What to Know
- Wallets linked to Bitget’s $387.5 million hack moved about $3.9 million in zcash into Zcash’s private payment system on Wednesday.
- Transaction records show that 2,746 ZEC entered Ironwood, Zcash’s newest shielded pool, in three transfers between 08:15 and 08:46 UTC.
- The deposits represented about 15% of the ZEC stolen in the Sept. 24 breach.
- Zcash’s shielded pool conceals senders, recipients and transfer amounts inside the private environment.
- Investigators can still see the amount that enters Ironwood and may compare future public exits using timing, amounts and other metadata.
- Pseudonymous blockchain investigator ZachXBT flagged the movements earlier Wednesday.
- The funds reportedly came through two intermediary addresses funded by a wallet Bitget identified as belonging to the attacker.
- Other attacker-linked proceeds have moved across blockchains through swap services, including about $6.3 million in ether-to-bitcoin swaps through THORChain.
Stolen ZEC Enters Zcash’s Private Payment System
Wallets linked to Bitget’s $387.5 million hack moved about $3.9 million in zcash into Zcash’s private payment system on Wednesday, adding a new layer of complexity to the effort to follow stolen assets across public blockchains. The movement involved 2,746 ZEC entering Ironwood, Zcash’s newest shielded pool, in three transfers between 08:15 and 08:46 UTC.
The transfers are notable because Zcash is designed to support both transparent and private payments. On its public side, transaction flows can be viewed in a way that resembles activity on many other blockchains. Inside the shielded pool, however, the system is structured to hide key transaction details, including the sender, recipient and amount moved within the private environment.
For Bitget and on-chain investigators tracking the aftermath of the Sept. 24 breach, the move into Ironwood may reduce the visibility of the funds compared with ordinary public transfers. While the deposits into the shielded pool remain visible at the point of entry, activity that takes place once the ZEC is inside Ironwood is not exposed as a direct public transaction trail.
Three Transfers Account for About 15% of Stolen ZEC
The 2,746 ZEC moved into Ironwood represented about 15% of the ZEC stolen in the Bitget breach. The attacker-linked wallet received nearly 18,917 ZEC during the Sept. 24 incident, according to information tied to the investigation of the flows. The Wednesday deposits therefore marked a meaningful, but not complete, shift of the stolen ZEC into a privacy-preserving mechanism.
Pseudonymous blockchain investigator ZachXBT flagged the movements earlier Wednesday. The funds came through two intermediary addresses that were funded by a wallet Bitget identified as belonging to the attacker. That path shows that the ZEC did not simply sit idle after the breach; instead, it was routed through additional addresses before entering Zcash’s shielded infrastructure.
Such intermediary movements are commonly watched by blockchain analysts because they can indicate attempts to fragment, reposition or obscure the provenance of funds. In this case, the most consequential part of the path was the final move into Ironwood, where visibility becomes more limited than it would be if the funds remained entirely on public addresses.
Why Ironwood Makes Tracking More Difficult
Zcash’s shielded pool is built to protect transaction privacy. When funds cross into Ironwood, observers can see the amount entering the pool. Once inside, however, the pool conceals the sender, recipient and transfer amount for shielded activity. This means investigators do not get a simple public sequence that links one shielded transaction to another in the same way they would with transparent addresses.
That does not necessarily make recovery or tracing impossible. If funds later return to a public address, the amount leaving the pool becomes visible again. Investigators may then compare entry and exit points by analyzing timing, amounts and other metadata. The challenge is that Zcash itself does not expose a transaction trail directly linking a specific deposit into the pool with a later withdrawal from it.
This distinction matters for exchange hacks because speed and traceability are often central to recovery efforts. Public blockchain trails can help exchanges, investigators and service providers identify suspicious flows and respond when stolen funds reach platforms that can freeze, block or monitor deposits. Shielded systems introduce a different analytical problem by reducing the number of visible clues available on-chain.
Privacy Technology Meets Exchange Hack Fallout
The movement of funds into Ironwood highlights the tension between legitimate financial privacy and the challenges of tracing stolen assets. Zcash’s privacy features are designed to allow users to transact without broadcasting every payment detail publicly. For ordinary users, that can be viewed as a privacy benefit. For investigators following hacked funds, the same architecture can complicate attribution and recovery.
Market participants often distinguish between privacy tools as neutral technology and the illicit use of those tools by attackers. Zcash’s shielded design does not by itself determine the purpose of any transaction. In this instance, however, the funds are linked to wallets associated with Bitget’s $387.5 million breach, putting the movement under close scrutiny from the crypto security community.
