Crypto Intelligence
DeFi

Chainalysis Links $387M Bitget Hack to North Korea Using AI Tracing

A major exploit drained $387.5 million from Bitget, and blockchain intelligence firm Chainalysis has traced the funds to North Korean state-linked actors using AI-powered analysis. The hack is already reshaping how the industry thinks about DeFi protocol accountability.

By USA Crypto Group

Chainalysis Links $387M Bitget Hack to North Korea Using AI Tracing
## North Korea's Fingerprints Are on the $387M Bitget Exploit Blockchain intelligence firm Chainalysis confirmed this week that AI-assisted tracing linked the $387.5 million Bitget hack to North Korea-affiliated hackers — one of the largest exchange exploits in recent memory. The attribution, reported by Decrypt on October 3, marks another chapter in the Lazarus Group's long-running campaign against centralized and decentralized crypto infrastructure. Bitget publicly called out DeFi protocols in the aftermath, criticizing what it described as inadequate security coordination across the ecosystem. The exchange also credited NEAR Intents for assisting in recovery efforts — a notable detail that puts cross-chain interoperability tools in a constructive light during an otherwise damaging event. ## What Happened and How the Funds Were Traced The exploit netted $387.5 million, making it a top-tier theft by dollar value. Chainalysis deployed AI tooling to follow the money across wallets and chains, ultimately pointing to infrastructure and movement patterns consistent with North Korean state-sponsored operations. These actors have refined their laundering techniques over years — mixing services, cross-chain bridges, and rapid token swaps are standard procedure — but AI-assisted graph analysis is closing the gap between theft and attribution. North Korean hackers have stolen an estimated several billion dollars from the crypto industry over the past several years, according to prior Chainalysis reports. The Bitget incident, if the attribution holds, would represent one of their larger single-event takes. ## Bitget's Public Posture: Blame the Ecosystem Bitget's decision to publicly criticize DeFi protocols after the hack is worth examining carefully. The exchange's stance implies that the broader DeFi ecosystem bears some responsibility for either enabling the exploit or failing to coordinate a faster freeze response. That argument will land differently depending on who's listening. For centralized exchange operators, it reinforces long-standing skepticism about permissionless protocols and their ability to respond to theft in real time. For DeFi natives, it reads as an attempt to shift accountability away from Bitget's own security posture. The reality, as usual, sits somewhere in between — cross-protocol coordination during an active exploit remains genuinely difficult, and the fact that NEAR Intents played a constructive role suggests that some infrastructure is evolving to meet that challenge. ## What Traders Need to Watch Several things are worth tracking in the days ahead: - **Attribution confirmation**: Chainalysis's AI-assisted tracing is credible but not court-proven. Watch for corroboration from on-chain researchers or government agencies. If the North Korea link solidifies, expect it to fuel policy discussions around DeFi sanctions compliance. - **Bitget's recovery claims**: The exchange credited NEAR Intents for recovery assistance. Specifics on how much was recovered — and through what mechanism — have not been fully disclosed. Traders with exposure to Bitget should monitor official communications closely. - **Regulatory blowback**: A $387.5 million hack with a state-actor attribution is the kind of event that hands regulators concrete ammunition. ESMA is already moving to tighten stablecoin custody rules in the EU this week. A high-profile North Korea link to a major exchange hack accelerates the case for stricter KYC and on-chain monitoring requirements across both CeFi and DeFi venues. - **NEAR token**: NEAR Intents received a direct positive mention from Bitget during a crisis. That kind of real-world validation — even under messy circumstances — tends to get priced in. The Bitget hack is not an isolated event. It is part of a documented, multi-year campaign by state-sponsored actors who treat crypto infrastructure as a sanctions evasion and revenue generation tool. Chainalysis using AI to accelerate attribution is a meaningful development, but tracing stolen funds is not the same as recovering them or deterring the next attack. Until cross-chain security coordination matures and exchanges harden their custody architecture, nine-figure exploits will remain a recurring feature of this market — not an anomaly.
By USA Crypto Group
October 3, 2026