Glassnode Tells Where Bitcoin Is Headed After the Asset’s Jump Above $85,000
Two addresses belonging to the same whale withdrew 5,965 ETH from Binance
Polymarket Gives Dems 62% Midterm Sweep Odds, CLARITY Act in Jeopardy
*US FEB. RETAIL SALES RISE 0.6% M/M; EST. +0.5%*US FEB. RETAIL SALES EX-AUTO RISE 0.5% M/M; EST.
Solana is Primed for a Massive 2027 as User Adoption Hits Rooftop Levels
HUGE: China pushes to establish a "National Blockchain Network".According to Xinhua, China...
Cardano Pushes .ada Internet Domain Ambitions as Whale Activity Hits 4-Month High
Relay to Discontinue Vaults Service, Users Must Withdraw Funds by End of 2026
Papertrade Hits $125M In Deposits As Trading Set To Begin In 1 Hour: Onchain ...
XRP Ledger Patches Bug That Could Have Created XRP From Nothing
French Committee Backs Stablecoin Swap Tax and Crypto Exit Tax, Then Rejects the Budget
Market Overview: BTC : $82741 ETH : $2494.55 BNB : $747.67 SOL : $109.64 Market Cap :Total :...
Bitcoin Price Rises Amid Declining Futures Open Interest
NEAR Treasury Company SVRN Acquires Infrastructure Platform FastNEAR
One Year After $19 Billion Crash, Crypto Faces a New Reality
Can AMZN Stock Break Above $280 as Wall Street Turns Bullish?
Collector_Crypt FLIPS fomo IN 24H REVENUE ...
Zhao Changpeng Supports Diverse Wallet Solutions for Cryptocurrency Security
StarkWare Considers Shift of Starknet to Layer 1 as Strategic Move
Bitcoin Price Clings to $82,800 as the Next Breakout Remains Elusive
Vitalik Buterin: Without AI, Ethereum's Lean Roadmap Might Have to Wait Until 2040Ethereum...
CZ Talks Wallet Security Again: Not Against Hardware Wallets, Different Products Suit Different Use Cases
Tron Launches Post-Quantum Cryptography on Test Network
Bitcoin Approaches Breakeven Threshold, Capital-Weighted Cost Basis of $80,500 in Focus
XRP Ledger Fixed Two Dangerous Bugs: One Could Disrupted XRP Issuance, and Other Could Brought Network to Halt
Bitcoin and Ether Liquidity Rebounds One Year After October 2025 Crash
Paxos Labs and Theo Launch Yield-Bearing Tokenized Commodities
One Year After the '1011 Crash', Crypto Market Risks Persist
One year after 10/10, bitcoin and ether liquidity have rebuilt, but other altcoins still face risks
Tokenized commodities look beyond gold as lending and oil open new markets
Next Week's Macro Outlook: Gold "Spinning in Place" with Direction Still Unclear? CPI Tests Fed's Pause Expectations
Bernstein Breaks Down AI Infrastructure Costs: Up to $39.5 Billion per Gigawatt
Hunter Biden’s $LAPTOP Post-Mortem: What Went Wrong With the Token Launch
South Korea's FSC responds to controversy over shareholding limits on virtual asset exchanges: strengthening regulatory responsibility, not targeting specific companies
Ledger investigates alleged $92.9 million crypto theft tied to hardware wallets sold by reseller ...
Wallet Associated with CryptoBilis Thefts Transfers 464 ETH to Tornado Cash
Morgan Stanley's total Bitcoin holdings rise to 10,639 BTC, worth about $880 million
UK Sanctions Cryptomus and TokenSpot Over Alleged Russia Evasion Links
Bitcoin's $19 billion wake-up call: One-year later, has crypto learned anything?
NEAR Rockets by 10% Daily, BTC Price Eyes $83K: Weekend Watch
Hong Kong SFC Releases Securities Industry Financial Review: Virtual Asset Trading Commission Income Down 13.5% Quarter-on-Quarter
HyperliquidX-BASED PERP EXCHANGE papertrade_xyz PRE-LAUNCH DEPOSITS SURPASS $100M...
