From Theft to Re-entry: How Was $292 Million "Laundered"?

marsbitDipublikasikan tanggal 2026-04-26Terakhir diperbarui pada 2026-04-26

Abstrak

A sophisticated crypto laundering operation was executed following the $292 million hack of Kelp DAO on April 18. The attack, attributed to the North Korean Lazarus group, began with anonymous infrastructure preparation using Tornado Cash to fund wallets untraceably. The hacker exploited a vulnerability in Kelp’s cross-chain bridge, stealing 116,500 rsETH. To avoid crashing the market, the attacker used Aave and Compound as laundering tools—depositing the stolen rsETH as collateral to borrow $190 million in clean, liquid ETH. This move triggered a bank run on Aave, causing an $8 billion drop in TVL. After consolidating funds, the attacker fragmented them across hundreds of wallets to evade detection. A major breakpoint was THORChain, where over $460 million in volume—30 times its usual activity—was processed in 24 hours, converting ETH into Bitcoin. This shift to Bitcoin’s UTXO model exponentially increased tracing complexity by shattering funds into countless untraceable fragments. The final destination was Tron-based USDT, the primary channel for illicit crypto flows. From there, funds were cashed out via OTC brokers in China and Southeast Asia, using unlicensed underground banks and UnionPay networks outside Western sanctions scope. Ultimately, the laundered money supports North Korea’s weapons programs, which rely heavily on crypto hacking for foreign currency. The incident underscores structural challenges in DeFi: its openness, composability, and lack of central c...

Editor's Note: On April 18, Kelp DAO was attacked, with approximately $292 million in assets stolen. So, in a completely transparent on-chain system, how exactly was this money step-by-step "cleaned" to become liquid assets?

This article uses this incident as a starting point to dissect a highly industrialized path for crypto money laundering: from the preparation of anonymous infrastructure before the attack, to using Tornado Cash to sever on-chain links; from leveraging Aave and Compound to mortgage "toxic assets" and exchange them for clean liquidity, to using THORChain, cross-chain bridges, and the UTXO structure to exponentially increase tracking difficulty, ultimately funneling into the USDT system on Tron and being converted into cash in the real world via over-the-counter (OTC) networks.

Throughout this process, there were no complex black-box operations; almost every step was "playing by the rules." Precisely because of this, what this path reveals is not a single vulnerability, but the structural tension within the DeFi system under its openness, composability, and uncensorability—when the protocol design itself permits these operations, so-called "fund recovery" is no longer a technical problem but a systemic boundary issue.

The Kelp DAO incident is therefore not just a security breach; it's more like a stress test of the crypto world's operating logic: it shows how hackers turn your money into their money, and it also shows why this system, in principle, struggles to prevent this process from happening.

As you know, on April 18, a North Korean hacker stole $292 million from Kelp DAO. Five days later, over half of it had vanished, fragmented across thousands of wallets, exchanged through unstoppable protocols, and ultimately funneled to a very specific destination.

The interesting part is: how to turn $292 million of documented stolen crypto assets, with no one able to stop it, into cash in Pyongyang's pockets.

The purpose of this article is to reveal why the modern crypto money laundering pipeline works, why it is structurally unstoppable, and what each laundered dollar ultimately buys.

Phase 1: Setup (Hours Before the Attack)

The attacker did not start with the direct theft. The Lazarus Group's playbook always begins with infrastructure preparation.

Approximately 10 hours before the attack, 8 brand new wallets were pre-funded via Tornado Cash—a mixer that severs the link between the source and destination of funds.

Each wallet received 0.1 ETH, used to pay for the Gas fees of all subsequent operations. Since these wallets' funds came from a mixer, they had no exchange KYC records, no historical transaction traces, and could not be linked to any known entity. Clean slates.

On the eve of the attack, the attacker initiated 3 cross-chain transfers from Ethereum mainnet to Avalanche and Arbitrum—clearly aiming to pre-fund Gas on these two L2s and test the bridge operations, ensuring smooth large transfers.

