BTC—ETH—BNB—SOL—XRP—USDC—TRX—ADA—DOGE—
Data by CoinGecko
Scam Watch▼Bearish

Suspects in $387M Crypto Hack Ask for Help in Public Chats

Independent blockchain investigator ZachXBT has revealed a bizarre development following a massive digital asset theft. Individuals who are allegedly laundering proceeds from a $387.5 million exploit are actively seeking technical support in public chat rooms.

The funds stem from a major platform breach on September 24. According to Gracy Chen, the chief executive officer of the targeted exchange, the attackers successfully deceived the company's internal approval system to sign off on the unauthorized transfers. Chen indicated that actors from North Korea were "very likely" responsible for the security incident.

Public Pleas for Missing Swaps

According to the on-chain research, the individuals moving the stolen assets are Chinese money launderers operating on behalf of the suspected North Korean attackers. Instead of hiding their tracks quietly, these operatives have been posting openly in the Telegram channels and Discord servers of the decentralized services they rely on to obscure the funds.

ZachXBT publicly identified five different accounts, explicitly matching each profile to a specific on-chain transaction. His published screenshots capture these users actively complaining to the staff at THORChain, a decentralized network designed to swap coins between different blockchains without requiring user accounts. The launderers reportedly reached out to complain that their attempted XRP-to-Bitcoin swaps never arrived.

The details of these support requests highlight the scale of the operations. One user, posting under the name "Cc," wrote in the public chat that a total of 277,724 XRP went into the system, but only 431 tokens came back out. Another user, going by the name "jack," pleaded for assistance, telling support staff that losing the digital assets "would cause a lot of trouble in my life."

Suspects in $387M Crypto Hack Ask for Help in Public Chats
wrote in the public chat that a total of 277,724 XRP went into the system, but only 431 tokens came back out. Another user, going by the name

In one instance, a moderator for the swap service SwapKit responded to the perpetrators' complaints by simply replying with a photograph of Kim Jong Un.

Tracking TraderTraitor Activity

The investigator noted that one of the accounts, using the handle "lolo," was also involved in laundering digital assets from a separate $292 million exploit of Kelp DAO in April. During the public chat interactions, lolo confirmed operating under the alias "Marin" on Telegram.

“I’ve observed the same pattern after multiple TraderTraitor attributed exploits, and I’ve closely tracked these groups,” the blockchain sleuth stated in his report.

TraderTraitor is the official designation utilized by the FBI for a specific North Korean hacking collective. The federal bureau previously blamed this same group for a $308 million digital asset theft that struck the Japanese trading platform DMM Bitcoin in 2024.

Currently, the stolen assets are being moved across different blockchains through cross-chain bridges. The investigator noted that the funds are eventually landing in privacy mixers such as Wasabi, a specialized wallet that blends coins together to hide their transaction trail. Despite the public identification of the actors, THORChain has refused to block the specific wallets tied to the attackers.

Withdrawals for the victims of the original September 24 breach are scheduled to reopen on Monday. Meanwhile, ZachXBT has announced plans to release additional data regarding these laundering groups in the coming weeks.

← All stories