When investigators began tracing the $387M stolen from Bitget, it was clear that the attackers behind it would move quickly. So the investigators used specialized AI to build purpose-built automated tools, so that the speed of the analysis could match the speed at which the funds were moving.
The largest crypto theft of the year: what happened to Bitget and who may have been behind the attackSep 28, 2026Read moreWorking around the clock, the investigation team stayed in contact with Bitget and law enforcement, passing on the latest tracing results. The work was accelerated by building purpose-built automation tools that removed much of the manual tracing of complex transactions across several blockchains and the matching of activity at each stage.
As the graph below shows, though it displays only part of the transfers, hundreds of transactions were made after the attack began. Funds moved between different networks, for example from Ethereum to Bitcoin.

This was not simply a matter of using AI as an auxiliary tool for building fund flow graphs. The agentic platform allowed specialists to query various data sources and quickly build specialized solutions tailored to the specific tasks of the investigation.
The ability to quickly detect and understand illicit activity is becoming increasingly important, as North Korean and other cybercriminal groups use sophisticated automation to move and conceal stolen funds. Investigators need to keep pace with these methods while applying professional judgment and expertise to interpret complex on-chain activity.
That is why speed is becoming a critical part of an investigation. Within minutes of the stolen funds being detected, the corresponding labels appeared in the information system, giving compliance teams and law enforcement the data they needed to take action.
Reconstructing the route of the stolen funds
After that, investigators identified several different laundering mechanisms used by the attackers, including cross-chain liquidity and messaging protocols, as well as instant swaps. Links to services used for money laundering were also found.

The ability to reconstruct the movement of funds along different routes proved especially important in investigating the stolen XRP. Instead of sending the XRP directly to a crypto exchange, the attackers ran it through a cross-chain liquidity protocol and received Bitcoin at the other end of the route.

The investigators matched the deposits to the corresponding payouts, connecting data from different blockchains and continuing to follow the chain of transfers.
Over roughly a day and a half, several tens of millions of dollars passed through this mechanism. The investigators traced these funds to their final destinations and then kept following them through subsequent transactions, including operations across several blockchain protocols, until the funds reached attacker-controlled Bitcoin addresses that are now under monitoring. This tracing was made possible by automation running on top of more than a decade of accumulated data on cross-chain relationships, which makes it possible to link operations across different protocols that would otherwise look completely unrelated.
The visualization below shows, in condensed form, part of the transfers made after the attack, as well as the use of various services, including cross-chain bridges, mixers and decentralized exchanges.

Discuss integration
Visit site
