← Zcash Ironwood Shielded Pool — DPRK Laundering Vector1 decision on this page
Audit log
Every state-changing event for Zcash Ironwood Shielded Pool — DPRK Laundering Vector: moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.
- #1publishby system:backfill2026-10-01 12:13:22ZScore: ? → ? (no score change)anchoranchored
- chain
- ●mainnet-betaslot 452,284,334
- sig
4rNh9oguY3Ni…3EjSqNLvexplorer ↗- hash
3MfSnpbj3aQG…wJgXk7YUsha256 → base58
verifying row…full verify ↗canonical bytes (31757 B) ▸
{"actor":"system:backfill","investigation_id":"27995d3d-bbc0-4136-a46a-dc9c09762ae7","kind":"publish","page_slug":"zcash-ironwood-shielded-pool-dprk-laundering-vector","published_at":"2026-10-01T12:13:21.968Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Zcash Ironwood Shielded Pool — DPRK Laundering Vector","sections":[{"content":"On September 24, 2026, Bitget detected unauthorized transfers beginning at 18:31 UTC. Attackers gained privileged access to third-party security appliances used by the exchange, deployed a web shell, established command-and-control connectivity, and then moved laterally to Bitget's production wallet job server to deploy malicious packages. The attack spoofed legitimate transaction data through Bitget's automated authorization process, allowing hot and warm wallets to be drained while cold wallets were unaffected. Final confirmed losses reached $387.5 million across multiple blockchain networks, making it the largest single crypto theft of 2026. Stolen assets included approximately 103 million XRP (worth roughly $157 million at the time), plus ETH, USDT, ZEC, and additional tokens. Bitget engaged forensic firms Mandiant and SlowMist to investigate. Bitget CEO Gracy Chen stated publicly — including via livestream — that the attack pattern closely resembled techniques associated with North Korea's Lazarus Group, and that IP addresses linked to VPN services previously associated with DPRK-linked operations were identified. As of October 1, 2026, no formal attribution has been issued by the FBI, OFAC, or any government agency. The Mandiant and SlowMist investigation was ongoing and had not publicly confirmed the DPRK link. The attribution is therefore an allegation originating from Bitget, not an adjudicated finding.","heading":"The Bitget Breach: Background and Attribution Status","severity":"critical","sources":[{"credibility":2,"name":"Bitget Suffers Year's Largest Crypto Hack as Losses Top $387 Million — PYMNTS","type":"news_article","url":"https://www.pymnts.com/cryptocurrency/2026/bitget-suffers-years-largest-crypto-hack-as-losses-top-387-million/"},{"credibility":1,"name":"Bitget hacked via zero-day in third-party security products — BleepingComputer","type":"news_article","url":"https://www.bleepingcomputer.com/news/security/bitget-hacked-via-zero-day-in-third-party-security-products/"},{"credibility":1,"name":"North Korea Suspected in $351 Million Bitget Crypto Heist — SecurityWeek","type":"news_article","url":"https://www.securityweek.com/north-korea-suspected-in-351-million-bitget-crypto-heist/"},{"credibility":1,"name":"Bitget blames North Korea for $387.5M crypto wallet raid — The Register","type":"news_article","url":"https://www.theregister.com/cyber-crime/2026/09/25/bitget-blames-north-korea-for-3875m-crypto-wallet-raid/5299218"},{"credibility":2,"name":"Bitget Hacked for $351.6M: Withdrawals Frozen as CEO Points to North Korea — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/09/25/bitget-hacked-for-351-6m-withdrawals-frozen-as-ceo-points-to-north-korea/"}]},{"content":"Zcash's Ironwood network upgrade (formally designated NU6.3) activated on July 28, 2026, at block height 3,428,143. The upgrade was a direct response to a critical soundness vulnerability discovered in May 2026 in Zcash's prior Orchard shielded pool. Security researcher Taylor Hornby identified an under-constrained elliptic-curve multiplication operation in Orchard's zero-knowledge circuit; the flaw could theoretically have allowed an attacker to spend the same