China's Central Committee and State Council Advocate for National Blockchain Network
Strive Is Running Saylor’s Playbook and Has Raised Enough for 638 Bitcoin
Hardware wallet manufacturer Ledger issued an official statement addressing recent wallet exploits,...
CPC Central Committee and State Council: Build a National Blockchain Network and a Nationwide Integrated Computing Power Network
Claude AI Model Sent Fake Murder Report to US Police
700 $BTC (57,979,730 USD) transferred from #Antpool to #Binance...
Ledger: No signs that security infrastructure, systems, or services have been compromised
Papertrade Launches 1000x Perpetual Contracts with $85 Million in Deposits
Over the past year, the $USDT supply on #Tron increased by 18.67B $USDT to 94.25B $USDT, up...
Musk "advised against" by chip experts: Terafab project harder than launching Starship rocket
Aerodrome's AERO Token Surges 48% Ahead of Merger with Velodrome Finance
On-chain detective Specter questions Serpin's token issuance decisions: says low-liquidity launch and lack of follow-up damage credibility
Another unlucky guy!His old wallet had been safe for 8 years.But a month ago, after more than 4...
Whale transfers 10 million POL to Binance, facing a loss of nearly $400,000 if sold
717 $BTC (59,480,543 USD) transferred from unknown wallet to #Antpool...
Hong Kong to crack down on unlicensed payment platforms, taking appropriate enforcement action as needed
Arkham: Grayscale Ethereum Mini Trust ETF has accumulated over $100 million in ETH purchases over the past 20 days
Robinhood to explore launching stock tokens tied to actively managed ETFs on Robinhood Chain
Chainlink's CCIP Vault Adapters Pull Deposits From 80 Chains, No Bridge Needed
A Decade-Old XRP Ledger Bug Could Have Minted XRP Out of Thin Air
U.S. crypto ETFs record $1.29 billion in weekly outflows led by Bitcoin and Ether fundsRead...
Triple-A hacker moves 4,970 ETH to Tornado Cash, worth about $12.4 million
Crypto ETFs Lost over $1.2B in Week: Bitcoin Funds Saw Biggest Outflows
White House requires AI companies to mandatorily report and fix security incidents, previously a voluntary mechanism
XRP’s Nasdaq Moment Is Here: Evernorth Completes Merger
Inflation target of 2% may not stop the next Fed rate freeze
470,087 $SOL (51,661,039 USD) transferred from unknown wallet to Coinbase...
Stealing $1.5B in crypto is easy, cashing out is the trap
North Korean hackers stole around $1.5 billion from Bybit in February 2025. While the hack itself has been widely covered and analyzed, few have focused on what happened afterward and what became of the stolen funds.
To move all that money, hackers needed to rely on an entire network of people willing to handle stolen assets, creating a chain of relationships that someone prepared to spend enough money could infiltrate.
That's what ZachXBT, a pseudonymous blockchain investigator, did. He committed 349,700 USDC and accepted a 5% loss on each completed order while posing as a client of a Chinese laundering network.
He eventually obtained information that helped him trace more than $12 million in Bybit-linked funds and, according to his account, contributed to Tether freezing 442,000 USDT.
His investigation led him to a network he believes laundered more than $1 billion from crypto thefts linked to the North Korean Lazarus Group, including proceeds from the Bybit attack.
The implications of his investigations extend to a much larger market for criminal financial services that American authorities have spent the past two years trying to disrupt.
In September, the US Treasury sanctioned Xinbi Guarantee, a marketplace it said has processed more than $24 billion in digital assets and fiat currency through its platforms since 2022, and explicitly identified North Korean hackers among the illicit actors reported to have used its services.
Treasury also acknowledged that criminals tried to preserve their operations by moving from Huione to Xinbi after it was sanctioned, showing how removing one marketplace doesn't eliminate the relationships and demand that supported it in the first place.
Believe it or not, hacking an exchange and stealing funds is actually the easiest part of this crime. Converting stolen crypto into fiat or another form of real purchasing power is where it gets difficult.
To do that, hackers rely on payment services and other shady relationships that let investigators and regulators intervene.
