A crypto tracking and compliance platform for everyone. Built by @SlowMist_Team

Web3 Security
We won the Gold Award in the FinTech (RegTech: Regulatory and Risk Management) at the #HKICT Awards 2025! 🏆
1/ 🎉 On Nov 21, 2025, at the #HKICT Awards in Hong Kong, SlowMist’s blockchain AML tracking system @MistTrack_io won the Gold Award in the FinTech (RegTech: Regulatory and Risk Management)! 🏆 📸 SlowMist Partner & CPO——Keywolf joined government, regulators & industry leaders to witness this milestone. HKICT Awards, established in 2006, is one of Hong Kong’s most recognized tech awards, organized by the Gov Digital Policy Office.🇭🇰
15
27,971
Please use the official @Bitget API for hacker addresses; our Google Sheet will no longer be updated. bitget.com/support/articles/…
So far, we have identified the following addresses associated with the @bitget exploiter that still hold funds. We will continue to update this list. @GracyBitget @xiejiayinBitget @Bitget_zh docs.google.com/spreadsheets…
1
1
12
3,154
Tether banned the wallet owned by the bitget exploiter etherscan.io/tx/0xdd30e4831e…
So far, we have identified the following addresses associated with the @bitget exploiter that still hold funds. We will continue to update this list. @GracyBitget @xiejiayinBitget @Bitget_zh docs.google.com/spreadsheets…
12
16
166
58,325
THORChain and Stolen Funds: The Industry Needs Answers After the $1.46B @Bybit_Official hack last year, nearly $1.2B in stolen funds was reportedly traced through @THORChain as the attackers moved assets across chains. Today, following another major security incident at @Bitget , we are once again observing Bitget Exploiter funds being sent into the THORChain for asset swaps and cross-chain transfers. The question is no longer: “Does THORChain know these funds are associated with hackers?” The attacker addresses have already been publicly flagged and are being actively tracked by exchanges, blockchain security/aml firms, and the wider crypto industry. The real question is: When a protocol is aware that funds originate from a publicly identified major hack, yet continues to facilitate large-scale cross-chain swaps, how should the industry view this under the banner of “decentralization”? Decentralization should not become a blanket excuse when dealing with known stolen funds. If, after every major crypto hack, attackers can continue using THORChain as a route to move funds from ETH → BTC, BNB → BTC, and across other chains, the industry needs to seriously ask: What responsibility should THORChain bear when handling known stolen funds? @GracyBitget @xiejiayinBitget @benbybit
18
7
90
43,268
MistTrack🕵️ retweeted
We’re working closely with @bitget on the ongoing investigation. For further details, please refer to Bitget’s official updates.
Replying to @bitget
[UPDATES] We are currently working with independent third-party experts Mandiant and SlowMist for a full investigation. Our first priority is our users. User balances remain intact, and Bitget's User Protection Fund covers the impact on this platform-wide incident. Bitget Wallet operates as a self-custodial wallet on a completely separate and independent infrastructure from Bitget Exchange and was not affected by this incident. Bitget Wallet users' assets remain onchain under users' control and remain unaffected. The Bitget Exchange platform continues to operate normally. Withdrawals are still temporarily paused while we complete additional security checks, and we will restore them as soon as we are confident that it is safe to do so. We know that during an incident like this, users want answers quickly. We will provide timely updates through Bitget's official channels.
