Operators laundering funds from Bitget’s $387.5 million security breach have sharply increased their use of Zcash’s privacy infrastructure, moving 2,746.31 ZEC into the Ironwood shielded pool on September 30 in three large transactions.
On-chain investigator ZachXBT identified deposits of 876.43 ZEC, 993.46 ZEC and 876.42 ZEC originating from funds associated with the Zcash address Bitget has publicly designated as attacker-controlled. At prices around $1,400 per ZEC shortly before the transfers, the batch was worth roughly $3.8 million.
The size of the move is more important than the dollar value. Previous Bitget-linked deposits into Ironwood had generally been measured in tens of ZEC. The September 30 batch alone represents about 14.5% of the roughly 18,916.72 ZEC that flowed to the attacker’s Zcash address during the original breach.
Combined with earlier activity, approximately 3,081.85 ZEC linked to the theft is now known to have entered Ironwood, equivalent to roughly 16.3% of the stolen ZEC position.

Small Zcash Transfers Have Turned Into Much Larger Moves
The laundering pattern did not begin at this scale.
The first documented Bitget-linked Ironwood transaction occurred on September 25, when approximately 5.102 ZEC moved away from the known theft address and almost the same amount entered the shielded pool. Roughly 34 minutes later, 5.1 ZEC emerged toward a NEAR Intents 1Click swap, which subsequently paid Bitcoin to an address that also appears on Bitget’s attacker list.
Seven additional transactions followed through September 27. Together, those first eight shielding transactions accounted for about 246.74 ZEC. Investigators reconstructed possible exits by comparing transaction timing, closely matching amounts, NEAR Intents order data and subsequent Bitcoin movements.
Another 44.03 ZEC entered Ironwood on September 29 and was followed by three NEAR Intents transactions paying roughly 0.73 BTC. Later that day, three more deposits added about 44.77 ZEC, although no sufficiently supported exit route had been established for those funds at the time of review.
The September 30 activity changes the scale dramatically. The 2,746.31 ZEC batch is roughly eight times the total amount previously documented entering Ironwood between September 25 and September 29.
That progression is consistent with operators moving from relatively small transactions toward much larger shielding operations. It does not prove that the earlier transfers were deliberate tests, but the behavioral change is difficult to ignore.
Ironwood Creates a Harder Forensic Boundary
Ironwood is particularly important because it changes what investigators can observe once the stolen ZEC crosses into the shielded system.
The Ironwood shielded pool was activated with Zcash’s NU6.3 upgrade on July 28 at block 3,428,143. It reuses much of the Orchard protocol while maintaining separate consensus state, including its own note commitment tree and nullifier set.
A transparent Zcash address can be followed much like a Bitcoin address. Investigators can see transfers, amounts and balances. Once ZEC enters Ironwood, however, individual shielded note values, recipients and transaction relationships are no longer publicly exposed in the same way.
Investigators can therefore establish that 876.43 ZEC entered the pool from a known Bitget-linked source, but they cannot simply follow those exact coins through a continuous public transaction graph afterward.
Earlier Bitget flows could be partially reconstructed because later transactions produced strong circumstantial matches across timing, values, cross-chain swap records and known Bitcoin destinations. That is useful evidence, but it is fundamentally different from directly tracing an asset from address to address.
Earlier Routes Led From Zcash Into Bitcoin
The previous transactions provide one possible roadmap for what investigators will now watch.
Some of the smaller Bitget-linked ZEC flows appear to have followed a path from transparent Zcash addresses into Ironwood, out through NEAR Intents and eventually into Bitcoin. Similar efforts to move other assets stolen from Bitget have already touched multiple cross-chain services.
That laundering environment is becoming more hostile. Dave Finances previously reported that a Bitget-linked Chainflip deposit was rejected by the broker handling the transaction, forcing the assets back to their source address rather than completing the intended swap.

NEAR Intents has also said its SHIELD screening system rejected more than $50 million in attempted Bitget-linked transactions. According to the platform, approximately $503,000 was frozen during execution, while about $166,000 successfully passed through.
Other Bitget-linked assets have taken different routes. Investigators have traced stolen funds through several networks into Bitcoin and Wasabi CoinJoin, illustrating how the laundering operation is already rotating between assets, bridges and privacy-enhancing infrastructure.
No publicly supported exit route for the new 2,746.31 ZEC batch had been identified at the time of publication.