shielded note multiple times while generating different nullifiers, enabling undetectable balance inflation within the pool. No evidence of exploitation was found prior to the fix. The Ironwood pool is architecturally distinct from Orchard: it maintains a separate note-commitment tree, nullifier set, and value-pool accounting ledger. It retains Orchard's Actions and Halo 2 proving system while introducing formally verified circuit logic, an aggregate withdrawal limit preventing more value from leaving Orchard than was verifiably deposited, and quantum-recoverable notes under ZIP 2005. New shielded deposits and internal shielded-to-shielded transfers are no longer permitted within Orchard; funds departing Orchard must pass through the protocol's turnstile mechanism before entering Ironwood. The Orchard pool held approximately 3.6–3.7 million ZEC (roughly $1.7–1.9 billion at activation prices) at the time the upgrade went live. Within the first day, tens of thousands of ZEC migrated to Ironwood; approximately 87–88% of Orchard's balance had migrated by early September 2026. A nearly two-year SEC investigation into the Zcash Foundation closed in January 2026 with no enforcement action taken.","heading":"Ironwood Shielded Pool: Technical Architecture and Activation","severity":"medium","sources":[{"credibility":2,"name":"Privacy Focused Zcash (ZEC) Launches Ironwood Upgrade Following Orchard Security Vulnerability — CrowdFund Insider","type":"news_article","url":"https://www.crowdfundinsider.com/2026/07/294291-privacy-focused-zcash-zec-launches-ironwood-upgrade-following-orchard-security-vulnerability/"},{"credibility":2,"name":"Zcash Ironwood NU6.3 Goes Live: What the New Shielded Pool Means for ZEC Holders — KuCoin","type":"news_article","url":"https://www.kucoin.com/blog/zcash-ironwood-nu6-3-shielded-pool-migration"},{"credibility":2,"name":"Zcash Activates Ironwood Network Upgrade — CoinReporter","type":"news_article","url":"https://www.coinreporter.io/2026/07/zcash-activates-ironwood-network-upgrade/"},{"credibility":3,"name":"Zcash Seals $1.7B Shielded Pool: Ironwood Explained — Bitrue","type":"news_article","url":"https://www.bitrue.com/blog/zcash-ironwood-upgrade-shielded-pool-explained"},{"credibility":2,"name":"Zcash to Activate Ironwood in July, ZEC Rebounds to $466 — Bitcoin Foundation News","type":"news_article","url":"https://bitcoinfoundation.org/news/crypto-companies-news/zcash-ironwood-upgrade/"}]},{"content":"On September 30, 2026, on-chain investigator ZachXBT published findings alleging that wallets linked to the Bitget breach moved approximately 2,746 ZEC into Zcash's Ironwood shielded pool through three separate transactions between 08:15 and 08:46 UTC — a 31-minute window. The dollar-equivalent value reported across sources ranges from $3.8 million to $3.9 million. ZachXBT identified the source transparent Zcash address as t1WgMdtND8NF7NDUuYmq8MpMj1NTCXkMDVG and documented six total Ironwood deposit transactions. The 2,746 ZEC transferred into the shielded pool represents approximately 15% of the estimated 18,917 ZEC received by attacker-linked addresses during the September 24 breach. The ZachXBT findings have not been independently confirmed by Mandiant, SlowMist, Chainalysis, or any government agency as of October 1, 2026. Coinfomania, which covered the incident, characterized the allegations as unconfirmed. CryptoTimes noted that its publication had not independently verified the account linkages ZachXBT described. Elliptic reportedly assessed the North Korea link as 'highly likely' based on on-chain ties, but that assessment has not been publicly detailed. Importantly, ZachXBT is an independent on-chain investigator, not a law enforcement or regulatory body; his work constitutes Tier 2 community research, not a formal attribution finding. Once funds enter an Ironwood shielded transaction, the sender identity, recipient address, and transferred amount are cryptographically concealed, breaking the public ledger trail. Deposit transactions are themselves