BitOK
前往频道在 Telegram
BitOK provides crypto AML and blockchain analytics for risk checks, investigations and transaction monitoring. ◽️Check a wallet, address or transaction: @BitOK_AML_bot ◾️Community: @bitok_eng ◾️Support: @BitOK_support ◾️Website: https://bitok.org/
显示更多285
订阅者
+324 小时
+137 天
+1030 天
数据加载中...
吸引订阅者
九月 '26
九月 '26
+18
在0个频道中
八月 '26
+4
在1个频道中
Get PRO
七月 '26
+20
在0个频道中
Get PRO
六月 '26
+13
在0个频道中
Get PRO
五月 '26
+29
在1个频道中
Get PRO
四月 '26
+7
在0个频道中
Get PRO
三月 '26
+6
在0个频道中
Get PRO
二月 '26
+34
在0个频道中
Get PRO
一月 '26
+2
在0个频道中
Get PRO
十二月 '25
+169
在0个频道中
Get PRO
十一月 '250
在0个频道中
Get PRO
十月 '25
+5
在1个频道中
Get PRO
九月 '250
在1个频道中
Get PRO
八月 '250
在1个频道中
Get PRO
七月 '250
在1个频道中
Get PRO
六月 '25
+5
在0个频道中
Get PRO
五月 '250
在0个频道中
Get PRO
四月 '250
在0个频道中
Get PRO
三月 '25
+8
在1个频道中
Get PRO
二月 '25
+3
在1个频道中
Get PRO
一月 '25
+524
在1个频道中
| 日期 | 订阅者增长 | 提及 | 频道 | |
| 05 九月 | +3 | |||
| 04 九月 | +4 | |||
| 03 九月 | +5 | |||
| 02 九月 | +6 | |||
| 01 九月 | 0 |
频道帖子
| 2 | 📈 Pump a Token by Hundreds of Times, Drain the Liquidity: Inside the Tectonic Attack
On August 30, an attacker targeted Tectonic, a lending protocol on Cronos. The key was manipulating the price of the illiquid TONIC token, pushing it up by hundreds of times and using the inflated value to borrow liquid assets.
🟩 The attack unfolded in several steps:
➤ 5M USDC was deposited into the position;
➤ borrowed USDC and CRO were used to buy TONIC across three VVS pools;
➤ TONIC’s price increased by roughly 454× against USDC, 599× against WCRO, and 668× against VVS;
➤ TONIC was repeatedly borrowed and supplied back into Tectonic, allowing liquid assets to be withdrawn from the protocol.
🔍 Some of the funds left Cronos before the network stopped
After the attack, the assets were distributed across several addresses. BitOK analysts traced 6.34M USDC from Cronos to Ethereum, where the entire amount was swapped for ETH. At the time of our check, the main Ethereum address still held 2,592 ETH.
Expanding the cluster revealed earlier links. One address in the funding chain had received funds from Tornado Cash. Another connected branch moved 4,532 USDC through Arbitrum to Hyperliquid, where it was used to buy XMR1. No withdrawal of native XMR to the Monero network was confirmed.
Less than two hours after the position was created, Cronos stopped producing new blocks. Assets still on Cronos therefore can’t move while the network remains halted. That doesn’t mean the funds were seized or permanently frozen.
❤️ Funds can move across chains, services, and wallets. Check their history and risk before you transact with BitOK Bot.
Website | Telegram | BitOK bot | 79 |
| 3 | 🇲🇽 BitOK is heading to SiGMA North America in Mexico City
From September 1–3, the BitOK team will be at SiGMA North America, the event’s first edition in Mexico, bringing together the North American and Latin American markets.
iGaming operators, payment providers, fintech companies, technology providers, and regulators will all meet in one place. For us, it’s a chance to discuss how the industry is approaching crypto payments and the risks that come with them across the region.
💵 Crypto payments require more than KYC
Exposure to sanctioned addresses, scams, stolen funds, and other high-risk sources exists at the on-chain transaction level.
In Mexico City, we’ll be talking about how AML/KYT helps iGaming businesses identify these connections before a transaction and build stronger controls around crypto risk.
❤️ Going to SiGMA North America?
Message us and let’s meet to talk AML, KYT, and the crypto risks businesses are dealing with today.
