FILTERED RESULTS
FILTERS
Ads Top
DARK MODE
CHART
    Filters
      Symbols
      Sentiment
      Impact
      Search
      FILTERED RESULTS

        

      Upgrade your plan
      Dashboard

      Hackers Funnel $3.9M from Bitget Breach Into Zcash Privacy Network

      Key Points

      • Cryptocurrency addresses associated with the Bitget security breach transferred approximately $3.9 million in Zcash tokens into the Ironwood private payment pool.
      • The attackers executed three separate transactions totaling 2,746 ZEC during a 31-minute window on Wednesday morning between 08:15 and 08:46 UTC.
      • Ironwood’s privacy features completely obscure sender identities, recipient addresses, and transaction values for funds held within the pool.
      • These transfers represent roughly 15% of the complete ZEC haul obtained during the September 24 Bitget compromise.
      • Previously, investigators documented separate movements involving approximately $6.3 million in ethereum-to-bitcoin exchanges conducted via THORChain.

      Cybercriminals responsible for the Bitget security incident have channeled a significant portion of their illicit proceeds into a privacy-oriented payment infrastructure, substantially complicating tracking efforts. The cryptocurrency addresses involved are connected to an attack that siphoned $387.5 million from the trading platform.

      Early Wednesday morning, approximately $3.9 million in Zcash cryptocurrency was deposited into Ironwood, a shielded transaction pool. Ironwood represents the most advanced privacy technology currently deployed on the Zcash blockchain.

      Transaction data examined by CoinDesk indicates the deposits occurred across three separate operations. The entire sequence unfolded during a half-hour period starting at 08:15 UTC and concluding at 08:46 UTC.

      Collectively, 2,746 ZEC tokens entered the privacy pool. This quantity accounts for approximately 15% of the total ZEC cryptocurrency misappropriated during the security incident.

      Understanding Zcash’s Privacy Architecture

      The Zcash protocol supports two distinct transaction types. The first operates transparently, allowing full public visibility into transaction details. The second employs privacy-preserving technology through shielded pools such as Ironwood.

      When cryptocurrency enters a shielded pool, transaction metadata immediately becomes inaccessible to external observers. The originating address, destination address, and precise transfer amounts all become cryptographically concealed.

      While external parties can observe deposits entering the privacy pool, they cannot track internal movements or relationships between transactions.

      Should funds subsequently exit the shielded pool and transfer to transparent addresses, those outbound transactions regain public visibility. Forensic analysts can then attempt reconstruction efforts.

      Investigators examine variables including transaction timestamps and transfer quantities. These analytical approaches can potentially correlate outbound transactions with earlier inbound deposits, although definitive attribution remains challenging.

      Discovery and Investigation

      Blockchain forensics specialist ZachXBT initially identified these fund movements on Wednesday. He has established a reputation for monitoring cryptocurrency security breaches and documenting stolen asset flows across distributed ledger systems.

      Based on ZachXBT’s analysis, the cryptocurrency traveled through two intermediary addresses before reaching the privacy pool. These intermediate wallets received funding from an address that Bitget has officially attributed to the perpetrator.

      This attacker-controlled wallet originally received approximately 18,917 ZEC during the September 24 security breach. The recent deposits into the shielded pool constitute only a fraction of that total amount.

      Bitget continues asset recovery operations. Transferring stolen funds into privacy-focused pools represents a standard adversarial tactic designed to obstruct or prevent successful recovery initiatives.

      These recent movements are not the perpetrators’ first attempt at concealment. CoinDesk has previously documented additional transactions originating from the same attacker-controlled addresses.

      In one documented instance, approximately $6.3 million in ethereum was converted to bitcoin. These cryptocurrency exchanges were facilitated through THORChain’s decentralized liquidity protocol.

      In contrast to the Zcash shielded pool methodology, THORChain transactions maintain public visibility. Forensic investigators could observe the incoming ethereum deposits and corresponding bitcoin withdrawals.

      This distinction underscores why Zcash’s privacy pools present substantially greater challenges for blockchain analysis firms. The technology eliminates transaction visibility completely during the custody period within the pool.

      As of Wednesday afternoon, no withdrawals from the Ironwood pool had been detected. The misappropriated assets remain distributed across multiple concealment strategies, with varying degrees of transparency.


      Source: Parameter
      .

      Terra Founder Do Kwon Sentenced to 15 Years in Prison for Fraud