North Korea-Linked Hackers Launder Stolen Bitget Funds via CoW, Chainflip
SlowMist, a security firm, has tracked the movement of funds stolen from Bitget to North Korea-linked hackers using CoW Protocol and Chainflip. The attackers paired CoW orders with Chainflip deposit addresses, converting the proceeds to Bitcoin (BTC).
Cos, the founder of SlowMist, argues that anti-money laundering checks are falling behind automated laundering scripts. Cos claims that Chainflip tried to block the suspected laundering activity but was unable to stop it due to the use of automated fragmentation and repeated attempts across different bridges.
The funds were ultimately converted to BTC before being obscured further through CoinJoin. SlowMist's investigation traced the theft itself to activity that started on August 31, when a service on one third-party product was compromised through a zero-day vulnerability.