Data from XRP Scan reveals that the threat actor stole the tokens from Coins.ph before sending them out through OKX, WhiteBIT, OrbitBridge, SimpleSwap, ChangeNOW, and Fixed Float among others.