Search the site
Press ESC to close
LIVE
Loading...
Updating...

North Korean Hackers Use Cow and Chainflip to Wash Stolen Bitget Funds

Fact-checked
3 min read
412 words
Share

Security analysts from SlowMist have identified a sophisticated new money laundering technique employed by North Korean cybercriminals to obfuscate the trail of assets stolen from the Bitget exchange. According to monitoring data released on September 30, 2026, the hackers have integrated Cow Protocol and Chainflip into their workflow, utilizing automated scripts to facilitate cross-chain transfers. This tactical shift highlights the evolving complexity of decentralized finance (DeFi) exploits used by state-sponsored actors to convert illicit gains into Bitcoin (BTC).

Automation and Cross-Chain Obfuscation

The investigation conducted by SlowMist TrackAgent reveals that the attackers are no longer relying on simple manual mixers. Instead, they utilize automated scripts to interact with Cow Protocol, a meta-aggregation layer for decentralized exchanges. These scripts programmatically create orders where the designated receiving address is a Chainflip Deposit-related contract address. By routing funds through these specific smart contracts, the hackers can trigger automated swaps without direct manual intervention at each stage of the transaction.

  • Interaction with Cow Protocol to minimize slippage and prevent front-running during the initial swap phase.
  • Redirection of output funds to pre-configured Chainflip deposit contracts.
  • Execution of cross-chain swaps to move assets from the source blockchain to the Bitcoin network.

Tactical Shift in Asset Conversion

The use of Chainflip, a decentralized cross-chain protocol, allows the North Korean entities to bypass traditional centralized exchanges that implement rigorous Know Your Customer (KYC) protocols. Chainflip facilitates native swaps between disparate blockchains, such as Ethereum and Bitcoin, without requiring wrapped tokens or centralized custody. This mechanism provides the attackers with a permissionless gateway to move stolen liquidity into BTC, which remains the preferred asset for long-term storage and eventual liquidation in the underground economy.

North Korean hackers' automated scripts create orders through Cow Protocol, setting the receiving address for the orders to a pre-prepared Chainflip Deposit-related contract address. Once the orders are successful, the assets are cross-chained on Chainflip and converted to BTC.

The discovery by SlowMist Cosine underscores the persistent challenge facing the cryptocurrency industry regarding the security of cross-chain bridges and decentralized liquidity pools. As hackers continue to refine their methods by combining multiple DeFi protocols, blockchain security firms are forced to enhance their monitoring tools to track increasingly fragmented transaction paths. The transition of funds from the Bitget exploit into the Bitcoin network serves as a reminder of the ongoing systemic risks posed by advanced persistent threat (APT) groups in the digital asset space.

Frequently Asked Questions

Quick answers to the most common questions about this topic.