After the Hack: Halborn and Crypto’s Recovery Race in 2026
When a protocol is drained, prevention is over and a very different clock starts. Inside the incident-response machine Halborn helped build, and why most stolen crypto never comes home.
On April 18, 2026, the most expensive crypto theft of the year did not begin with a broken line of Solidity. It began with a single forged cross-chain message. Within a handful of blocks, roughly 116,500 rsETH, worth about $292 million, had drained out of the liquid restaking protocol KelpDAO through a poisoned cross-chain verifier and started scattering across networks. Reviewing the wreckage, auditor OpenZeppelin titled its own report bluntly, and its conclusion was even blunter: the contracts performed exactly as written. There was no bug to patch. There was only a clock, and it had already started ticking.
Most crypto security coverage stops at prevention: the audit, the pentest, the bug bounty. Yet every headline exploit has a second act that almost nobody watches, the frantic hours after the money moves, when a small and largely invisible industry tries to trace it, freeze it, negotiate for it, and, on a good day, claw some of it back. Miami-based Halborn sits close to the center of that second act. It is best known as an offensive-security firm and a smart-contract auditor, but it also runs incident response, writes the definitive post-mortems for many of the year’s biggest hacks, and, since 2023, plugs directly into the tracing-and-recovery machine through a partnership with blockchain analytics giant Chainalysis.
This is a field guide to what switches on after the breach: who runs it, which levers actually move money, and why, in 2026, getting the funds back remains the exception rather than the rule.
The Clock Starts When the Money Moves
Incident response in crypto compresses into a window that traditional cybersecurity would consider absurd. In a corporate breach, an attacker who exfiltrates data still has to find a buyer. In a crypto breach, the attacker already holds a bearer asset that settles in seconds and can be swapped, bridged, or mixed before the victim has finished reading the alert. The job of a responder is to win a race that started before they knew it was running.
Chainalysis, which sells a retainer-based Crypto Incident Response service, describes the stakes in mechanical terms. When stolen assets are still sitting on an exchange, speed is everything: if our investigators can work with those platforms to freeze the funds before they are moved off of the platform, the funds are much more likely to be recovered, the firm writes, sketching a scenario in which an attacker cycles stolen Ether through exchanges inside 30 minutes. Miss that window and the money is gone into a maze of self-custodied wallets no company can touch.
The response itself follows a rough sequence: detect and contain, scope the damage, trace the outflow, request freezes, attribute the attacker, disclose publicly, and only later write the post-mortem and patch. Each phase has a different owner, and the earliest phases matter most. The table below maps the first week of a typical nine-figure exploit.
| Window | What happens | Who acts |
|---|---|---|
| Minute 0 to 30 | Detection, containment, first trace; attacker begins moving funds | Protocol team, IR firm, on-chain sleuths |
| Hour 1 to 6 | Exchange and stablecoin freeze requests; public disclosure | Chainalysis, TRM, Tether, Circle, exchanges |
| Hour 6 to 48 | Attribution, whitehat bounty offer, legal threat | Investigators, protocol, counsel |
| Day 2 to 7 | Post-mortem, patch, governance and freeze votes | Auditors, validators, DAO |
| Week 2 and beyond | Seizure, sanctions, litigation, user reimbursement | FBI, DOJ, OFAC, protocol treasury, insurers |
Why an Auditor Shook Hands With a Surveillance Firm
On April 4, 2023, Halborn and Chainalysis announced a data-driven security partnership that split the security lifecycle cleanly in two. Halborn positioned itself as the expert on preventative security and smart-contract auditing; Chainalysis brought the investigative tooling to trace and recover funds once an incident had already happened. The idea was to give a Web3 company one relationship that covered both ends of a hack, the wall and the manhunt, rather than scrambling to find a forensics vendor at 3am with money already in flight.
