uz
Feedback
BitOK

BitOK

Kanalga Telegram’da o‘tish

BitOK provides crypto AML and blockchain analytics for risk checks, investigations and transaction monitoring. ◽️Check a wallet, address or transaction: @BitOK_AML_bot ◾️Community: @bitok_eng ◾️Support: @BitOK_support ◾️Website: https://bitok.org/

Ko'proq ko'rsatish
313
Obunachilar
Ma'lumot yo'q24 soatlar
-47 kun
+4430 kun
Postlar arxiv
🌍 September in AML: 5 events that should change how you think about screening Checked an address, saw low risk, and moved on
🌍 September in AML: 5 events that should change how you think about screening Checked an address, saw low risk, and moved on? September showed where that approach breaks down. New sanctions can change the status of previously screened addresses, regulators are strengthening on-chain analytics, and stolen funds can keep moving long after the initial incident. 💵 Outside sanctions yesterday. On the SDN List today On September 9, OFAC added Xinbi Guarantee to the SDN List together with 52 TRON addresses. If those addresses were screened earlier, the old result no longer reflects their current sanctions status. The transaction history stayed the same. The risk assessment changed. 💻 On-chain analytics is becoming part of supervision On September 15, AMLA named cryptoassets as one of its strategic priorities and highlighted the need to strengthen blockchain analytics at the EU level. Rules alone are not enough. Regulators also need tools to see links between addresses, trace fund flows, and identify risks that emerge after a transaction has already taken place. ✅ AML registration won’t replace full authorization On September 30, the FCA opened applications under the UK’s new crypto regime. Exchanges, custodians, staking services, and other firms carrying out newly regulated activities will need separate authorization. Existing AML registration will not automatically convert into it. The focus is moving beyond customer and transaction checks to how firms manage risk in practice. 🐾 DeFi is also being tied to identifiable points of control The updated CLARITY Act included provisions that could bring certain non-decentralized DeFi protocols under the Bank Secrecy Act. The bill didn’t advance in the September 15 procedural vote, so no new requirements are in force yet. But the direction is clear: where a DeFi arrangement still has an identifiable operator or point of control, regulatory obligations may be attached to it. 🔞 The hack ends. The fund flow doesn’t On September 6, around $319M in BTC was drained from Liquid Network. About 85% was later returned, while roughly $47M remained with the attackers. A first screening only captures one point in time. Days or weeks later, funds may move to new addresses, pass through different services, or become active again. All five events point to the same conclusion: risk is not a static label. The blockchain preserves history, but the risk around an address keeps changing. That means an old screening result can’t replace a current assessment. 😮 Before sending crypto, check the current risk of the address and transaction in BitOK Bot. Website | Telegram | BitOK bot

🇰🇷 Next stop for BitOK: Seoul On September 30 and October 1, the BitOK team will be at Korea Blockchain Week 2026, one of A
🇰🇷 Next stop for BitOK: Seoul On September 30 and October 1, the BitOK team will be at Korea Blockchain Week 2026, one of Asia’s major crypto events. This year’s agenda puts stablecoins, DeFi, digital asset regulation, and institutional adoption in the spotlight. 😮 For us, the focus is practical: source of funds, risky transactions, cross-chain asset flows, and investigations where a single wallet check is no longer enough. We’ll be meeting Web3 teams, partners, and industry peers to discuss real AML/KYT cases and share insights from BitOK’s on-chain investigations. September 30 – October 1 | Seoul, South Korea 🌎 See you at Korea Blockchain Week! Website | Telegram | BitOK bot

🌎 BitOK is a Sapphire Sponsor of Blockchain Life 2026, joining the companies shaping what comes next for crypto On December
🌎 BitOK is a Sapphire Sponsor of Blockchain Life 2026, joining the companies shaping what comes next for crypto On December 1–2, Blockchain Life returns to Dubai, bringing together 15,000+ attendees from 130+ countries. The forum will kick off one of the busiest tech weeks of the year, packed with side events, meetings with teams from around the world, and the Formula 1 finale in Abu Dhabi. 👤 What to expect this year: ➤ 3 stages and 200+ speakers from across the crypto industry; ➤ 200+ companies in the expo, from exchanges and Web3 to mining, AI, and fintech; ➤ the debut of AI Future Forum, focused on AI, robotics, and emerging technologies; ➤ a full week of networking around Web3, digital finance, regulation, and the next market trends; ➤ the legendary Blockchain Life Afterparty with a world-class headliner. 😮 Meet us at booth S12: let’s talk real AML/KYT cases, on-chain investigations, and how teams are managing crypto risk today. See you in Dubai. The countdown is on. 💵 Get 10% off your ticket with promo code “BitOK”.