visible on-chain, but the subsequent movement of shielded funds cannot be linked to their origin without the sender's private viewing key.","heading":"Alleged DPRK Use of Ironwood: The September 30 Transactions","severity":"critical","sources":[{"credibility":2,"name":"Alleged North Korean Bitget Hackers Shield $3.8M in Zcash's Ironwood Pool, ZachXBT Says — CryptoTimes","type":"community_report","url":"https://www.cryptotimes.io/2026/09/30/alleged-north-korean-bitget-hackers-shield-3-8m-in-zcashs-ironwood-pool-zachxbt-says/"},{"credibility":2,"name":"Bitget Hackers Funnel $3.9M Through Zcash Privacy Shield to Evade Detection — MoneyCheck","type":"news_article","url":"https://moneycheck.com/bitget-hackers-funnel-3-9m-through-zcash-privacy-shield-to-evade-detection"},{"credibility":2,"name":"Zcash in the Spotlight After DPRK Hackers Leverage Ironwood — Coinfomania","type":"news_article","url":"https://coinfomania.com/zcash-in-the-spotlight-after-dprk-hackers-leverage-ironwood/"},{"credibility":2,"name":"Hackers Shift 2,700 ZEC into Zcash's Ironwood Shielded Pool — Coinfomania","type":"news_article","url":"https://coinfomania.com/hackers-shift-2700-zec-into-zcashs-ironwood-shielded-pool/"},{"credibility":3,"name":"Bitget Attackers Move 2,700 ZEC Into Zcash's Ironwood Shielded Pool — Hokanews","type":"news_article","url":"https://www.hokanews.com/2026/09/bitget-attackers-move-2700-zec-into.html"}]},{"content":"The Ironwood deposits were one component of a broader, multi-chain laundering operation. ZachXBT identified five alleged intermediaries operating under Discord and Telegram aliases: Cc (Discord: cc02006), jack (Discord: jack_34808), Melon (Discord: under0346), lolo/Marin (Telegram: pvpcz; Discord: losern), and HELP ME (Discord: helpme031897). The alias lolo/Marin was also tied to the earlier Kelp DAO exploit. ZachXBT's methodology involved monitoring support channels where operators publicly sought help with stalled swaps, cross-referencing Discord usernames and numeric IDs with transaction hashes and blockchain data, and producing flow charts attributed to TRM Labs watermarks. Independent confirmation from other blockchain tracing firms remained pending as of the time of publication. The primary early laundering route ran through THORChain: approximately $79 million (29,088 ETH) was converted to Bitcoin via THORChain by September 29. Bitget CEO Gracy Chen made a direct public appeal to THORChain requesting the blacklisting of attacker-linked addresses. THORChain declined, citing its policy as a decentralized and permissionless protocol comparable to Bitcoin and Ethereum. THORChain's volume reportedly surged to $678 million over two days following the breach, compared to a prior daily average of $20–60 million, generating approximately $1.2 million in protocol income. On September 30, a separate $50 million swap attempt through NEAR Protocol's SHIELD risk system was largely blocked; NEAR froze approximately $503,000 mid-transaction while $166,000 passed through before intervention. Wasabi CoinJoin was used for approximately 4 BTC traced through the path: TRON (TRX) to USDT to Ethereum (145 ETH) to THORChain to 4.59 BTC to Wasabi mixer. As of October 1, attacker-linked addresses continued converting DAI to USDT via Uniswap and bridging to Tron via USDT0 cross-chain bridges, with further conversion to USDD and TRX on SunSwap. Circle and Tether combined froze approximately $318,000 — representing roughly 0.08% of total losses — primarily limited by the speed with which stablecoins were converted to other assets (within 41 minutes in some cases).","heading":"Full Laundering Route: THORChain, NEAR Intents, Wasabi CoinJoin, and Stablecoin Bridging","severity":"critical","sources":[{"credibility":2,"name":"ZachXBT Exposes 5 Launderers Moving $387.5M Bitget Hack Funds for North Korea — CryptoTimes","type":"community_report","url":"https://www.cryptotimes.io/2026/09/28/zachxbt-exposes-5-launderers-moving-387-5m-bitget-hack-funds-for-north-korea/"},{"credibility":2,"name":"Bitget's