Phase 2: Theft

An independent attack initiation wallet (0x4966...575e) called a function named lzReceive on the LayerZero EndpointV2 contract. As the validator had been successfully deceived, this call was treated as a legitimate cross-chain message. Kelp's bridge contract, Kelp DAO: RSETH_OFTAdapter (Etherscan address: 0x85d...), subsequently released 116,500 rsETH to 0x8B1.

18% of the total circulating rsETH. Gone in one function call.

46 minutes later, at 18:21 UTC, Kelp's emergency multi-signature wallet paused the protocol. At 18:26 and 18:28 UTC, the attacker attempted two more operations in exactly the same way, each trying to steal about 40,000 rsETH (approx. $100 million each). Both were rolled back due to Kelp's timely shutdown. Had this not happened, the total theft could have approached $500 million.

Phase 3: Aave + Compound Operations

rsETH is a receipt token; once Kelp paused the bridge or blacklisted the stolen tokens, its value would immediately drop to zero. The attacker had only minutes to convert it into assets that could not be frozen. Kelp paused 46 minutes after the theft—it was already too late.

Selling $292 million of illiquid restaking tokens on the open market would crash the price by over 30% in minutes. So he did not choose to sell, but instead used DeFi lending protocols as money laundering tools for a quick exit.

The receiving wallet 0x8B1 dispersed the 116,500 stolen rsETH to 7 other branch wallets. Each branch then entered Aave and Compound V3, deposited a portion of the rsETH as collateral, and borrowed ETH.

The cumulative positions of the 7 branches were as follows:

· Deposited Collateral: 89,567 rsETH

· Borrowed: approx. 82,650 WETH + 821 wstETH, totaling approx. $190 million in clean, liquid Ethereum assets

· The health factor for each branch was set between 1.01 and 1.03—the absolute upper limit allowed by the protocol before liquidation

The attacker exchanged this batch of $292 million worth of marked and nearly unsellable rsETH for $190 million worth of ETH. When this rsETH was eventually marked as nearly worthless (because Kelp's bridge became insolvent and unredeemable), the lending protocol's depositors bore the loss.

As the market realized Aave was holding over $200 million in bad debt, users panicked and withdrew funds. Aave lost $8 billion in TVL (Total Value Locked) within 48 hours. The largest DeFi lending protocol experienced its first true bank run—triggered by an attacker using it exactly as designed.

Phase 4: Fund Consolidation and Splitting

After completing the Aave/Compound borrowing, the 7 branches pushed the borrowed ETH to a third-layer consolidation wallet (0x5d3).

The operational cluster now showed a clear three-tier structure:

1. Receipt: 0x8B1 (also funded via Tornado Cash), received the original theft of 116,500 rsETH

2. Operations: 7 branch wallets funded via Tornado Cash, executed Aave/Compound operations

3. Consolidation: 0x5d3 re-aggregated the borrowed funds, approx. 71,000 ETH, unifying them for the laundering process

The funds were then distributed across two chains:

· 75,700 ETH remained on Ethereum Mainnet

· 30,766 ETH on Arbitrum (approx. $71 million)

The Arbitrum Security Council voted to freeze these assets on Arbitrum, moving the $71 million to a governance-controlled wallet that could only be unlocked by subsequent governance decisions.

Shortly after the freeze, the hacker moved the remaining ETH on Mainnet and accelerated the laundering process. These actions suggested he clearly did not anticipate Arbitrum taking such action.

Phase 5: First Wave of Laundering

Four days after the attack, 0x5d3 began to empty. Arkham tracked 3 independent transfers within hours.

The timing was deliberately chosen: Tuesday during European trading hours. US investigators were still resting, European compliance departments were dealing with Monday's backlog, and Asian exchanges were nearing close.

Then, the transfer pattern began to explode. Every first-wave destination immediately fragmented further: 0x62c7 pushed to about 60 newly generated wallets, 0xD4B8 pushed to another ~60. Within hours, the neat cluster of 10 wallets expanded to over 100 disposable addresses, all funded in parallel, each holding amounts small enough to evade detection.

