Stolen Bitget Funds Converted to BTC via CoW, Chainflip: Report

5 days ago 6



Chainflip rejected an attempted deposit tied to the Bitget theft, returning the funds instead of allowing the swap to proceed. Security firm SlowMist says North Korean hackers are laundering funds stolen from Bitget by pairing CoW Protocol orders with Chainflip deposit addresses and then converting the proceeds to Bitcoin. The firm’s founder, who posts on X as Cos, argues that anti-money laundering checks are falling behind automated laundering scripts, even as Chainflip tried to block the flows. SlowMist Traces the Attack Into Third-Party Systems In a September 29 post, Cos said SlowMist had detected North Korea-linked hackers using CoW Protocol and Chainflip to move funds from Bitget. An automated script created CoW orders with the receiving address set to a pre-prepared Chainflip deposit contract. After execution, Chainflip handled the cross-chain swap, and the asset was converted to BTC. Cos later described a broader pattern after tracking the funds for several hours. Chainflip was attempting to block the suspected laundering activity, but automated fragmentation and repeated attempts across different bridges could let the operators try another route when a transfer was rejecte...

Read Entire Article