How Investigators Follow Stolen Crypto

As of September 2026: No arrests for the Bybit theft have been reported in the sources reviewed. The 2026 Drift and KelpDAO figures and their North Korea attribution come from TRM Labs analysis, not a court finding or, in the sources reviewed, an FBI notice.

When a large crypto theft happens, the thief’s address is public within minutes. Then the race starts. The thief tries to turn one asset on one ledger into something spendable before anyone can act. Investigators try to follow the value across every hop. The Bybit theft of February 21, 2025, about US$1.5 billion in ether, is the clearest recent example of both sides, and it shows how chain hopping works from the investigator’s chair.

Step 1: Name the addresses

Bybit’s own wallets made the starting point obvious. Analytics firms such as TRM Labs set up a dedicated label for the exploiter’s wallets and watched them in real time. On February 26, the FBI attributed the theft to North Korea’s “TraderTraitor” actors, the cluster tied to the Lazarus Group, and published the Ethereum addresses it linked to the laundering. The notice asked exchanges, bridges, node operators and analytics firms to block transactions with or derived from those addresses.

That request is the first real tool. A published list turns every regulated VASP into a checkpoint. It is the same logic as an SDN listing, applied to wallets.

Step 2: Cluster, then follow the fan-out

The funds did not sit still. TRM described them moving through many intermediary wallets, then cross-chain bridges and decentralized exchanges, with conversion largely into bitcoin. The FBI said the assets were spread across thousands of addresses on multiple blockchains. Bybit’s CEO later put it at nearly 7,000 wallets holding about US$1 billion in bitcoin.

Tracers handle a fan-out by clustering: grouping addresses that behave as one operator, for example because they were funded by the same source, move in the same pattern, or consolidate into the same place. One label on the parent wallet then carries down to thousands of children. This is the core of blockchain analytics.

Step 3: Match the bridge deposit to the withdrawal

Here is where the hop happens. A bridge or swap protocol takes value in on one chain and pays out on another. The two sides are different ledgers, but each side is public. Analytics firms study how a given protocol records its transfers, so that a deposit event on chain A can be matched to a release on chain B by amount, timing and the protocol’s own event data. When that mapping is solid, the trail continues. When it is not, the tracer has a gap and must say so.

For Bybit, the crossing point that mattered was a cross-chain swap protocol that turned ether into bitcoin. Once the value is on a bitcoin address, tracers switch tools and start again: new clusters, new labels, same target.

Step 4: Watch the exits

Freezes happen at the edges. A stablecoin issuer can blacklist its own token. A centralized exchange can hold a deposit. Neither can touch native bitcoin sitting in a private wallet. So investigators watch where value is likely to touch a regulated service, and mixers and OTC brokers are the places where the trail usually gets harder.

The Ronin Bridge case shows the method working. After a March 2022 theft, Chainalysis described tracing the funds through intermediary wallets, a mixer, conversion to bitcoin and a second round of mixing, then to cash-out services. Tracing to those cash-out points, plus coordination with law enforcement and industry, led to a seizure of more than US$30 million, about 10% of the haul, announced in September 2022.

What Bybit’s trail actually yielded

Results were partial. On March 4, 2025, Bybit’s CEO said about 77% of the funds were still traceable, 20% had “gone dark”, and 3% (about US$42 million) had been frozen. Speed was the problem: TRM counted about US$160 million laundered within 48 hours and more than US$400 million by February 26.

The swap service eXch was one of the pieces investigators later pulled apart. German police (the BKA) and Frankfurt prosecutors seized the platform on April 30, 2025, securing about EUR 34 million in crypto. The BKA said the service required no registration or identity check. Press coverage of the announcement reported the BKA’s estimate that about US$1.9 billion had passed through it since it began, and that Bybit proceeds were suspected to be among the funds. The operators face suspicion of commercial money laundering. A seizure like this matters less for the money than for the data: the servers and records can help trace funds that once looked anonymous.

The honest limits

Follow-the-money works on public ledgers, but it is not fast.

  • Speed. Chainalysis’ analysis of 2025 North Korean laundering describes a cycle of about 45 days after a major theft, with the heaviest layering in the first five. Freezes must land in that window.
  • No one to call. A decentralized protocol has no compliance desk. Tracing tells you where value went; it cannot make a protocol reject a transfer.
  • Off-chain gaps. Chainalysis notes that OTC sales for cash are not visible on-chain. The trail can end at a broker’s door.
  • Attribution is not arrest. Naming a state actor produces sanctions and address lists. It rarely produces defendants.

Update: 2026

The pattern has repeated. TRM Labs reported that the April 2026 KelpDAO theft (about US$292 million) was tied to North Korea, that roughly US$175 million was converted to bitcoin mostly through THORChain, and that about US$75 million was frozen on Arbitrum by that network’s Security Council. TRM also linked the April 2026 Drift Protocol theft (US$285 million) to North Korean hackers, with funds bridged to Ethereum, swapped and left dormant. Those are TRM’s findings, and they show both sides of the contest: fast hops, and a freeze that worked because a party with authority could act in time.

What to take from it

For readers, the lesson is not how to hide value. It is where detection works. Public ledgers, bridge records, address labels and quick calls between victims, exchanges and police can pull real money back. See detection for how these tools fit into the wider system.

Related reading

Sources

  1. North Korea Responsible for $1.5 Billion Bybit Hack (FBI PSA250226) (FBI Internet Crime Complaint Center, February 26, 2025).
  2. The Bybit Hack: Following North Korea's Largest Exploit (TRM Labs, February 2025).
  3. Bybit CEO: 20% of $1.4B stolen funds 'gone dark' (Cointelegraph, March 4, 2025).
  4. Krypto-Swapping-Dienst eXch abgeschaltet (press release) (Bundeskriminalamt (BKA), May 9, 2025).
  5. Germany takes down eXch cryptocurrency exchange, seizes servers (BleepingComputer, May 2025).
  6. North Korean hackers: $30 million seized from the Ronin Bridge theft (Chainalysis, September 2022).
  7. 2025 crypto theft and DPRK laundering analysis (Chainalysis, 2026).
  8. North Korea Stole 76% of All Crypto Hack Value in 2026 With Just Two Attacks (TRM Labs, 2026).