This website uses cookies
We use cookies to personalise content and ads, to provide social media features and to analyse our traffic. We also share information about your use of our site with our social media, advertising and analytics partners who may combine it with other information that you’ve provided to them or that they’ve collected from your use of their services.
Consent Selection
Details
  • Necessary cookies help make a website usable by enabling basic functions like page navigation and access to secure areas of the website. The website cannot function properly without these cookies.
  • Preference cookies enable a website to remember information that changes the way the website behaves or looks, like your preferred language or the region that you are in.
    • We do not use cookies of this type.

  • Statistic cookies help website owners to understand how visitors interact with websites by collecting and reporting information anonymously.
    • We do not use cookies of this type.

  • Marketing cookies are used to track visitors across websites. The intention is to display ads that are relevant and engaging for the individual user and thereby more valuable for publishers and third party advertisers.
    • We do not use cookies of this type.

  • Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    • __emg_sidPending
      Maximum Storage Duration: 1 dayType: HTTP Cookie
      __emg_vidPending
      Maximum Storage Duration: 1 yearType: HTTP Cookie
      nl-read-countPending
      Maximum Storage Duration: PersistentType: HTML Local Storage
Cookie declaration last updated on 8/12/26 by Cookiebot
[#IABV2_TITLE#]
[#IABV2_BODY_INTRO#]
[#IABV2_BODY_LEGITIMATE_INTEREST_INTRO#]
[#IABV2_BODY_PREFERENCE_INTRO#]
[#IABV2_BODY_PURPOSES_INTRO#]
[#IABV2_BODY_PURPOSES#]
[#IABV2_BODY_FEATURES_INTRO#]
[#IABV2_BODY_FEATURES#]
[#IABV2_BODY_PARTNERS_INTRO#]
[#IABV2_BODY_PARTNERS#]
About
Cookies are small text files that can be used by websites to make a user's experience more efficient.

The law states that we can store cookies on your device if they are strictly necessary for the operation of this site. For all other types of cookies we need your permission.

This site uses different types of cookies. Some cookies are placed by third party services that appear on our pages.

You can at any time change or withdraw your consent from the Cookie Declaration on our website.

Learn more about who we are, how you can contact us and how we process personal data in our Privacy Policy.

Please state your consent ID and date when you contact us regarding your consent.
NewsLayer.com
NewsLayer PulseLIVEBTC$63,365-0.08%ETH$1,885+0.41%SOL$76.18+0.82%XRP$1.01+0.34%DOGE$0.0701+0.81%ADA$0.182-0.17%Total Cap$2.28T-0.09%Layer Index45 Neutral
BreakingExternal ReportingPublicado há 4 dias

Where Stolen Crypto Really Goes: Inside the 45-Day Laundering Machine

The article examines how stolen cryptocurrency is often moved through a rapid, multi-step laundering process that can unfold in roughly 45 days. It outlines the use of swaps, mixers, bridges, exchanges and cash-out routes to obscure…

Where Stolen Crypto Really Goes: Inside the 45-Day Laundering Machine
Source Bitcoin News 4 min de leitura
Image via Bitcoin News
Traduzindo…

Pontos-Chave

  • Stolen crypto is commonly dispersed quickly across multiple wallets and blockchain networks.
  • Launderers may use mixers, cross-chain bridges, decentralized platforms and intermediaries to mask fund origins.
  • The speed and complexity of these movements can make tracing, freezing and recovering assets difficult for victims and investigators.

Market Context

Bitcoin

BTC

$63,365

-0.08% 24h

Layer Index

45

↑ 10 pts in 24h

Key Takeaways

  • Chainalysis logged $3.4B stolen in 2025, with Bybit’s $1.5B hack alone accounting for 44% of that total.
  • H1 2026 set a record 212 incidents per Blockaid, with Lazarus-linked crews behind about 55% of these losses.
  • KelpDAO’s $293M April exploit was 2026’s largest single hit.

Six Years, More Than $16 Billion Gone

Crypto theft is no longer a phase that the digital asset industry is slowly getting out of but an industry unto itself. To this point, over the past half a decade alone, onchain sleuths have counted ballooning stolen totals ($3.7 billion in 2022, $1.7 billion in 2023, $2.2 billion in 2024, and $3.4 billion in 2025), figures that have shown no signs of stopping.

