AI in the service of the law: how it sped up the investigation into the Bitget attack

AI in the service of the law: how it sped up the investigation into the Bitget attack

The attackers moved funds between Ethereum, XRP, Zcash and Tron, and then used cross-chain protocols and swap services to make tracing harder.

Oct 7, 2026

When investigators began tracing the $387M stolen from Bitget, it was clear that the attackers behind it would move quickly. So the investigators used specialized AI to build purpose-built automated tools, so that the speed of the analysis could match the speed at which the funds were moving.

The largest crypto theft of the year: what happened to Bitget and who may have been behind the attackSep 28, 2026Read more

Working around the clock, the investigation team stayed in contact with Bitget and law enforcement, passing on the latest tracing results. The work was accelerated by building purpose-built automation tools that removed much of the manual tracing of complex transactions across several blockchains and the matching of activity at each stage.

As the graph below shows, though it displays only part of the transfers, hundreds of transactions were made after the attack began. Funds moved between different networks, for example from Ethereum to Bitcoin.

Scaling cross-chain transfer analysis with specialized AI tools. Visualization: Chainalysis
Scaling cross-chain transfer analysis with specialized AI tools. Visualization: Chainalysis

This was not simply a matter of using AI as an auxiliary tool for building fund flow graphs. The agentic platform allowed specialists to query various data sources and quickly build specialized solutions tailored to the specific tasks of the investigation.

The ability to quickly detect and understand illicit activity is becoming increasingly important, as North Korean and other cybercriminal groups use sophisticated automation to move and conceal stolen funds. Investigators need to keep pace with these methods while applying professional judgment and expertise to interpret complex on-chain activity.

That is why speed is becoming a critical part of an investigation. Within minutes of the stolen funds being detected, the corresponding labels appeared in the information system, giving compliance teams and law enforcement the data they needed to take action.

Reconstructing the route of the stolen funds

After that, investigators identified several different laundering mechanisms used by the attackers, including cross-chain liquidity and messaging protocols, as well as instant swaps. Links to services used for money laundering were also found.

Cross-chain transfers identified with AI tools. Visualization: Chainalysis
Cross-chain transfers identified with AI tools. Visualization: Chainalysis

The ability to reconstruct the movement of funds along different routes proved especially important in investigating the stolen XRP. Instead of sending the XRP directly to a crypto exchange, the attackers ran it through a cross-chain liquidity protocol and received Bitcoin at the other end of the route.

A laundering scheme for stolen funds using cross-chain transfers. Visualization: Chainalysis
A laundering scheme for stolen funds using cross-chain transfers. Visualization: Chainalysis

The investigators matched the deposits to the corresponding payouts, connecting data from different blockchains and continuing to follow the chain of transfers.

Over roughly a day and a half, several tens of millions of dollars passed through this mechanism. The investigators traced these funds to their final destinations and then kept following them through subsequent transactions, including operations across several blockchain protocols, until the funds reached attacker-controlled Bitcoin addresses that are now under monitoring. This tracing was made possible by automation running on top of more than a decade of accumulated data on cross-chain relationships, which makes it possible to link operations across different protocols that would otherwise look completely unrelated.

The visualization below shows, in condensed form, part of the transfers made after the attack, as well as the use of various services, including cross-chain bridges, mixers and decentralized exchanges.

The full structure of the movement of funds stolen from Bitget. Visualization: Chainalysis
The full structure of the movement of funds stolen from Bitget. Visualization: Chainalysis

Discuss integration

Visit site
#Cryptoexchange#Hack#AI#Lazarus
The future is here: AI traced the Bitget laundering chain in 10 minutes