Stolen Bitget Funds Converted to BTC via CoW, Chainflip: Report
Security firm SlowMist says North Korean hackers are laundering funds stolen from Bitget by pairing CoW Protocol orders with Chainflip deposit addresses and then converting the proceeds to Bitcoin. The firm’s founder, who posts on X as Cos, argues that anti-money laundering checks are falling behind automated laundering scripts, even as Chainflip tried to block the flows. In a September 29 post, Cos said SlowMist had detected North Korea-linked hackers using CoW Protocol and Chainflip to move funds from Bitget. An automated script created CoW orders with the receiving address set to a pre-prepared Chainflip deposit contract. After execution, Chainflip handled the cross-chain swap, and the asset was converted to BTC. Cos later described a broader pattern after tracking the funds for several hours. Chainflip was attempting to block the suspected laundering activity, but automated fragmentation and repeated attempts across different bridges could let the operators try another route when a transfer was rejected or returned. The funds were ultimately converted to BTC before CoinJoin was used to obscure the movements further. MistTrack, a crypto tracking and compliance platform built by SlowMist, reported that Chainflip had rejected one attempted deposit. The message returned was “Deposit rejected by the broker,” but the funds were refunded rather than frozen. Recall that MistTrack had earlier highlighted that funds from the Bitget hack were flowing into THORChain for cross-chain swaps, arguing that the permissionless L1 should bear responsibility for handling stolen funds. However, the DEX claimed it was decentralized and permissionless and “doesn’t censor by design.” SlowMist’s investigation traced the theft itself to activity that started before the transfers, with the earliest malicious acts in available logs dating back to August 31, when a service on one third-party product was compromised through a zero-day vulnerability. The attacker later accessed a second product’s management platform on September 25 using an internal employee identity and attempted to inject commands and write malicious files. SlowMist also recovered a customized withdrawal tool from deleted files that was tailored to Bitget’s wallet withdrawal logic, forging risk-control parameters, constructing withdrawal requests, and invoking the
AI Analysis:
Disclaimer: This information is from public sources for reference only. Traceless does not guarantee accuracy.