Bitget Hack Funds Move Into Zcash’s Ironwood Shielded Pool

Bitget hack funds entering Zcash’s Ironwood shielded pool.

Key insights:

  • About 2,746 ZEC entered Ironwood, representing roughly 15% of the stolen Zcash.
  • The deposits passed through two intermediary addresses before reaching the shielded pool.
  • Earlier THORChain swaps show the attackers have also used cross-chain routes to move assets.

Bitget hack proceeds took another step toward obscurity on September 30, after wallets linked to the theft moved about $3.9 million in Zcash into Ironwood, the network’s newest shielded pool. The transfer involved 2,746 ZEC and could make recovery harder as investigators track funds from the $387.5 million exchange breach.

The funds entered Ironwood through three transactions between 08:15 and 08:46 UTC. On-chain investigator ZachXBT first flagged the movements and linked the deposits to intermediary wallets funded by an address associated with the attacker.

Stolen Zcash moves into shielded storage

The Bitget hack began on September 24 when attackers drained assets from the exchange’s hot wallet. The attacker-linked wallet later received nearly 18,917 ZEC, according to blockchain tracking reviewed by investigators.

ZachXBT identified the latest movement on September 30 and published the relevant deposit transactions. The funds passed through two intermediary addresses before reaching Ironwood, adding another layer between the stolen assets and the privacy pool.

The 2,746 ZEC represented roughly 15% of the Zcash taken during the breach. The remaining stolen ZEC stayed outside Ironwood at the time of the transfers, although its current location remains subject to further blockchain monitoring.

ZachXBT has also linked the attackers to North Korea. However, that attribution remains an allegation from the blockchain investigator and does not represent a confirmed finding from Bitget.

Ironwood limits direct blockchain visibility

Zcash allows users to make both transparent and shielded payments. Wallet addresses and transaction amounts are revealed in public transactions, whereas the parties to the transaction and the amount of balance protected in shielded transactions.

Investigators were able to still watch the stolen ZEC enter Ironwood. However, there is no direct transaction trail on blockchain addresses like that as with public blockchain addresses.

That distinction creates a significant tracing challenge if the funds later leave the pool. Investigators may examine withdrawal timing, transaction amounts and other available metadata, but the network does not publicly connect a specific withdrawal with a particular deposit.

The movement therefore changes the nature of the investigation. Rather than following a visible wallet-to-wallet trail, analysts must examine activity surrounding the pool and identify possible links when funds reappear.

Cross-chain swaps expand tracking challenges

The latest Zcash transfers follow other movements involving assets stolen during the Bitget hack. CoinDesk previously traced about $6.3 million in Ether from an attacker-linked wallet into Bitcoin through THORChain.

Those transactions offered investigators visible entry and exit points because the assets crossed between public blockchain networks. However, the use of privacy-focused infrastructure introduces fewer directly observable links between the original stolen funds and potential future withdrawals.

Meanwhile, Bitget continues efforts to trace and recover assets following the September breach. The exchange has previously estimated the total loss at about $387.5 million.

Assist in the recovery of assets using privacy tools.

The Bitget hack is an example of how cryptocurrency investigations can involve varying degrees of visibility. Public blockchains can reveal the movement of wallets instantly, and privacy systems can distinguish between the transactions that are known and the subsequent ones.

This doesn’t mean that funds can’t be tracked if they are stolen. Access to shielded pools can be monitored and analytics can be performed on transactions before and after privacy layers. Once assets are put in protected transaction systems, however, the evidence becomes less direct.

Additionally, the latest move has underscored the general debate on asset recovery and privacy technology. While privacy pools are intended for legitimate users who wish to have greater transaction confidentiality, investigators will have to deal with decreased visibility when stolen assets are introduced into those pools.

If the stolen ZEC continues to increase in Ironwood then the situation is likely to deteriorate further. Investigators will probably be keeping an eye on the remaining balances and any future withdrawals from the pool.

Conclusion

Ironwood is currently the more challenging stage of the Bitget hack investigation, with 2,746 ZEC moving into the area. The transfer will not destroy the public history that records the original transfer but will restrict the transaction transactions that investigators can directly connect to the protected pool.

The ongoing momentum would shape the extent to which the stolen Zcash can be tracked using traditional blockchain analysis. Investigators are still tracking down the addresses linked to the breach and the assets that have been transferred through privacy and cross-chain platforms.

Brenda Mary

Brenda Mary is a cryptocurrency journalist, SEO analyst, and editor with over 3 years of experience in blockchain, digital assets, and crypto market analysis. She has contributed to leading platforms including Crypto.news, Cryptopolitan, The Coin Republic, and Analytics Insight.
At CoinRaftar, she covers crypto news, market trends, and Web3 developments, simplifying complex topics into clear, reader-friendly insights.
Bachelor’s in International Business Management, University of Nairobi.
https://www.linkedin.com/in/brenda-mary-248b2422b/

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top