💱 600 BTC Woke Up After 14 Years: What the On-Chain Trail Revealed On September 22, an address that had held 600 BTC since July 2012 spent those coins for the first time in more than 14 years. 🚀 BitOK reconstructed how the funds were accumulated and where they moved next: ➤ 7 separate transfers in 2012 built up the 600 BTC balance. ➤ One route followed a 200 → 100 → 50 BTC sequence through linked UTXO change. ➤ In 2026, 35 inputs were consolidated into one output and then split into two branches of roughly 300 BTC each. The incoming history on the graph shows that part of the flow is linked to an MtGox cluster. Transaction analysis confirms how the funds moved and how the outputs are connected, but it does not establish the owner’s identity or prove that the BTC were sold. 🤑 At our latest check, around 600 BTC remained across two addresses, roughly 300 BTC on each. We mapped the full route, from the 2012 accumulation to the 2026 split, in BitOK Graph. 🧠 Want to try an on-chain investigation yourself? Build your own transaction graph in BBitOK Graph and reconstruct the route step by step. Website | Telegram | BitOK bot

🔞 What’s really behind a transaction? Let’s talk at ETHSofia On September 24, the BitOK team will be in Bulgaria for ETHSofi
🔞 What’s really behind a transaction? Let’s talk at ETHSofia On September 24, the BitOK team will be in Bulgaria for ETHSofia 2026. As part of Blockchain Week Bulgaria, the conference will bring together Ethereum developers, Web3 teams, researchers, and security experts. 🟩 On the agenda: smart contract security, on-chain privacy, DeFi, and asset tokenization. Speakers include representatives from Chainlink Labs, CertiK, and ChainSecurity. At ETHSofia, we’ll discuss how to verify the source of funds, detect risky transactions, and trace assets after hacks. We’ll also share insights from BitOK investigations and talk about how AML/KYT can be integrated into Web3 workflows. 🌎 See you tomorrow at ETHSofia! Website | Telegram | BitOK bot

❤️ New 0% Scam challenge from BitOK: taking our pink around the world First, our pink made it to Niagara Falls. Then it showe
+2
❤️ New 0% Scam challenge from BitOK: taking our pink around the world First, our pink made it to Niagara Falls. Then it showed up on safari. Now we want to see where BitOK merch can make it next. ✔️ So starting today, we’re launching the 0% Scam challenge and building a world map from real photos of our community wearing BitOK merch. Traveling, heading to a conference, or simply somewhere BitOK hasn’t been yet? Take your merch with you, snap a photo, tag BitOK, and add #0ScamBitOK. 👤 The creator of the best photo will receive $250 + 250 checks in BitOK Bot. Let’s see how much of the world we can turn pink and where BitOK shows up next. #0ScamBitOK Website | Telegram | BitOK bot

🇯🇵 From on-chain to offline: BitOK is heading to ETHTokyo September 19–27, Tokyo will bring together builders, researchers,
🇯🇵 From on-chain to offline: BitOK is heading to ETHTokyo September 19–27, Tokyo will bring together builders, researchers, founders, and Ethereum teams for ETHTokyo Week 2026 with conferences, meetups, workshops, and hackathons happening across the city. 🔍 Building a Web3 product? In Tokyo, we’ll be talking about how AML/KYT fits into Web3: checking the source of funds, spotting risky connections, and tracing asset flows across wallets and chains. We’ll also share insights from our on-chain investigations and real cases we’ve worked on. ❤️ Going to ETHTokyo? Drop us a message. We’d love to meet new teams, catch up with partners and clients, and discuss your use cases in person. Website | Telegram | BitOK bot

