mt logoMyToken
ETH Gas
日本語

SlowMist Monitoring: North Korean Hackers Cross-Chain Transfer Bitget Stolen Funds and Convert to BTC

収集collect
シェアshare

SlowMist monitoring shows North Korean hackers used Cow and Chainflip to transfer Bitget stolen funds cross-chain and convert them to BTC, with automated scripts involved. The incident has warning value for exchange risk controls and on-chain tracing.

Key takeaways: SlowMist monitoring shows that North Korean hackers used Cow and Chainflip to transfer Bitget stolen funds cross-chain and convert them to BTC, with automated scripts involved in the process. The incident has warning value for exchange risk controls and on-chain tracing.

Latest developments: SlowMist monitoring discloses cross-chain transfers and conversion to BTC

According to SlowMist monitoring, North Korean hackers have conducted cross-chain transfers via Cow and Chainflip, moving Bitget stolen funds to different chains and further converting them to BTC. The monitoring information also notes that the related operations involved automated scripts. The currently public material does not disclose the specific amount, number of transactions, or time window, but the cross-chain transfer and conversion to BTC already constitute the core factual development in this incident. For institutions focused on crypto security, this means the disposal of stolen funds is entering a cross-chain circulation phase.

Entities involved: Bitget, Cow, Chainflip, and North Korean hackers

Based on disclosed information, the entities involved include crypto exchange Bitget, cross-chain-related platforms Cow and Chainflip, the North Korean hackers identified in the monitoring link, and security monitoring firm SlowMist. Key facts center on three points: first, the funds are related to the Bitget theft incident; second, the hackers used Cow and Chainflip to complete cross-chain transfers; third, the related funds were converted to BTC. In addition, the appearance of automated scripts indicates that the transfer process may have programmatic and batch characteristics. The above facts form the main framework of currently publicly disclosed information.

Cross-chain link: Cow and Chainflip appear in the fund transfer path

In this incident, Cow and Chainflip were explicitly mentioned as the cross-chain transfer link. After the stolen funds were transferred cross-chain, they were then converted to BTC. For on-chain tracing, cross-chain links increase the complexity of the fund path, because after assets flow between different networks, correlation analysis must be conducted across multiple on-chain environments. Although the material does not provide specific addresses, transaction hashes, or a complete path, the combination of cross-chain transfer and conversion to BTC already shows that the disposal of funds did not remain on a single chain or in a single asset form.

Asset form conversion: conversion to BTC changes the tracing focus

The conversion of funds to BTC is another key piece of information in this incident. After the stolen funds are converted from their original form to BTC, the tracing focus will shift accordingly to address changes, flow paths, and subsequent deposit and withdrawal activity on the BTC network. For exchange risk controls, attention should be paid to BTC inflows associated with known risk addresses; for on-chain tracing teams, it is necessary to link addresses before the cross-chain transfer, the cross-chain link, and the BTC addresses after conversion. The material emphasizes that the security incident's details are complete and that it has warning value for exchange risk controls and on-chain tracing, indicating that asset form conversion is a key node in risk monitoring.

Automated script involvement: improving transfer efficiency and increasing identification difficulty

The content summary mentions that the related operations involved automated scripts. The significance of automated scripts in on-chain fund transfers is that they can execute multiple operations according to preset rules, reducing manual intervention and improving transfer efficiency. For security monitoring, automated scripts create identification and aggregation difficulties: funds may be split, cross-chain transferred, and converted, forming more complex paths. For exchange risk controls, attention should be paid to abnormal cross-chain behavior, automated trading characteristics, and inflows and outflows after funds are converted to BTC. For on-chain tracing teams, cross-chain links such as Cow and Chainflip should be incorporated into analysis models, and script behavior should be identified.

Risk control warning: exchanges need to strengthen monitoring of cross-chain-origin funds

The warning this incident provides for exchange risk controls is that stolen funds did not remain on a single chain or in a single asset form, but were cross-chain transferred and converted to BTC. This requires exchanges to continuously update risk address databases in deposit, withdrawal, risk control, and compliance processes, and to remain sensitive to cross-chain-origin funds. The material points out that the incident has warning value for exchange risk controls and on-chain tracing. The industry's focus is not only the initial theft incident itself, but also the monitoring and interception capabilities when cross-chain tools are used for fund transfers. Without cross-chain data integration, a single platform may find it difficult to fully reconstruct the fund path.

On-chain tracing challenges: multi-chain data correlation becomes the focus

In terms of on-chain tracing, information disclosed by SlowMist monitoring shows that North Korean hackers used Cow and Chainflip to cross-chain transfer Bitget stolen funds and convert them to BTC. Tracing teams need to process multi-chain data and correlate original-chain funds, cross-chain transactions, and BTC network addresses. The use of automated scripts further increases the possibility of fund splitting and path jumping. The current material does not provide the stolen amount, specific transaction hashes, or a complete address list, so follow-up should still be subject to subsequent monitoring and platform disclosures. For security institutions, cross-chain transfers and asset conversions are high-risk links in tracing work.

Industry observation: the role of cross-chain links in security incidents draws attention

From the material's description, cross-chain transfers were used in the disposal of Bitget stolen funds, highlighting the role of cross-chain links in security incidents. Cross-chain technology itself is used for asset flow across networks, but in security incidents, related paths may be used to increase the difficulty of fund tracing. This incident involves North Korean hackers, cross-chain money laundering, and automated scripts at the same time, and has warning value for exchange risk controls and on-chain tracing. Although current information does not disclose more details, the path information provided by SlowMist monitoring already offers key clues for the industry to understand how stolen funds are disposed of.

Follow-up focus: fund flows, platform response, and cross-chain monitoring

Directions worth watching include: the further flow of Bitget stolen funds after cross-chain transfer; address changes after the related funds are converted to BTC; whether more related transactions appear in cross-chain links such as Cow and Chainflip; whether trading platforms will update risk control measures; and whether security institutions such as SlowMist will disclose more monitoring details. The article does not make market predictions and does not constitute investment advice. Overall, this incident once again places cross-chain money laundering, exchange security, and on-chain tracing capabilities at the center of industry discussion.

免責事項:この記事の著作権は元の作者に帰属し、MyTokenを表すものではありません(www.mytokencap.com)ご意見・ご感想・内容、著作権等ご不明な点がございましたらお問い合わせください。
MyTokenについて:https://www.mytokencap.com/aboutusこの記事へのリンク:https://www.mytokencap.com/news/598598.html
community_x_prefix
X(https://x.com/MyTokencap)
community_tg_prefixcommunity_tg_name
(https://t.me/mytokenGroup)