When someone steals $387 million from a crypto exchange, they have a problem, which is that the money is a detailed public record of everything they do with it. When North Korea steals $387 million from a crypto exchange, it has the same problem, but it also has practice. On Wednesday, the blockchain analytics firm Chainalysis formally attributed the Sept. 24 hack of the Bitget exchange to actors tied to the Democratic People’s Republic of Korea, adding that the theft pushed the total value of crypto stolen by North Korea-linked groups in 2026 past $1 billion. The firm says it has been working with Bitget and law enforcement to trace the funds since the attack.

The hack itself was less a break-in than a forgery — attackers spoofed the transaction paperwork rather than cracking the vault, as we covered when Bitget effectively signed off on its own robbery. What Chainalysis has now documented is what happened next: the laundering. And the laundering was fast.

In the first three hours, the firm reports, $387 million left Bitget across 23 transfers and fanned out onto four networks. Ethereum took 49.7% of it — roughly $192 million. XRP took 40.8%, call it $158 million. Zcash got 7.6% and Tron 1.8%, the small bills of the operation. From there the funds were run through cross-chain liquidity and messaging protocols, instant-swap services and laundering platforms, the standard apparatus for making money harder to follow.

The XRP leg got particular attention in the report. Rather than sending it to an exchange — where it might be frozen — the attackers ran it through a cross-chain liquidity protocol and withdrew Bitcoin from the other side. Tens of millions of dollars moved this way over roughly a day and a half before landing in attacker-controlled Bitcoin addresses, which are now under watch. Imagine you are trying to fence a stolen painting and the fence converts it, mid-transaction, into a different stolen painting. That is more or less the service a cross-chain bridge provides, and it is why tracing this stuff is miserable work.

The chase has played out in public, with independent sleuths tracking the movements. Chainalysis notes the attacker began parking funds in Zcash’s shielded pool, the privacy feature that makes balances invisible. The swap services split on how to respond: Near Intents rejected more than $50 million in swaps tied to the hacker — and was then itself hacked days later, which is either a coincidence or a review — while Thorchain kept processing. Circle and Tether froze roughly $318,000 in stablecoins, or about 0.08% of the take.

The interesting competitive detail is how Chainalysis kept up. The firm says it built custom in-house AI automation that compressed what it estimates would have been more than 20 hours of manual bridge reconciliation into under 10 minutes — a speedup on the order of a hundredfold, by the firm’s own arithmetic. It stresses that the technology accelerated human investigators rather than replacing them, with people still directing the work. This is the crypto traceability arms race in miniature: the launderers get faster plumbing, the tracers get faster spreadsheets.

The attribution itself is a consensus at this point rather than a scoop. Bitget CEO Gracy Chen said days after the breach that its patterns matched North Korean hackers, and the analytics firm Elliptic called a DPRK link “highly likely.” Chainalysis is the third authoritative voice to say the same thing, and no one has said anything different.

North Korea, then, is past $1 billion in crypto theft for 2026 with a quarter of the year still to go. The funds are sitting in watched addresses and shielded pools, which means the world can see the money, name the thief, and — for now — do roughly $318,000 worth of something about it.