Skip to content
FinaPedia logoFinaPedia
Security

North Korean Hackers Launder Bitget Funds via CoW, Chainflip

By FinaPedia Editorialvia CryptoPotato2 min read
North Korean Hackers Launder Bitget Funds via CoW, Chainflip
The Brief

North Korean-linked hackers are allegedly exploiting decentralized protocols to launder funds stolen from the Bitget exchange. Security firm SlowMist reports that attackers are utilizing CoW Protocol to create orders that pair with Chainflip deposit addresses, ultimately converting the stolen assets into Bitcoin.

The process reportedly involves automated scripts that set receiving addresses to Chainflip deposit contracts. Once executed, Chainflip facilitates the cross-chain swap, and the funds are converted to Bitcoin. Security analysts note that these methods outpace traditional anti-money laundering checks. While Chainflip attempted to block some of these suspected laundering activities, the hackers employed strategies like automated fragmentation and repeated attempts across different bridges to circumvent rejections.

SlowMist's investigation traced the initial compromise to a zero-day vulnerability in a third-party product exploited on August 31, followed by a further breach on September 25 using compromised employee credentials. The firm also recovered a custom withdrawal tool designed to bypass Bitget's risk controls and initiate illicit fund transfers. The stolen funds were eventually obscured further using CoinJoin.

By the numbers

Prices as of, September 30, 2026 · Data: CoinGecko

BitcoinBTC
$84,011.00
+1.20% 24h+0.59% 7d$1.7T market cap$34.4B 24h volume
React
Share

This is an AI-assisted summary. Original reporting by CryptoPotato.

Read the original

Related stories