Suspected North Korean hackers move Bitget hack proceeds via CoW Protocol, Chainflip
Security & Exploits ·
Blockchain security firm SlowMist says its tracing tools spotted the roughly $350 million Bitget theft's proceeds being funneled through two decentralized platforms to mask their path toward Bitcoin.
SlowMist's founder, known as Cos, reported that the firm's TrackAgent monitoring system flagged activity consistent with North Korean-linked actors channeling stolen Bitget assets through a pairing of CoW Protocol and Chainflip, according to wublockchain.xyz. The scale of the underlying breach, previously put at roughly $350 million, remains one of the larger exchange compromises under active investigation.
The laundering method described relies on scripted automation rather than manual transfers. Programs generate orders on CoW Protocol that designate Chainflip deposit contracts, set up in advance, as the destination for settled funds. That structure lets assets clear directly into cross-chain swap mechanisms without pausing in intermediate wallets, a design that complicates efforts by investigators to follow the money as it is converted into BTC, per the same reporting.
Attribution to North Korean-linked hackers is described as a working suspicion rather than a confirmed finding, with the investigation still ongoing. The technique itself is notable less for the platforms involved than for the automation layer stitching them together, which reduces the manual footprints that tracing firms typically rely on to map fund flows across protocols.
This laundering disclosure follows a separate finding from SlowMist's broader review of the Bitget incident: the firm identified a zero-day vulnerability that had reportedly existed for weeks before it was exploited in the theft, according to cointelegraph.com. Taken together, the two threads sketch a picture of an intrusion that was prepared well ahead of execution and followed by a laundering process built for speed and obfuscation rather than improvisation.
Unresolved questions include the exact identity of the actors behind the theft, since North Korean involvement is still labeled suspected rather than established. Also unclear is how much of the roughly $350 million has already completed the CoW-to-Chainflip-to-BTC pathway versus funds still in transit, and whether either platform will take steps in response to the flagged activity. The timeline connecting the zero-day's weeks-long dormancy to the moment of exploitation has not been fully detailed, leaving open how the vulnerability was discovered and by whom before it was used. Further disclosures from SlowMist or the exchange itself would be needed to close these gaps.