AI face-swapping steals 4.7 million USDT: Trading platform alerts triggered.

CN
智者解密
10 hours ago

On September 9, 2025, after being wanted by the police in Guangdong, China for several months, a 30-year-old Chinese man named Zhang was finally arrested in Pattaya, Thailand. According to a single source, he is accused of collaborating with at least three accomplices to use self-developed AI face-swapping and video software to successfully impersonate a victim's identity, operate their OKX account, and steal approximately 4.707 million USDT; this case is a typical cross-border pursuit involving "no physical movement, a face swapped, and money gone," where the key lies not in violently breaching the system, but in accurately disguising as the user. Merely half a month later, on September 25, the head of the Chinese-speaking region of another leading platform, Bitget, publicly admitted that the platform had experienced an attack and announced that it had commissioned a third-party security team to conduct an independent forensic investigation, emphasizing that multiple parties would work together to validate remedial measures, confirm the attack route, and cooperate with law enforcement. Two cases, unrelated in timing, entities, and details, nonetheless pointed to the same battlefield: one side is the misuse of AI technology pushing "identity impersonation" into a new stage that is difficult to distinguish with the naked eye, while the other side shows that trading platforms, when faced with black-box attacks, must introduce external security forces to rebuild trust. This signifies that the security landscape of cryptocurrency trading platforms is being rewritten, and under the dual pressures of AI impersonation of accounts and platform infrastructure simultaneously under strain, user asset security and industry trust are both facing a substantial "comprehensive upgrade of security threats."

Pattaya Arrest: The Accusation of Stealing 4.7 Million U with AI Face-Swapping

According to a single source, the story's starting point is not Pattaya, but earlier in Guangdong. In 2025, the Guangdong police had publicly issued a wanted notice for Zhang, listing him as a fugitive related to the theft of assets from an OKX account, which had already sent "red flags" domestically. Subsequently, his trajectory changed from "fugitive" in documents to "crossing borders" on maps: until September 9, 2025, this 30-year-old Chinese man was arrested by Thai police in the tourist city of Pattaya, with cross-border evasion and cross-border capture constituting the first layer of tension in this case.

What truly propelled this arrest into the spotlight was the technological label behind the accusation. According to the same source, publicly released information from the Thai side stated that Zhang was not acting alone but colluding with at least three accomplices, with the core method being "self-developed AI face-swapping + video software," which was used to impersonate the OKX account holder in key operational steps, meaning that the "face" on the screen was forcibly connected to the real account owner through an algorithm. Accompanying this technological label is a number that ordinary users and platform risk control cannot ignore—approximately 4.707 million USDT, which was allegedly transferred during this impersonation operation. However, these timelines, methods of operation, and amounts are currently only seen in a single report; information about the victim's identity, the destination of the funds, whether they have been frozen or recovered, and what judicial phase the case is in in Thailand or China has yet to be disclosed, leaving only the direction of the accusation confirmed: AI face-swapping was used for identity impersonation and a giant number significant enough to shake the nerves of platform risk control.

After Cross-Border Pursuit: Whether Assets Can Be Recovered Is Still Unknown

From the Guangdong police issuing the wanted notice in 2025 to the arrest of Zhang by the Thai police in Pattaya on September 9, 2025, this case has followed a typical path of "domestic wanted, overseas capture." For the police of both China and Thailand, achieving such cross-border collaboration in cases involving crypto assets is a signal: even if the suspect attempts to "run outside the chain, escape abroad," traditional criminal pursuit mechanisms can still extend their reach, at least in terms of personal control. However, just because the person has been captured does not automatically mean that the approximately 4.707 million USDT has been found, frozen, or is ready to be returned, and whether judicial cooperation can extend to on-chain assets and to what extent remains the real difficulty ahead, easily overestimated by the public.

As of now, there is no authoritative channel disclosing whether the relevant crypto assets have been seized, whether the flow of funds has been locked on-chain, nor any clear report on whether Zhang has pleaded guilty, whether he has been extradited, or whether he has entered the judicial process. In most cross-border cases involving crypto assets, the journey from criminal detention to judicial assistance, and then to asset recovery and final compensation, often entails a long process of procedural negotiation and technical verification; this "time difference" directly impacts the victims: after their accounts are emptied, it is difficult to obtain timely compensation promises and complete information on progress, leaving them to endure uncertainty amidst a vacuum of information and fragmented rumors. At this highly opaque stage, what can be reasonably inferred from the outside is "someone has been arrested," but it is impossible to extend from this to optimistically conclude "the money has been recovered" or "the case has been concluded." Each premature judgment only further presses risk onto an already fragile user protection mechanism.

Bitget Attacked: Independent Forensic Investigation and Self-Rescue

On September 25, another message from the platform tightened the industry’s nerves again. Xie Jiayin, the head of the Chinese-speaking region of Bitget, confirmed to the public that the platform had "previously experienced an attack," and this belated admission pointed all the failures, maintenance issues, and rumors circulating in the community towards the same term: security incident. However, unlike many announcements that only vaguely mention "technical issues," his key action in the same statement was to commission a third-party security team to conduct "independent forensic investigations," with the goal not to soothe the public but to restore the attack route as much as possible and externally validate the remedial measures already taken internally.