🐾 Where does Hamas on-chain trail lead? What BitOK found beyond the FBI-listed addresses The FBI disclosed addresses used by Al-Qassam to collect crypto donations. BitOK traced their connections further and found dozens of intermediaries, cross-chain movements between TRON, Ethereum and BSC, and larger settlement nodes. One of the key clues wasn’t USDT. It was small TRX transfers. In one case, a donation wallet received 14 TRX and just 63 seconds later sent 4,018 USDT to an operational address. Similar TRX top-ups appeared across other wallets, linking addresses that looked unrelated based on USDT flows alone. 👤 10 intermediaries, three blockchains In one reconstructed route, funds moved through ten intermediaries, consolidated in a single wallet and crossed chains via a bridge: TRON → Ethereum → BSC On BSC, the funds were distributed again before converging at reused nodes. 122,449 USDT returned to TRON On July 20, funds from eight BSC addresses were consolidated and sent through a bridge. Just 35 minutes later, 122,449 USDT arrived at a TRON wallet that related addresses had already funded with TRX. Nearly the entire amount then moved into a larger settlement cluster. 💵 Related wallets are still active The latest related activity was recorded on September 4 and 6, 2026. In one case, funds moved through several intermediaries in just nine minutes. The addresses and chains changed, but the same pattern kept appearing: intermediaries → consolidation → cross-chain transfer → consolidation → larger settlement nodes. 🔍 In BitOK Graph, we reconstructed the routes across TRON, Ethereum and BSC and uncovered connections that aren’t obvious when looking at individual addresses. Want to see where an on-chain trail leads? Build the route yourself in BitOK Graph. Website | Telegram | BitOK bot

🔞 COLDCARD is moving again: Wasabi, THORChain and 660 ETH into Tornado Cash In August, BitOK analysts mapped four waves of attacks on COLDCARD linked to 1,815.78 BTC. Now part of those funds is moving again. As of September 8, BitOK confirmed new routes for roughly 156.9 BTC. 🐾 136 BTC moved through a series of Wasabi CoinJoins The funds entered four CoinJoin transactions. The most active flow started with 61.12 BTC and passed through 10 consecutive rounds, with the largest remaining output repeatedly rolled into the next CoinJoin. After the tenth round, the largest probable remainder was around 19 BTC. Beyond that point, the trail starts to fragment inside CoinJoin. 💱 And it didn’t stay on Bitcoin Another 20.69 BTC moved through THORChain and was swapped into 668.57 ETH. From there, the route split: ➤ 660 ETH went into Tornado Cash; ➤ around 8.07 ETH reached KuCoin 17 after mixing with other funds; ➤ the remainder went to intermediate transfers and fees. ✔️ Along the KuCoin route, we traced around 8.07 ETH to KuCoin 17, with the funds mixing into other flows before the deposit. By then, the structure had become much more layered: CoinJoin → cross-chain → Tornado Cash / KuCoin. But the story doesn’t end here. COLDCARD remains on BitOK’s radar. And if you want to avoid receiving funds tied to routes like these, check the address before accepting a transfer with BitOK Bot. Website | Telegram | BitOK bot

💻 Who Controls a Billion Tokens? Hunter Biden’s New Memecoin LAPTOP $LAPTOP is scheduled to launch today. The project promis
💻 Who Controls a Billion Tokens? Hunter Biden’s New Memecoin LAPTOP $LAPTOP is scheduled to launch today. The project promises community airdrops, charitable donations and token burns tied to election results, celebrity mentions and other events. BitOK examined who can move the tokens. 👤 Seven Wallets, the Same Control Structure As of September 8, 97.7% of the supply sat in seven Safe wallets with the same owner addresses. Each requires two of three approvals to execute a transaction. One of those addresses is itself a Safe, where any one of four owner addresses can approve. So “two of three” doesn’t necessarily mean two independent people. ⚙️ The Airdrop Terms Changed Before Launch Updated documents reassigned 40 million LAPTOP from the Channel 5 audience to Hunter’s Substack subscribers. We found no explanation for the change in the materials reviewed. The documents also describe custody arrangements and unlock schedules. But the public wallet configuration doesn’t show how those restrictions are enforced. ❤️ BitOK mapped the token’s control structure. After launch, we’ll check whether actual transfers match the published terms. As the market picks up, expect more projects that warrant scrutiny. Trust the analysis, not the promises. Website | Telegram | BitOK bot

