BLOCKCHAIN AI.NEWS

Security

Ten Minutes of AI Tracing, and a North Korea Verdict With the Working Left Out

Chainalysis says its in-house AI compressed more than 20 hours of bridge reconciliation on the $387 million Bitget theft to under 10 minutes, and that the theft pushes North Korea's 2026 total past $1 billion. The post states the attribution as settled and explains it nowhere. Elliptic, six days earlier, published the address overlaps it relied on. No government has attributed the theft, and the money anyone has actually stopped totals $318,013 frozen and $503,000 held.

Editorial illustration: thousands of thin frosted-glass threads stream across a dark chrome table from four directions and converge into one small knot glowing warm gold, while a narrow electric-blue beam sweeps across them
✓ Chainalysis's October 1 post read in full by this desk · crypto.news and The Defiant were earliest among the outlets this desk found, then Decrypt on October 3 · Elliptic and TRM Labs assessments of September 25 · Taylor Monahan via Gizmodo · Freezes via CoinDesk · The FBI's Bybit notice and Chainalysis's 2025 report for comparison

Chainalysis published its account of the Bitget theft on October 1, and the sentence that will be quoted is in the FAQ at the bottom: "On September 24, 2026, DPRK-attributed threat actors stole $387 million from cryptocurrency exchange Bitget. Within three hours, the stolen funds had moved across four blockchains: Ethereum (49.7%), XRP (40.8%), Zcash (7.6%), and Tron (1.8%)." The post's actual subject is speed. Its headline is about how the firm used AI to follow the money, and its central claim is that "more than 20 hours of manual bridge reconciliation was compressed to under 10 minutes." Decrypt led with that framing on October 3. The attribution to North Korea rides along in the first clause, and nowhere in the post does Chainalysis say what it rests on.

What the ten minutes bought

The work being compressed is specific. Chainalysis says the $387 million left Bitget "across 23 transfers" in the first three hours. The XRP, the second-largest slice, was not sent to an exchange. The attackers "pushed it through a cross-chain liquidity protocol and took Bitcoin out the other side," and "tens of millions of dollars moved through this mechanism over roughly a day and a half." The post does not name the protocol. The Defiant, reporting the same post, says on-chain records show the XRP going through THORChain, which matches what this desk found when it covered Bitget's request that THORChain refuse the addresses. CoinDesk's own analysis a week ago put completed swaps through THORChain at about $6.3 million, against far larger and unconfirmed estimates from GoPlus Security.

Matching a deposit on one chain to a payout on another is the manual part. "Such protocols let someone deposit one asset on one chain and receive a different asset on another without an account or intermediary connecting the two sides," Chainalysis writes. "But each swap still leaves an on-chain record." Its investigators "matched deposits to their corresponding payouts, bridging the gap between blockchains and extending the trail," using "in-house AI to create custom automations" that ran on top of "the cross-chain attribution data Chainalysis has built over more than a decade." Within minutes of identification, it says, labels flagging the stolen funds were live in its platform, and its customer team "kept Bitget and law enforcement partners updated." The FAQ anticipates the obvious question. Did AI replace the investigators? "No. Our investigators still defined the logic, reviewed outputs, and directed the investigation."

That is a claim about throughput, and a credible one. It is not a claim about new evidence. Nothing in the post says the automation found a link to North Korea that a person would have missed, and the destination it describes, "attacker-controlled Bitcoin addresses now being monitored," is where the trail currently ends.

Where the $387 million landed in the first three hours

Ethereum49.7%
XRP Ledger40.8%
Zcash7.6%
Tron1.8%
Share of stolen value by chain across the first 23 transfers, as published by Chainalysis on October 1. The XRP portion was later moved through a cross-chain liquidity protocol into Bitcoin; Chainalysis does not name it, The Defiant and this desk's earlier reporting identify THORChain.

Who said North Korea, and what they showed

By October 1 the attribution was already a consensus among the people who count such things, and the record of how each arrived at it is worth laying side by side. Bitget's chief executive, Gracy Chen, said on September 25 that VPN and IP addresses and signing patterns resembled a known North Korean group, and in the same breath, as this desk reported, that the attacker's identity "hasn't been confirmed." TRM Labs wrote the same day that on-chain overlaps "point to TraderTraitor," the FBI's name for the unit behind the Bybit theft, while adding that it "has not definitively attributed the attack." Elliptic, also on September 25, went furthest and showed the most: it called the theft "highly likely to be DPRK-linked," citing a connection between XRP from the Bitget exploit and ether from a previous DPRK-attributed exploit, and further links between Bitget funds and addresses that laundered proceeds of the 2025 Bybit theft. MetaMask's Taylor Monahan posted the same kind of evidence in one line, per Gizmodo: funds stolen from Bitget "ends up in an address that previously received funds stolen from Bybit."

Chainalysis's post uses "DPRK-attributed" and "North Korea-attributed" as settled adjectives. It offers no address overlap, no cluster, no tradecraft comparison, no confidence language. The firm may well hold all of that; it sells it to governments and exchanges, and a public blog is not an evidence file. But the post is a showcase for a tracing capability, and the one finding in it that matters most to Bitget's customers, to THORChain's node operators, and to anyone deciding whether to treat these addresses as if they were sanctioned, is the one presented without working. No government has attributed the theft. The FBI's public service announcement on Bybit came five days after that theft, named TraderTraitor, and asked node operators, exchanges and bridges to block a published list of addresses. This desk found no equivalent notice for Bitget as of publication, ten days on.

A billion dollars, two-thirds of it named

Both Chainalysis and Elliptic say Bitget pushes North Korea's 2026 total past $1 billion. Neither itemizes the total. The two largest components are not hard to find: Bitget at $387 million, and the April 1 Drift theft, which the Drift Foundation now puts at $295.4 million and which Mandiant attributed in a June 3 finding to a North Korean group it tracks as UNC6862. Together they are about $682 million. Elliptic says it has tracked "more than 51 DPRK-linked incidents" this year; the other fifty or so account for the remaining three hundred million and change, and neither firm has published the list. For scale, Chainalysis's own year-end report put North Korea's 2025 take at $2.02 billion, $1.5 billion of it from Bybit, and its all-time total at $6.75 billion.

Against the $387 million, the money anyone has actually stopped is small enough to state in full. Circle and Tether froze $318,013 in stablecoins in one exploiter address on September 25, by CoinDesk's account. NEAR Intents holds $503,000 it refused to swap. Everything else is in motion or in Bitcoin, and the post's closing promise is to keep labeling destination addresses "while working with exchanges, issuers, and law enforcement partners to trace the funds and support efforts to disrupt their movement."

The Take

Chainalysis is probably right, and that is not the point. Four firms and the victim converge on North Korea, Elliptic's overlaps are the kind of evidence that has held up before, and the Bybit pattern is unmistakable to anyone who followed it. The point is that the company whose post travels furthest, because it comes wrapped in a story about AI, is the one that published nothing a reader could check. "Twenty hours to ten minutes" is a fact about Chainalysis's product. "DPRK-attributed" is a fact about the world, with consequences for who gets frozen, who gets subpoenaed, and which node operators are told they are laundering for a state. The first kind of fact can be asserted. The second kind should come with its receipts, especially when the FBI, which has them, has said nothing. The industry is learning to let analytics firms do the attributing that governments used to do. That works only if the firms hold themselves to the standard governments are held to, which is to show the overlap, not just name the adjective.

More on the subject