The logic is that prevention and recovery are not separate disciplines but opposite ends of the same timeline. An auditor who has mapped a protocol’s contracts and infrastructure knows where the money lives and how it should move, which is exactly the knowledge a tracer needs when it starts moving the wrong way. A worked example landed later with cross-chain protocol ZetaChain, which retained both firms so that Halborn hardened the code while Chainalysis stood ready to trace any breach.
The recovery side has a track record worth stating plainly, because it is both impressive and small. Since its founding, Chainalysis says it has helped organizations recover $11 billion in stolen crypto, with roughly $50 million of that retrieved specifically through its Crypto Incident Response program since 2022, and it claims that 80% of retainer customers recover more than they spent on the service. Eleven billion dollars is a large number. Fifty million through the dedicated rapid-response product, against a backdrop of billions stolen every year, is a reminder of how narrow the recoverable slice really is.
Following the Money: How Tracing Actually Works
The strange gift of a public blockchain is that the crime scene and the evidence are the same object. Every hop the stolen funds take is recorded forever, in the open, for anyone with the tooling to read it. Forensics firms exploit this by clustering addresses that behave as if they share an owner, labeling known entities such as exchanges and mixers, and following the taint as it spreads. When funds hit an off-ramp that performs identity checks, tracing turns an anonymous string of hex into a subpoena target.
Three commercial players dominate: Chainalysis, TRM Labs, and Elliptic, each selling investigators and law enforcement a labeled map of the chain. But the loudest voice in attribution is often a pseudonymous independent. On-chain investigator ZachXBT has repeatedly published credible attributions while stolen funds were still moving, sometimes days before any government confirmation. Fellow researcher Nick Bax has described ZachXBT manually working through hundreds of transactions in a matter of hours, an output rate that matters because the trail goes cold fast.
Speed cuts both ways. The public mempool that searchers mine for value is also where whitehats sometimes race a thief, front-running a malicious transaction to rescue funds before the attacker can land it. The same transparency that lets a bot extract value lets a defender snatch it back. But once assets cross into a mixer, a cross-chain bridge, or a chain with weaker analytics coverage, even the best map starts to lose the thread. Tracing tells you where the money went; it does not, by itself, get it back.
That is why tracing is only the first of a handful of levers. The table below lays out the full set, because understanding which one applies to a given hack is most of the battle.
| Lever | How it works | Who controls it | Works when |
|---|---|---|---|
| On-chain tracing | Cluster and label addresses, follow funds to off-ramps | Chainalysis, TRM, Elliptic, ZachXBT | Always available; value depends on speed |
| Exchange freeze | A centralized exchange freezes deposited funds on request | Centralized exchanges | Funds reach a cooperating exchange |
| Stablecoin freeze | Issuer blacklists an address inside the token contract | Tether, Circle | Funds are held in USDT or USDC |
| Base-layer freeze | Validators or a security council quarantine the funds | Chain validators, multisig councils | Chain has few validators or a council |
| Whitehat bounty | Protocol offers the attacker a cut to return the rest | The victim protocol | Attacker is opportunistic and wants to exit |
| Law enforcement seizure | Warrant, sanctions, forfeiture at the off-ramp | FBI, DOJ, OFAC | A custodian is within reach of US law |
The Freeze Button Belongs to the Stablecoins
The single most effective recovery lever in crypto is also the least decentralized. Fiat-backed stablecoin issuers can freeze funds unilaterally, because a blacklist function is written into the token contract itself. Tether can flag an address and instantly render its USDT untransferable, and it can go further, destroying the frozen balance and reissuing an equivalent amount to a clean wallet controlled by law enforcement. No court order is technically required to hit the button, only a decision.
Tether uses this power at scale and increasingly in lockstep with Washington. On April 23, 2026, the company said it had supported the freezing of more than $344 million in USDT across two addresses in coordination with OFAC and US law enforcement. Chief executive Paolo Ardoino framed the freeze as policy, not favor: “USDT is not a safe haven for illicit activity. When credible links to sanctioned entities or criminal networks are identified, we act immediately and decisively.” For a US-focused victim, this is the practical face of recovery: not the SEC, but the Treasury’s OFAC sanctions list plus a private issuer’s smart-contract admin key.
