h hoge.gg
Subscribe
BTC$67,432.18+2.34%ETH$3,521.44+1.08%SOL$178.62-0.62%BNB$612.30+0.41%XRP$0.6234-0.18%ADA$0.4521+3.12%DOGE$0.1623+1.86%AVAX$38.71-1.24%LINK$17.84+0.92%HOGE$0.00004120+4.21%
BTC$67,432.18+2.34%ETH$3,521.44+1.08%SOL$178.62-0.62%BNB$612.30+0.41%XRP$0.6234-0.18%ADA$0.4521+3.12%DOGE$0.1623+1.86%AVAX$38.71-1.24%LINK$17.84+0.92%HOGE$0.00004120+4.21%
● Security & Exploits

The Bridge Hack Money Trail: Where Stolen Crypto Goes in 2026

A bridge hack is really two events: the drain, then the laundering race that decides who gets paid back. We follow the money, from two-second launders to bounties and coalition rebuilds.

When a cross-chain bridge gets drained, the theft is usually the fastest part of the story. The attacker who emptied the XRP-to-tx bridge (the brand that now runs the former Coreum network) needed just 97 minutes and 94 back-to-back withdrawals to move roughly 199,916 XRP, about $200,000, without touching a single private key or the XRP Ledger itself, according to forensic accounts of the incident. The people who lost 116,500 rsETH, about $292 million, in April’s KelpDAO exploit watched it vanish in the time it takes to confirm a message. The drain is act one. What comes next, moving the money before it is frozen, traced, or clawed back, is the part that actually decides who wins.

2026 has been a strange year for bridge security. The engineering got better, the post-mortems got sharper, and yet the launderers got faster; in a twist that says everything about where the risk now sits, the bridges themselves became the single most popular tool for washing stolen crypto. This is an analysis of the money trail: the five acts of a modern bridge hack, why speed became the attacker’s main weapon, how bridges ate the mixers, and the small set of recovery mechanisms that decide whether victims ever see their funds again.

The drain is the easy part

Bridges hold pooled value, and that is the whole problem. A bridge locks assets on one chain and issues a wrapped claim on another, so the contract or multisig guarding the lock sits on a concentrated pile of collateral that grows with adoption. Break the guard and you get everything at once. That is why, as TRM Labs reported for the first half of 2026, infrastructure, key, and operational compromises accounted for only about 15% of incidents but roughly 76% of the value stolen. Most headline bridge losses were not clever Solidity bugs; they were stolen keys, forged proofs, and verification logic that trusted the wrong input.

The numbers have been ugly for years. Chainalysis counted roughly $2 billion stolen across 13 bridge hacks in 2022 alone, about 69% of all crypto stolen that year. 2026 has been lighter in aggregate but top-heavy: cross-chain protocols lost more than $328 million in the first four and a half months, with KelpDAO’s $292 million accounting for most of it.

Ben Fisch, CEO of Espresso Systems, gave the cleanest one-line diagnosis after the KelpDAO exploit. ‘The bridge worked as designed,’ he told CoinDesk. ‘It just believed the wrong information.’ Most bridges, he added, do not fully verify what happened on another chain; they rely on a smaller system to report it. Vitalik Buterin made the structural version of the argument back in 2022, warning of fundamental limits to the security of bridges that hop across multiple zones of sovereignty. The multi-chain world arrived anyway, and with it a permanent supply of honeypots.

An exploit post-mortem tells you how the guard failed. It rarely tells you where the money went. For that, you have to follow it.

Bridge (year)Approx. lossHow the guard failedWhere the money ended up
Ronin (2022)~$625M5 of 9 validator keys, spear-phishingUsers reimbursed via a Binance-led $150M raise plus balance sheet
Poly Network (2021)>$610MContract privilege abuseAlmost all returned by the attacker
BNB Bridge (2022)~$566M mintedForged proofChain halted, ~$430M frozen on-chain
Wormhole (2022)~$325MForged signature bypassJump Crypto replaced all 120,000 ETH in about a day
KelpDAO (2026)~$292MCompromised RPC, single verifierRebuilt by the DeFi United coalition, no user losses
Nomad (2022)~$190MBlank trusted root, open free-for-all~$36M returned under a 10% bounty
Multichain (2023)~$130M+Operator collapseMostly gone, ~$63M USDC frozen
Harmony (2022)~$100M2 of 5 multisigLaundered via mixers, minimal recovery

A bridge hack has five acts

Once the guard is beaten, the attacker faces a problem closer to logistics than hacking. Hundreds of millions of dollars sit in a wallet the entire industry can watch in real time. Getting it somewhere spendable, before Circle blacklists the stablecoins, before exchanges freeze the deposit addresses, and before a white-hat negotiator talks the team into a bounty, is a race against the clock.

