North Korean Hackers Use CoW and Chainflip to Launder Stolen Bitget Funds
North Korean hackers have allegedly laundered funds stolen from Bitget by using CoW Protocol and Chainflip. SlowMist, a security firm, detected this activity in a report that details how the attackers used automated scripts to move funds across different blockchains.
The funds were initially converted to BTC, worth $84,052, before being obscured further through CoinJoin. This is not the first time Chainflip has been involved in such activities, with SlowMist's MistTrack platform reporting that one attempted deposit was rejected but the funds were refunded rather than frozen.
SlowMist's investigation found that the theft itself began on August 31, when a service on a third-party product was compromised through a zero-day vulnerability. The attackers later accessed a second product's management platform on September 25 using an internal employee identity and attempted to inject commands and write malicious files.