Chinese money launderers allegedly moving funds from the $387.5 million Bitget exploit on behalf of North Korean actors have been spotted asking for customer support in public Discord servers and Telegram channels, according to blockchain investigator ZachXBT.
Public Support Requests for Stolen Funds
The $387.5 million breach hit cryptocurrency exchange Bitget on September 24, when attackers tricked internal approval systems into authorizing illicit transfers. CEO Gracy Chen subsequently noted that North Korea was "very likely" responsible for the attack. The breach previously forced the venue to pause operations, following recent reports that Bitget froze XRP withdrawals after stolen tokens moved to THORChain.
On September 28, 2026, ZachXBT named five public accounts linked directly to laundering transactions across decentralized swap platforms. Screenshots show the accounts complaining to staff on THORChain and related services after cross-chain XRP-to-Bitcoin swaps failed to deliver expected outputs.
Specifically, an account named "Cc" reported that 277,724 XRP was submitted into a swap, but only 431 returned. Another user going by "jack" claimed that losing the assets "would cause a lot of trouble in my life." In response to the complaints, a moderator for swap service SwapKit replied with a photograph of Kim Jong Un.
Connection to Kelp DAO and TraderTraitor Pattern
According to ZachXBT, an account identified as "lolo"—who acknowledged using the Telegram handle "Marin"—was previously involved in laundering funds from the $292 million Kelp DAO exploit in April.
"I’ve observed the same pattern after multiple TraderTraitor attributed exploits, and I’ve closely tracked these groups," ZachXBT wrote. TraderTraitor is the official FBI designation for North Korea's state-sponsored cybercriminals, who were also blamed for the $308 million exploit of Japanese exchange DMM Bitcoin in 2024.
The stolen assets are being bridged across multiple blockchains before being routed into coin mixers like Wasabi Wallet. Despite requests, THORChain has refused to freeze addresses linked to the hackers. Bitget stated that withdrawals are scheduled to reopen on Monday, while ZachXBT indicated plans to release further investigative data in the coming weeks.
Key Takeaways
- Public Helpdesk Inquiries: Suspected launderers named "Cc," "jack," and "lolo" openly messaged support channels after failed XRP-to-Bitcoin swaps.
- Repeated Exploit Ties: User "lolo" ("Marin") was linked to both the $387.5 million Bitget breach and April's $292 million Kelp DAO hack.
- Uncooperative Infrastructure: THORChain declined to block actor wallets, as funds move into mixers like Wasabi.
- Attribution: The FBI associates these methods with North Korean threat group TraderTraitor, previously linked to $308 million stolen from DMM Bitcoin.
Why It Matters
The willingness of high-profile exploiters to openly seek customer assistance highlights the unique operational friction non-custodial bridging protocols introduce to large-scale crypto laundering. While permissionless architectures like THORChain prevent centralized freezing of funds, automated routing bugs and slippage can trap ill-gotten gains mid-transit. As state-sponsored groups rely heavily on decentralized privacy tools, regulatory and community pressure on protocol front-ends and liquidity providers is likely to intensify.



