Suspected North Korean-linked hackers allegedly utilized decentralized finance protocols to launder cryptocurrency stolen from the Bitget exchange breach. SlowMist founder Cos reported that MistTrack’s TrackAgent identified transactions linking the exploit to CoW Protocol and Chainflip. The analysis suggests attackers used automated scripts to create CoW orders with pre-generated Chainflip deposit contracts as recipients, allowing settled assets to enter Chainflip’s infrastructure for cross-chain exchanges before conversion into Bitcoin.

Bitget initially estimated losses at $351.6 million but raised the figure to approximately $387.5 million after identifying additional losses in ZEC and TRX. A separate investigation by Bitquery traced 21 transfers across eight blockchains, documenting routes through THORChain, Chainflip, bridges, and other services. Specific findings include 2,450 ETH sent to a Chainflip liquidity pool resulting in a 74.46 BTC withdrawal, while another route involved 812 ETH and $14.6 million in stablecoins converted into Bitcoin. Additionally, 90.5% of stolen XRP was exchanged for Bitcoin via THORChain.