This layer of "independent forensic investigation" is a clear signal in an industry long accustomed to black-box operations: the platform is willing to place itself under the scrutiny of external professional forces, rather than shutting the door and self-proving its innocence. Xie Jiayin mentioned that multiple teams would collaborate closely to verify whether the remedial measures are truly effective, and at the same time clarify how the attack occurred, in order to cooperate with law enforcement later. Accompanying this is a nearly textbook sequence of self-rescue through online lockdown—first conducting a comprehensive investigation to eliminate all potential hazards, and then discussing the opening of withdrawals; only after "the incident has settled down" will they share the investigation results externally at an appropriate time. For users, this approach doesn't immediately fill the information void, but at least provides a clear timeline: the rights to fund movement and the narrative of the event are temporarily paused, prioritizing a risk cleaning process that is recorded by a third party.

From AI Face-Swapping to Attacks on Exchanges: The Attack Surface Has Been Significantly Extended

The theft of the OKX account and the attack on Bitget are discussed on the same timeline, not because they belong to the same case or the same group—research briefs repeatedly emphasize that the two events are entirely independent in terms of timing, platform, and direct parties involved and cannot be forcefully merged into a "super case." Their true commonality lies in their focus on the security of user assets on cryptocurrency trading platforms, yet they hit different ends of the security landscape—suspicious actions in the OKX related case concentrate on "impersonating the account holder," with the risk point being the breach of user identity verification; Bitget publicly acknowledges that it "has experienced an attack" and has invited a third-party security team for independent investigation, with the focus directly on the exchange’s system or infrastructure itself. One infiltrates from the user entry point, while the other directly knocks on the platform’s door, together forming simultaneous pressure on the industry from both the "user-side identity impersonation" and "platform-side system attack."

In this extended attack surface, technology is merely an amplifier. In the public accusations of the OKX case, Zhang is alleged to have used self-developed AI face-swapping and video software to bypass the identity verification steps intended to protect accounts; in the broader context of security, the combination of AI face-swapping, automated scripts, and traditional social engineering and account hacking tactics makes “impersonating you” a more efficient and scalable endeavor. Meanwhile, with the expansion of the crypto market, attackers may not only target several million USDT in a single account but also attempt to attack the exchange itself to gain platform-level profits, which has been regarded as a trend in recent years. For platforms, this means that security systems can no longer simply lean towards one side: KYC processes must begin to consider new types of identity fraud brought by AI forgery, risk control and multi-factor verification must simultaneously defend against accounts being "performed" away and systems being "breached", and abnormal behavior monitoring must establish a more sensitive early warning link between personal account anomalies and platform underlying abnormalities, to keep the risk manageable when the next opaque night appears.

The Defense-Offense Race is Still in Its Early Stages: Both Platforms and Users Need to Learn

From the theft of millions of USDT from the OKX account through AI face-swapping to Bitget's emergency locking of withdrawals and bringing in a third-party security team for independent investigation, these two unrelated events together give a common answer: AI and automated tools have become the "standard configuration" for attackers, raising the overall security threshold, while many platforms and users remain stuck in the previous generation of threat models. For platforms, relying on one-time KYC and static facial recognition to fend off risks is a thing of the past; identity verification must layer live detection, multi-factor checks, and cross-comparisons of devices, geographical locations, and historical behavior; account behavior risk control must be able to identify "looks like the user, but behaves unlike the user" abnormal patterns, automatically elevating verification levels for high-risk operations; and withdrawal audits need to fine-tune rules regarding limits, frequency, and destination addresses to exchange a bit of delay for the opportunity to intercept attacks beforehand, rather than being forced to freeze functions widely later, making all users bear the cost of short-term liquidity. Bitget's decision to hand independent investigations over to third-party teams after the incident and its promise to cooperate with law enforcement is another essential lesson: regular external security audits and independent investigations, coupled with cross-border police collaboration, are becoming the basic combination for addressing major security incidents. At the same time, users can no longer completely outsource security to platforms—avoiding remote authorizations in unclear scenarios, configuring multiple verifications for key accounts, and maintaining sensitivity to abnormal login alerts to report them promptly are all now the minimum actions for self-protection. Looking back at 2026, these two cases are merely samples from the early phases of the attack-defense race; whether the industry can standardize cross-border law enforcement cooperation, third-party forensics, and user security education will determine whether trust in this industry can be rebuilt after each attack.

Join our community, let’s discuss together and become stronger!
Exclusive Hyperliquid benefits for AiCoin: https://app.hyperliquid.xyz/join/AICOIN88
Exclusive Aster benefits for AiCoin: https://www.asterdex.com/zh-CN/referral/9C50e2
On-chain Telegram community: https://t.me/AiCoinWhaleData
On-chain community: https://www.aicoin.com/link/chat?cid=N6OVMor5g
AiCoin on-chain Twitter: https://x.com/aicoinwhaledata

Disclaimer: This article represents only the personal views of the author and does not represent the position and views of this platform. This article is for information sharing only and does not constitute any investment advice to anyone. Any disputes between users and authors are unrelated to this platform. If the articles or images on the webpage involve infringement, please provide relevant proof of rights and identity documents and send an email to support@aicoin.com. The relevant staff of this platform will conduct an investigation.