Chainflip is a cross-chain liquidity network that enables swaps between different blockchains. It is similar to Uniswap, but users can exchange major blockchains without the need for wrapped tokens, special wallets, or specialized software.
Odaily News — According to monitoring by SlowMist's Yu Xian, MistTrack_io's TrackAgent discovered that North Korean hackers used automated scripts to create orders on CoW Protocol and set the receiving address to pre-prepared Chainflip Deposit-related contract addresses. After the orders were filled, the relevant assets could complete cross-chain operations on Chainflip and be swapped into BTC. The operation involves stolen Bitget funds.
Odaily report: According to monitoring by SlowMist's Cos, the Chainflip bridge is attempting to block North Korean hacker money laundering, but the response speed of AML/KYT lags behind the speed of money laundering. Money laundering groups use automation to split funds into large numbers of small amounts, transferring them across chains through various bridges; if funds are intercepted or returned by risk controls, they immediately try the next money laundering path, ultimately converting to BTC and continuing to obfuscate the source of funds through CoinJoin. This money laundering operation is still continuously evolving.
MistTrack monitoring indicates that a Bitget attacker recently attempted to transfer stolen funds through the cross-chain liquidity network Chainflip, but the deposit was rejected by the relevant broker (Broker). The platform did not freeze the funds, but instead executed a return to the originating address. MistTrack stated it will continue to track the subsequent flow of the stolen funds.
Odaily reports: Cross-chain protocol Chainflip has disclosed that an attack targeting Tron USDT occurred yesterday. It has been confirmed that 736,442.17 USDT was stolen through 6 unauthorized payments, while another 115,654.41 USDT in user swaps remained in the vault due to failed payments. All other funds were unaffected.Chainflip stated that the attacker exploited a vulnerability in the Tron transaction memo mechanism by attaching custom memos to transactions already signed by validators, causing the system to identify the same deposit as separate swaps and issue refunds again, ultimately resulting in duplicate payments. The attacker carried out 8 operations over approximately 90 minutes, gradually increasing the amounts. Chainflip said it has completed a fix and has flagged the stolen funds to relevant authorities in an attempt to recover them. The protocol is expected to resume operations as early as Monday and will be responsible for compensating affected users for their losses.
Odaily News — According to monitoring by SlowMist's Yu Xian, MistTrack_io's TrackAgent discovered that North Korean hackers used automated scripts to create orders on CoW Protocol and set the receiving address to pre-prepared Chainflip Deposit-related contract addresses. After the orders were filled, the relevant assets could complete cross-chain operations on Chainflip and be swapped into BTC. The operation involves stolen Bitget funds.
Odaily report: According to monitoring by SlowMist's Cos, the Chainflip bridge is attempting to block North Korean hacker money laundering, but the response speed of AML/KYT lags behind the speed of money laundering. Money laundering groups use automation to split funds into large numbers of small amounts, transferring them across chains through various bridges; if funds are intercepted or returned by risk controls, they immediately try the next money laundering path, ultimately converting to BTC and continuing to obfuscate the source of funds through CoinJoin. This money laundering operation is still continuously evolving.
MistTrack monitoring indicates that a Bitget attacker recently attempted to transfer stolen funds through the cross-chain liquidity network Chainflip, but the deposit was rejected by the relevant broker (Broker). The platform did not freeze the funds, but instead executed a return to the originating address. MistTrack stated it will continue to track the subsequent flow of the stolen funds.
Odaily reports: Cross-chain protocol Chainflip has disclosed that an attack targeting Tron USDT occurred yesterday. It has been confirmed that 736,442.17 USDT was stolen through 6 unauthorized payments, while another 115,654.41 USDT in user swaps remained in the vault due to failed payments. All other funds were unaffected.Chainflip stated that the attacker exploited a vulnerability in the Tron transaction memo mechanism by attaching custom memos to transactions already signed by validators, causing the system to identify the same deposit as separate swaps and issue refunds again, ultimately resulting in duplicate payments. The attacker carried out 8 operations over approximately 90 minutes, gradually increasing the amounts. Chainflip said it has completed a fix and has flagged the stolen funds to relevant authorities in an attempt to recover them. The protocol is expected to resume operations as early as Monday and will be responsible for compensating affected users for their losses.