The catch is that the freeze only bites while the loot is still denominated in a controllable stablecoin. Sophisticated attackers know this and swap into native ETH, into a chain’s own gas token, or into privacy tooling within minutes, precisely to escape the blacklist. The freeze button is devastating against fraud rings and opportunists who park value in USDT, and nearly useless against a state-sponsored crew that treats stablecoins as a hot potato. It is a kill switch that works best on the people least worth chasing.
Freezing at the Base Layer: Validators and Security Councils
On a handful of chains, the freeze can happen one layer deeper, at consensus itself. When the Sui-based DEX Cetus was drained of roughly $223 million in May 2025, the chain’s validators simply refused to process the attacker’s transactions, freezing about $162 million of the stolen funds in place. Days later the community ran an on-chain vote, and validators approved returning the frozen assets to users with 90.9% in favor, moving the money into a multisig held in trust pending repayment.
KelpDAO saw a similar rescue at the edges. As the April 2026 theft unfolded, an Arbitrum security council froze a large tranche of ETH and blocked a second attempted drain worth tens of millions, buying time the protocol used to migrate its cross-chain messaging to a hardened setup. The same validators who are paid to keep a chain honest can, on chains built this way, also be asked to hold it still.
This is the most philosophically awkward tool in the kit. Reversing or quarantining transactions is exactly the censorship that crypto was supposed to make impossible, and every base-layer freeze reignites a debate about whether a chain that can be paused is a chain at all. It also simply does not exist on Ethereum mainnet or Bitcoin, where no small group of validators can coordinate a freeze and no council holds an emergency key. Base-layer recovery is a feature of younger, more concentrated chains, and it comes bundled with the trust assumptions that concentration implies.
Paying the Thief: The Whitehat Bounty
When freezing fails and law enforcement is too slow, protocols try the oldest tool of all: negotiation. The template is now familiar. After perpetuals exchange GMX lost about $42 million to a reentrancy exploit on its V1 deployment in July 2025, the team wrote directly to the attacker on-chain, offering a deal and a deadline. GMX signed a message reading, in part, we want to offer a 10% white-hat bounty for the return of the exploited funds, and warned that legal action would follow in 48 hours if the money stayed put. It worked: the attacker returned the bulk of the haul, keeping roughly $5 million as the agreed bounty.
The whitehat bounty reframes a felony as a consulting fee, and it is popular because it is fast, needs no court, and often recovers far more than tracing ever would. It also raises an uncomfortable question about what, exactly, is being paid for. When security firm CertiK held about $3 million of Kraken’s funds during a 2024 dispute over a bug, the exchange’s then chief security officer Nick Percoco was scathing: this is not white-hat hacking, it is extortion. The line between a negotiated bounty and a paid ransom is drawn almost entirely by who ends up with the money and whether they ever asked for permission.
Crucially, the tactic only works against an attacker who wants an exit that does not end in prison. An opportunist who can be identified has every reason to take a clean 10% and walk. A state-sponsored operator with no fear of a US courtroom has none. That single distinction, whether the thief is negotiable, is what separates the hacks that end in a triumphant return tweet from the ones that end in a write-off.
Naming the Attacker: The Attribution Industry
Attribution is not a vanity exercise. Knowing who took the money determines whether any lever will work: a doxxable teenager might negotiate, a sanctioned entity triggers OFAC and unlocks stablecoin freezes, and a North Korean crew signals that recovery is effectively hopeless. In 2026 the answer is depressingly consistent. Chainalysis attributes at least $2.02 billion of 2025’s thefts to North Korea, a record 76% of all service compromises and part of a cumulative haul the firm now puts near $6.75 billion. TRM Labs found the same pattern holding into 2026, with DPRK-linked groups tied to roughly $643 million, about 66% of first-half losses, including the twin April strikes on Drift and KelpDAO that alone accounted for around $577 million.
