Blockchain compliance firm AMLBot reported that wallets associated with the $387.5 million Bitget hack have lost approximately $700,000 due to a script error during laundering attempts. The attackers executed two automated transfers seconds apart via CoW Protocol, mistakenly sending $267,000 in USDC from Ethereum to an Arbitrum-only Chainflip deposit channel and 160 ETH (valued at roughly $430,000) from Arbitrum to an Ethereum-only Chainflip channel.
Chainflip is a decentralized cross-chain swap protocol where funds sent to a deposit channel on the wrong blockchain are not recognized by the system. Circle subsequently blacklisted the receiving address for the stranded USDC, preventing its transfer, while the ETH remains inaccessible as no contract on Arbitrum can sweep those funds. AMLBot described the errors as likely script-driven, citing the mirrored nature of the mistakes which suggests a configuration error swapping network parameters rather than a manual slip. This incident follows earlier observations by MistTrack regarding operators using automated orders with pre-set addresses to move Bitget proceeds toward Bitcoin.
The loss of $700,000 highlights a critical operational vulnerability in automated money laundering infrastructure: the reliance on rigid scripts without human verification or dynamic chain validation. While the amount is negligible compared to the total theft, it demonstrates how technical mismatches between decentralized finance protocols like Chainflip and layer-2 networks such as Arbitrum can create dead ends for illicit actors. The fact that these transfers were likely driven by pre-set configurations indicates that sophisticated laundering operations are increasingly dependent on automation, which introduces specific points of failure that compliance firms and security researchers can exploit to trace and freeze assets.
From a market structure perspective, this event underscores the growing efficacy of issuer-level controls, such as Circle’s blacklisting mechanism, in neutralizing stolen stablecoins even when they are moved through complex cross-chain routes. However, the stranded ETH illustrates a persistent gap in recovery mechanisms for native assets stuck in non-standard states across different chains. As attackers continue to leverage decentralized exchanges and privacy tools, the industry must watch for further instances where protocol incompatibilities or smart contract limitations inadvertently trap illicit funds, potentially offering new avenues for asset recovery or forensic attribution.