7
10
79
16,809
RT @evilcos: 来自 @SpecterAnalyst 的链上分析关联出朝鲜黑客历史上的有关资金。另外,这次手法上确实和之前朝鲜黑客相关组织的手法类似,包括资金归集习惯… 更多信息见 Bitget 官方披露就好,我们在协同调查中。
16
181
So far, we have identified the following addresses associated with the @bitget exploiter that still hold funds. We will continue to update this list. @GracyBitget @xiejiayinBitget @Bitget_zh docs.google.com/spreadsheets…
[SECURITY NOTICE] Bitget Hot Wallet Incident — September 24, 2026 At 18:31 UTC on September 24, 2026, Bitget's security systems detected unauthorized transfers from some of our hot wallets. Our security team activated emergency response protocols immediately. What we have confirmed: -Estimated funds affected: approximately $351.6 million -Cold wallets remain fully secure. Bitget operates a three-tier wallet architecture — the breach contained only a portion of the hot wallet and warm wallet layers. -User funds are safe. The full amount of this loss falls within the coverage of Bitget's User Protection Fund, which currently holds over $464 million Actions we have taken: -Emergency response team activated within minutes of detection -Abnormal transfer addresses identified, flagged, and reported -Withdrawals temporarily suspended as a precautionary measure, pending security review -Law enforcement and on-chain security firms have been formally notified and are engaged What this means for you: -Your account balances are accurate and your assets are protected -Deposits and trading remain fully operational Withdrawals are temporarily paused and will be restored as soon as the security review is complete -What comes next: We will provide updates on an hourly basis across this channel and all official platforms. A full incident report — including root cause analysis and corrective actions — will be published within 24 hours. We will not speculate on the attack vector until the investigation is complete. Bitget has navigated multiple market cycles. We will not run from this. Every dollar and every decision will be accounted for, transparently and in full. Updates will be posted here and across all official Bitget channels as they become available. — Gracy Chen, CEO, Bitget
2
14
61
80,321
Updated to include additional hacker wallet addresses on the Ripple network.
1
5
2,413
All hacker addresses have been tagged. We’re actively monitoring fund transfers and expanding our blacklist. We remain fully committed to combating illicit transactions.
[SECURITY NOTICE] Bitget Hot Wallet Incident — September 24, 2026 At 18:31 UTC on September 24, 2026, Bitget's security systems detected unauthorized transfers from some of our hot wallets. Our security team activated emergency response protocols immediately. What we have confirmed: -Estimated funds affected: approximately $351.6 million -Cold wallets remain fully secure. Bitget operates a three-tier wallet architecture — the breach contained only a portion of the hot wallet and warm wallet layers. -User funds are safe. The full amount of this loss falls within the coverage of Bitget's User Protection Fund, which currently holds over $464 million Actions we have taken: -Emergency response team activated within minutes of detection -Abnormal transfer addresses identified, flagged, and reported -Withdrawals temporarily suspended as a precautionary measure, pending security review -Law enforcement and on-chain security firms have been formally notified and are engaged What this means for you: -Your account balances are accurate and your assets are protected -Deposits and trading remain fully operational Withdrawals are temporarily paused and will be restored as soon as the security review is complete -What comes next: We will provide updates on an hourly basis across this channel and all official platforms. A full incident report — including root cause analysis and corrective actions — will be published within 24 hours. We will not speculate on the attack vector until the investigation is complete. Bitget has navigated multiple market cycles. We will not run from this. Every dollar and every decision will be accounted for, transparently and in full. Updates will be posted here and across all official Bitget channels as they become available. — Gracy Chen, CEO, Bitget
1
1
24
8,333
如果你手机上安装过 FomoPeek 而且最近有被盗,可以把被盗地址、黑客地址提交给我们 aml.slowmist.com/cn/recovery…