hackers turn to Zcash after $50 million laundering route gets blocked — CryptoSlate","type":"news_article","url":"https://cryptoslate.com/bitgets-hackers-turn-to-zcash-after-50-million-laundering-route-gets-blocked/"},{"credibility":2,"name":"THORChain Declines to Freeze Addresses Linked to $387M Bitget Breach — Parameter","type":"news_article","url":"https://parameter.io/thorchain-declines-to-freeze-addresses-linked-to-387m-bitget-breach/"},{"credibility":2,"name":"THORChain refuses to block Bitget funds, despite pausing after own hack — Protos","type":"news_article","url":"https://protos.com/thorchain-refuses-to-block-bitget-funds-despite-pausing-after-own-hack/"},{"credibility":2,"name":"Bitget Hack Funds Hit Wasabi CoinJoin as DAI Flows to Tron, Freezes Catch Just $318K — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/10/01/bitget-hack-funds-hit-wasabi-coinjoin-as-dai-flows-to-tron-freezes-catch-just-318k/"},{"credibility":2,"name":"THORChain's response to Bitget's $387.5M hack sparks blacklist debate — Cryptonomist","type":"news_article","url":"https://en.cryptonomist.ch/2026/09/28/thorchain-response-hack/"}]},{"content":"The alleged use of Zcash's Ironwood pool occurs within a documented pattern of evolving DPRK laundering tradecraft. According to Chainalysis, North Korean hackers stole $2.02 billion in cryptocurrency in 2025, a 51% year-over-year increase, pushing their cumulative total to approximately $6.75 billion. The FBI formally attributed the $1.5 billion Bybit theft of February 2025 to DPRK-linked TraderTraitor actors. Sanctions.io's 2026 analysis of DPRK laundering tactics describes a four-stage sequence: rapid cross-chain bridging to Ethereum within hours of a theft; mixing service usage; chain-hopping via non-KYC bridges and decentralized exchanges; and OTC conversion to fiat through underground brokers, particularly in Southeast Asia and the Middle East. Following the 2022 OFAC designation of Tornado Cash and the August 2025 conviction of its co-founder Roman Storm, DPRK actors reportedly shifted to alternative mixing services, peer-to-peer transactions, and privacy coins with built-in anonymization. The Ironwood pool would represent a qualitatively more obfuscating tool than earlier mixers: whereas Bitcoin mixers such as Wasabi CoinJoin leave transaction graphs that can partially be reconstructed through heuristics, shielded Zcash transactions using the zk-SNARK-based Sapling or Halo 2 circuits provide cryptographic privacy guarantees rather than probabilistic obfuscation. The Bitget incident, if the attribution is confirmed, would mark the first documented large-scale use of the Ironwood pool specifically — activated only two months prior — as a laundering destination. The US State Department issued a trilateral cooperation statement in June 2026 addressing DPRK cyber-enabled revenue generation, reflecting continued interagency and international attention to this threat vector.","heading":"DPRK Crypto Laundering Tactics: Broader Context","severity":"high","sources":[{"credibility":2,"name":"The Lazarus Group and DPRK Crypto Theft in 2026: What Compliance Teams Need to Know — Sanctions.io","type":"research","url":"https://www.sanctions.io/blog/the-lazarus-group-and-dprk-crypto-theft-in-2026"},{"credibility":1,"name":"2025 Crypto Theft Reaches $3.4 Billion — Chainalysis","type":"research","url":"https://www.chainalysis.com/blog/crypto-hacking-stolen-funds-2026/"},{"credibility":1,"name":"OFAC Targets DPRK IT Workers Using Crypto — Chainalysis","type":"regulatory","url":"https://www.chainalysis.com/blog/ofac-targets-north-korean-it-workers-crypto-march-2026/"},{"credibility":2,"name":"Bitget Hack Pushes North Korean Crypto Haul Past $1 Billion — Insurance Journal","type":"news_article","url":"https://www.insurancejournal.com/news/international/2026/09/29/887051.htm"},{"credibility":2,"name":"Report: North Korean hackers stole a record $2.02B in crypto in 2025 — Yahoo News","type":"news_article","url":"https://www.yahoo.com/news/articles/report-north-korean-hackers-stole-014016987.html"},{"credibility":1,"name":"Advancing