The playbook behind those numbers is increasingly human rather than technical. The Bybit theft of about $1.5 billion in February 2025, the largest in the industry’s history, did not crack the exchange’s multisig; the FBI attributed it to a DPRK crew it tracks as TraderTraitor, and the attackers subverted the signing interface rather than the keys, a reminder that multisig is only as strong as the layer above the keys. Other 2026 incidents traced back to operational compromise of the same species that drained the lending protocol Radiant, where a handful of stolen keys did what no contract bug could.
Once the money is named as North Korean, the laundering is quick and well-rehearsed. Investigators including ZachXBT have documented Lazarus-linked funds moving through cross-chain swap protocols, obliging offshore exchanges, and Chinese over-the-counter desks, a layered pipeline built to outrun exactly the freeze requests described above. Attribution, in other words, often arrives right on time to confirm that nothing can be done.
Why Almost Nothing Comes Back
Add the levers up and the arithmetic is grim. Chainalysis’s mid-year read on 2025 found more than $2.17 billion stolen from services in the first half alone, already past the entirety of 2024, and by year-end the total exceeded $3.4 billion. Against those inflows, recovery is the exception: for the largest exchange hacks, the share of stolen value ever returned typically sits well under one percent, because the money is gone into self-custody or through a mixer before a single freeze request can land.
The core problem is a speed asymmetry that favors the attacker structurally. Settlement is final and near-instant, the ledger is global, and a competent crew can be three chains deep before a victim has confirmed the loss. The recovery industry’s honest pitch reflects this: the retainer model exists precisely because you cannot buy your way in after the fact. Chainalysis’s 80% success figure applies to customers who were already on retainer with a trace ready to fire in minute one. Cold-start victims, the ones searching for a forensics firm after the money moves, have usually already lost the only window that mattered.
This is why the mature security firms have quietly reframed their promise. Nobody serious sells guaranteed recovery. What they sell is preparedness, the runbook, the retainer, the pre-mapped infrastructure, and the relationships with exchanges and issuers that let a freeze request be taken seriously at 3am. Recovery, when it happens, is a byproduct of having done the boring work before the alarm, not a service you can summon after it.
The Costliest Hacks Never Touch the Code
Here is the finding that should reorganize how the industry thinks about security spending. TRM Labs recorded a record 207 separate hacks in the first half of 2026, yet total losses fell to $972 million, down 57% from the $2.3 billion of a year earlier. The composition matters more than the total: infrastructure and operational compromises were only about 15% of incidents but roughly 76% of the value, while 125 smart-contract exploits made up most of the incident count and a small fraction of the money.
Read that twice. The thing audits are designed to catch, the buggy contract, is the most common vector and the least costly one. The thing that actually empties the treasury, a compromised key, a poisoned signing UI, a social-engineered developer, mostly lives outside an auditor’s scope. It is the same lesson the year’s marquee incidents keep teaching, and it is why an audit badge and a recovery plan are answers to different questions. Cetus was reviewed by multiple firms before its overflow bug slipped through; Balancer had been audited more than ten times before a rounding error cost it around $129 million in November 2025. The audit is necessary and nowhere near sufficient, and the aftermath machine exists to handle everything the badge could never see.
The table below tallies the recent flagship exploits against the only metric that matters to a victim: how much came home.
| Incident | Date | Loss | Attributed to | What came back |
|---|---|---|---|---|
| Bybit | Feb 2025 | ~$1.5B | DPRK (TraderTraitor) | Small fraction frozen; Bybit covered users |
| Cetus | May 2025 | ~$223M | Unattributed | $162M frozen by validators, returned by vote |
| GMX V1 | Jul 2025 | ~$42M | Opportunistic | Most returned for a ~$5M bounty |
| Balancer | Nov 2025 | ~$129M | Unattributed | Minimal |
| Drift | Apr 2026 | ~$285M | DPRK | Minimal |
| KelpDAO | Apr 2026 | ~$292M | DPRK (Lazarus) | Second leg blocked; large ETH tranche frozen |
| Humanity Protocol | Jun 2026 | ~$36M | Suspected insider | Under investigation |
When Recovery Goes Wrong
Even the freezes that work create a new problem: who owns the frozen money, and who decides? Once assets are blacklisted or quarantined they sit in a legal limbo, and that limbo attracts opportunists of its own. ZachXBT publicly accused US law firm Gerstein Harrow of filing what he called fraudulent claims over roughly $71 million of frozen assets linked to North Korea’s Lazarus Group, arguing the maneuver would siphon money away from the actual victims of the underlying hacks. Recovery, it turns out, has its own attack surface.