It helps to think of a modern bridge hack in five acts:

  • Exploit: the guard fails and the funds move to an attacker-controlled address.
  • Obscure: the funds are split, wrapped, or pushed through a mixer to break the obvious trail.
  • Distribute: the money hops across chains and assets, usually through bridges and swap services, to outrun single-chain analytics.
  • Cash out or freeze: the attacker races toward a spendable asset while defenders try to blacklist and freeze faster.
  • Recover or launder: either a backstop, coalition, or bounty makes users whole, or the funds are washed and the loss becomes permanent.

The rest of this analysis walks those acts in order, because that is where 2026’s real developments happened: not in the exploit code, but in the speed and the plumbing of everything after it.

Speed is the weapon

The most important change in bridge-hack economics over the past year is timing. In a 2026 laundering study, blockchain-analytics firm Global Ledger found that the fastest first movement of stolen funds in the second half of 2025 was two seconds, and that multistage laundering appeared in 99% of the 255 hacks it reviewed. In an earlier dataset covering the first half of 2025, the firm found that funds began moving before public disclosure in 68.1% of cases, moved on average about 75 times faster than the alerting systems meant to catch them, and in more than 30% of cases were fully laundered within a single day; the fastest complete laundering run took two minutes and 57 seconds.

Read those numbers next to how long a careful post-mortem takes to write and the problem is obvious. By the time a team has traced root cause, drafted an incident report, and coordinated with exchanges, the money has often already crossed three chains. The defensive tools, freezing, blacklisting, and negotiation, all depend on catching the funds before they disperse, and launderers have optimized specifically for the minutes when nobody is watching yet.

How bridges ate the mixers

Here is the irony that defines the year: the same cross-chain infrastructure that keeps getting hacked has become the preferred tool for laundering the proceeds. Global Ledger found that bridges handled about $2.01 billion in stolen funds in 2025, close to half of all traced illicit flows and more than three times the volume that went through mixers and privacy protocols combined. Analysts describe bridges being used roughly 4.4 times more often than mixers in recent incidents, chosen for their speed, deep liquidity, and lighter regulatory scrutiny.

The shift is recent. As late as 2024, mixers still processed roughly half of the funds from the 25 largest hacks, and bridges were secondary. The Bybit theft in early 2025 was the template for the reversal: of the roughly $1.5 billion stolen, analysts traced about 94.91% of the laundered funds moving through bridges. Cross-chain routing does something a single mixer cannot. It hands investigators a trail that stops at a chain boundary and forces them to pick it back up in a different ledger, a different explorer, sometimes a different analytics vendor. Every hop is a place to lose the thread.

Laundering channelRole around 2024Role in 2025-2026Why it shifted
Cross-chain bridgesSecondaryPrimary rail (~$2.01B, ~50% of stolen funds)Speed, liquidity, cross-chain blind spots
Mixers (e.g. Tornado Cash)~50% of top-25-hack fundsRebounded to the majority of cases (74.3% by late 2025)Legal cloud lifted after delisting
No-KYC coin-swap servicesNiche>$1.2B high-risk crypto launderedConnect-wallet, no identity checks, some support Monero
Centralized exchangesCash-out chokepointMain freeze battlegroundWhere KYC and blacklists finally bite

Chain-hopping and the coin-swap underground

Beyond bridges, a parallel service industry has grown up specifically to move dirty crypto across chains. Forensics firm Elliptic reported that a category of cross-chain coin-swap services has laundered more than $1.2 billion in high-risk and illicit crypto, with over $1.1 billion of it originating in Bitcoin. These services let a user connect a wallet and swap one asset for another across chains with no identity checks, and some support privacy coins such as Monero, which severs the trail entirely once funds arrive.

The newest off-ramps pair cross-chain intent systems with privacy assets. In the summer wave of 2026, the attacker who drained about $3.86 million from the Bitcoin layer-2 project B2 Network sold the loot for BNB and then routed it through NEAR Intents toward Zcash, a pattern investigators increasingly see as the successor to the old deposit-into-Tornado playbook. Global Ledger’s finding that 99% of 2025 hacks used multistage laundering captures the same reality: nobody dumps stolen funds into one mixer and waits anymore. They chain-hop, they split, they slow down deliberately after the first fast move, and they let time and complexity do the work a single privacy tool used to do alone.