Lazarus runs HD wallet scripts—a single seed phrase can mathematically derive thousands of new addresses in seconds,配合 a worker pool (Python + web3, ethers.js, or their own internal tools) to sign and broadcast the entire address tree in parallel. They have been iterating on this code since 2018.

By the end of this phase, the linearly traceable chain had disappeared. The operational cluster of 10 wallets exploded into over 100 fragmented wallets, with funds entering privacy channels simultaneously from dozens of independent entry points.

Phase 6: THORChain – The Escape Machine

The real breakpoint happened at THORChain.

THORChain is a decentralized protocol supporting cross-chain native asset swaps. You send ETH on Ethereum, it gives you BTC on the Bitcoin network.

On April 22 alone, THORChain's 24-hour swap volume reached $460 million. The protocol's normal daily volume is around $15 million. This single hack accounted for 30 times the protocol's normal usage in one day.

Within the same 24-hour window, the protocol generated $494,000 in revenue, shared among bonders (node operators), liquidity providers, the development fund, alliance integrators, and the marketing fund.

Simultaneously, funds also flowed through a set of smaller but complementary privacy rails:

· Umbra: A stealth address protocol on Ethereum. Allows sending funds to disposable addresses, only the recipient can calculate the address using a shared key. On-chain monitors cannot know the true destination. Initial activity of ~$78,000 was tracked here before tools lost the trail.

· Chainflip: Another cross-chain DEX, similar to THORChain.

· BitTorrent Chain: A low-cost, low-regulation sidechain connected to Tron.

· Tornado Cash: The same mixer used for the initial Gas pre-funding. The US Treasury Department sanctioned it in 2022.

Each layer of protocol increases the tracking cost by roughly a factor of 10. After 5 layers, forensic firms could theoretically still track every fragment, but the economic cost exceeds the recoverable value.

Phase 7: Bitcoin UTXO Fragmentation

Completing the ETH-to-BTC conversion via THORChain essentially turns the money into confetti.

Ethereum uses an account model; your balance is a number attached to an address, simple and direct. Bitcoin is different; it uses a UTXO (Unspent Transaction Output) model—each UTXO is a specific chunk of a coin with a complete transaction history. Every time you spend Bitcoin, these chunks are split and recombined, forming new chunks.

Imagine tearing a $100 bill into 87 pieces, then tearing each piece into another 87 pieces, repeating this cycle 7 times. Technically, every fragment can be traced back to that original bill. Practically, no manual forensic team can track thousands of parallel chains in real-time and piece together the complete picture fast enough to take action.

Thus, THORChain accomplished two things simultaneously: moving funds across a boundary no sanction could cross, and fragmenting the funds into untraceable dust.

Phase 8: Tron USDT Rail

After passing through Bitcoin and privacy layers, the funds reconverged on the same endpoint: USDT on Tron.

Most people assume the main battlefield for money laundering is BTC; this is incorrect. The real main battlefield is USDT on Tron. Data shows USDT-Tron consistently ranks first in annual illicit crypto asset transaction volume, exceeding the sum of all other chains.

In this Kelp fund flow, the specific path was: cross-chain transfer from BTC to Tron, exchange for USDT, then multiple transfers between Tron addresses. Each hop on Tron costs mere pennies, allowing for another 10 layers of fragmentation.

Phase 9: Cashing Out – Crypto to Cash

The endpoint of every hack sees the funds converted into fiat cash through a specific, well-known network of human intermediaries.

A group of over-the-counter (OTC) brokers active in mainland China and Southeast Asia receive USDT-Tron deposits and settle in local currency cash. These brokers are essentially unlicensed underground banks. They aggregate fund flows from multiple clients (compliant and non-compliant), net them internally, and settle in fiat via China's domestic payment network (UnionPay)—which operates completely outside the SWIFT system and Western sanction enforcement.

From accounts controlled by these brokers, funds flow into North Korean-controlled bank accounts, often held in the name of shell companies registered in Hong Kong, Macau, or third-party jurisdictions. From these accounts, funds are sent back to Pyongyang through Hawala-style informal clearing, physical cash transport, and procurement front companies.

