Due to payments to users from previously laundered funds and the dilution of assets, tracking specific transactions makes sense only before the funds enter the bot cluster. Further analytical work is carried out only with impersonal tools included in the ML-bot cluster.
Our investigation team traced the path of funds out of the cluster ML-bot and determined that most of the assets were transferred to RenBTC bridge.
To find the connections between the source transactions to the addresses of the RenBTC project and the subsequent converted assets in the form of RenBTC tokens, the analytical tool Drawbridge from MatchSystems was used.
The principle of operation of Drawbridge is reduced to a comparison of the combination of factors of the source assets and their analogue after passing through the RenBTC bridge.
As a result of the analysis of the ML-bot cluster, a scheme of its work was revealed, described in the diagram below.