Trilateral Cooperation to Disrupt DPRK Cyber-Enabled Revenue Generation — US State Department (June 2026)","type":"regulatory","url":"https://www.state.gov/releases/office-of-the-spokesman/2026/06/advancing-trilateral-cooperation-to-disrupt-democratic-peoples-republic-of-korea-dprk-cyber-enabled-revenue-generation"}]},{"content":"The alleged use of Ironwood by DPRK-linked actors occurs during a period of heightened regulatory attention to privacy coins. A 2026 analysis identified ten countries that have restricted or restricted the trading of privacy coins including Monero and Zcash. A significant exchange-driven privacy coin delisting wave accelerated in 2025 and 2026, with multiple major venues removing XMR, ZEC, and DASH citing AML compliance concerns. Against this backdrop, a nearly two-year SEC investigation into the Zcash Foundation closed in January 2026 with no enforcement action, and Zcash received regulatory differentiation from Monero — in part because its transparent transaction layer preserves an audit trail for users who do not elect shielded transactions, and because the Ironwood upgrade itself introduced supply verifiability (users can confirm that the total shielded supply matches expected issuance without revealing individual balances). Grayscale launched the first US spot Zcash ETF product in 2026 following that regulatory clarity. The Ironwood laundering allegations, if confirmed by government authorities, would likely intensify regulatory scrutiny of the protocol and its shielded pool in particular. As of October 1, 2026, no OFAC designation, FATF guidance update, or formal regulatory action had been issued in direct response to the Bitget-Ironwood allegations.","heading":"Privacy Coin Regulatory Environment","severity":"medium","sources":[{"credibility":2,"name":"10 Countries Restricting Privacy Coins Like Monero and Zcash in 2026 — CCN","type":"news_article","url":"https://www.ccn.com/education/crypto/countries-banning-privacy-coins-monero-zcash-2026/"},{"credibility":2,"name":"Privacy Coin Delisting Wave: Why Exchanges Are Removing XMR, ZEC, and DASH — Transnet","type":"news_article","url":"https://transnetinc.com/privacy-coin-delisting-wave-why-exchanges-are-removing-xmr-zec-and-dash"},{"credibility":2,"name":"Zcash hits $1,000: privacy coin gets first US spot ETF — Crypto.news","type":"news_article","url":"https://crypto.news/zcash-1000-privacy-coin-spot-etf-grayscale/"},{"credibility":2,"name":"Zcash Ironwood upgrade Secures Network with Verified Shielded Pool — Cryptonomist","type":"news_article","url":"https://en.cryptonomist.ch/2026/07/29/zcash-ironwood-upgrade-security/"}]},{"content":"Several important caveats limit the confidence of any conclusions drawn from the available evidence as of October 1, 2026. First, no government agency — including the FBI, OFAC, or any allied intelligence service — has formally attributed the Bitget breach to DPRK or to any specific threat actor. The attribution originates from Bitget's own CEO via public statements, supplemented by ZachXBT's independent on-chain tracing. Second, ZachXBT's identification of the Ironwood deposits relied on tracing funds from the source transparent Zcash address t1WgMdtND8NF7NDUuYmq8MpMj1NTCXkMDVG into the shielded pool; this demonstrates the deposit itself but does not independently establish that the depositor was DPRK-affiliated rather than one of the alleged Chinese intermediary launderers or another party in the chain. Third, CryptoTimes explicitly noted that it had not independently verified the account linkages described by ZachXBT. Fourth, Mandiant and SlowMist were still conducting their forensic investigation as of late September 2026, and no findings had been published. Fifth, Elliptic reportedly assessed the North Korea link as 'highly likely,' but that assessment had not been detailed publicly. These limitations do not exonerate any party; they establish that the page's claims should be read as