Inside the 45-day laundering cycle for stolen crypto
Hackers stole $3.4 billion in crypto in 2025 and about $1.1 billion in H1 2026; investigators identify a three-wave laundering cycle that runs about 45 days.
Hackers stole $3.4 billion in crypto in 2025 and roughly $1.1 billion in the first half of 2026. Investigators describe a three-wave laundering cycle that typically takes about 45 days from the first transfer to final cashout.
Security firms recorded the totals and incident counts. One firm logged $3.4 billion in stolen tokens for 2025, with a single February breach of an exchange’s cold wallet accounting for about $1.5 billion, or roughly 44% of that year’s total. Another firm counted a record 212 incidents and about $1.1 billion in losses in the first half of 2026. A separate tracker logged 207 incidents over the same six months. A firm that includes phishing and personal-wallet drains put first-half damage at $1.32 billion across 344 incidents.
Researchers outline the laundering cycle in three waves. In the first five days after a theft, attackers move tokens quickly through decentralized finance (DeFi) swaps and into mixing services that pool and shuffle coins; activity on those services can spike by as much as 370 percent.
Between days six and ten, the funds are routed across blockchains via cross-chain bridges and passed through exchanges with limited know-your-customer controls.
From about day 20 to day 45, remaining holdings are split into smaller tranches, often below $500,000 to avoid reporting thresholds, and cashed out through no-KYC venues, instant exchangers, and Chinese-language over-the-counter networks and guarantee services, including marketplaces that have been sanctioned.
Several incidents illustrate the pattern and its limits. Less than 5 percent of funds from the large cold-wallet exchange breach were recovered. On April 19, 2026, an exploit of a restaking protocol resulted in a $293 million loss, the largest single hit in the first half of 2026. April 2026 set a monthly record with $641.67 million stolen. A hardware-wallet exploit that drained roughly $116 million showed the same laundering steps being applied to bitcoin. Security assessments attribute about 55 percent of first-half losses to groups linked to North Korea.
Recovery efforts face technical and legal barriers. Blockchain records allow tracing of token flows, but onchain transfers are irreversible and require cooperation from centralized services to recover assets. Stablecoin issuers can blacklist addresses at the contract level to freeze USDT or USDC balances; that mechanism has been used when stolen funds remain in those tokens. To avoid freezes, attackers often convert stablecoins into ether or bitcoin within minutes of a breach.
Sanctions and cross-border legal processes can add friction to laundering but frequently occur after funds have passed through multiple chains, mixers and jurisdictions, limiting practical recovery options.
The material on GNcrypto is intended solely for informational use and must not be regarded as financial advice. We make every effort to keep the content accurate and current, but we cannot warrant its precision, completeness, or reliability. GNcrypto does not take responsibility for any mistakes, omissions, or financial losses resulting from reliance on this information. Any actions you take based on this content are done at your own risk. Always conduct independent research and seek guidance from a qualified specialist. For further details, please review our Terms, Privacy Policy and Disclaimers.








