Bitget Hackers Move $3.8M in ZEC Into Zcash Ironwood Shielded Pool
About 2,700 ZEC worth approximately $3.8 million has reportedly been moved into Zcash’s Ironwood shielded pool in transactions linked by blockchain investigator ZachXBT to the attackers behind the Bitget security breach. The reported movement is significant because Ironwood is designed to shield transaction details using Zcash’s privacy technology, potentially making subsequent onchain tracing considerably more difficult. The development comes as Bitget continues investigating a breach that the exchange now estimates affected approximately $387.5 million in assets.
Bitget confirmed that the incident involved assets across Ethereum and other EVM networks, the XRP Ledger, Zcash and TRON. Its updated investigation identified approximately $387.5 million transferred to attacker-controlled addresses, revising an earlier estimate of $351.6 million after accounting for additional assets on Zcash and TRON. Bitget has said the incident is contained and that no further unauthorized transfers have been identified.
2,700 ZEC Reportedly Enter Ironwood
The movement of approximately 2,700 ZEC into Ironwood would represent a relatively small portion of the total Bitget breach, but it could have an important effect on the visibility of those particular funds. Zcash allows users to move coins from transparent addresses into shielded pools, where zero-knowledge technology prevents public observers from seeing individual transaction amounts, senders and recipients. The Block reported earlier this month that nearly 5 million ZEC was already held in shielded pools, demonstrating the scale of Zcash’s privacy infrastructure.
Ironwood is Zcash’s newest shielded pool and became active with the NU6.3 network upgrade in July 2026. It replaced Orchard as the network’s primary new shielded pool following the discovery of a vulnerability in Orchard’s proof circuit. Ironwood uses a corrected circuit and was designed to allow stronger verification of the pool’s overall supply.
Related: Google Co-Founder Expresses Optimism for Zcash ($ZEC) and Zero-Knowledge Technology
The reported transfer therefore does not mean that the ZEC has disappeared from the blockchain. Rather, moving ZEC into a shielded pool changes what information is publicly observable. The underlying coins remain represented within Zcash’s accounting system, but individual transaction details inside the shielded pool are protected by the protocol’s privacy mechanisms. This distinction is important when describing stolen cryptocurrency as being “hidden” or “untraceable.”
For investigators, the transition into a shielded pool can make conventional address-based tracking more difficult. Before shielding, blockchain analysts can generally follow visible wallet addresses and transaction amounts across the public ledger. Once funds enter a shielded pool, the public record does not expose the same sender, recipient and amount information for transactions conducted within that pool. Zcash’s privacy design is therefore relevant to the ongoing effort to follow the movement of the allegedly stolen funds.
Bitget Recovery Efforts Continue as Funds Move Across Networks
The reported ZEC movement comes only days after Bitget suffered one of the largest cryptocurrency thefts of 2026. The exchange initially reported approximately $351.6 million in unauthorized transfers from parts of its hot and warm wallet infrastructure. After further analysis, Bitget raised the figure to approximately $387.5 million and said the revision included assets on Zcash and TRON that were not part of the initial calculation.
Bitget has said the underlying vulnerability has been identified and remediated. The exchange is working with cybersecurity firms including Mandiant and SlowMist and has launched a recovery bounty program intended to encourage actions that lead to stolen funds being frozen or recovered. Bitget said some affected assets had already been frozen through cooperation with exchanges, blockchain projects, security firms and other industry participants.
The alleged connection to North Korean attackers remains an attribution rather than a legally established fact. Bitget CEO Gracy Chen has discussed evidence suggesting similarities to North Korean hacking groups, while independent reporting has also described indicators pointing in that direction. The investigation remains ongoing, and attribution can change as forensic and onchain evidence develops.
Related: THORChain Prepares Zcash Integration as Nodes Begin Scanning the ZEC Blockchain
Chen has also expressed limited confidence that all of the stolen assets will ultimately be recovered. In comments reported by Cointelegraph, she compared the situation with the 2025 Bybit hack, where only a portion of the stolen funds were frozen or recovered.
The movement of ZEC into Ironwood adds another complication to that recovery effort. Once funds enter the shielded pool, investigators may have fewer publicly visible transaction details with which to follow subsequent movements. However, that does not by itself prove that the attackers can permanently retain the funds or that recovery is impossible. Exchanges, blockchain companies and investigators can still monitor observable transactions, identify counterparties when funds leave shielded infrastructure and coordinate freezes where assets eventually reach services capable of restricting them.
For Zcash, the incident also highlights the dual-use nature of privacy technology. The same shielding mechanisms designed to protect legitimate users from unnecessary financial surveillance can also be used by bad actors attempting to obscure the movement of stolen assets. The reported Bitget-related transfer therefore places Zcash’s privacy capabilities directly in the spotlight while the wider investigation into the $387.5 million breach continues.
Related: Bitget Reports $351.6M Security Incident as XRP Suffers Largest Single-Chain Loss