allegations and investigative findings under active corroboration, not as adjudicated facts.","heading":"Attribution Confidence and Investigative Limitations","severity":"medium","sources":[{"credibility":2,"name":"Alleged North Korean Bitget Hackers Shield $3.8M in Zcash's Ironwood Pool, ZachXBT Says — CryptoTimes","type":"community_report","url":"https://www.cryptotimes.io/2026/09/30/alleged-north-korean-bitget-hackers-shield-3-8m-in-zcashs-ironwood-pool-zachxbt-says/"},{"credibility":1,"name":"Bitget Says Suspected North Korean Hackers Stole $351.6M After Backend Compromise — The Hacker News","type":"news_article","url":"https://thehackernews.com/2026/09/bitget-says-suspected-north-korean.html"},{"credibility":2,"name":"Bitget Security Breach Costs $387.5M, IPO Plans Intact — Cryptonomist","type":"news_article","url":"https://en.cryptonomist.ch/2026/09/26/bitget-security-breach-loss/"}]}],"sources_used":[{"credibility":2,"name":"Alleged North Korean Bitget Hackers Shield $3.8M in Zcash's Ironwood Pool, ZachXBT Says — CryptoTimes","type":"community_report","url":"https://www.cryptotimes.io/2026/09/30/alleged-north-korean-bitget-hackers-shield-3-8m-in-zcashs-ironwood-pool-zachxbt-says/"},{"credibility":2,"name":"ZachXBT Exposes 5 Launderers Moving $387.5M Bitget Hack Funds for North Korea — CryptoTimes","type":"community_report","url":"https://www.cryptotimes.io/2026/09/28/zachxbt-exposes-5-launderers-moving-387-5m-bitget-hack-funds-for-north-korea/"},{"credibility":2,"name":"Bitget's hackers turn to Zcash after $50 million laundering route gets blocked — CryptoSlate","type":"news_article","url":"https://cryptoslate.com/bitgets-hackers-turn-to-zcash-after-50-million-laundering-route-gets-blocked/"},{"credibility":2,"name":"Bitget Hackers Funnel $3.9M Through Zcash Privacy Shield to Evade Detection — MoneyCheck","type":"news_article","url":"https://moneycheck.com/bitget-hackers-funnel-3-9m-through-zcash-privacy-shield-to-evade-detection"},{"credibility":1,"name":"Bitget hacked via zero-day in third-party security products — BleepingComputer","type":"news_article","url":"https://www.bleepingcomputer.com/news/security/bitget-hacked-via-zero-day-in-third-party-security-products/"},{"credibility":1,"name":"North Korea Suspected in $351 Million Bitget Crypto Heist — SecurityWeek","type":"news_article","url":"https://www.securityweek.com/north-korea-suspected-in-351-million-bitget-crypto-heist/"},{"credibility":1,"name":"Bitget blames North Korea for $387.5M crypto wallet raid — The Register","type":"news_article","url":"https://www.theregister.com/cyber-crime/2026/09/25/bitget-blames-north-korea-for-3875m-crypto-wallet-raid/5299218"},{"credibility":1,"name":"Bitget Says Suspected North Korean Hackers Stole $351.6M After Backend Compromise — The Hacker News","type":"news_article","url":"https://thehackernews.com/2026/09/bitget-says-suspected-north-korean.html"},{"credibility":2,"name":"THORChain refuses to block Bitget funds, despite pausing after own hack — Protos","type":"news_article","url":"https://protos.com/thorchain-refuses-to-block-bitget-funds-despite-pausing-after-own-hack/"},{"credibility":2,"name":"THORChain Declines to Freeze Addresses Linked to $387M Bitget Breach — Parameter","type":"news_article","url":"https://parameter.io/thorchain-declines-to-freeze-addresses-linked-to-387m-bitget-breach/"},{"credibility":2,"name":"Bitget Hack Funds Hit Wasabi CoinJoin as DAI Flows to Tron, Freezes Catch Just $318K — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/10/01/bitget-hack-funds-hit-wasabi-coinjoin-as-dai-flows-to-tron-freezes-catch-just-318k/"},{"credibility":2,"name":"Zcash Ironwood NU6.3 Goes Live: What the New Shielded Pool Means for ZEC Holders — KuCoin","type":"news_article","url":"https://www.kucoin.com/blog/zcash-ironwood-nu6-3-shielded-pool-migration"},{"credibility":2,"name":"Privacy Focused Zcash (ZEC) Launches Ironwood Upgrade Following Orchard Security Vulnerability — CrowdFund