Due to payments to users from previously laundered funds and the dilution of assets, tracking specific transactions makes sense only before the funds enter the bot cluster. Further analytical work is carried out only with impersonal tools included in the ML-bot cluster.
Our investigation team traced the path of funds out of the cluster ML-bot and determined that most of the assets were transferred to RenBTC bridge.
To find the connections between the source transactions to the addresses of the RenBTC project and the subsequent converted assets in the form of RenBTC tokens, the analytical tool Drawbridge from MatchSystems was used.
The principle of operation of Drawbridge is reduced to a comparison of the combination of factors of the source assets and their analogue after passing through the RenBTC bridge.
As a result of the analysis of the ML-bot cluster, a scheme of its work was revealed, described in the diagram below.
Concrete example: - Our funds: bc1q6efxz3q6w9983tqm7m6p3yhu59h062r6a53wc9;
- Transaction 0c04c2bcf32c56511bb020468fcb2a6e46ce010de293069c63afd4509697da7d to the address of ML-bot;
- One-time address of ML-bot: 1B1XnbaDUehX2B1hH77kBj9JFzW1g4Jn2P;
- Transaction 9eab1b7b609b7620cd7137804faad446a1ac630d4c4627d128c2b6dd3c598920 to the cluster of ML-bot;
- Recipient of assets in the cluster of ML-bot: 1H17AgGngwiUTnMjKvhzUxwzBLxphQMj88 (included in the cluster with root-address (18oxDVbE9BDNn1LLdy5CGAP7HUr4fGVFBT);
- One of many transactions of the cluster of ML-bot to RenBTC: 5c9a0d3cf7e4c8a51bd6560a5139c2ceab0f46c463981e0755ab544facea6d6a;
- RenBTC: 3LVVAj5cLjYRKsAWgSjn7pNKoDxT5XMa1L
- Matched by DrawBridge mint- transaction (BSC) with RenBTC tokens from RenBTC bridge: 0x4c512826228960 0cf3942345e4cc55446e1dce09e76f18f13 13f8eac44c2a28d;
- Matched by DrawBridge recipient of RenBTC tokens (BSC), address: 0x6e5f03731bc53debe3ad673ec9436053a500e22d;
- Matched by DrawBridge burn-transaction (BSC) with RenBTC tokens to RenBTC bridge: 0xed41e5941f0a46fac0ac032916a46abb951e24345b9e6cebb2e71b7bdbdb9400;
- RenBTC: 0x95de7b32e24b62c44a4c44521eff4493f1d1fe13
- Matched by DrawBridge transaction withdraw BTC from RenBTC: 36f5553753c68104f6be77de52518905e35096683865f742044ee9cada393504
- Matched by DrawBridge recipient of BTC: 3PHLr246vZ2GQRW2dAHE73Szm2wMShKiSG (in this case it is Kraken exchange deposit address).