Crypto: Bitget hackers turn to Zcash to cover their tracks
Summarize this article with:

Hackers linked to the Bitget crypto hack are changing their methods. After an attempt to launder over $50 million through NEAR Intents failed, they sent approximately 2,746 ZEC, or almost $3.9 million, into Zcash’s Ironwood protected pool. Once funds enter this system, tracking them becomes much more difficult.

Analysts track a scrambled crypto stream through Zcash at a cybersecurity center.

In brief

  • Around $3.9 million in ZEC was sent into the Ironwood private pool.
  • NEAR Intents claims to have blocked more than $50 million in swaps linked to the hack.
  • The Bitget hack is now estimated to be worth around $387.5 million.

Zcash becomes a new route for stolen cryptos

Three transactions were enough. Approximately 2,746 ZEC were sent into Ironwood, Zcash’s protected pool. The sum represents almost 15% of the 18,917 ZEC stolen during the attack on the Bitget crypto platform. The move comes days after the Bitget hack, now estimated to be worth $387.5 million.

Zcash allows crypto-protected transactions where the sender, recipient and amount can be hidden. Deposits to Ironwood remain visible on the blockchain, but subsequent movements within the pool are significantly more difficult to link to the original funds.

This does not necessarily make the assets impossible to trace. The investigators can still analyze schedules, amounts or future outputs to public addresses.

But the track becomes less comfortable. This feature partly explains why Zcash remains a benchmark among privacy-focused cryptos. For investigators tracking Bitget’s funds, this change of route now adds another layer.

Your first cryptos with Bitget
This link uses an affiliate program

More than $50 million blocked before the switch to Zcash

Before Zcash, hackers had tried another route. NEAR Intents claims to have declined more than $50 million in swaps linked to addresses involved in the Bitget hack. The crypto protocol notably uses filtering mechanisms intended to identify certain suspicious funds before their conversion.

The majority of this attempt was therefore unsuccessful. Funds also circulated through THORChain. On this network, the situation was different. Bitget had publicly requested that addresses linked to the theft be blocked, but THORChain did not interrupt their activity. The protocol operates without a central authority capable of directly freezing an address.

The sequence above all shows the speed with which the perpetrators of crypto theft can change tools. A firm road. Another is tested. Zcash offers precisely what surveillance platforms seek to avoid in this matter: a partial breakdown of the public link between the entry and exit of funds.

The network was not designed for hackers. Its privacy features can be used by any crypto user wishing to avoid all of their payments being publicly visible. Technology simply becomes much more complicated to manage when it encounters stolen assets.

Bitget now has to track funds that are much harder to trace

Bitget has already gradually reopened its withdrawals after several days of suspension. Bitcoin returned first, followed by Ethereum and USDT, while other services are to be restored in stages. The exchange claims that customer balances remain intact.

The problem now shifts to recovery. According to Bitget, the September 24 attack did not compromise private keys or cold wallets. The attacker allegedly exploited a vulnerability in a third-party security product to obtain high-level internal credentials and send fake takedown orders.

The total amount then climbed to around $387.5 million, after additional transactions were discovered, including on Zcash and Tron. With the support of partners in the sector, investigators have already succeeded in freezing part of the funds. Mandiant, SlowMist, several crypto exchanges and on-chain analysis specialists also contribute to asset tracing and tracking suspicious movements.

But Ironwood changes the nature of work. A typical crypto transaction leaves a relatively clear trail between two public addresses. A protected Zcash transaction can cut this link.

This mechanism is once again attracting the attention of the market. Zcash and Monero have recently brought the capitalization of privacy coins to significantly higher levels. In the Bitget file, around $3.9 million has already gone in this direction. This is only a fraction of the 387.5 million stolen. For investigators, this is already enough to seriously complicate the trail.

Maximize your Tremplin.io experience with our ‘Read to Earn’ program! For every article you read, earn points and access exclusive rewards. Sign up now and start earning benefits.

Similar Posts