The freeze power itself is now being tested in court. Two Thai businessmen sued Tether over a roughly $42.4 million USDT freeze, alleging the company blacklisted their addresses on October 30, 2025, with the corresponding seizure order arriving 112 days later, in February 2026. Whatever the merits, the case cuts to the constitutional heart of the whole recovery model: a private issuer can immobilize funds on an informal request long before a warrant exists, which is exactly what makes stablecoin freezes so effective and exactly what makes them so contestable.
The tidiest answer anyone has found is the one Sui reached for with Cetus: move recovered funds into a multisig held in trust and let a transparent, voted process decide the payout, rather than leaving the money in a single company’s or firm’s discretion. It is slower and clumsier than a unilateral freeze, and it only works on a chain willing to hold a governance vote about it, but it at least puts the question of ownership somewhere other than a support ticket.
Who Actually Pays the Users Back
Recovery of the stolen assets and reimbursement of the victims are not the same event, and conflating them causes most of the public confusion after a hack. Funds can be gone forever while users are still made whole, if someone else eats the loss. Bybit, solvent and well-capitalized, pledged to cover its shortfall regardless of how much of the $1.5 billion it ever clawed back. Cetus stitched together a recovery from the validator-frozen $162 million, its own treasury, and an emergency loan from the Sui Foundation to reach full user repayment.
For everyone without a deep balance sheet, the backstop is meant to be insurance. On-chain coverage providers such as Sherlock run pools that pay protocols when an in-scope bug is exploited, and Nexus Mutual writes discretionary cover that has paid real claims. But the coverage market is thin relative to the sums at risk; a nine-figure hole is more than most pools can absorb, and cover is narrow, priced, and full of exclusions. Insurance smooths the small and medium disasters and largely bounces off the catastrophic ones.
The reimbursement problem also has a nasty way of spreading. Because much of the rsETH stolen from KelpDAO had already been recycled as collateral across lending markets, the hit rippled straight into the on-chain credit system well beyond Kelp itself, forcing an unrelated set of protocols to worry about bad debt they never signed up for. A modern exploit is rarely contained to its victim, which is one more reason the aftermath is a systemic concern and not a private one.
The Post-Mortem as Reputational Currency
If recovery is rare, why does a firm like Halborn invest so heavily in the aftermath at all? Because the post-mortem has become the most valuable marketing a security firm can produce. Halborn’s Explained series, which dissects the year’s biggest hacks from Balancer to KelpDAO to the Humanity Protocol theft in June 2026, is read across the industry as the definitive forensic account. Writing the credible autopsy signals competence far more persuasively than any sales deck, and it keeps a firm’s offensive engineers fluent in exactly the failure modes clients pay to avoid.
That reputation is now being pointed at institutions. Under chief executive Jacques Boschung, hired from the traditional cybersecurity world, Halborn has leaned into banks, custodians, and tokenized-asset issuers, packaging its offensive-security and incident-response pedigree for firms that answer to auditors and boards. The pitch to that audience is not that a breach is impossible but that, when it comes, the same team that wrote the industry’s post-mortems will be the one running yours.
The firm is also blunt that the frontier of the fight has moved to people. Halborn co-founder and chief technology officer Steven Walbroehl has warned that attackers now use AI for highly personalized, context-aware attacks that bypass traditional security awareness training, the same human-layer tradecraft behind Bybit and the DPRK operations. If the costliest hacks no longer touch the code, the most important post-mortems are increasingly about a person who clicked, not a function that reverted.
