Crypto Markets in Focus: Stolen Bitget Funds Converted to BTC via CoW, Chainflip: Report Amid Shifting On-Chain Metrics
Security firm SlowMist says North Korean hackers are laundering funds stolen from Bitget by pairing CoW Protocol orders with Chainflip deposit addresses and then converting the proceeds to Bitcoin. The firm’s founder, who posts on X as Cos, arg...
In an important development shaping the global Finance space, Security firm SlowMist says North Korean hackers are laundering funds stolen from Bitget by pairing CoW Protocol orders with Chainflip deposit addresses and then converting the proceeds to Bitcoin. Recent observations, according to dispatches from CryptoPotato (Crypto & Financial Markets), point to structural shifts with notable ramifications for industry participants and analysts alike.
Executive Key Takeaways
- Primary Signal: Security firm SlowMist says North Korean hackers are laundering funds stolen from Bitget by pairing CoW Protocol orders with Chainflip deposit addresses and then converting the proceeds to Bitcoin.
- Contextual Driver: The firm’s founder, who posts on X as Cos, argues that anti-money laundering checks are falling behind automated laundering scripts, even as Chainflip tried to block the flows.
- Strategic Outlook: SlowMist Traces the Attack Into Third-Party Systems In a September 29 post, Cos said SlowMist had detected North Korea-linked hackers using CoW Protocol and Chainflip to move funds from Bitget.
Security firm SlowMist says North Korean hackers are laundering funds stolen from Bitget by pairing CoW Protocol orders with Chainflip deposit addresses and then converting the proceeds to Bitcoin. The firm’s founder, who posts on X as Cos, argues that anti-money laundering checks are falling behind automated laundering scripts, even as Chainflip tried to block the flows. SlowMist Traces the Attack Into Third-Party Systems In a September 29 post, Cos said SlowMist had detected North Korea-linked hackers using CoW Protocol and Chainflip to move funds from Bitget. An automated script created CoW orders with the receiving address set to a pre-prepared Chainflip deposit contract. After execution, Chainflip handled the cross-chain swap, and the asset was converted to BTC. Cos later described a broader pattern after tracking the funds for several hours. Chainflip was attempting to block the suspected laundering activity, but automated fragmentation and repeated attempts across different bridges could let the operators try another route when a transfer was rejected or returned. The funds were ultimately converted to BTC before CoinJoin was used to obscure the movements further. MistTrack, a crypto tracking and compliance platform built by SlowMist, reported that Chainflip had rejected one attempted deposit. The message returned was “Deposit rejected by the broker,” but the funds were refunded rather than frozen. Recall that MistTrack had earlier highlighted that funds from the Bitget hack were flowing into THORChain for cross-chain swaps, arguing that the permissionless L1 should bear responsibility for handling stolen funds. However, the DEX claimed it was decentralized and permissionless and “doesn’t censor by design.” SlowMist’s investigation traced the theft itself to activity that started before the transfers, with the earliest malicious acts in available logs dating back to August 31, when a service on one third-party product was compromised through a zero-day vulnerability. The attacker later accessed a second product’s management platform on September 25 using an internal employee identity and attempted to inject commands and write malicious files. Withdrawal Tool Connected the Attack to On-Chain Transfers SlowMist also recovered a customized withdrawal tool from deleted files that was tailored to Bitget’s wallet withdrawal logic, forging risk-control parameters, constructing withdrawal requests, and invoking the withdrawal process. Logs show it began executing the theft at 01:49 on September 25, with on-chain activity starting at 02:31 as 93 TRX was sent to the attacker’s address, followed 11 seconds later by 0.84 ETH arriving on Ethereum. The transfers continued across several blockchains until 05:23, covering about 2 hours and 52 minutes. At the same time, the attacker also attempted to alter withdrawal records and trigger additional BTC withdrawals, according to the SlowMist report. Bitget attributed the incident to a backend system in its wallet infrastructure rather than a stolen private key, and the exchange has said its User Protection Fund will cover those affected by the incident. The post Stolen Bitget Funds Converted to BTC via CoW, Chainflip: Report appeared first on CryptoPotato.
Market & Strategic Implications
Beyond immediate headlines, market participants are weighing secondary effects. The intersection of capital allocations, regulatory scrutiny, and shifting macroeconomic postures continues to elevate risk sensitivity across comparable assets and jurisdictions.
As further clarity emerges in upcoming briefings, institutional observers emphasize unit economics, policy enforcement, and counterparty exposure as primary barometers for long-term trajectory.
Comments (0)
No comments yet. Be the first to share your thoughts!
Leave a Comment