Skip to main content
AVOID.NET

Zcash Ironwood Shielded Pool — DPRK Laundering Vector

avoid.net/zcash-ironwood-shielded-pool-dprk-laundering-vector→22/100·72% conf.
[AI-DRAFTED · AWAITING VERIFICATION]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·4rNh9o…qNLv

Summary

On September 30, 2026, on-chain investigator ZachXBT alleged that wallets linked to the September 24, 2026 Bitget exchange breach — a $387.5 million theft attributed by Bitget's CEO to a North Korean state-backed hacking group — moved approximately 2,746 ZEC (roughly $3.8–3.9 million) into Zcash's newly activated Ironwood shielded pool across three transactions in a 31-minute window. The Ironwood pool, activated on July 28, 2026 as part of the NU6.3 network upgrade, was designed to replace the vulnerable Orchard pool and provides cryptographic shielding of sender identity, recipient address, and transaction amounts, making subsequent fund tracing substantially more difficult. No formal attribution of the Bitget breach to North Korea has been issued by the FBI, OFAC, or any government agency as of October 1, 2026; the attribution rests on Bitget's CEO's statements, IP-pattern analysis, and ZachXBT's on-chain tracing.

Connected Entities

2 entities
Organizations
□Zcash Ironwood Shielded Pool — DPRK Laundering Vector
Wallets
◇t1WgMd…MDVG
Relationships
  • t1WgMd…MDVG→mentioned with→Zcash Ironwood Shielded Pool — DPRK Laundering Vector(50%)
Have evidence about Zcash Ironwood Shielded Pool — DPRK Laundering Vector?

Timeline(10 events)

1 May 2026

Security researcher Taylor Hornby discovers a critical soundness vulnerability (under-constrained elliptic-curve multiplication) in Zcash's Orchard shielded pool zero-knowledge circuit. No evidence of exploitation is found.

CrowdFund Insider

1 June 2026

US State Department issues a trilateral cooperation statement on disrupting DPRK cyber-enabled revenue generation.

US State Department

28 July 2026

Zcash Ironwood network upgrade (NU6.3) activates at block height 3,428,143. The Orchard pool is restricted to withdrawals only; new shielded deposits route exclusively to Ironwood.

CoinReporter

24 September 2026

Bitget detects unauthorized transfers beginning at 18:31 UTC. Attackers exploited a zero-day in third-party security appliances to spoof transaction approvals and drain hot and warm wallets. Total losses ultimately confirmed at $387.5 million across seven blockchain networks. Bitget CEO Gracy Chen cites IP patterns resembling DPRK-linked operations.

BleepingComputer

25 September 2026

Bitget freezes withdrawals. Engages Mandiant and SlowMist for forensic investigation. Attacker-linked addresses hold approximately 68,300 ETH and 102.6 million XRP.

The Hacker News

26 September 2026

Bitget CEO publicly names North Korea's Lazarus Group as suspected perpetrator in a livestream. The exchange states no private keys were compromised.

The Register

28 September 2026

ZachXBT publishes findings identifying five alleged Chinese intermediaries laundering Bitget hack proceeds. THORChain declines Bitget's public request to freeze attacker-linked addresses, citing permissionless protocol design. Approximately $79 million in ETH had already been converted to Bitcoin via THORChain.

CryptoTimes / Protos

29 September 2026

90.5% of stolen XRP converted to Bitcoin. THORChain volume reportedly reaches $678 million over the two days following the breach. Bitget restores its User Protection Fund to full balance.

PYMNTS

30 September 2026

NEAR Protocol's SHIELD risk system blocks most of an approximately $50 million swap attempt linked to attacker wallets, freezing approximately $503,000 while $166,000 passes through. In a separate 31-minute window (08:15–08:46 UTC), approximately 2,746 ZEC (roughly $3.8–3.9 million) moves from transparent Zcash address t1WgMdtND8NF7NDUuYmq8MpMj1NTCXkMDVG into the Ironwood shielded pool across three transactions. ZachXBT flags the deposits and attributes them to wallets linked to the Bitget breach.

CryptoSlate / CryptoTimes / MoneyCheck

1 October 2026

Attacker-linked addresses continue converting DAI to USDT via Uniswap and bridging to Tron. Approximately 4 BTC enters Wasabi CoinJoin. Circle and Tether have combined frozen approximately $318,000 (0.08% of total losses). No formal government attribution has been issued. Mandiant and SlowMist investigation remains ongoing.

CryptoTimes
Provenance & Audit Trail

Decision Log

This investigation is cryptographically anchored to the Solana blockchain (1 event). 23 of 24 cited source URLs have an Internet Archive snapshot.

model: claude-sonnet-4-6

generated: 10/1/2026, 12:13:11 PM

last updated: 10/2/2026, 1:18:55 AM

avoid.net — verified advice for a post-truth world