⚠️最近一些 iPhone 用户的钱包被盗,是因为安装了 FomoPeek 这个 App,v1.1-1.2 主要版本引入了恶意 SDK,其包含一套专业的 iOS 内核攻击框架,集成 8 种漏洞利用方案,可根据设备型号及系统版本自动选择攻击方式,已知受影响 iOS 版本:iOS 12.0–18.7、26.0–26.1。 攻击成功后,该 App 可突破 iOS 沙盒隔离机制,进而读取并解密系统钥匙串(Keychain),并访问设备上其他 App 的数据文件。用户存储在设备中的私钥、助记词、登录凭据、聊天记录及文件等,均可能因此面临泄露风险。此外,该 App 还会连接与公开业务无关的隐蔽服务器,接收远程指令。 ⚠️⚠️⚠️这里重点做个提醒,由于该手法已经开始泛滥,iPhone 千万不要下载不明 App。 并保持 iPhone 及时更新到最新版本,比如现在是 27(不代表以后不会有风险,攻防对抗永远在升级)。 具体细节见我们的推文👇
6
7
21
11,079
MistTrack🕵️ retweeted
🚨 SlowMist TI Alert: FomoPeek App v1.1–1.2 Asset Theft 🚨 We have recently received multiple reports of users having assets stolen. Our investigation found that the affected cases involved private key exposure, and some of the users had previously installed and used @FomoPeek App versions 1.1–1.2. A joint investigation by the @SlowMist_Team and @okx security teams confirmed that the app contains malicious code.⚠️ Besides its normal features, FomoPeek includes two modules that are unrelated to its stated business functions. One of them contains an #iOS kernel exploitation framework with eight different exploit methods. The framework can automatically choose an attack method based on the device model and iOS version. ‼️Affected iOS versions: iOS 12.0–18.7 and iOS 26.0–26.1.‼️ If the exploit succeeds, the app may escape the iOS sandbox, access and decrypt Keychain data, and read files belonging to other apps on the device. 🔐 This means sensitive data stored on the device, including private keys, seed phrases, login credentials, chat history, and files, may be exposed. The app also connects to hidden servers that are unrelated to its public-facing services and can receive remote commands. Based on plaintext traffic captured during our analysis, the attack functionality is currently enabled and runs automatically at regular intervals. In general, devices running older iOS versions are at higher risk. If you have installed or used FomoPeek versions 1.1–1.2, we recommend that you take action immediately: 1️⃣ Check your accounts and assets for any unusual activity. 2️⃣ On a trusted device where FomoPeek has never been installed, create a new account and generate a new private key and seed phrase. 3️⃣ Move your assets to the new account as soon as possible. 4️⃣ Update your device to the latest available iOS version. 5️⃣ Do not continue using or reinstalling FomoPeek. 6️⃣ If you notice any suspicious asset activity, contact the official support team of the relevant platform and keep the affected device and related evidence for further investigation.
53
75
267
639,111
🚨 MistTrack Fund Tracking 🚨 Following the @likwid_fi incident reported by @SlowMist_Team, we tracked the on-chain movement of the stolen funds. 💸 Loss: 74.31 $BNB 📌 Attacker: 0x90bde1e0bb16b3deeb9d638acf8d01f19fd2f31e 🧭 Fund Flow: Attacker → Tornado Cash 🧩 Key Findings: • Multiple withdrawals by the attacker were traced to Tornado Cash, which also provided the initial funding. • 31.8 $BNB was transferred to the attacker from FixedFloat. 🔎 MistTrack has added the related addresses to its malicious address library. light.misttrack.io/address/B…
🚨SlowMist TI Alert🚨 💸 @likwid_fi Loss: 74.31 BNB 🔍 Root Cause: LikwidMarginPosition._executeAddCollateralAndBorrow (leverage=0 branch) never assigns delta.pairDelta, so the borrow path leaves pairReserves untouched. getAmountOut(pairReserves,...) returns the same 4.7857 BNB quote on every call — the attacker repeated the margin/borrow cycle 14 times, settling 211.8M TOKEN at the first-trade marginal price with no AMM price impact. 📌 Attacker EOA: 0x90bde1e0bb16b3deeb9d638acf8d01f19fd2f31e 📌 Attack Contract: 0xc63fb27f52ed8d06673c60c3075b2d3bd26cf4aa 📌 Vulnerable Contract: 0x6bec0c1dc4898484b7f094566ddf8bc82ed7abe8 (LikwidMarginPosition) 📌 Victim Contract: 0x065d449ec9d139740343990b7e1cf05fa830e4ba (LikwidVault) Powered by SlowMist.AI Tx: bscscan.com/tx/0x83cbd07d59a…
3
24
5,316
MistTrack🕵️ retweeted
Following exposure by @Bitrace_team and @MistTrack_io , Fulilai Guarantee(福利来担保) rebranded as Falali Guarantee(法拉利担保).
1
1
10
2,640
🚀 MistTrack is now live on @WorkBuddy_AI ! You can now ask WorkBuddy to run on-chain risk checks with MistTrack — risk scores, entity labels, transaction tracing, and counterparty analysis. Just bring your own MistTrack API Key.✨ Find the MistTrack expert in WorkBuddy and start tracing.
