Seeing a lot of chat about how the Bitget hack funds are being moved, so I wanted to share how it looks from our side at
@chainflip.
@MistTrack_io picked up that the exploiter tried to push funds through Chainflip and got rejected at the broker. Nothing was frozen. The deposit just got sent back to the refund address. That's how our screening works: every swap gets checked in real time, and if something is flagged, it doesn't go through and gets returned to the sender.
I want to be honest, though; this is one example of the system doing its job. It doesn't mean we've stopped everything, and I'm not going to pretend we have. I think anyone that has claimed that is not reading the flows correctly. These funds are touching almost every major DEX. It's an ongoing battle, and it will continue to be so until everything has moved.
What makes this one particularly hard is how the funds are moving. The hackers are routing through several hops first to obfuscate where the funds came from. By the time they come out the other side, they often don't get flagged as dirty along the way, even though they obviously are.
Chainflip tends to sit at the end of that chain of steps as they are moving to Bitcoin, so for us it's the point where things really have to be tight. If we miss it, there often isn't another checkpoint after us.
@evilcos made a point I completely agree with. The laundering is automated. Funds get split up and bridged across chains, and the second one rejects them; they move on to the next one. AML and KYT tools are still catching up to that speed. So for us it's about being fast and constantly adjusting as the methods change.
This is where I have to signal out
@SEAL_Org and
@zeroshadow_io. The live tracking they do is honestly some of the most up-to-date I've seen in the data sources we use, and they put a lot of effort into getting protocols, exchanges, and issuers to work together and help where they can. We couldn't keep up without people like them.
On the bigger debate, some have gone down the route of freezing funds; others don't screen at all. We've tried to land somewhere in between: we don't want stolen funds using Chainflip at all, but we also don't want to be taking custody and freezing.
Someone put the argument against freezing well: "My cash dollar has literally no opinion if I hand it over to buy coffee or drugs; that's the whole point." Once a protocol starts making decisions about whose funds to hold, it's hard for it to be seen as neutral. I think there's something to that, and it's part of why refunding feels like the right approach for us.
That said, I'm really not trying to call anyone out. Whatever approach someone takes, as long as there's a genuine effort to stop these flows, I respect it.
We've been here before too.
@Bybit_Official,
@KelpDAO , and a bunch of other big incidents all taught everyone something, and each time the response has gotten a bit better. This one will be no different.
If anyone wants to chat more about screening or how we handle this stuff, my DMs are open.