The $349,700 customer
The FBI attributed the Bybit theft to North Korean hackers on Feb. 26, 2025, identifying the activity as TraderTraitor and warning that stolen assets were being converted into Bitcoin and other cryptocurrencies before being distributed across thousands of blockchain addresses.
While it took no time to identify the hackers, identifying the intermediaries handling the stolen money required much more investigative work.
According to ZachXBT, he began that work when he saw more than 15 accounts in public Telegram and Discord groups seeking help with transactions tied to the stolen Bybit funds, suggesting that at least part of the subsequent laundering process involved intermediaries openly soliciting or arranging services.
He contacted several of those accounts and eventually developed a relationship with someone using the Telegram alias Jimmy Green, who presented himself as someone who needed help moving cryptocurrency between networks.
On March 6, 2025, ZachXBT says he funded a new Ethereum address with 349,700 USDC and began exchanging the dollar-linked token for USDT on Tron through the contact, accepting unfavorable exchange terms while trying to establish himself as a credible customer.
The 349,700 USDC represented capital committed to the transactions rather than a disclosed net investigative loss, while the 5% he says he lost on each order is the cost he was prepared to accept for access to information that ordinary blockchain analysis could not provide.
The arrangement also carried the risk that the intermediary could just disappear with the funds.
Hackers depend on intermediaries who might steal from them in turn, and without enforceable commercial protections, reputation and personal familiarity become especially important to keeping those relationships working.
That gave ZachXBT a way into the operation, since a customer willing to conduct repeated transactions became more valuable to the person providing the service.
The relationship eventually produced information beyond wallet addresses, including discussions of planned fund movements before the transactions occurred, allowing ZachXBT to compare statements made privately with activity subsequently recorded on public blockchains.
In one instance, the intermediary discussed moving funds to Solana before the corresponding movement took place, while other exchanges and wallet connections allegedly helped identify a larger cluster of assets linked to the Bybit theft.
This was a major turning point in his investigation, because on-chain data can't identify the person behind the transaction or its intent. Private conversations about a transaction provided the key evidence about who controlled it and what they used it for.
Even though ZachXBT's investigation still doesn't completely match the FBI's official record, it's still one of the most significant investigative efforts we've seen in a while. It showed that personal and commercial relationships can provide evidence blockchain alone can't, and that similar tactics could help investigate and eventually resolve other thefts.
Tracing $12 million differs from recovering it
ZachXBT said information from his relationship with Jimmy Green helped identify a cluster with more than $12 million in Bybit-linked funds, including transactions across several networks.
He also reported that Tether later froze 442,000 USDT linked to the North Korean hack. This showed that quickly identifying stolen assets, while they remain accessible through issuer-controlled tokens like USDT or USDC, can be crucial to recovering the funds.
The two amounts should not be confused: tracing more than $12 million does not mean the entire amount was frozen, and freezing 442,000 USDT does not mean the tokens were seized or returned to Bybit.
The specific 442,000 USDT figure and its connection to ZachXBT's investigation come from his account, although Tether has separately disclosed larger freezes tied to the Bybit theft.
There's a considerable distance between observing stolen cryptocurrency, identifying the people handling it, and obtaining legal or technical control over the proceeds.
Public blockchains don't prevent the assets from moving again, especially when they pass through services that refuse to cooperate with investigators or operate beyond the reach of relevant authorities.
Centrally issued stablecoins create a potential intervention point because their issuers can retain the administrative ability to restrict transfers from designated addresses.
Native Bitcoin has no equivalent issuer-controlled restriction, although authorities can still restrain assets held by custodians or seize the keys controlling them when they obtain the necessary access and legal authority.
That leaves investigators dependent on more than tracing accuracy, since an identified balance must also remain within reach of someone who has the technical ability and authority to act.
During Bybit's recovery effort, court orders and cooperation from financial intermediaries could restrict assets long after the initial theft, without guaranteeing full recovery.
The problem is that stolen cryptocurrency can become increasingly fragmented as it moves between wallets, chains, custodians, and trading counterparties, with each additional service potentially requiring another source of evidence or another legal process before the pursuit can continue.