The Regulator’s Absent Hand
An American reader might reasonably ask where the government is in all this. The answer is that no US regulator mandates smart-contract audits, accredits crypto auditors, or runs a recovery fund. The SEC, under chair Paul Atkins, has spent 2026 reorienting around token classification through its Project Crypto agenda, a debate about which tokens are securities, not about code quality or clawbacks. Whatever comes of it, it will not put a freeze on a drained protocol.
The actual government muscle in recovery sits elsewhere. The FBI attributes attacks and issues alerts like the Bybit notice; the Department of Justice pursues seizure and forfeiture at off-ramps within its reach; and the Treasury’s OFAC provides the sanctions designations that give a Tether freeze its legal spine, as it did behind the $344 million action in April. These are law-enforcement and sanctions tools, slow and jurisdictional, not a market regulator’s rulebook.
Which leaves the industry where it has been for years, policing itself by reputation and improvising recovery from a handful of centralized chokepoints. The uncomfortable synthesis of 2026 is that the most reliable kill switch in decentralized finance is a private stablecoin issuer’s blacklist, backed by a sanctions list, executed by an admin key. Prevention still belongs to the auditors and red teams. But when prevention fails, and it will, the money comes back, if it comes back at all, through exactly the centralized institutions crypto was built to route around.
Frequently Asked Questions
Can stolen cryptocurrency actually be recovered?
Sometimes, but rarely, and it depends almost entirely on speed, on where the funds land, and on who took them. If stolen assets reach a cooperating exchange or stay in a freezable stablecoin like USDT, a fast trace can lead to a freeze and eventual return. If they are swapped into native tokens or run through mixers first, which sophisticated attackers do within minutes, recovery odds collapse. For the largest exchange hacks the share of value ever returned is typically well under one percent, which is why firms sell preparedness and retainers rather than guaranteed recovery.
What is Halborn’s role after a hack?
Halborn is primarily a preventative firm, an offensive-security team and smart-contract auditor, but it also runs incident response and writes widely cited forensic post-mortems of major exploits. Since April 2023 it has partnered with analytics firm Chainalysis, splitting the work so Halborn hardens the code and Chainalysis brings the tracing and fund-recovery tooling once an incident is already in motion. In practice Halborn helps a victim reconstruct what happened and contain the damage, while recovery itself depends on tracing, freezes, and law enforcement.
How do stablecoin issuers freeze stolen funds?
Issuers like Tether and Circle build a blacklist function directly into their token contracts, so they can flag an address and instantly make its USDT or USDC untransferable, and can even destroy the frozen balance and reissue clean tokens to law enforcement. Tether said it supported freezing more than $344 million in April 2026 in coordination with OFAC and US authorities. The limitation is that this only works while the loot is still held in that stablecoin; attackers who swap into native assets escape the freeze entirely.
Why can’t Ethereum just reverse a hack?
Ethereum mainnet and Bitcoin have no central operator and no small group that can coordinate to freeze or roll back transactions, which is the entire point of their design. A few younger, more concentrated chains can do it: Sui validators froze $162 million of the Cetus loot and voted to return it, and an Arbitrum security council froze funds during the KelpDAO attack. That power comes bundled with the trust and centralization tradeoffs that critics say make such a chain less censorship-resistant in the first place.
Who steals the most crypto, and does that money ever come back?
North Korea’s state-sponsored crews dominate. Chainalysis tied at least $2.02 billion of 2025’s thefts to the DPRK, and TRM Labs found DPRK-linked groups responsible for roughly two-thirds of first-half 2026 losses, including the Drift and KelpDAO attacks. That money is the least recoverable of all, because these operators cannot be negotiated with, do not fear US courts, and launder through cross-chain swaps and offshore desks built specifically to outrun freeze requests.
Anneke de Vries covers security and exploits for HOGE Wire.