Addresses associated with the massive $387.5 million Bitget security breach transferred roughly $3.9 million worth of zcash into the digital asset’s confidential transaction network on Wednesday, severely complicating efforts by the exchange to trace the capital.
Ledger data inspected by CoinDesk indicates that 2,746 ZEC made their way into Ironwood, which is the most recent shielded pool on Zcash, via a trio of transactions occurring between 08:15 and 08:46 UTC.
Anonymous on-chain analyst ZachXBT initially highlighted these token movements on Wednesday morning. He explained that the capital routed through a pair of intermediate wallets financed by a specific address flagged by Bitget as belonging to the culprit, which had collected close to 18,917 ZEC during the September 24 incident.
Zcash provides options for both transparent and shielded transactions. While analysts can observe the volume entering the Ironwood environment, internal movements within the privacy pool obscure the originator, destination, and exact quantity.
Should the capital eventually transition back to a transparent address, the exiting figure becomes transparent once more. Analysts can attempt to correlate these deposit and withdrawal metrics using timestamps, values, and supplementary metadata, but the underlying Zcash protocol does not provide a visible audit trail connecting the two endpoints.
These trio of transactions account for roughly 15% of the total pilfered ZEC. Additional funds have been transited across different chains utilizing cross-chain exchange protocols: CoinDesk previously tracked approximately $6.3 million converted from ether to bitcoin via THORChain originating from an address connected to the perpetrator. Those exchanges maintained an open public log of the incoming ether and the corresponding outgoing bitcoin.
Originally published at https://www.coindesk.com/markets/2026/09/30/bitget-hackers-move-usd4-million-into-zcash-s-private-pool-making-funds-harder-to-trace.