Key Points
- Approximately $3.9 million in Zcash from the Bitget hack was transferred into the Ironwood privacy pool by addresses connected to the attackers.
- The transfers occurred in three separate transactions totaling 2,746 ZEC between 08:15 and 08:46 UTC on Wednesday.
- Zcash’s shielded pool technology conceals sender identities, recipient addresses, and transaction amounts from public view.
- These deposits represent roughly 15% of the total Zcash stolen during the September 24 Bitget security breach.
- Earlier tracking efforts identified approximately $6.3 million in stolen assets converted from ether to bitcoin via THORChain.
Cybercriminals responsible for the Bitget security breach have transferred a significant portion of stolen cryptocurrency into a privacy-focused payment system, substantially complicating tracking efforts. The addresses involved are connected to an attack that resulted in $387.5 million being siphoned from the cryptocurrency exchange.
On Wednesday, approximately $3.9 million in Zcash was deposited into Ironwood, a shielded pool representing the latest privacy enhancement on the Zcash blockchain.
Transaction data examined by CoinDesk reveals the deposits occurred across three separate operations. The activity transpired between 08:15 and 08:46 UTC.
Collectively, 2,746 ZEC was deposited into the privacy pool. This figure constitutes approximately 15% of the entire ZEC haul taken during the September exploit.
Understanding Zcash’s Privacy Technology
The Zcash network offers users two distinct transaction methods. The transparent method operates similarly to Bitcoin, with all details publicly accessible. The alternative is the shielded method, utilizing privacy pools like Ironwood.
When cryptocurrency enters a shielded pool, its transaction details become cryptographically obscured. Sender information, recipient data, and transfer amounts all vanish from the public blockchain.
While outside parties can observe funds entering the privacy pool, they cannot track activity occurring within the shielded environment.
Should the cryptocurrency eventually exit the pool and transfer to a transparent address, that outbound transaction regains visibility. Investigators can then attempt to establish connections.
Analysis typically focuses on patterns including timing correlations and amount matching. These techniques can potentially link funds exiting the pool with earlier deposits, although definitive attribution remains challenging.
Discovery of the Transaction Activity
Blockchain forensics specialist ZachXBT initially identified the transfers on Wednesday. He has established a reputation for investigating cryptocurrency exploits and monitoring stolen asset movements across blockchain networks.
Based on ZachXBT’s analysis, the cryptocurrency was routed through two intermediary addresses before entering Ironwood. These intermediary wallets received funding from an address Bitget has officially attributed to the threat actor.
This attacker-controlled wallet originally received approximately 18,917 ZEC during the September 24 breach. The recent Ironwood deposits account for only a fraction of this total.
Bitget continues pursuing asset recovery operations. Transferring stolen funds into shielded pools represents a standard tactic employed by attackers to frustrate or prevent recovery initiatives.
This marks not the first occasion where threat actors connected to this incident have attempted to obscure their digital footprint. CoinDesk has previously documented additional transfers associated with the same attacker-controlled addresses.
In a prior movement, approximately $6.3 million worth of ether was exchanged for bitcoin. These conversions were executed through THORChain’s decentralized exchange protocol.
Unlike the Zcash privacy pool, THORChain transactions maintain public visibility. Investigators could monitor ether deposits and corresponding bitcoin withdrawals throughout the exchange process.
This contrast underscores why the Zcash shielded pool presents a substantially greater challenge for forensic analysts. It eliminates transaction visibility entirely during the period assets remain within the pool.
As of Wednesday evening, no outbound movements from the Ironwood pool had been detected. The stolen cryptocurrency remains distributed across various channels, with some transactions visible on public blockchains while others remain concealed within privacy protocols.