The Bitget Investigation Now Reaches Back to August
The laundering developments are unfolding as investigators uncover a longer intrusion timeline than was initially apparent.
Bitget has said the attacker exploited a zero-day vulnerability in a third-party security product, obtained internal access and generated forged withdrawal commands that its wallet systems processed as legitimate. Private keys were not compromised and cold wallets were unaffected.
The distinction was central to earlier Dave Finances coverage showing how Bitget’s backend wallet system was compromised even though its cryptographic keys remained secure.
SlowMist’s latest forensic findings push the earliest detected malicious activity back to August 31, weeks before funds actually left the exchange. Investigators also recovered a customized withdrawal tool designed around Bitget’s wallet withdrawal logic and found evidence of unauthorized access involving an internal employee identity.
The actual on-chain theft began at 18:31 UTC on September 24 and continued across several blockchains for roughly two hours and 52 minutes.
North Korea Is Suspected, Not Confirmed
The identity of the attackers remains unresolved.
Bitget CEO Gracy Chen has described North Korean involvement as “very likely,” citing IP information that the company says overlaps with VPN infrastructure associated with a DPRK-linked group. TRM Labs has separately identified overlaps between the laundering network handling Bitget funds and infrastructure used in earlier attacks associated with North Korean operators.
But TRM has explicitly stopped short of definitively attributing the Bitget theft to North Korea. There has also been no public government attribution comparable with the FBI’s formal attribution of the 2025 Bybit hack.
The safer description remains suspected DPRK-linked operators rather than treating North Korean responsibility as established fact.
The Laundering Strategy May Be Changing
The September 30 move matters because criminals laundering hundreds of millions of dollars face a basic trade-off between speed and concealment.
Small transactions reduce the value exposed to any single failed route, but they take time. Time gives investigators, exchanges, stablecoin issuers and compliance providers more opportunities to identify addresses and block infrastructure around them.
Large privacy-pool deposits solve part of that problem. Moving nearly 1,000 ZEC at a time into Ironwood quickly removes substantial value from the transparent transaction graph. The problem comes later: those assets still need to emerge somewhere if the operators want to convert them into Bitcoin, stablecoins, fiat or other usable liquidity.
The increasingly aggressive screening around NEAR Intents and other cross-chain services could therefore explain why privacy infrastructure is becoming more important. It could also force the operators to diversify their exit routes.
The same dynamic is visible elsewhere in the stolen portfolio. More than half of the XRP initially held in the attacker’s first wallets had already moved by September 27, including roughly $83 million in stolen XRP that left three holding accounts as investigators tried to keep pace.
Zcash Is Now Part of a Real-World Privacy Test
The Bitget case also creates an unusually visible real-world test for Zcash’s newest privacy infrastructure.
That should not be interpreted as evidence that Zcash is uniquely designed for criminal activity, nor does one case establish it as the preferred privacy technology of sophisticated hacking groups. Privacy systems have legitimate uses, and the identity of the Bitget attackers itself remains unresolved.
What can be measured is much narrower: thousands of ZEC originating from a major exchange theft have moved from a publicly traceable address into a shielded pool where direct transaction tracing becomes considerably more difficult.
That makes the next movement important.
If matching amounts emerge and enter NEAR Intents again, investigators may be able to extend the earlier reconstruction. If the assets instead appear through another bridge, swap provider, OTC channel or liquidity venue, September 30 may ultimately mark the point when the laundering operation changed tactics in response to stronger screening.
For now, the blockchain gives investigators an unusually clear view right up to the privacy boundary.
Then the trail becomes much harder to follow.
Shane Neagle is a financial markets analyst and digital assets journalist specializing in cryptocurrencies, memecoins, prediction markets, and blockchain-based financial systems. His work focuses on market structure, incentive design, liquidity dynamics, and how speculative behavior emerges across decentralized platforms.
He closely covers emerging crypto narratives, including memecoin ecosystems, on-chain activity, and the role of prediction markets in pricing political, economic, and technological outcomes. His analysis examines how capital flows, trader psychology, and platform design interact to create rapid market cycles across Web3 environments.
Alongside digital assets, Shane follows broader fintech and online trading developments, particularly where traditional financial infrastructure intersects with blockchain technology. His research-driven approach emphasizes understanding why markets behave the way they do, rather than short-term price movements, helping readers navigate fast-evolving crypto and speculative markets with clearer context.

