Chain-hopping and cross-chain bridges

LayeringCryptoModern

What is chain-hopping in crypto money laundering?

Chain-hopping is moving illicit cryptocurrency from one blockchain to another (bitcoin to Ethereum to Tron) through cross-chain bridges and swap services, often with no identity checks. Each hop lands the funds on a new ledger with new tooling, forcing investigators to re-establish the trail from scratch. It is the signature laundering method of North Korea's Lazarus Group, which used it to move the $1.5 billion Bybit theft.

As of August 2026: No arrests have been announced in the Bybit case, and no recovery beyond the early freezes and the eXch seizure. Attribution notices, sanctions designations, and seizure totals in this area change frequently.

What is chain-hopping?

Blockchain tracing has one quiet dependency: it works chain by chain. A bitcoin investigator follows bitcoin. An Ethereum tracer follows ether and its tokens. The tools, the address formats, the clustering heuristics: all of it is ledger-specific. Chain-hopping is the laundering technique built on that seam: move stolen value from one blockchain to another, then another, so that no single chain’s analytics ever see the whole journey.

The hops run through two kinds of infrastructure. Cross-chain bridges lock an asset on one chain and release equivalent value on another: legitimate plumbing that also happens to teleport funds between ledgers. Swap services exchange one crypto asset for another directly, and the ones that matter for laundering are the ones that ask no questions: no account, no identity check, coins in and different coins out. Between hops, launderers fan funds across hundreds or thousands of wallets, mix in peel chains, and convert into whatever asset moves fastest, increasingly the stablecoin rails described in stablecoins and OTC brokers.

Chain-hopping is layering at machine speed. Where a 1990s launderer needed weeks to push money through six jurisdictions, a hack crew can push value through three ledgers in an afternoon. It is the technique of choice for the most sophisticated actor in the space: North Korea’s Lazarus Group, whose thefts fund the regime and whose laundering playbook (bridge, swap, fan out, cash out) has been documented across a decade of incidents.

How does chain-hopping work?

  1. The theft lands. A hack or exploit delivers a large balance in one asset on one chain: say, half a million ETH. From the first minute, the attacker’s addresses are public knowledge and freezes are coming, so speed is everything.
  2. Fan out. The balance is split across hundreds or thousands of fresh wallets, so no single address holds enough to be worth an emergency intervention and automated tracing has to follow every branch.
  3. Hop. The funds move through bridges and no-KYC swap services into a different asset on a different chain, commonly toward native bitcoin, which has the deepest liquidity, or toward stablecoins for cash-out. Each hop resets the ledger, the address format, and the toolset a tracer needs.
  4. Repeat and layer. Hops are chained: ETH to BTC, BTC onward through further swaps, sometimes through mixers between chains. Freezable assets (stablecoins that issuers can blacklist) are avoided mid-route and used only at the edge.
  5. Cash out. The final hop reaches something spendable: over-the-counter brokers, guarantee marketplaces, or exchange accounts opened with stolen or rented identities.
How chain-hopping resets the trail at every ledger Stolen funds move from Bitcoin through a cross-chain bridge to Ethereum, through a no-KYC swap service to USDT on Tron, and out through an OTC broker to cash, with analytics forced to restart the trace on each new chain. stolen coins land bridged out new ledger, trail resets swapped, no ID asked third ledger, third toolset USDT to broker settled off-chain Hacker with stolen funds Bitcoin Cross-chain bridge Ethereum No-KYC swap service Tron (USDT) OTC broker Cash-out
Each hop is a new ledger, a new asset, and often a service that never asked who was swapping.

Why does chain-hopping work?

Every hop imposes a cost on the pursuer that the launderer doesn’t pay. Bridges and swap protocols are permissionless and instant; cross-chain tracing is neither. Analytics firms have to map each bridge’s internal mechanics to say with confidence that value which left chain A is the same value that arrived on chain B, and a court needs that confidence to be evidence-grade. Multiply that across thousands of wallets and three or four ledgers, and tracing a single theft becomes a project measured in weeks, against a laundering operation measured in days.

Hops also shed jurisdiction and cooperation. A bitcoin exchange can freeze a deposit from a flagged bitcoin address, but it has no view into what happened on Tron. A stablecoin issuer can blacklist its own token, but not the bitcoin the token was swapped into. Each hop crosses not just a technical boundary but a boundary between who can act, and the no-KYC swap services in the middle are chosen precisely because they act for no one. eXch kept processing Bybit funds after the FBI published the laundering addresses; that refusal was its business model.

The technique’s weakness is liquidity. A billion-dollar hop needs somewhere deep enough to absorb it, and only a handful of bridges and protocols qualify. That funnels the biggest launderers through a short list of venues that everyone (analysts, exchanges, and eventually police) is watching.

The Bybit hack: $1.5 billion in ten days

On February 21, 2025, attackers stole roughly $1.5 billion in ether (about 500,000 ETH) from the exchange Bybit, the largest crypto theft in history. The breach itself was a supply-chain compromise: a Safe{Wallet} developer machine was hacked, producing a malicious transaction that hijacked a routine cold-to-warm wallet transfer. Five days later the FBI publicly attributed the theft to TraderTraitor, North Korea’s Lazarus Group, and published 51 Ethereum addresses tied to the laundering.

The laundering was faster than the attribution. Within about ten days, analysts at Arkham, Elliptic, and TRM watched the entire 500,000 ETH move: fanned across thousands of wallets, then swapped, mostly into native bitcoin, through the cross-chain protocol THORChain, which processed over $5.5 billion in volume during that window. Roughly 86% of the haul became some 12,836 BTC spread across about 9,100 wallets. A major secondary conduit was eXch, a swap service that asked no identity questions and continued serving the funds after the FBI notice. Only about 3% of the stolen value was frozen in the weeks after the hack; Bybit absorbed the loss with emergency ETH purchases and made customers whole.