In fact, it bears mentioning that nearly half of last year’s total came from a single event, i.e. the February 2025 Bybit hack, in which attackers compromised the exchange’s cold-wallet signing process and walked away with $1.5 billion (making it the largest crypto theft in history).

The first half of this year was eerily similar, adding roughly $1.1 billion across a record 212 incidents, per security firm Blockaid. The largest single hit was the April 19 exploit of restaking protocol KelpDAO (at $293 million), and TRM Labs counted 207 incidents over these six months, more than double the same period a year earlier.

The 45-Day Playbook

What typically happens after the aforementioned thefts has become almost like a script at this point, with researchers describing a distinctive laundering cycle that runs roughly 45 days in three waves.

During days zero through five, speed matters most and the stolen tokens are typically swapped through decentralized finance (DeFi) protocols (activity spikes as much as 370%) and pushed into mixing services, which pool and shuffle coins to break the link between source and destination. During days six through ten, the funds hop chains via cross-chain bridges and flow through exchanges with limited know-your-customer (KYC) checks.

Then, from roughly day 20 to day 45, the coins are cashed out in small tranches (typically under $500,000 to stay beneath reporting thresholds) through no-KYC venues, instant exchangers, and Chinese-language over-the-counter (OTC) networks and guarantee services such as the sanctioned Huione marketplace.

Consequently, by the end of the cycle, the money has crossed through so many chains, mixers and jurisdictions that even though attribution remains possible (since blockchains never forget), recovery rarely is. For perspective’s sake, less than 5% of Bybit’s stolen funds were ever recovered, even though the exchange had some of the most prolific white hat personnel on their side.

2026: More Hacks, Smaller Hauls

This year, attackers have widened their targets because, alongside protocol exploits like KelpDAO’s, April alone set a monthly record with $641.67 million stolen. Lazarus-linked North Korean crews were behind about 55% of first-half losses, and CertiK’s count, which includes phishing and personal-wallet drains, puts the period’s damage at $1.32 billion across 344 incidents.

Most recently, the Coldcard hardware-wallet exploit showed how the playbook is adapting to bitcoin as well. After draining roughly $116 million from weak-seed wallets, the attacker began consolidating coins while onlookers watched every hop. In light of the incident, bitcoin’s core USPs, ala transparency and irreversibility, became double-edged swords almost overnight because even though everyone could see the stolen coins move, no one could move them back.

Why Recovery Almost Never Happens

When all of these attacks are going down, the one lever that has time and again worked reliably is the centralized stablecoin freeze. Tether and Circle can blacklist addresses at the contract level, instantly stranding any USDT or USDC that thieves are still holding, which is precisely why sophisticated attackers swap stolen stablecoins into ether or bitcoin within minutes of a breach, accepting price risk to escape the freeze radius.

It’s a revealing asymmetry, i.e. the most censorship-resistant assets are the easiest to launder, and the most freezable ones are the easiest to recover. Every laundering playbook is ultimately a race to convert the catchable into the uncatchable before anyone with a pause button notices.

The uncomfortable math of crypto theft is that prevention is nearly the whole game. Exchanges and analytics firms can freeze funds that touch compliant platforms, which is exactly why launderers front-load DeFi and mixers, where no one can freeze anything.

Sanctions on mixers and services like Huione raise costs but merely push flows to successors rather than stopping them. And the 45-day clock means that by the time cross-border legal process is even underway, the coins have usually finished their journey.

For users and platforms, the lesson is that, once stolen, the overwhelming majority of their funds are never coming back. Furthermore, the attackers’ cycle is faster than compliance, and every year that “crypto theft is declining” appears in a headline, the next billion-dollar counterexample is already in motion. The blockchain records everything and returns nothing.

Follow the Story

  1. Aug 9Where Stolen Crypto Really Goes: Inside the 45-Day Laundering Machine
  2. Aug 13KULR Technology Group (NYSE: KULR) swings to Q2 2026 loss amid bitcoin hit
  3. Aug 13Bitcoin Mining Stocks Surge This Year on AI Infrastructure Pivot
  4. Aug 13Bitcoin miner stocks rally on AI and HPC infras...

Attribution

Originally reported by Bitcoin News

Última Hora

Não perca nenhuma notícia de última hora

As grandes notícias chegam rápido — receba primeiro no X e no Telegram.

Get stories like this, daily.

Daily crypto + regulation intelligence, straight to your inbox. Free.

Notícias Relacionadas