SlowMist traces ~$350M Bitget hack funds being laundered through CoW Protocol and Chainflip by suspected North Korean hackers using automated scripts to obscure the trail.
Security & Exploits ·
SlowMist's MistTrack TrackAgent has identified suspected North Korean hackers moving roughly $350 million in stolen Bitget funds through CoW Protocol and Chainflip, according to analysis by SlowMist founder Cos. The attackers employ automated scripts that generate CoW orders using pre-constructed Chainflip deposit contracts as receiving addresses, enabling assets to flow seamlessly into cross-chain swaps before conversion to Bitcoin—a routing pattern designed to obscure transaction visibility.
North Korean-linked actors remain the suspected attribution for the Bitget hack, though the investigation is ongoing. The technique combines two separate protocols to fragment the transaction trail, making it more difficult for blockchain monitors to track asset movement and identify final recipients. The exact identity and operational details of the threat actors have not been conclusively established.