Website | Telegram | BitOK bot | 61 |
| 4 | ✔️ Pump the Price, Take $8.7M: Breaking Down the Moonwell Attack
On August 27, $8.7M in assets was drained from Moonwell. The key to the attack wasn’t a bug in the code. It was the price of the collateral.
The attacker pushed up the price of the illiquid MAMO token through a series of large buys, deposited it into Moonwell at an inflated valuation, and borrowed liquid assets against it.
⚙️ The attack started six days before the funds moved
BitOK analysts reconstructed the preparation behind the attack. A linked address received 800 ETH from Tornado Cash, moved part of the funds across Ethereum, Cronos, and Arbitrum, and then prepared the capital for the attack on Base.
On Base, funds and MAMO were sent to a separate address. Then the attack unfolded:
➤ large buys pushed up the price of MAMO;
➤ at least 35.5M MAMO was deposited into Moonwell as collateral;
➤ against the inflated collateral, the attacker borrowed 71.36 cbBTC, 2.56M USDC, 560 WETH, and 368 wstETH.
🔍 From Moonwell back to Ethereum: where did the $8.7M end up?
After the withdrawal, the assets were converted to USDC and moved from Base to Ethereum via Circle CCTP. There, 8.728M USDC was swapped for DAI and sent back to the address where the attack preparation had started.
After all the swaps and cross-chain transfers, the funds returned to the original address as $8.7M in DAI.
At the time of our analysis, the funds were still sitting in that wallet with no confirmed onward movement.
❤️ Funds can change chains, assets, and wallets, but their history remains part of the risk picture. Check addresses and transaction history before you transact with BitOK Bot.
Website | Telegram | BitOK Bot | 55 |
| 5 | 🧠 When Governance Gets Exploited: Where Term Finance’s $8.5M Went
The attacker didn’t need to find a smart contract vulnerability to drain millions from Term Finance. A small stake in the vault was enough to propose the changes they needed and wait for no one to say “no.”
The weak point wasn’t the code. It was the protocol’s governance.
⚙️ Six days to stop the withdrawal
The attacker swapped 0.5 ETH for a stake in the ETH Meta Vault, received governance tokens, and submitted a proposal containing 17 actions.
Those actions included removing the protective delay, pulling WETH back from four strategies, and adding an attacker-controlled exit strategy.
The proposal remained open for around six days. No one vetoed it. Once the window closed, the protocol executed the actions and transferred 2,841.74 WETH to the attacker.
A similar setup targeted five USDC vaults. Separate proposals changed key roles and risk controls, allowing another 1.68M USDC to be withdrawn.
🔍 Where did the funds go? BitOK analysts traced the full flow:
➤ WETH was converted to ETH;
➤ USDC was swapped for DAI via KyberSwap and Maker PSM;
➤ the ETH and DAI were consolidated into a single wallet.
The attacker didn’t need to break the code. They used Term Finance’s own rules: propose the right changes, wait for no one to stop them, then let the protocol execute the rest.
❤️ Want to break down similar cases and trace on-chain fund flows yourself? Use BitOK Graph for your own investigations.
Website | Telegram | BitOK bot | 55 |
| 6 | ✅ The AML Check That Could Cost You Your Crypto
Scammers have found a more sophisticated way to get to your assets: offering to check whether your crypto is “clean” first.
A fake AML service can look convincing, and the process itself feels familiar and safe. You enter an address, the website simulates transaction history analysis and walks you through the stages of the check. Then comes a request to connect your wallet, approve an action, or even send a small amount supposedly to complete the analysis.
That’s where the AML check ends and phishing begins.
⚙️ That’s Not How AML Works
For a basic check, a service only needs a public wallet address or transaction hash. The transaction history is already on-chain, so it can be analyzed without access to the wallet itself.
There’s no need to connect your wallet, sign transactions, grant token permissions, or send funds to complete the check.
🐾 Scammers Have Learned to Sell Safety
What stands out about this scheme is the social engineering behind it. Instead of tempting users with easy money, scammers target their desire to protect what they already have.
Fake analysis, familiar AML language, and the promise of a risk score make the process feel legitimate. Against that backdrop, connecting a wallet can seem like just another technical step, followed by a request to sign a transaction or grant access to your assets.
