, citing ZachXBT's flag. The amount is about 15% of the 18,917 ZEC stolen from the exchange on September 24. CoinDesk and Decrypt corroborated the movements. ZachXBT described the actors as alleged DPRK-linked attackers; attribution remains unconfirmed.

Deposits into Ironwood remain visible on-chain, but transactions inside the pool conceal senders, recipients and amounts — breaking the public trail investigators use to follow stolen funds once they enter.

The Squeeze That Preceded the Shift

The move into Zcash follows a series of closed doors. NEAR Intents General Manager Alex Shevchenko said wallets connected to the theft attempted to process more than $50 million through the protocol; its SHIELD risk system rejected most of those transactions before execution, froze roughly $503,000 after swaps had begun, and let about $166,000 through. The rejected assets remained under the attackers' control — free to seek other routes.

One route stays wide open. THORChain, which has refused Bitget's requests to block addresses linked to the theft, processed an estimated 29,088 ETH — roughly $79 million — swapped into Bitcoin through September 29, according to a Bitquery analysis. THORChain's DEX volume has surpassed $1.5 billion in the days since the breach, versus about $146 million in the week before, per DeFiLlama data reviewed by CryptoSlate — a surge coinciding with hacker-linked flows, though total volume is not attributable to the attackers.

A Fragmented Response

The two protocols' positions mark a widening divide over what decentralized infrastructure owes victims of theft. NEAR's argument: permissionless access does not obligate its liquidity providers to execute known illicit transactions. THORChain's: selective censorship would undermine the network's design principles, a position it has maintained since the Bybit hack routed nearly $1.2 billion through the protocol last year.

For Bitget, the practical consequence is that blocking one venue does not freeze anything — it redirects the attacker toward either permissionless rails or privacy pools. The Ironwood transfers are the first large-scale use of Zcash's newest shielded pool to launder a 2026 exchange breach, and they come at a moment when screening elsewhere in the market is tightening. Each step in that direction lowers the already-limited odds of recovery: CEO Gracy Chen said this week she is "not very optimistic" about getting the funds back.

TrustGrade tracks the security posture of platforms and protocols in digital assets. Verified trust data: trustgrade.ai.