Cos(余弦)😶🌫️|Sep 30, 2026 02:59
Our @MistTrack_io TrackAgent has detected North Korean hackers using a combination of Cow Protocol + Chainflip for cross-chain operations: Funds stolen from Bitget are processed through automated scripts by North Korean hackers. They create orders via Cow Protocol, setting the recipient address to a pre-prepared Chainflip Deposit contract address. Once the order is successful, the cross-chain asset transfer to Chainflip is completed and converted into BTC.
For example, this transaction:
Order created on CoW Protocol:
https://((etherscan.io))/tx/0xae6b1153446a05db7123e94ed5e2de828a2f9f5dc4802429a77ba88fc2497b0a
Order executed:
https://((etherscan.io))/tx/0xfcb591c1c6aa0d0a6937b1ab3b834c27b9f6c096859b7a44b6df018187a80409
Recipient address (Chainflip Deposit Contract):
0xcEAE932A8bEE3a81a681A59890cb26d3110FDb65
Corresponding Chainflip record:
https://scan.(chainflip.io)/swaps/1861124
Cross-chain asset transferred to BTC address:
bc1qa0rjjhyu9pg3adgpel4v7dct6a8606az863jyh
@MistTrack_io @SlowMist_Team
Share To
HotFlash
APP
X
Telegram
CopyLink