💻 Security Starts With the Service You Choose
Scams evolve alongside the industry. As AML checks and other security tools become more common, scammers are increasingly likely to imitate them. So don’t just check the wallet. Check the service you trust to do it.
❤️ With BitOK, a public wallet address or transaction hash is enough for a basic check. There’s no need to connect your wallet, share your seed phrase, or grant access to your assets.
Website | Telegram | BitOK bot | 52 |
| 7 | 🔞 Have bridges become the new “mixers”?
SUPERFORTUNE. Humanity Protocol. Kelp DAO. Bybit.
In each of these cases, BitOK analysts found bridges appearing after the hack, as the stolen funds began moving on-chain.
Bridges allow assets to move between networks, adding swaps and intermediary addresses along the way.
📊 Why bridges?
Mixers make funds harder to trace by mixing transaction flows. Bridges work differently: they move assets between blockchains, allowing the flow of funds to continue on another network.
A route can end up looking like this: hack → new address → bridge → another network → swap → another bridge → BTC
In the SUPERFORTUNE case, the stolen funds moved through a series of bridges before ending up across three wallets.
Following the Humanity Protocol and Kelp DAO hacks, the funds also moved through bridges and swaps before being converted into BTC. They eventually converged in a cluster that had previously received assets linked to the Bybit Hack.
🤑 But bridges don’t make “dirty” crypto clean
Moving funds to another network doesn’t erase their history. Links to a hack or stolen funds don’t disappear after a bridge, a swap, or several intermediary addresses.
By the time assets reach the final wallet, they may have already moved across several networks and addresses. Without tracing the full flow, the original connection to a hack can be easy to miss.
That’s why at BitOK, we don’t look at transactions in isolation. We reconstruct the full flow of funds across addresses, assets, and blockchains using BitOK Graph for on-chain investigations.
🔍 Want to trace the full route? Explore BitOK Graph: https://bitok.org/graph
Website | Telegram | BitOK bot | 59 |
| 8 | 🧠 Strong AML needs two things: visibility and expertise
We’re partnering with AML Incubator to combine on-chain analytics with hands-on compliance expertise.
BitOK helps businesses screen wallets and transactions for exposure to sanctions, scams, stolen funds, and other high risk activity.
AML Incubator works on the other side of the process, helping companies build and strengthen their compliance functions.
📊 The key point: identifying risk is only part of the job. Teams also need the right processes to assess its impact and decide what to do next.
And this is just the start. More to come from BitOK × AML Incubator.
Website | Telegram | BitOK bot | 69 |
| 9 | 🌍 BitOK Is Heading to Blockchain Life 2026
On December 1–2, BitOK will join the 17th edition of Blockchain Life, one of the leading international events for the crypto industry.
Over the years, the forum has become a key meeting point for companies, investors, Web3 teams, and industry experts shaping the market and its future direction.
❤️ BitOK CEO Dmitry Machikhin and the BitOK team look forward to meeting colleagues and partners in person, sharing their experience, and discussing how on-chain analytics, AML, KYT, and risk management are evolving.
This year, the event will take place during Dubai’s major business week ahead of Formula 1. A great way to wrap up the crypto year together with the industry.
💵 Get 10% off your Blockchain Life 2026 tickets with promo code «BitOK»: https://blockchain-life.com/
Website | Telegram | BitOK bot | 1 366 |
| 10 | 没有文字... | 71 |
| 11 | ⚙️ $186.5M Across Three Routes: Inside Darknet Kraken’s Financial Infrastructure
After Hydra was shut down in 2022, new platforms moved into the Russian speaking darknet market. One of the largest was Kraken, which has no connection to the cryptocurrency exchange of the same name. The marketplace brings together hundreds of independent vendors while providing shared infrastructure for trading and payments, creating common financial nodes where their flows converge. By tracing these nodes, BitOK analysts identified three withdrawal routes totaling at least $186.5 million, with approximately $147.5 million reaching cryptocurrency exchange infrastructure.
1. Darknet marketplace Kraken interface. The platform brings together independent vendors and provides shared infrastructure for trading and payments.
