Where is the Bitget hacker moving funds after Near Intents blocked $50M in swaps?

The Bitget exploiter has shifted to Zcash’s Ironwood privacy pool to hide approximately $3.8 million in ZEC. This pivot follows a successful intervention by Near Intents, which rejected the hacker's attempts to swap $50 million in stolen assets.
Where is the Bitget hacker moving funds after Near Intents blocked $50M in swaps?

The attacker responsible for the $387.5 million Bitget heist has shifted tactics, now utilizing Zcash’s Ironwood privacy pool to mask $3.8 million in ZEC. This transition occurred in early 2026 immediately after the Near Intents protocol rejected the hacker's attempt to facilitate $50 million in swaps. The move demonstrates a tightening net around large-scale illicit fund movements on mainstream interoperability platforms, forcing exploiters toward dedicated privacy-centric ecosystems.

The $387.5 million theft from Bitget stands as one of the most significant security breaches of the current year. Initially, the hacker attempted to leverage the liquidity and cross-chain capabilities of Near Intents to convert and obfuscate stolen assets. However, the protocol's ability to identify and block the exploiter's addresses forced the attacker to seek out the Ironwood pool, which utilizes zero-knowledge proofs to offer enhanced transaction anonymity.

This event underscores the growing pressure on decentralized protocols to implement proactive screening mechanisms. US regulators, including the Treasury Department, have intensified their focus on how cross-chain bridges handle tainted assets. The refusal by Near Intents to process the funds reflects a maturing compliance stance within the DeFi sector, as protocols seek to avoid regulatory blowback by preventing high-profile laundering attempts.

For the broader crypto market, this shift highlights the ongoing tension between legitimate financial privacy and the misuse of privacy coins by bad actors. While Zcash provides essential privacy for law-abiding users, its recurring use by hackers could invite further scrutiny from the Office of Foreign Assets Control (OFAC). Investors should monitor whether other privacy-focused protocols will follow Near’s lead in implementing filters or if this will drive hackers deeper into unregulated privacy pools.

Editorial method

This report is based on the linked source and is labeled with its publication date, provider, category and market-impact assessment. Market interpretation is informational, not investment advice.