EntryCrypto

How stolen crypto is laundered, and why it matters to you

10 min read · Updated

Peel chains, destination tags, THORChain and round-lot parking: how the Bitget and Bybit proceeds were moved, what can be frozen, and why it matters to ordinary holders.

Key facts

  • Large thefts follow a fixed sequence: convert freezable assets (USDT, USDC, tokenized gold) into unfreezable ones (ETH, XRP, BTC) within minutes, park the proceeds in round lots, wait, then move them through peel chains into exchange deposit accounts or cross-chain swap services.
  • Stablecoin issuers can blacklist addresses; nobody can freeze native ETH, BTC or XRP. The XRP Ledger's freeze feature applies only to issued tokens through trust lines.
  • A peel chain shaves small amounts off a large balance through throwaway accounts; the Bitget attacker used about 25 distribution accounts, a five-account hub and four exit accounts to move 60 million XRP into four Binance customer accounts in three days.
  • On the XRP Ledger a deposit to an exchange is a payment to the exchange's shared hot wallet plus a destination tag identifying the customer account, so tags are the first point at which a launderer can be identified.
  • THORChain is the dominant route for turning stolen ETH into BTC: about 85 percent of the Bybit proceeds and at least 19,000 ETH of the Bitget proceeds went through it, and the protocol has said it will not selectively refuse swaps.
  • For ordinary users the practical risks are receiving tainted coins from a swap service, having a deposit frozen by an exchange's compliance screening, and being targeted by address-poisoning bots that watch any large balance.

Everyone can watch a crypto theft happen. The transfers are public, the wallets get labeled within hours, and analysts post flow charts the same night. Yet most of the money still gets away. This guide explains how, using what we traced in the Bitget hack of September 2026, and what it means if you are not a thief but simply hold crypto.

Step one: escape the freezable assets

Not all crypto is equally stealable. Tokens with an issuer, above all USDT and USDC, carry a blacklist function in their contract: the issuer can freeze any address and, for USDT, destroy the balance. Tokenized gold, tokenized treasuries and most stablecoins work the same way. Native assets do not. Nobody can freeze ETH, BTC or XRP, because there is no issuer to do it. The XRP Ledger has a freeze feature, but it applies only to tokens issued through trust lines, never to XRP itself.

So the first move after any large theft is a race. The Bitget attacker received 34.75 million USDT at 18:58 UTC and had converted it, plus 12.85 million USDC and 3,000 XAUT, into 22,320 ETH by 19:30. Twenty-three minutes, through an EIP-7702 delegated account that batched swaps across Uniswap, UniswapX and 1inch. Tether and Circle never had a chance to act. By contrast the 103 million XRP could be left sitting for a day, because nothing could touch it.

Step two: park in round lots and wait

The proceeds then go into fresh wallets in round amounts and sit. The Bitget attacker parked ETH in eight wallets, six of exactly 10,000 ETH, and XRP in five accounts, four of exactly 20,000,000 XRP. This is the same pattern seen after Bybit in 2025. The waiting period serves two purposes: attention fades, and the operator can watch which addresses get labeled and which exchanges announce freezes before committing to a route.

Round lots also make the eventual movement harder to follow by amount. When one 10,000 ETH wallet feeds twelve intermediates in chunks of 100 to 1,000 ETH, and each intermediate makes a couple of hundred swaps, matching inputs to outputs becomes a statistical exercise rather than a lookup.

Step three: the peel chain

A peel chain is the workhorse of laundering. A large balance is “peeled” in small transfers through a sequence of throwaway accounts, each created for the purpose and abandoned after one or two uses, until the amounts are small enough to blend into normal exchange traffic.

The Bitget XRP route is a textbook example, and we could watch it operate in real time:

  1. A parking wallet released 146,000 XRP roughly every two hours to a hop account created minutes earlier.
  2. The hop passed it, minus a few hundred XRP, to a second hop, then a third.
  3. The third hop paid into one of five hub accounts that had been set up on September 17 to 20, before the hack.
  4. The hub paid four exit accounts in lots of 2,000 to 11,000 XRP.
  5. Each exit deposited into an exchange within about a minute of receiving funds.

Once the operator was satisfied the route worked, the parking wallets were emptied in bulk. Between September 25 and 28 the four exits made about 5,000 deposits totalling 59.9 million XRP into four Binance customer accounts. Nothing about the chain is technically sophisticated. Its strength is volume: thousands of ordinary-sized deposits from accounts with a history, into accounts that had been receiving deposits for a week before the hack.

