SlowMist founder Cos said MistTrack’s TrackAgent detected funds stolen from Bitget moving through CoW Protocol and Chainflip. The suspected North Korean-linked actors used automated scripts to route assets into cross-chain swaps and convert them into BTC.
Why it matters
The method links automated CoW orders to pre-generated Chainflip deposit contracts, which serve as recipient addresses. That setup sends settled assets directly into cross-chain swaps and makes the fund trail harder to follow.
Market impact
North Korean-linked actors are suspected in the roughly $350 million Bitget hack, but attribution remains under investigation. The reported route highlights how cross-chain services can complicate tracing stolen funds; it does not establish who carried out the attack.
Frequently asked questions
-
How did the stolen Bitget funds move through CoW Protocol and Chainflip?
Automated scripts created CoW orders that used pre-generated Chainflip deposit contracts as recipients, sending settled assets into cross-chain swaps.
-
What happened to the funds after the cross-chain swaps?
The assets were ultimately converted into BTC, according to the analysis described by SlowMist founder Cos.
-
Why does this routing make the fund trail harder to follow?
The route sends assets through cross-chain swaps before converting them into BTC, adding steps that complicate tracing.
-
Who is suspected in the roughly $350 million Bitget hack?
North Korean-linked actors are suspected, but attribution remains under investigation.
-
What detected the movement of funds from Bitget?
SlowMist founder Cos said MistTrack’s TrackAgent detected the movement through CoW Protocol and Chainflip.
WuBlockchain