5
2,258
MistTrack🕵️ retweeted
On Sept 9, OFAC and DOJ took joint action against Xinbi Guarantee and its supporting service network, restricting more than $52 million in crypto assets. Xinbi Guarantee is a Chinese-language online escrow marketplace connecting scam groups with merchants offering money laundering, scam-site development, and other illicit services. OFAC designated Xinbi Guarantee as a significant Transnational Criminal Organization (TCO), and also sanctioned supporting firms SafeW Technology and Anwen Technology. DOJ seized related Telegram channels and wallets, including ~$12M from 2 collection wallets. Treasury said the marketplace has processed over $24B in digital assets and fiat since around 2022. The case highlights the importance of tracking illicit fund flows across service networks. SlowMist @MistTrack_io will continue updating related risk labels to support on-chain monitoring and illicit fund analysis. Read more 👇 medium.com/@slowmist/u-s-ofa…
5
6
28
6,463
MistTrack🕵️ retweeted
THE BLOCK: Tether earlier today froze about $39.3 million in USDT across 10 Tron addresses linked to Xinbi Guarantee, a source with direct knowledge of the matter told The Block. Xinbi is a Chinese-language guarantee marketplace that emerged on Telegram around 2022. TRM Labs has described it as one of Southeast Asia's largest illicit crypto marketplaces, saying it has processed about $24.2 billion in transactions. MistTrack, an onchain tracing platform developed by SlowMist, first reported the USDT freeze.
15
14
75
16,693
Hours ago, Tether froze approximately 39,273,713 USDT across 10 TRON addresses linked to Xinbi Guarantee新币担保. Following its freeze of 汇旺担保Huione-linked funds, this appears to mark another crackdown on illicit Telegram-based escrow platforms. light.misttrack.io/address/U…
8
16
98
31,407
补充一点:高风险资金网络不会随着“汇旺担保”消失,而是会持续改名和迁移。 目前 MistTrack 已识别并标记数十种汇旺担保变种,包括土豆担保、七天担保、福利来担保、金贝担保、新币担保等;同时覆盖 @bcgame @Stake @rollbit @betfury_gaming GoFun娛樂城、優塔UTown等上百个博彩及体育投注平台的相关出入金地址与资金路径。 建议所有用户在向交易所充值前,先使用 MistTrack 检查自己的钱包与这些高风险平台是否存在直接或间接关联。我们提供免费的黑 U 检测工具 misttrack.io/aml_risks/ ,以及付费版深度 AML/KYT 筛查与资金追踪平台 dashboard.misttrack.io/
从高风险地址向 OKX 充值,可能触发更严格的反洗钱和风险审查。根据具体情况,审查可能持续 15 天甚至更久,账户部分功能以及资金也可能受到限制;对于确认涉及高风险或非法活动的账户,我们可能终止服务。 包括但不限于通过TG 群担保交易、汇旺及其变种等渠道获得的资金,都可能带来较高的资金来源风险。 请勿将 OKX 账户用于洗钱、诈骗、非法资金流转或其他违法活动。
6
13
91
33,149
联合国毒品和犯罪问题办公室(UNODC) 曾在报告中指出,东亚和东南亚的赌场、博彩中介与加密货币,已经成为地下银行、洗钱和网络诈骗基础设施的重要组成部分。一种典型洗钱模式是通过博彩交易制造资金来源的“合法外观”:犯罪资金先进入博彩账户,再通过少量下注、内部转移或其他交易行为形成记录,随后以所谓博彩收益的形式提取。
3
2,848
🚀MistTrack & SlowMist KYT Partner Program is officially launched! As stablecoin payments and digital asset businesses continue to grow, on-chain #AML, #KYT, and risk analysis are becoming increasingly important for organizations worldwide. 🌍 SlowMist is now looking for global partners with expertise and resources across #Web3, finance, payments, compliance, security, and local markets. Partner Benefits: 🔹 Exclusive customer discount codes 🔹 10% commission on @MistTrack_io subscriptions, based on the customer’s actual payment amount 🔹 20% commission on the contract value of SlowMist KYT institutional projects 🔹 Commission period of up to 3 years 🔹 Free trials, product materials, and technical support 🔹 Automatic order & commission tracking 🔹 Flexible settlement options Two products, different needs: Standardized, scalable promotion → MistTrack Institutional, customized projects → SlowMist KYT 📌 Apply now: dashboard.misttrack.io/affil… 🔎 Learn more: misttrack.io/partners.html?u… We welcome partners who understand local markets and customer needs to join us in bringing proven on-chain AML, KYT, and risk analysis capabilities to more customers worldwide.🙌 Read more:slowmist.medium.com/slowmist…
1
2,765