📈 Pump a Token by Hundreds of Times, Drain the Liquidity: Inside the Tectonic Attack On August 30, an attacker targeted Tect
📈 Pump a Token by Hundreds of Times, Drain the Liquidity: Inside the Tectonic Attack On August 30, an attacker targeted Tectonic, a lending protocol on Cronos. The key was manipulating the price of the illiquid TONIC token, pushing it up by hundreds of times and using the inflated value to borrow liquid assets. 🟩 The attack unfolded in several steps: ➤ 5M USDC was deposited into the position; ➤ borrowed USDC and CRO were used to buy TONIC across three VVS pools; ➤ TONIC’s price increased by roughly 454× against USDC, 599× against WCRO, and 668× against VVS; ➤ TONIC was repeatedly borrowed and supplied back into Tectonic, allowing liquid assets to be withdrawn from the protocol. 🔍 Some of the funds left Cronos before the network stopped After the attack, the assets were distributed across several addresses. BitOK analysts traced 6.34M USDC from Cronos to Ethereum, where the entire amount was swapped for ETH. At the time of our check, the main Ethereum address still held 2,592 ETH. Expanding the cluster revealed earlier links. One address in the funding chain had received funds from Tornado Cash. Another connected branch moved 4,532 USDC through Arbitrum to Hyperliquid, where it was used to buy XMR1. No withdrawal of native XMR to the Monero network was confirmed. Less than two hours after the position was created, Cronos stopped producing new blocks. Assets still on Cronos therefore can’t move while the network remains halted. That doesn’t mean the funds were seized or permanently frozen. ❤️ Funds can move across chains, services, and wallets. Check their history and risk before you transact with BitOK Bot. Website | Telegram | BitOK bot

🇲🇽 BitOK is heading to SiGMA North America in Mexico City From September 1–3, the BitOK team will be at SiGMA North America
🇲🇽 BitOK is heading to SiGMA North America in Mexico City From September 1–3, the BitOK team will be at SiGMA North America, the event’s first edition in Mexico, bringing together the North American and Latin American markets. iGaming operators, payment providers, fintech companies, technology providers, and regulators will all meet in one place. For us, it’s a chance to discuss how the industry is approaching crypto payments and the risks that come with them across the region. 💵 Crypto payments require more than KYC Exposure to sanctioned addresses, scams, stolen funds, and other high-risk sources exists at the on-chain transaction level. In Mexico City, we’ll be talking about how AML/KYT helps iGaming businesses identify these connections before a transaction and build stronger controls around crypto risk. ❤️ Going to SiGMA North America? Message us and let’s meet to talk AML, KYT, and the crypto risks businesses are dealing with today. Website | Telegram | BitOK bot

✔️ Pump the Price, Take $8.7M: Breaking Down the Moonwell Attack On August 27, $8.7M in assets was drained from Moonwell. The key to the attack wasn’t a bug in the code. It was the price of the collateral. The attacker pushed up the price of the illiquid MAMO token through a series of large buys, deposited it into Moonwell at an inflated valuation, and borrowed liquid assets against it. ⚙️ The attack started six days before the funds moved BitOK analysts reconstructed the preparation behind the attack. A linked address received 800 ETH from Tornado Cash, moved part of the funds across Ethereum, Cronos, and Arbitrum, and then prepared the capital for the attack on Base. On Base, funds and MAMO were sent to a separate address. Then the attack unfolded: ➤ large buys pushed up the price of MAMO; ➤ at least 35.5M MAMO was deposited into Moonwell as collateral; ➤ against the inflated collateral, the attacker borrowed 71.36 cbBTC, 2.56M USDC, 560 WETH, and 368 wstETH. 🔍 From Moonwell back to Ethereum: where did the $8.7M end up? After the withdrawal, the assets were converted to USDC and moved from Base to Ethereum via Circle CCTP. There, 8.728M USDC was swapped for DAI and sent back to the address where the attack preparation had started. After all the swaps and cross-chain transfers, the funds returned to the original address as $8.7M in DAI. At the time of our analysis, the funds were still sitting in that wallet with no confirmed onward movement. ❤️ Funds can change chains, assets, and wallets, but their history remains part of the risk picture. Check addresses and transaction history before you transact with BitOK Bot. Website | Telegram | BitOK Bot