Step four: the exit

There are three kinds of exit, and each has a different weakness.

Exchange deposit accounts. The oldest route and still the biggest. On the XRP Ledger the exchange’s hot wallet is shared and the customer is identified by a destination tag, so the tag is the point at which a launderer becomes a person with a KYC file. The Bitget exits used four tags at Binance and one at MEXC. Whether the exchange notices in time is the whole question; the tags kept accepting deposits for at least four days.

Cross-chain swap protocols. THORChain lets anyone swap ETH for BTC without an account. About 85 percent of the Bybit proceeds went through it in 2025, and at least 19,000 ETH of the Bitget proceeds did within a week. Bitget asked THORChain to refuse the attacker’s addresses; THORChain replied that its only emergency tool is a network-wide halt, not a selective freeze. The output is bitcoin in fresh wallets, which then goes through its own peel chain.

Instant-swap services. No-KYC swappers such as FixedFloat, ChangeNOW or eXch take one asset and pay out another, with the memo or destination tag carrying the order id. They are convenient for small amounts and for testing; the Bitget attacker sent 100, 500 and 1,000 XRP test orders to FixedFloat before choosing the exchange route. Several have been shut down or sanctioned; the survivors screen deposits with varying rigour.

What can actually be frozen

Asset or venueWho can freezeTrack record
USDT, USDC, XAUT and other issued tokensThe issuerReliable, but only if the coins sit still long enough
ETH, BTC, XRP, TRX and other native assetsNobodyNever
Exchange deposit accountsThe exchangeDepends on compliance screening; Binance froze $4.2 million of XRP from the 2024 Ripple theft
THORChain and other decentralised swap routesNobody, short of halting the networkRefused in both Bybit and Bitget cases
Bridges (CCTP, Stargate, LayerZero)The bridge operator for some, nobody for othersRarely used in practice

Recovery rates reflect this. Bybit got back a few percent through freezes and bounties. Bitget offered a 5 percent bounty on anything frozen and said “some assets” were frozen through partners, without numbers. Assume that once a theft is in native assets, the money is gone unless a human at an exchange stops it.

Why this matters if you are not a thief

Tainted coins. If you buy through an instant-swap service or a peer-to-peer trade, the coins you receive may have come out of a peel chain an hour earlier. Exchanges run deposit screening against known-bad addresses. A deposit that scores badly gets frozen while you explain, and explaining can take weeks. Prefer regulated on-ramps for size, and keep records.

Address poisoning. Laundering operations attract poisoning bots that spray zero-value transfers and counterfeit tokens from look-alike addresses at any wallet with a visible balance, hoping the operator copies the wrong address. The Bitget attacker’s wallets were hit within hours. Yours will be too if it holds anything worth stealing. Our scams guide covers the defence.

Reading the news. When a headline says “hacker moves $83 million,” check whether the funds reached an exit or just another parking wallet. Movement between attacker addresses is not laundering; a destination tag or a THORChain deposit is. The difference tells you whether recovery is still possible.

Choosing an exchange. An exchange that receives 5,000 deposits into four accounts from a known theft over three days without acting has a compliance problem, whatever its trust score. It is a fair question to ask any exchange what its deposit screening does with a flagged address, and how fast.

The short version

Stolen crypto is laundered in four moves: swap out of anything freezable within minutes, park in round lots, peel through throwaway accounts, and exit through exchange deposits or decentralised swaps. Every step is visible on-chain and none of it is preventable on-chain. The only interventions that work are an issuer freezing a token that has not yet been swapped, or an exchange freezing an account before it withdraws. Both depend on speed, which is why the first hour after a theft decides most of what follows.

Questions

Can stolen crypto be traced?

Almost always, and often in real time. Every transfer is public, exchange hot wallets are labeled, and destination tags identify customer accounts. Tracing is not the hard part; freezing is, because only issuers of tokens like USDT can block transfers, and only exchanges can freeze accounts.

Why do hackers swap into ETH or BTC first?

Because Tether, Circle and other issuers can blacklist addresses holding their tokens, sometimes within hours. Native assets have no issuer and no blacklist. The Bitget attacker converted about $60 million of stablecoins and tokenized gold into ETH within 23 minutes of receiving them.

Could I accidentally receive stolen coins?

Yes, through instant-swap services or peer-to-peer trades where the counterparty's funds came from a hack. Exchanges screen deposits against known-bad addresses, so a tainted deposit can be frozen while you prove where it came from. Prefer regulated on-ramps and keep records of large purchases.

More guides