Insider","type":"news_article","url":"https://www.crowdfundinsider.com/2026/07/294291-privacy-focused-zcash-zec-launches-ironwood-upgrade-following-orchard-security-vulnerability/"},{"credibility":2,"name":"Zcash Activates Ironwood Network Upgrade — CoinReporter","type":"news_article","url":"https://www.coinreporter.io/2026/07/zcash-activates-ironwood-network-upgrade/"},{"credibility":2,"name":"The Lazarus Group and DPRK Crypto Theft in 2026 — Sanctions.io","type":"research","url":"https://www.sanctions.io/blog/the-lazarus-group-and-dprk-crypto-theft-in-2026"},{"credibility":1,"name":"2025 Crypto Theft Reaches $3.4 Billion — Chainalysis","type":"research","url":"https://www.chainalysis.com/blog/crypto-hacking-stolen-funds-2026/"},{"credibility":1,"name":"OFAC Targets DPRK IT Workers Using Crypto — Chainalysis","type":"regulatory","url":"https://www.chainalysis.com/blog/ofac-targets-north-korean-it-workers-crypto-march-2026/"},{"credibility":1,"name":"Advancing Trilateral Cooperation to Disrupt DPRK Cyber-Enabled Revenue Generation — US State Department","type":"regulatory","url":"https://www.state.gov/releases/office-of-the-spokesman/2026/06/advancing-trilateral-cooperation-to-disrupt-democratic-peoples-republic-of-korea-dprk-cyber-enabled-revenue-generation"},{"credibility":2,"name":"Bitget Hack Pushes North Korean Crypto Haul Past $1 Billion — Insurance Journal","type":"news_article","url":"https://www.insurancejournal.com/news/international/2026/09/29/887051.htm"},{"credibility":2,"name":"10 Countries Restricting Privacy Coins Like Monero and Zcash in 2026 — CCN","type":"news_article","url":"https://www.ccn.com/education/crypto/countries-banning-privacy-coins-monero-zcash-2026/"},{"credibility":2,"name":"Zcash hits $1,000: privacy coin gets first US spot ETF — Crypto.news","type":"news_article","url":"https://crypto.news/zcash-1000-privacy-coin-spot-etf-grayscale/"},{"credibility":2,"name":"Zcash in the Spotlight After DPRK Hackers Leverage Ironwood — Coinfomania","type":"news_article","url":"https://coinfomania.com/zcash-in-the-spotlight-after-dprk-hackers-leverage-ironwood/"},{"credibility":2,"name":"Bitget Suffers Year's Largest Crypto Hack as Losses Top $387 Million — PYMNTS","type":"news_article","url":"https://www.pymnts.com/cryptocurrency/2026/bitget-suffers-years-largest-crypto-hack-as-losses-top-387-million/"},{"credibility":2,"name":"Zcash Ironwood upgrade Secures Network with Verified Shielded Pool — Cryptonomist","type":"news_article","url":"https://en.cryptonomist.ch/2026/07/29/zcash-ironwood-upgrade-security/"}],"summary":"On September 30, 2026, on-chain investigator ZachXBT alleged that wallets linked to the September 24, 2026 Bitget exchange breach — a $387.5 million theft attributed by Bitget's CEO to a North Korean state-backed hacking group — moved approximately 2,746 ZEC (roughly $3.8–3.9 million) into Zcash's newly activated Ironwood shielded pool across three transactions in a 31-minute window. The Ironwood pool, activated on July 28, 2026 as part of the NU6.3 network upgrade, was designed to replace the vulnerable Orchard pool and provides cryptographic shielding of sender identity, recipient address, and transaction amounts, making subsequent fund tracing substantially more difficult. No formal attribution of the Bitget breach to North Korea has been issued by the FBI, OFAC, or any government agency as of October 1, 2026; the attribution rests on Bitget's CEO's statements, IP-pattern analysis, and ZachXBT's on-chain tracing.","timeline":[{"date":"2026-05-01","event":"Security researcher Taylor Hornby discovers a critical soundness vulnerability (under-constrained elliptic-curve multiplication) in Zcash's Orchard shielded pool zero-knowledge circuit. No evidence of exploitation is found.","source":"CrowdFund Insider","source_url":"https://www.crowdfundinsider.com/2026/07/294291-privacy-focused-zcash-zec-launches-ironwood-upgrade-following-orchard-security-vulnerability/"},{"date":"2026-06-01","event":"US State Department issues a trilateral cooperation statement on disrupting DPRK cyber-enabled revenue generation.","source":"US