Tornado Cash did not die

The mixers did not disappear, though; they came back. Global Ledger’s data shows Tornado Cash usage rebounding from about 42.9% to 74.3% of laundering cases by late 2025, a jump that tracked almost exactly with the lifting of its sanctions. The US Treasury’s Office of Foreign Assets Control had sanctioned Tornado Cash in August 2022, citing more than $7 billion laundered, including funds from the Ronin, Harmony, and Nomad bridge hacks specifically. For two years, compliant actors treated it as radioactive.

Then the legal ground shifted. In November 2024 the US Court of Appeals for the Fifth Circuit ruled that OFAC had exceeded its authority, because Tornado Cash’s immutable smart contracts are not property that any person can own or control once deployed. Treasury delisted the protocol in March 2025, removing more than 100 addresses from the sanctions list. The tool regulators had tried to erase was, within months, handling the majority of tracked laundering again. Code that no one controls is hard to secure and, as it turned out, just as hard to sanction.

The freeze race

Not every asset is so slippery. The one structural advantage defenders have is that a large share of stolen value sits in centralized stablecoins, and the issuers can freeze them. Circle can blacklist USDC; Tether can freeze USDT. When a bridge is drained, the clock that matters most is often the race between the launderer trying to swap into something unfreezable and the issuer trying to blacklist the address first.

The Wanchain case in July 2026 showed both the power and the limits of the freeze. After roughly 515 million NIGHT tokens were drained from its Cardano bridge, major exchanges blacklisted the attacker wallets, froze accounts, and suspended NIGHT deposits and withdrawals, and the team set a public bounty deadline. But a large share of the tokens had already been sold on Cardano decentralized exchanges before the freeze took hold, so the lockdown was only partial.

Older cases show how long a freeze can drag on. After the Multichain collapse in 2023, a New York court froze roughly $63 million of stolen USDC through Circle’s blacklist, and the matter was still winding through liquidation years later. The BNB Bridge attacker in 2022 minted around $566 million of BNB but got only a fraction off the chain: BNB Chain’s small validator set halted the entire network within hours, freezing an estimated $430 million in place. The uncomfortable lesson is that the fastest freezes come from the most centralized systems, the same centralization that security purists spend the rest of the year criticizing.

The white-hat bounty, crypto’s strangest negotiation

When freezing fails, the next tool is a negotiation that would look absurd in any other industry: the victim publicly offers the thief a cut to give the rest back. It works more often than it should, because stolen crypto is frequently easier to freeze than to spend, and a clean 10% with a promise of no lawsuit can beat the gamble of laundering the full amount past a watching industry.

The template is Poly Network in 2021. After more than $610 million was drained, the team addressed the attacker as ‘Mr. White Hat,’ offered a $500,000 bounty and, remarkably, a symbolic role as chief security advisor, and recovered essentially all of it within about two weeks. Nomad offered a 10% bounty in 2022 and clawed back around $36 million of its $190 million. The Verus bridge attacker returned about $8.5 million of an $11.58 million haul under a white-hat deal in 2026. And Wanchain gave its Cardano attacker until August 6, 2026 to keep 10% and return the rest with no civil claims, a deadline that passed without any public confirmation the funds came back.

The ritual has even been semi-formalized. The Security Alliance’s Safe Harbor framework proposes standard terms, a set response window and a bounty capped around 10% and $1 million, so a panicked team is not improvising the offer during the worst hour of its life. It is a strange equilibrium, but for many victims it is the fastest money they will ever see.

Who actually gets their money back

Step back from the individual cases and a pattern emerges: users are made whole only when someone with a balance sheet, or a coalition willing to act like one, chooses to eat the loss. The chain guarantees nothing. Recovery in 2026 falls into four rough archetypes.

ArchetypeExamplesMechanismUser outcome
Deep-pocket backstopWormhole, RoninA backer replaces the funds or raises capital to reimburseMade whole
White-hat bountyPoly Network, Nomad, VerusAttacker returns most funds for a cut plus legal immunityMostly or fully made whole
Coalition rebuildKelpDAO (DeFi United)Peers rebuild the backing over weeksMade whole, slowly
NothingMultichain, HarmonyNo backstop; funds laundered or frozen indefinitelyPermanent loss

The Wormhole case set the backstop standard: after the $325 million forged-signature exploit, Jump Crypto replaced all 120,000 ETH within about a day. Ronin, the largest crypto theft ever at roughly $625 million, was covered by a Binance-led $150 million raise plus Sky Mavis’s balance sheet. The KelpDAO recovery is the case the industry now points to as proof it can respond: after the $292 million rsETH exploit, a coalition branded DeFi United, including Aave and Mantle, rebuilt the rsETH backing over roughly five weeks, paid accrued staking rewards through, and passed no losses to users.

