Meta Force Space
BTC $83,803.00 +0.29% ETH $2,674.39 -0.79% SOL $117.91 -1.14% XRP $1.49 -0.55% BNB $766.07 +1.39% DOGE $0.0941 -0.11%
← Back to the news

Stolen Bitget Funds Converted to BTC via CoW, Chainflip: Report

Security firm SlowMist says North Korean hackers are laundering funds stolen from Bitget by pairing CoW Protocol orders with Chainflip deposit addresses and then converting the proceeds to Bitcoin.

The firm’s founder, who posts on X as Cos, argues that anti-money laundering checks are falling behind automated laundering scripts, even as Chainflip tried to block the flows.

SlowMist Traces the Attack Into Third-Party Systems

In a September 29 post, Cos said SlowMist had detected North Korea-linked hackers using CoW Protocol and Chainflip to move funds from Bitget. An automated script created CoW orders with the receiving address set to a pre-prepared Chainflip deposit contract. After execution, Chainflip handled the cross-chain swap, and the asset was converted to BTC.

Cos later described a broader pattern after tracking the funds for several hours. Chainflip was attempting to block the suspected laundering activity, but automated fragmentation and repeated attempts across different bridges could let the operators try another route when a transfer was rejected or returned.

The funds were ultimately converted to BTC before CoinJoin was used to obscure the movements further.

MistTrack, a crypto tracking and compliance platform built by SlowMist, reported that Chainflip had rejected one attempted deposit. The message returned was “Deposit rejected by the broker,” but the funds were refunded rather than frozen.

Recall that MistTrack had earlier highlighted that funds from the Bitget hack were flowing into THORChain for cross-chain swaps, arguing that the permissionless L1 should bear responsibility for handling stolen funds. However, the DEX claimed it was decentralized and permissionless and “doesn’t censor by design.”

SlowMist’s investigation traced the theft itself to activity that started before the transfers, with the earliest malicious acts in available logs dating back to August 31, when a service on one third-party product was compromised through a zero-day vulnerability.

The attacker later accessed a second product’s management platform on September 25 using an internal employee identity and attempted to inject commands and write malicious files.

Withdrawal Tool Connected the Attack to On-Chain Transfers

SlowMist also recovered a customized withdrawal tool from deleted files that was tailored to Bitget’s wallet withdrawal logic, forging risk-control parameters, constructing withdrawal requests, and invoking the withdrawal process.

Logs show it began executing the theft at 01:49 on September 25, with on-chain activity starting at 02:31 as 93 TRX was sent to the attacker’s address, followed 11 seconds later by 0.84 ETH arriving on Ethereum.

The transfers continued across several blockchains until 05:23, covering about 2 hours and 52 minutes. At the same time, the attacker also attempted to alter withdrawal records and trigger additional BTC withdrawals, according to the SlowMist report.

Bitget attributed the incident to a backend system in its wallet infrastructure rather than a stolen private key, and the exchange has said its User Protection Fund will cover those affected by the incident.

Originally published by CryptoPotato on

Read the original on CryptoPotato ↗

Text and images are the property of CryptoPotato and are reproduced here with attribution and a link to the original publication.

More stories

All the latest news