SlowMist founder says North Korean hackers used CoW Protocol and Chainflip to move funds into BTC

SlowMist founder says North Korean hackers used CoW Protocol and Chainflip to move funds into BTC

N
News Editor
2026-09-30 03:05:09
SlowMist founder Yu Xian said on Sept. 30 that the firm’s TrackAgent system identified a laundering route used by North Korean hackers to process funds stolen from Bitget. According to his post, the actors combined CoW Protocol with Chainflip in an automated workflow that started with an order on CoW Protocol and ended with the assets being bridged and converted into BTC. Yu Xian said the script set the payout address of a CoW Protocol order to a pre-arranged Chainflip deposit-related contract address. Once the order was filled, the cross-chain step on Chainflip could be completed and the funds would be swapped into bitcoin. He also shared one example transaction in which the recipient address, 0xcEAE932A8bEE3a81a681A59890cb26d3110FDb65, corresponded to a Chainflip Deposit Contract. Chainflip records tied that flow to a final BTC address, bc1qa0rjjhyu9pg3adgpel4v7dct6a8606az863jyh. Yu Xian added that Chainflip had been blocking North Korean laundering attempts, but the group used automated scripts to split funds into many pieces and quickly shifted to other cross-chain routes when risk controls or blocking measures appeared. He described the process as an "evolving laundering operation."

BlockBeats reported on Sept. 30 that SlowMist founder Yu Xian said the company’s TrackAgent system had identified a cross-chain laundering route used by North Korean hackers to handle funds stolen from Bitget, with the assets ultimately converted into BTC.

According to Yu Xian, the group used automated scripts to create orders on CoW Protocol. The payout address on those orders was set to a pre-prepared Chainflip deposit-related contract address. After an order was filled, the assets could complete the cross-chain step on Chainflip and be exchanged into BTC.

An example transaction shared by Yu Xian

Yu Xian said that in one related transaction, the hackers first created an order on CoW Protocol and the order was later filled. The recipient address, 0xcEAE932A8bEE3a81a681A59890cb26d3110FDb65, corresponded to a Chainflip Deposit Contract.

Chainflip records for the transaction showed that the bridged assets were ultimately sent to the BTC address bc1qa0rjjhyu9pg3adgpel4v7dct6a8606az863jyh.

Chainflip blocking attempts and shifting routes

Yu Xian had previously said that Chainflip had been blocking North Korean laundering activity. He said the laundering group used automated scripts to break funds into many pieces, and when risk controls or blocking measures were encountered, it immediately tried other cross-chain paths. The funds were then converted into BTC and moved through CoinJoin for additional obfuscation.

He described that process as an "evolving laundering operation."

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
3200

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.