That restaked collateral is exactly the kind of layered, yield-bearing asset that gets bridged across chains and treated as collateral elsewhere, which is what makes an exploit contagious in the first place; if you are new to how it works, our guide to restaking yield and risk lays it out. Aave’s rsETH market absorbed bad debt that outlets pegged somewhere between $177 million and $190 million. Sergej Kunz, co-founder of 1inch, warned about precisely this dynamic: once bridged assets are accepted as legitimate collateral across the ecosystem, that is how contagion happens. At the other end sits Multichain, where there was no backstop, no coalition, and no negotiation, just a protocol that stopped existing after its operator was detained and the keys went with him. Its users are still waiting.

The North Korea factor

No account of the bridge-hack money trail is complete without the actor that dominates it. Chainalysis attributed roughly $2.02 billion in crypto theft to North Korea in 2025, a record, pushing the regime’s all-time haul past $6.75 billion and up 51% year over year; DPRK-linked actors were behind about 76% of all service-level compromises. TRM Labs’ first-half-2026 data tells the same story on a shorter clock, tying roughly two-thirds of the period’s stolen value to North Korea, including the Drift and KelpDAO incidents.

What sets state-backed laundering apart is industrial discipline. Andrew Fierman, head of national security intelligence at Chainalysis, said North Korea facilitates the laundering of their crypto heists with consistency and fluidity indicative of the use of AI, combining mixers, DeFi protocols, and bridges early in the process and leaning on Chinese-language brokers, with a typical cash-out window around 45 days. A ransomware crew or a lone exploiter feels cash-out pressure; a nation-state does not. It can afford to wait, to split funds across dozens of wallets, and to treat laundering as a repeatable pipeline rather than a panic.

Charles Hoskinson, the Cardano and IOG founder whose ecosystem token was hit in the Wanchain exploit, framed the attacker’s side of that automation trend bluntly. ‘All software is under this enormous assault’ from increasingly automated vulnerability discovery, he told CoinDesk, and being mostly secure is not enough: ‘that is like being 90% resistant to a deadly disease. If you are exposed to it enough, eventually you still catch the disease.’ The point cuts both ways. The same tooling that helps attackers find bridge bugs faster is helping them wash the proceeds faster, which is why even mature Bitcoin infrastructure now ships a steady stream of security disclosures, a trend we tracked in our look at Lightning Network’s 2026 bug wave.

Bybit is the case study for all of it. When about $1.5 billion was stolen from the exchange in early 2025, the vast majority moved through bridges, and Bybit eventually resorted to suing North Korea and the Lazarus Group in August 2026, winning a preliminary injunction that froze part of the funds. Litigation against a sanctioned state is a measure of how few options a victim has once the money is on the rails.

You cannot sanction code, but you can convict a coder

The Tornado Cash saga has become the template for how US enforcement now approaches laundering infrastructure, and it is a story of a strategy pivot. Sanctioning the protocol failed on appeal because, as the Fifth Circuit found, immutable code with no controller is not property anyone can be said to own. So the Department of Justice went after a person instead.

Roman Storm, a Tornado Cash co-founder, was convicted in August 2025 of conspiracy to operate an unlicensed money-transmitting business, though the jury deadlocked on the more serious money-laundering and sanctions-violation counts. The single count that stuck carries up to five years. Prosecutors moved to retry him on the deadlocked charges, and as of late August 2026 that retrial has been pushed to April 2027, with sentencing on the existing conviction still pending. The government’s theory, that a developer can be criminally liable for building tools criminals use, is now the central question hanging over open-source crypto development, and the SEC’s own posture toward the sector is being rewritten in parallel; our explainer on how the SEC swapped lawsuits for rules covers that shift.

The through-line is uncomfortable for anyone who wants clean answers. The same property that makes a bridge or a mixer hard to secure, that no one is fully in control once it is deployed, also makes it hard to switch off or sanction after the fact. Enforcement has drifted toward the humans at the edges: the developers who write the code, the operators who run the front ends, and the occasional launderer who gets extradited, as one Nomad suspect was.

Where the SEC fits, and where it does not

For a US user who loses money in a bridge hack, the practical recourse is thin. The stolen tokens may or may not be securities, a question the SEC under chair Paul Atkins has been answering increasingly in the negative; a joint SEC and CFTC interpretation in March 2026 held that most crypto assets are not securities. The bridge operator may be an offshore entity or an anonymous team. There is no deposit insurance, no chargeback, and no regulator whose job is to make a hacked bridge’s users whole. When money comes back, it comes back because a backstop, a coalition, or a bounty put it back, not because a rule required it.