That's why investigators can see where the funds traveled but have no way to stop the next transaction or recover the funds.
$4 billion in crypto laundering
The use of outside intermediaries isn't limited to the Bybit theft, and American enforcement records show a longer history of attempts to identify businesses that convert stolen crypto into assets criminals can use.
In March 2020, the Justice Department charged two Chinese nationals, Tian Yinyin and Li Jiadong, with laundering more than $100 million worth of crypto, primarily through activity connected to exchange hacks.
These charges show how individuals who don't carry out the hack can still play an essential role in the crime.
The Treasury's sanctions announcement also revealed that Tian converted nearly $1.4 million in Bitcoin into prepaid Apple iTunes gift cards, showing how laundering can eventually involve ordinary retail instruments rather than the more elaborate financial services usually associated with international cybercrime.
The same economic requirement operates on a much larger scale through marketplaces that connect criminals with merchants offering settlement, exchange, payment and other services.
In May 2025, the Treasury's Financial Crimes Enforcement Network identified Cambodia-based Huione Group as a financial institution of primary money laundering concern, finding that its operations had laundered at least $4 billion in illicit proceeds between August 2021 and January 2025.
Of that amount, FinCEN identified at least $37 million in crypto stemming from North Korean cyber thefts, along with other proceeds from investment fraud and cyber scams.
The $4 billion figure reflects illicit activity across several crime categories, and the $37 million represents the minimum North Korean-linked component identified in the agency's findings.
FinCEN's assessment also identified serious deficiencies in anti-money-laundering and customer-verification controls across the group, including an acknowledgment that inadequate checks had allowed one component to indirectly receive funds connected to a North Korean heist.
The significance of those findings extends beyond any individual transaction because an intermediary that offers repeated access to payment services can become infrastructure for multiple criminal customers, reducing the need for each organization to build its own arrangements for converting stolen assets.
That concentrates activity around businesses that can become targets for sanctions, seizures, restrictions on banking relationships and other enforcement measures.
Huione's marketplace handled a substantial volume of transactions and illicit services, and operators tried to keep operating after Telegram disrupted access to parts of the network.
Those marketplace transaction figures and FinCEN's narrower estimates of identified illicit proceeds measure different categories of activity, making it key not to treat all funds moving through a platform as proven criminal proceeds.
The customers moved
The difficulty is that a criminal marketplace can lose infrastructure without losing the demand that made its services profitable, particularly when users can still contact alternative providers.
In June 2026, the Justice Department announced the seizure of a cloud computing account that hosted backend infrastructure used by Huione Group subsidiaries allegedly involved in moving proceeds from fraud, cyber scams and other criminal activity.
The action followed earlier US restrictions on the group and targeted technology that supports the transfer and concealment of illicit funds.
Removing that infrastructure doesn't automatically eliminate relationships between customers and the intermediaries willing to serve them.
The Treasury made that limitation particularly explicit on Sept. 9, when it sanctioned Xinbi Guarantee, describing an illicit marketplace that connected criminal organizations with merchants providing financial services, technology, and other resources needed to support their operations.
According to Treasury, Xinbi had processed the equivalent of more than $24 billion in digital assets and fiat currency since approximately 2022, with its services primarily supporting transactions involving Southeast Asian markets.
The scale makes the platform relevant to enforcement efforts against the broader financial infrastructure that serves criminal organizations.
Treasury also said cybercriminals had attempted to preserve their operations by migrating activities from Huione-related services to Xinbi following FinCEN's earlier action, with the new marketplace offering substantially similar services to an overlapping group of customers.
The agencies described a commercial market where participants could seek another provider when enforcement made their previous arrangements less reliable.
During the Huione crackdown, Telegram removed thousands of channels associated with Huione Guarantee as merchants moved to alternative marketplaces.
This is why a crackdown's success cannot be measured solely by the number of websites, accounts, or servers taken offline, since customers who still need an illicit financial service can try to rebuild access through providers that remain operational.
The disruption still imposes costs, particularly when balances are frozen, settlements fail, or established counterparties become unavailable, but the economic incentive to move stolen funds continues as long as the underlying crime remains profitable.