💱 $72.55M via BNB Smart Chain
The first route begins with BTC consolidation. Smaller incoming payments were grouped into nearly identical batches of around 9.995–9.997 BTC, left untouched for several days, and then progressively split first into roughly 5 BTC and later into transfers of around 1 BTC. The recurring batch sizes, pauses, and splitting sequence are consistent with automated processing.
2. Kraken → Bridgers. BTC from Kraken is consolidated and progressively split before being transferred through Bridgers. Transaction visualization in BitOK Graph.
After splitting, BTC was sent to Bridgers, with the destination address on another network embedded directly into the Bitcoin transaction via OP_RETURN. BTCB was then issued on BNB Smart Chain, swapped for USDT and USDC through PancakeSwap, distributed across dozens of wallets, and ultimately sent toward infrastructure associated with HTX, MEXC, KuCoin, and Gate.io. BitOK traced $72.55 million through this route.
💵 $74.19M via Avalanche and the Hydra Connection
The second route was the largest of the three. BTC moved through Avalanche Bitcoin Bridge, where BTC.b was issued on Avalanche, swapped for USDT via LFJ, and sent toward HTX infrastructure. BitOK traced $74.19 million through this route. This is also where the Hydra connection emerged. Two transaction chains linked to the closed marketplace had previously converged on one of the analyzed BTC addresses, totaling 190.31 BTC. Part of these funds remained dormant for almost three years before being split in January 2026. One tranche then moved through several intermediary wallets into the same Avalanche Bitcoin Bridge used by the Kraken route.
3. Hydra + Kraken → Avalanche Bitcoin Bridge. Funds linked to Hydra and Kraken converge on the same bridge infrastructure after passing through separate chains of intermediary BTC wallets. Transaction visualization in BitOK Graph.
What matters here isn't a single address overlap, but the similarity in infrastructure and transaction patterns: BTC splitting, intermediary wallets, and the use of the same bridge. This points to a likely shared financial infrastructure, but does not prove common ownership of Hydra and Kraken. One working hypothesis from BitOK is that both marketplaces may have relied on the same team or operator to move funds.
🔞 $39.75M via TRON
The third route began with Kraken’s built in exchange services. Vendors sent BTC and received USDT on TRON, with the USDT destination address again transmitted via OP_RETURN inside the Bitcoin transaction. In the confirmed sample, BitOK identified 104 payments from 20 BTC addresses totaling 60.94 BTC. Two observed swaps took only 171 and 157 seconds from the BTC transfer to the USDT payout. The USDT was then distributed across a network of intermediary wallets. One traced branch ultimately led to 708,400 USDT reaching WhiteBIT infrastructure. The total identified volume of this route was $39.75 million.
4. TRON → WhiteBIT. USDT is distributed across intermediary TRON addresses, with one traced branch leading to 708,400 USDT reaching WhiteBIT infrastructure.
👋 What the Investigation Revealed
The $186.5 million figure represents a lower bound of the identified flow, not Kraken’s total turnover. It covers only the three routes BitOK was able to trace and excludes privacy coins, unidentified clusters, and unlabelled internal transfers. Recurring batch sizes, pauses, splitting patterns, cross-chain movements, and common exit points made it possible to reconstruct the financial infrastructure even as individual addresses changed. Three routes, multiple blockchains, bridges, DEXs, and dozens of intermediary wallets made the flow more complex, but not invisible: by analyzing the full transaction chain, BitOK traced $186.5 million and identified a connection to Hydra linked funds almost three years after they last moved. ❤️
Website | Telegram | BitOK Bot | 1 |
| 12 | 🐾 Same wallet, second hack: $24M was only the beginning
In 2023, this Ethereum address lost around $24.2M in stETH and rETH after the owner signed malicious increaseAllowance transactions.
Almost three years later, the same address was compromised again. This time, together with a linked wallet, around $25.6M in assets was drained.
⚙️ But the second attack worked differently
There is no evidence that old token allowances were used. Instead, DeFi positions across both wallets were closed, liquidity was withdrawn, and tokens and ETH were transferred directly.
In other words, the attacker was able to control both wallets almost like the owner. On-chain data confirms control over transaction signing, but cannot tell us exactly how that access was obtained. The compromise could involve private keys, a signing device, a signer, or an active session.