The timing of the deposits also matters. The three transfers were clustered within a narrow window on Wednesday, between 08:15 and 08:46 UTC. Concentrated movements like that can give investigators certain timing markers, even if subsequent shielded activity is not fully visible. Analysts may continue watching for public exits from Ironwood that could align with known entry amounts or broader movement patterns.
Other Proceeds Moved Through Swap Services
The ZEC deposits into Ironwood are not the only notable flows linked to the Bitget hack. Other proceeds have moved across blockchains through swap services. About $6.3 million in ether-to-bitcoin swaps through THORChain were traced from one attacker-linked wallet. Those swaps left a public record of the incoming ether and outgoing bitcoin.
Cross-chain swaps are a common feature of modern crypto markets, allowing assets to move between networks without following the traditional route of a centralized exchange order book. For investigators, these services can create both challenges and opportunities. They can make the asset trail more complex by changing the token and blockchain involved, but public records may still show the incoming and outgoing legs of a swap.
That differs from the Ironwood move. In a swap, the chain of value may remain visible at each public step, even if it spans multiple networks. In a shielded pool, the visible path can be interrupted because the internal transaction details are hidden. That is why the ZEC transfer into Zcash’s private payment system stands out in the broader post-hack movement of funds.
Investigators May Watch for Public Exits
The next major point of attention will likely be whether the funds leave Ironwood for public addresses. If they do, the exit amounts and timing may become visible. Investigators can compare those exits against the known Wednesday deposits, though any match would depend on the available metadata and the behavior of the wallets involved.
Some chart watchers and blockchain sleuths may also monitor whether the attacker-linked funds are split into smaller amounts, held inside the shielded pool, or moved in a way that attempts to reduce pattern recognition. The source of the funds has already drawn attention because of the Bitget link, so any future public movement is likely to be examined closely by the market and the security community.
For now, the key fact is that about $3.9 million in ZEC tied to the Bitget hack has entered a privacy-focused area of the Zcash network. The move does not erase the known entry point, but it does limit what can be seen next unless the funds emerge into public view again.
Impact on Crypto Market Confidence
Large exchange hacks tend to ripple beyond the directly affected platform because they test market confidence in custody, monitoring and recovery practices. The Bitget-linked ZEC movement underscores how attackers may use a mix of intermediary wallets, privacy features and cross-chain services after a breach. Each step can complicate the job of reconstructing the full path of stolen assets.
For crypto users, the incident is another reminder that blockchain transparency varies significantly by network, asset and transaction type. A public ledger does not guarantee that every movement can be followed with equal clarity. Privacy-preserving networks are intentionally designed to limit disclosure, and that design can become especially important when stolen funds are involved.
FXCOINZ will continue to watch how the funds move if they reappear on public addresses, whether additional ZEC enters Ironwood, and whether other attacker-linked assets continue shifting through swap services. The case remains an important example of how post-hack fund movements are increasingly shaped by both transparent and privacy-preserving crypto infrastructure.
Frequently Asked Questions (FAQs)
What happened to the Bitget-linked ZEC?
Wallets linked to Bitget’s $387.5 million hack moved about $3.9 million in zcash into Zcash’s Ironwood shielded pool on Wednesday, making the funds harder to follow on-chain.
How much ZEC entered Ironwood?
Transaction records show that 2,746 ZEC entered Ironwood in three transfers between 08:15 and 08:46 UTC.
What share of the stolen ZEC did the transfers represent?
The three deposits represented about 15% of the ZEC stolen during the Sept. 24 breach.
Why does Ironwood make tracing harder?
Ironwood is a shielded pool that conceals senders, recipients and transfer amounts for activity inside the private environment, reducing the public transaction trail available to investigators.
Can investigators still track the funds?
Investigators can see the amount that entered Ironwood and may compare future public exits using timing, amounts and other metadata, but Zcash does not expose a direct trail linking a specific entry to a specific exit.
Who flagged the ZEC movements?
Pseudonymous blockchain investigator ZachXBT flagged the movements earlier Wednesday, drawing attention to the attacker-linked flow of funds.
Where did the funds come from before entering Ironwood?
The money came through two intermediary addresses funded by a wallet Bitget identified as belonging to the attacker.
Were other stolen assets moved in different ways?
Yes. Other proceeds have moved across blockchains through swap services, including about $6.3 million in ether-to-bitcoin swaps through THORChain from one attacker-linked wallet.
Does Zcash only support private transactions?
No. Zcash supports both public and private payments, but its shielded pool is designed to hide key transaction details once funds are inside it.