That vacuum is exactly why the post-mortem-and-bounty ritual carries so much weight. In the absence of a regulator that can force restitution, an attacker’s fear of being traced, plus the credible offer of legal immunity for returning funds, is often the only enforcement that moves quickly enough to matter. US policy is slowly filling parts of the gap through DOJ asset seizures, OFAC’s evolving stance, and a broader push to write clear crypto rules rather than litigate them case by case. But the securities framework was built for issuers and exchanges, not for autonomous cross-chain infrastructure that holds billions and answers to no one.

Closing the exits

The industry’s answer has been to attack the money trail from both ends: shrink the honeypot so there is less to steal, and stack the verification so a single failure cannot authorize a drain. Four changes stand out.

First, native issuance is replacing wrapped IOUs. Circle’s Cross-Chain Transfer Protocol burns USDC on the source chain and mints it natively on the destination, so there is no pooled reserve sitting in a bridge contract to drain. Delete the honeypot and you delete the incentive.

Second, defense in depth has replaced single verifiers. After KelpDAO’s exploit traced back to a setup where one verifier was enough to approve a cross-chain message, messaging systems increasingly require a quorum of independent verifiers, an X-of-Y-of-N configuration, before a message is accepted, and Chainlink’s CCIP runs a separate Risk Management Network as an independent second check.

Third, the market repriced bridge security with its feet. After the KelpDAO hack and a run of others, roughly $4 billion in bridged assets migrated from LayerZero to Chainlink’s CCIP within weeks, and the tally kept climbing: when custodian BitGo moved more than $7 billion of wrapped Bitcoin to CCIP as its sole provider in August 2026, the running total of switched assets approached $15 billion. Each CCIP lane is secured by a network of independent node operators, each with its own economic stake in behaving honestly, the same validator-incentive logic that underpins staking yield elsewhere in crypto.

Fourth, zero-knowledge light clients are starting to replace trusted committees with math, letting a destination chain verify a source chain’s consensus directly rather than trusting a set of signers to report it honestly. That is where Fisch’s critique points: stop believing a smaller system and start verifying the source.

None of this closes every exit. Governance keys, social engineering, and the sheer consolidation of value onto a few messaging standards remain open problems, and every new bridge design is a new attack surface. But the combination of smaller honeypots, stacked verification, and faster freeze coordination has, for the first time, started to make the money trail a losing bet often enough to matter.

Frequently Asked Questions

Why do hackers use bridges to launder stolen crypto?

Bridges move value across blockchains in seconds, hold deep liquidity, and face lighter scrutiny than mixers or exchanges, and cross-chain routing breaks the trail for investigators who then have to pick funds back up on another ledger. Global Ledger found bridges handled about $2.01 billion in stolen funds in 2025, close to half of all traced illicit flows and more than three times what went through mixers.

How fast do stolen bridge funds get moved?

Very fast. Analysts have recorded first movements within two seconds of a hack, funds moving before the exploit is even disclosed in most cases, and full laundering completed within a day in more than 30% of incidents. Attackers optimize for the minutes before anyone is watching, which is why freezing and recovery so often fail.

Do victims of bridge hacks usually get their money back?

Only when someone chooses to cover the loss. Users are typically made whole through a deep-pocket backstop, a white-hat bounty that persuades the attacker to return most of the funds, or a coalition rebuild like the DeFi United effort after the KelpDAO hack. When none of those happen, as with Multichain, the loss is usually permanent.

Can stolen crypto be frozen?

Centralized stablecoins can be. Circle can blacklist USDC and Tether can freeze USDT, and exchanges can blacklist deposit addresses, so a large share of stolen value is freezable if defenders act fast enough. Funds swapped into privacy coins or routed through no-KYC coin-swap services are effectively gone.

Is using a mixer like Tornado Cash illegal in the US?

It is unsettled. The US Treasury sanctioned Tornado Cash in 2022, a court found in 2024 that it overstepped because the immutable code has no controller, and Treasury delisted it in 2025. Separately, co-founder Roman Storm was convicted in 2025 of running an unlicensed money-transmitting business, with a retrial on other charges set for 2027. Using such tools to launder criminal proceeds remains prosecutable even though the protocol itself is no longer sanctioned.

Anneke de Vries is HOGE Wire’s security desk editor.

Share 𝕏 Post Telegram