🔍 Where did the funds go?
Most of the assets were converted into DAI and ETH and split across several addresses. At the time of our analysis, the largest single balance, 20M DAI, was still sitting at an identified storage address.
Another 206K USDC took a more complex route: Ethereum → Arbitrum → Hyperliquid → FXMR → an address where the funds mixed with other users’ flows
One address. Two major thefts. Almost $50M lost across two different compromise mechanisms.
😮 Before accepting a transfer, check the sender’s address and source of funds with the BitOK Bot to avoid receiving assets linked to this or other high-risk transaction chains.
Website | Telegram | BitOK bot | 55 |
| 13 | https://telegra.ph/Kraken-08-12-4 | 1 |
| 14 | ⚙️ How Tether Blacklisting Moved Beyond the Crypto Industry
Our research into USDT blacklisting served as one of the key sources for a new Forbes article, bringing the issue of the public freeze window into a broader discussion.
✅ The main takeaway remains the same: Tether has become faster, but the system has not become structurally safer. As long as information about an upcoming freeze becomes visible on-chain before execution, funds can still be moved before the freeze takes effect.
And the scale of the issue is growing alongside the role of USDT. Tether is increasingly freezing funds in cooperation with law enforcement, yet the process can still leave a public window for assets to be moved before the freeze takes effect.
🧠 What once looked like a technical feature of the blacklisting mechanism is now becoming a broader question of infrastructure resilience.
That is why we look beyond headline blacklist statistics. We analyze fund movements, the sequence of actions, and what happens before a freeze is actually executed.
❤️ BitOK research is now featured in Forbes. And we are already working on what could become the next big topic of discussion.
Read the full BitOK research: https://bitok.org/blog/tether-blacklisting-one-year-later
Website | Telegram | BitOK bot | 55 |
| 15 | 🔞 From 500 Wallets to $114M: Three More Waves of COLDCARD Attacks
In our previous investigation, we covered the first wave of mass BTC theft, where 594.477 BTC was drained from 500 Bitcoin wallets. BitOK analysts traced the complete flow of the stolen funds.
Further investigation revealed that this was not an isolated incident.
BitOK identified three additional waves of coordinated wallet drains that took place between July 30 and August 3. The total amount linked to these incidents has now reached 1,815.78 BTC, worth approximately $114.8 million.
📊 Where did the funds go?
In the first wave, a significant portion of the stolen BTC was gradually consolidated into three major wallets holding approximately 562 BTC, 398 BTC, and 89 BTC.
In the second wave, BitOK identified two additional addresses containing approximately 45.9 BTC and 30.18 BTC.
Funds from the third and fourth waves remain spread across numerous addresses, and no single final destination wallet has been identified yet.
💱 More than 1,158 BTC remain on the largest identified addresses
At the time of analysis, the six largest wallets identified in the investigation collectively held 1,158.65 BTC, with the largest address containing more than 562 BTC.
Stolen BTC doesn't disappear after an attack. It continues moving across the blockchain and can eventually reach new counterparties.
To reduce the risk of receiving funds linked to incidents like these, always screen wallet addresses and transactions with BitOK Bot before sending or accepting crypto.
Website | Telegram | BitOK bot | 71 |
| 16 | 💵 500 Wallets Drained in 15 Minutes: Where Did 594 BTC Go?
On July 30, attackers drained 594.477 BTC from 500 Bitcoin wallets in a coordinated operation.
The funds were first consolidated into a single address before 562.019 BTC were moved to a second wallet. BitOK traced the entire flow of funds.
⚙️ How the Funds Were Moved
All 500 transactions were executed within just 15 minutes. BitOK analysts identified several common characteristics:
• funds from different wallets were consolidated into a single address;
• almost all transactions were confirmed within four consecutive Bitcoin blocks;
• the transactions shared the same structure and similar fee patterns.
Taken together, these indicators point to a single, carefully coordinated operation.
🔍 What May Have Caused the Incident
The leading hypothesis is a vulnerability affecting seed phrase generation in certain versions of the COLDCARD firmware. Such a flaw could have allowed attackers to recover seed phrases and gain access to affected wallets.
In one of our previous posts, we explained that the problem may not lie in the seed phrase itself, but in the way it was generated. That's why high-quality randomness during seed generation is critical to wallet security.