🧠 When Governance Gets Exploited: Where Term Finance’s $8.5M Went The attacker didn’t need to find a smart contract vulnerability to drain millions from Term Finance. A small stake in the vault was enough to propose the changes they needed and wait for no one to say “no.” The weak point wasn’t the code. It was the protocol’s governance. ⚙️ Six days to stop the withdrawal The attacker swapped 0.5 ETH for a stake in the ETH Meta Vault, received governance tokens, and submitted a proposal containing 17 actions. Those actions included removing the protective delay, pulling WETH back from four strategies, and adding an attacker-controlled exit strategy. The proposal remained open for around six days. No one vetoed it. Once the window closed, the protocol executed the actions and transferred 2,841.74 WETH to the attacker. A similar setup targeted five USDC vaults. Separate proposals changed key roles and risk controls, allowing another 1.68M USDC to be withdrawn. 🔍 Where did the funds go? BitOK analysts traced the full flow: ➤ WETH was converted to ETH; ➤ USDC was swapped for DAI via KyberSwap and Maker PSM; ➤ the ETH and DAI were consolidated into a single wallet. The attacker didn’t need to break the code. They used Term Finance’s own rules: propose the right changes, wait for no one to stop them, then let the protocol execute the rest. ❤️ Want to break down similar cases and trace on-chain fund flows yourself? Use BitOK Graph for your own investigations. Website | Telegram | BitOK bot

✅ The AML Check That Could Cost You Your Crypto Scammers have found a more sophisticated way to get to your assets: offering to check whether your crypto is “clean” first. A fake AML service can look convincing, and the process itself feels familiar and safe. You enter an address, the website simulates transaction history analysis and walks you through the stages of the check. Then comes a request to connect your wallet, approve an action, or even send a small amount supposedly to complete the analysis. That’s where the AML check ends and phishing begins. ⚙️ That’s Not How AML Works For a basic check, a service only needs a public wallet address or transaction hash. The transaction history is already on-chain, so it can be analyzed without access to the wallet itself. There’s no need to connect your wallet, sign transactions, grant token permissions, or send funds to complete the check. 🐾 Scammers Have Learned to Sell Safety What stands out about this scheme is the social engineering behind it. Instead of tempting users with easy money, scammers target their desire to protect what they already have. Fake analysis, familiar AML language, and the promise of a risk score make the process feel legitimate. Against that backdrop, connecting a wallet can seem like just another technical step, followed by a request to sign a transaction or grant access to your assets. 💻 Security Starts With the Service You Choose Scams evolve alongside the industry. As AML checks and other security tools become more common, scammers are increasingly likely to imitate them. So don’t just check the wallet. Check the service you trust to do it. ❤️ With BitOK, a public wallet address or transaction hash is enough for a basic check. There’s no need to connect your wallet, share your seed phrase, or grant access to your assets. Website | Telegram | BitOK bot

🔞 Have bridges become the new “mixers”? SUPERFORTUNE. Humanity Protocol. Kelp DAO. Bybit. In each of these cases, BitOK anal
🔞 Have bridges become the new “mixers”? SUPERFORTUNE. Humanity Protocol. Kelp DAO. Bybit. In each of these cases, BitOK analysts found bridges appearing after the hack, as the stolen funds began moving on-chain. Bridges allow assets to move between networks, adding swaps and intermediary addresses along the way. 📊 Why bridges? Mixers make funds harder to trace by mixing transaction flows. Bridges work differently: they move assets between blockchains, allowing the flow of funds to continue on another network. A route can end up looking like this: hack → new address → bridge → another network → swap → another bridge → BTC In the SUPERFORTUNE case, the stolen funds moved through a series of bridges before ending up across three wallets. Following the Humanity Protocol and Kelp DAO hacks, the funds also moved through bridges and swaps before being converted into BTC. They eventually converged in a cluster that had previously received assets linked to the Bybit Hack. 🤑 But bridges don’t make “dirty” crypto clean Moving funds to another network doesn’t erase their history. Links to a hack or stolen funds don’t disappear after a bridge, a swap, or several intermediary addresses. By the time assets reach the final wallet, they may have already moved across several networks and addresses. Without tracing the full flow, the original connection to a hack can be easy to miss. That’s why at BitOK, we don’t look at transactions in isolation. We reconstruct the full flow of funds across addresses, assets, and blockchains using BitOK Graph for on-chain investigations. 🔍 Want to trace the full route? Explore BitOK Graph: https://bitok.org/graph Website | Telegram | BitOK bot