The pattern had a rehearsal. In March 2022, Lazarus drained the Ronin Bridge (the infrastructure behind the game Axie Infinity) of 173,600 ETH and 25.5 million USDC, worth about $625 million when discovered. OFAC formally tied the attacker’s address to Lazarus on April 14, 2022, and the funds ran the same course: fan-out, hops toward bitcoin, mixers in between. But Ronin also produced the counterexample: in September 2022, Chainalysis and law enforcement seized more than $30 million of the stolen funds: the first-ever seizure of crypto stolen by North Korean hackers, and proof that hops can be unwound after the fact.

The stakes kept rising. Chainalysis counted $1.7 billion stolen by DPRK-linked hackers in 2022, $1.34 billion in 2024, and a record $2.02 billion in 2025 (roughly 60% of everything stolen in crypto that year, with Bybit the dominant component) for a cumulative haul of about $6.75 billion.

How chain-hopping gets caught

The answer so far is: partially, slowly, and mostly at the edges.

Cross-chain analytics. The tracing industry has followed the launderers across the seams. Chainalysis, Elliptic, and TRM now trace value through major bridges and swap protocols as a product feature, and their attributions feed the freezes, seizures, and sanctions that follow. The Ronin seizure showed the ceiling rising: $30 million recovered from an adversary with state-level operational security.

Choking the venues. When tracing lags, enforcement targets the infrastructure. The German BKA’s April 2025 seizure of eXch (€34 million in crypto and 8 TB of records from a service that had laundered an estimated $1.9 billion) removed a major hop and converted the service’s “no logs” promise into an evidence trove. OFAC designations of swap services and bridge-linked addresses make every subsequent touch a sanctions violation, which is how banks and exchanges get pulled into blocking flows they cannot independently trace.

The cash-out chokepoint. However many ledgers the money crosses, it must eventually become something spendable, and the detection machinery waits there: exchanges screening deposits against designated-address lists many hops deep, stablecoin issuers freezing at the moment of conversion, OTC brokers themselves being sanctioned.

Patience. Attribution now outlives the sprint. No one has been arrested for Bybit, but the FBI’s addresses, the seized eXch records, and years of accumulated tracing mean the bitcoin sitting in those 9,100 wallets is marked indefinitely. As the Bitfinex case proved (the Bitfinex hack coins were seized six years after the theft, through every hop and mixer in the playbook), a trail that costs too much to follow today may simply be followed tomorrow.

Frequently asked questions

What is a cross-chain bridge?

A bridge is a protocol that lets value move between blockchains, typically by locking an asset on one chain and issuing an equivalent token on another, or by matching swappers on both sides. Bridges exist for legitimate reasons; they become laundering tools when they let stolen value change ledgers faster than investigators and exchanges can follow it. Bridges have also been targets themselves: the Ronin Bridge lost roughly $625 million to Lazarus in 2022.

Does hopping between blockchains actually defeat tracing?

Not permanently. Cross-chain analytics from firms like Chainalysis, Elliptic, and TRM Labs now follow value across major bridges and swap protocols. What hopping buys is time and cost: each hop forces a new tracing effort with different tools, and against a ten-day laundering sprint like Bybit's, time is usually enough to reach a cash-out point before freezes catch up.

Was any of the Bybit money recovered?

Very little. Bybit's own March 2025 accounting put frozen funds at roughly 3% of the theft, with perhaps $40–65 million potentially recoverable through exchange cooperation. The exchange covered the loss itself and customers were made whole, but as of August 2026 there have been no arrests and no large clawback beyond the early freezes and the eXch seizure.

What happened to eXch?

eXch was a swap service that asked no identity questions and kept operating even after the FBI publicly listed the Bybit laundering addresses. German BKA and Frankfurt prosecutors seized its infrastructure on April 30, 2025, recovering €34 million in crypto and 8 terabytes of data: evidence that now works against everyone who assumed the service kept no records.

Cases that used this technique

  • Lazarus Group · North Korea's state hackers have stolen roughly US$6.75 billion in cryptocurrency and launder it at a speed no other criminal group matches.
  • The Bitfinex hack laundering · A married couple spent five years laundering 119,754 bitcoin stolen from the Bitfinex exchange, and the blockchain recorded every move.

Related techniques

  • Mixers, tumblers, and CoinJoin · Services that pool many users' coins and pay out equivalent amounts from the pool, breaking the on-chain link between where crypto came from and where it went.
  • Stablecoins and OTC brokers · Moving illicit value through dollar-pegged stablecoins (above all USDT on Tron) and converting it to cash through over-the-counter brokers and guarantee marketplaces with little or no KYC.
  • Hawala and informal value transfer · Moving value across borders through trusted brokers who pay out locally and settle with each other later: no money actually crosses, and no transaction record exists.

Glossary

Sources

  1. North Korea Responsible for $1.5 Billion Bybit Hack (PSA250226) (FBI Internet Crime Complaint Center, February 26, 2025).
  2. Lazarus Group laundered Bybit hack funds via THORChain (BeInCrypto (citing Arkham Intelligence), March 2025).
  3. Germany takes down eXch cryptocurrency exchange, seizes servers (BleepingComputer, May 2025).
  4. US officials tie North Korean hacker group Lazarus to $625M Axie/Ronin exploit (CoinDesk, April 14, 2022).
  5. Axie Infinity Ronin Bridge DPRK hack seizure: more than $30 million recovered (Chainalysis, September 2022).
  6. 2026 Crypto Crime Report excerpt: North Korea stole a record $2.02 billion in 2025 (Chainalysis, December 2025).