The complete flow of funds is shown in the graph above.
Website | Telegram | BitOK bot | 84 |
| 17 | ✔️ BitOK's "Clean or Dirty" KYT Trainer is now available on Telegram
We've launched a Telegram mini-game where you make KYT decisions under time pressure.
🧠 Every transaction gives you 2–6 seconds to decide whether to allow or block it. Run out of time, and the transaction is processed automatically.
There are 9 shifts in total, each introducing new screening rules and a faster transaction flow.
Cases include exchange labels, sanctioned wallets with green risk scores, outdated screening results, flagged customers, and structuring around the $10,000 threshold.
🚀 Think you can make it through all 9 shifts? Climb the leaderboard: @bitok_game_bot
Website | Telegram | BitOK bot | 73 |
| 18 | 🐾 "Sign here." That became the most expensive lesson in Triple-A's history
Between July 24–25, an attacker drained more than $9M from wallets publicly linked to the project.
This wasn't a smart contract exploit. It wasn't a blockchain hack.
Every transaction was valid because it was signed with legitimate keys. The attacker didn't break the protocol — they compromised the wallet signing infrastructure.
The BitOK team reconstructed the entire flow of funds, tracing the assets from the first transfers across TRON, Ethereum, Polygon, and Arbitrum to the final wallet holding 5,228 ETH.
🧾 In our investigation, we break down:
➤ how the attacker gained the ability to authorize legitimate transactions;
➤ why the stolen funds were split across TRON, Ethereum, Polygon, and Arbitrum;
➤ how more than $9M ended up consolidated into 5,228 ETH;
➤ and why compromising a transaction signing system can be even more dangerous than many traditional exploits.
⚙️ Sometimes, stealing millions takes nothing more than a valid signature.
Website | Telegram | BitOK bot | 65 |
| 19 | 🔞 Why is July 23 being called crypto's unofficial Hacker Day? Let's break it down with BitOK
On July 23, the crypto industry was hit by three major exploits within just a few hours.
B² Network, Verus Bridge, and AFX Bridge were all compromised, with combined losses exceeding $35 million.
What makes these incidents stand out is that none of them relied on a conventional hack.
Each exploit followed a different attack path: one targeted a flaw in staking logic, another abused bridge verification, and the third exploited a critical weakness in the bridge's architecture.
At BitOK, we analyzed all three incidents to understand what happened, how each attack unfolded, and how the attackers moved the stolen funds.
🧾 Missed our investigations? Here's the full collection:
➤ The $3.9M Golden Key: How B² Network Was Exploited
➤ $7.5M Out of Thin Air: Inside the Second Verus Bridge Exploit
➤ The Perfect Heist: How AFX Bridge Lost $24M
⚙️ Three exploits. One day. More than $35 million stolen.
The biggest takeaway? Today's most damaging attacks rarely rely on brute force. Instead, they exploit subtle flaws in protocol logic that often go unnoticed until it's too late.
Website | Telegram | BitOK bot | 69 |
| 20 | 🚀 AML has become one of the fastest-growing areas of the crypto industry
Just a few years ago, AML was a specialized discipline within the digital asset market. Today, it is a core part of the industry’s infrastructure.
💻 As the market continues to develop, demand is growing for tools that help organizations assess crypto risk and meet evolving compliance requirements.
BitOK is growing too, and we are expanding our team.
We currently have more than 30 open positions, from leadership roles to engineering, analytics and compliance.
👤 Open roles include:
• Head of Sales;
• Head of PR;
• Chief Operating Officer;
• Head of International Development;
• Customer Success Specialist;
• Marketing and Growth Specialist;
• Business Development and Sales Manager;
• Operations Manager;
• Backend and Frontend Developers;
• Legal and Compliance Specialists;
• Analysts;
• DevOps Engineers;
• Data Analysts.
🔍 We are looking for people who want to develop AML and blockchain intelligence technologies, build products for the global market and solve real challenges across the digital asset industry.
Interested in joining BitOK team? Apply using the link or send your CV to hr@bitok.org ❤️
Know someone who could be a great fit? Share this post with them.
Website | Telegram | BitOK bot | 1 786 |
