Bitget Hackers Shield Millions in Stolen Zcash Using Privacy Pool

Bitget said the breach exploited a third-party security product and the exchange’s transaction-signing infrastructure, rather than compromising its private keys.
Bitget said its cold wallets were not affected; it later reported that it had identified the attack path, remediated the vulnerability, and was working with Mandiant and SlowMist on investigation and recovery efforts.
The original wallet Bitget attributed to the attacker received nearly 18,917 ZEC during the breach, before the funds passed through two intermediary addresses.
Ironwood went live on July 28, 2026; it operates alongside Zcash’s older shielded pools.
Hackers stole roughly $3.9 million in Zcash from the Bitget breach and moved it into a shielded pool on September 30, making the funds nearly impossible to trace. CryptoTimes reports the theft moved 2,746 ZEC—about 15% of the stolen Zcash—through three transfers into Zcash's Ironwood shielded pool. Inside the pool, transaction details are hidden from the public, blocking any direct link between deposits and future withdrawals.
The original Bitget breach on September 24 totaled approximately $387.5 million across multiple cryptocurrencies. GuruFocus noted that Bitget cold wallets were not affected, and the company said the attack exploited a third-party security product and its transaction-signing infrastructure. The exchange is working with Mandiant and SlowMist to investigate and recover stolen funds.
The attacker's original wallet received nearly 18,917 ZEC during the September 24 breach. The funds then passed through two intermediary addresses before entering Zcash's Ironwood shielded pool on September 30. CryptoTimes explains that shielded pools hide transaction details on the blockchain, preventing public tracking of fund movements inside the pool.
This privacy feature makes it extremely difficult to follow the money. Blockchain analysts may still infer connections if the funds reappear at regular, transparent addresses later. But for now, roughly $3.9 million of the stolen Zcash is hidden from direct public view.
Bitget said the breach did not stem from compromised private keys. Instead, hackers exploited a vulnerability in a third-party security product and the exchange's transaction-signing infrastructure. TechBuzz reports that Bitget has already identified the attack path and remediated the vulnerability with help from security firm Mandiant.
The company confirmed that cold storage wallets—which hold offline reserves—were not compromised. This means the exchange's most sensitive assets remained protected during the attack. However, hot wallets used for daily transactions were vulnerable to the breach.
TechBuzz reports that Bitget CEO Gracy Chen expressed pessimism about recovering stolen funds. The CEO stated the company is "not expecting to recover much" from the $387.5 million theft, despite freezing a small fraction of the stolen assets. The scale of the breach makes full recovery unlikely.
The move of funds into Zcash's shielded pool compounds recovery challenges. Ironwood, the shielded pool used, went live on July 28, 2026, and operates alongside older Zcash privacy features. Once funds enter shielded pools, tracing them becomes nearly impossible without additional intelligence or blockchain forensics.
Publishers
13
Articles
4
Reach
17