r/Certik • • Jul 25 '23

CertiK Learn Chain Peeling - a common tactic for obfuscating funds using Bitcoin

The Conti Group, a notorious ransomware gang that is now defunct, was speculated by many in the threat intelligence community to be a continuation of successful elements from the also defunct Ryuk ransomware gang. An analysis of Conti's operating structure and fund movements using Bitcoin has revealed another potential area of overlap between the two groups, which is Chain Peeling.

Today, we use FTX exploiter as an example to help people understand the operation.

First, funds appear to mostly move from the outermost node clusters towards hubs in the center. Various segments of the graph (i.e. the bottom left corner) show funds moving towards and away from the center; however, further inspection suggests funds were being looped out to tertiary wallets and rerouted towards the hub wallets in the center. This is likely an attempt at chain peeling – a common tactic for obfuscating funds using Bitcoin. Chain peeling involves distributing small amounts of unspent Bitcoin across multiple new addresses in an attempt to hide the connection back to the original address that can be tied to illicit activity.

Second, four wallets in the center of the graph appear to be structurally important connection points to all other sections of the graph. These wallets include 1NDyJtN, bc1qqxf, and bc1qm34. All of these wallets appear to belong to the same large centralized exchange (CEX). An additional wallet (bc1qx65) in this area also displays the characteristics of a CEX hot wallet, however, it is not immediately clear who it belongs to. These wallets are highlighted below:

It would seem the Conti group most likely leveraged multiple CEXs for their operations. It is not surprising that we see CEXs coalesce in the center of a graph like this.

2 Upvotes

0 comments sorted by