The problem for enforcement agencies is making those services increasingly expensive and unreliable across the network of potential replacements.
Tether's freezes push crypto laundering networks toward other payment options
The enforcement action against Xinbi shows how financial restrictions can disrupt criminal operations while prompting the businesses involved to change their payment arrangements.
A series of Tether freezes restricted over $45 million in USDT across at least 22 wallets associated with Xinbi's operations.
The marketplace responded by telling users it would move toward USDD, a stablecoin structure that doesn't offer the same issuer-controlled address-freezing mechanism as USDT.
That was an important shift because the ability to freeze a token can be valuable to investigators when suspected proceeds remain within the issuer's administrative reach, while customers attempting to avoid those restrictions have an incentive to move toward instruments with different controls.
The move shows how restrictions on one part of the payment system can redirect transactions toward another, requiring investigators to follow both the assets and the businesses that provide access to them.
During the September crackdown, authorities also targeted Xinbi-linked infrastructure and restrained over $52 million in cryptocurrency, while withdrawals accelerated and competing marketplaces reportedly began restricting laundering-related merchants.
Those developments differ from the 442,000 USDT freeze ZachXBT attributes to North Korean hackers, since public reporting does not establish that the same addresses, participants, or funds were involved.
Both cases show that criminal operations depend on financial intermediaries whose services can create opportunities for intervention even after the original theft is complete.
Where a token issuer can freeze assets, the relevant exposure may be the balance held in an identifiable address. Where a marketplace serves multiple criminal groups, its vulnerability may extend to the infrastructure, merchant relationships, and settlement arrangements supporting those customers.
Both routes can reduce the ability to move and use stolen money without additional cost or risk.
People behind the transfers are harder to replace
ZachXBT's investigation made an impact because he described how a paid relationship produced information about the people arranging the transactions.
Criminal intermediaries who repeatedly handle stolen cryptocurrency develop a commercial reputation, establish preferred counterparties, and learn which services can complete transactions without interfering with the proceeds.
Those relationships can make an operation more effective over time, especially when customers need to move large amounts of money without revealing their identities or risking that a counterparty will keep the assets.
However, they also create dependencies that are hard to replicate quickly when an established provider disappears, especially if alternatives charge higher fees, reject suspicious funds, or prove less reliable.
Those dependencies also provide investigators with another source of evidence because a service provider can reveal what it knows about future transactions, other participants, and the payment infrastructure required to complete an order.
Investigators still need to test the information against observable activity and other records, and the fact that an address receives funds connected to a theft does not establish the recipient's intent or knowledge.
But comparing private communications with subsequent blockchain movements can narrow that uncertainty in ways tracing transactions alone cannot.
The broader enforcement record points out that making criminal financial services less attractive requires more than periodically taking down their websites, because the customers and commercial incentives supporting those services can outlast the equipment used to deliver them.
Seizing assets, restricting financial access, prosecuting service providers, and identifying the people who control settlement arrangements can change that calculation, though the point at which those costs outweigh revenue from serving illicit customers will differ across businesses.
This is also why the dollar value of a cryptocurrency theft cannot automatically be treated as money successfully converted into spendable revenue for the responsible government, much less as a verified amount used for any particular military or state expenditure.
The original theft, the amount moved through intermediary addresses, the value successfully converted into other forms of purchasing power, and the amount ultimately recovered by authorities are separate measures that require separate evidence.
For North Korean hackers, relying on laundering services adds risk after the initial intrusion succeeds, since gaining control of stolen assets doesn't eliminate the need for others to accept, exchange, and ultimately spend them.
ZachXBT's reported infiltration shows how that requirement can turn a customer relationship into an investigative opening, while the US actions against Huione and Xinbi demonstrate how the surrounding businesses can become enforcement targets even when criminal customers attempt to migrate elsewhere.
The essential weakness is that stealing cryptocurrency and using it in practice are different, and the second still depends on commercial arrangements whose participants have assets, reputations, and financial interests to protect.
North Korean hackers' efforts to make that money spendable can still pull them back into relationships that require trust, and the people providing it have something to lose.
Source: CryptoSlate