State Department","source_url":"https://www.state.gov/releases/office-of-the-spokesman/2026/06/advancing-trilateral-cooperation-to-disrupt-democratic-peoples-republic-of-korea-dprk-cyber-enabled-revenue-generation"},{"date":"2026-07-28","event":"Zcash Ironwood network upgrade (NU6.3) activates at block height 3,428,143. The Orchard pool is restricted to withdrawals only; new shielded deposits route exclusively to Ironwood.","source":"CoinReporter","source_url":"https://www.coinreporter.io/2026/07/zcash-activates-ironwood-network-upgrade/"},{"date":"2026-09-24","event":"Bitget detects unauthorized transfers beginning at 18:31 UTC. Attackers exploited a zero-day in third-party security appliances to spoof transaction approvals and drain hot and warm wallets. Total losses ultimately confirmed at $387.5 million across seven blockchain networks. Bitget CEO Gracy Chen cites IP patterns resembling DPRK-linked operations.","source":"BleepingComputer","source_url":"https://www.bleepingcomputer.com/news/security/bitget-hacked-via-zero-day-in-third-party-security-products/"},{"date":"2026-09-25","event":"Bitget freezes withdrawals. Engages Mandiant and SlowMist for forensic investigation. Attacker-linked addresses hold approximately 68,300 ETH and 102.6 million XRP.","source":"The Hacker News","source_url":"https://thehackernews.com/2026/09/bitget-says-suspected-north-korean.html"},{"date":"2026-09-26","event":"Bitget CEO publicly names North Korea's Lazarus Group as suspected perpetrator in a livestream. The exchange states no private keys were compromised.","source":"The Register","source_url":"https://www.theregister.com/cyber-crime/2026/09/25/bitget-blames-north-korea-for-3875m-crypto-wallet-raid/5299218"},{"date":"2026-09-28","event":"ZachXBT publishes findings identifying five alleged Chinese intermediaries laundering Bitget hack proceeds. THORChain declines Bitget's public request to freeze attacker-linked addresses, citing permissionless protocol design. Approximately $79 million in ETH had already been converted to Bitcoin via THORChain.","source":"CryptoTimes / Protos","source_url":"https://www.cryptotimes.io/2026/09/28/zachxbt-exposes-5-launderers-moving-387-5m-bitget-hack-funds-for-north-korea/"},{"date":"2026-09-29","event":"90.5% of stolen XRP converted to Bitcoin. THORChain volume reportedly reaches $678 million over the two days following the breach. Bitget restores its User Protection Fund to full balance.","source":"PYMNTS","source_url":"https://www.pymnts.com/cryptocurrency/2026/bitget-suffers-years-largest-crypto-hack-as-losses-top-387-million/"},{"date":"2026-09-30","event":"NEAR Protocol's SHIELD risk system blocks most of an approximately $50 million swap attempt linked to attacker wallets, freezing approximately $503,000 while $166,000 passes through. In a separate 31-minute window (08:15–08:46 UTC), approximately 2,746 ZEC (roughly $3.8–3.9 million) moves from transparent Zcash address t1WgMdtND8NF7NDUuYmq8MpMj1NTCXkMDVG into the Ironwood shielded pool across three transactions. ZachXBT flags the deposits and attributes them to wallets linked to the Bitget breach.","source":"CryptoSlate / CryptoTimes / MoneyCheck","source_url":"https://cryptoslate.com/bitgets-hackers-turn-to-zcash-after-50-million-laundering-route-gets-blocked/"},{"date":"2026-10-01","event":"Attacker-linked addresses continue converting DAI to USDT via Uniswap and bridging to Tron. Approximately 4 BTC enters Wasabi CoinJoin. Circle and Tether have combined frozen approximately $318,000 (0.08% of total losses). No formal government attribution has been issued. Mandiant and SlowMist investigation remains ongoing.","source":"CryptoTimes","source_url":"https://www.cryptotimes.io/2026/10/01/bitget-hack-funds-hit-wasabi-coinjoin-as-dai-flows-to-tron-freezes-catch-just-318k/"}]},"v":1}Verify offline (run on your own machine)python -m src.verify_decision 0ad01a76-1236-4219-8f7a-8257eacd1b59
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine —
python -m src.verify_decision <event_id>.