The UN Security Council, FBI, and US Treasury Department have independently documented the final destination of these funds. North Korea's ballistic missile program, nuclear weapons development, and circumvention of international sanctions rely on the continuous support of such fund flows.

A 2024 UN report estimated that crypto hacks account for about 50% of North Korea's total foreign exchange income, making it the primary funding source for its weapons program—exceeding the sum of coal exports, arms sales, and labor exports.

[Original Title]

Pertanyaan Terkait

QWhat was the total amount stolen in the Kelp DAO attack and what was the primary method used to initially obscure the funds?

AApproximately $292 million was stolen. The primary method used to initially obscure the funds was using Tornado Cash, a cryptocurrency mixer, to fund the initial attack wallets, severing the on-chain link to their source.

QHow did the attacker convert the illiquid, marked rsETH tokens into liquid, 'clean' assets without crashing the market?

AThe attacker used DeFi lending protocols Aave and Compound as a laundering tool. They deposited the stolen rsETH as collateral and borrowed out approximately $190 million worth of liquid ETH and wstETH, effectively swapping the toxic assets for clean, fungible ones.

QWhich decentralized protocol served as the major 'exit vehicle' for the funds, and what two key functions did it perform?

ATHORChain served as the major exit vehicle. It performed two key functions: 1) It enabled cross-chain swaps (e.g., from ETH to BTC), moving funds across jurisdictional boundaries. 2) It exponentially increased tracking difficulty by fragmenting the funds through Bitcoin's UTXO model.

QAccording to the article, what is the final destination for most laundered crypto assets like those from this hack, and what stablecoin is predominantly used?

AThe final destination is the Tron blockchain, where the funds are predominantly converted into USDT (Tether). Tron's USDT is cited as the primary battlefield for illicit crypto asset transactions.

QWhat is the ultimate real-world outcome for the laundered funds, and how do they reportedly benefit the attacker's nation-state?

AThe funds are converted into fiat cash through a network of OTC brokers in Asia and then funneled to North Korea. According to UN reports, such funds are a primary source of foreign currency, supporting the nation's ballistic missile and nuclear weapons programs.

Bacaan Terkait

Negara Besar Memblokir Chip, Raksasa Membeli Pembangkit Nuklir: Mengapa Sekarang Waktunya Serius Mencermati DeAI

**Ringkasan Artikel: Mengapa DeAI Perlu Diperhatikan Serius Sekarang?** Pada Mei 2026, tiga peristiwa di benua berbeda menyoroti realitas baru: persaingan daya komputasi AI telah melampaui industri teknologi. AS menutup celah ekspor chip canggih ke China, Kenya menghentikan proyek data center raksasa karena konsumsi listriknya, sementara Huawei memproyeksikan pendapatan besar dari chip AI. Era oligopoli AI sedang terbentuk. Sedikit perusahaan (seperti NVIDIA, AWS, Microsoft, OpenAI) menguasai seluruh rantai pasok AI, dari chip, cloud, model, hingga distribusi. Konsentrasi ini menciptakan risiko: ketergantungan pada beberapa pemain, kerentanan infrastruktur, dan kesenjangan teknologi yang diperparah oleh geopolitik "tirai besi AI" dalam ekspor chip. Negara-negara bereaksi berbeda. Negara Teluk berinvestasi besar-besaran untuk membeli daya komputasi. UE berusaha meningkatkan kedaulatan digitalnya. Sementara banyak negara berkembang berjuang dengan sumber daya yang terbatas dibandingkan belanja modal raksasa perusahaan tech AS. Persaingan ini semakin bergantung pada variabel mendasar: pasokan listrik. Dalam konteks ini, AI Terdesentralisasi (DeAI) muncul sebagai kemungkinan ketiga. Ide intinya adalah menciptakan infrastruktur AI terbuka yang terkoordinasi oleh protokol, menghubungkan daya komputasi GPU yang menganggur di seluruh dunia tanpa kendali pusat tunggal. DeAI bertujuan untuk: - Memecahkan konsentrasi pasar dengan menciptakan jaringan pemasok yang terdesentralisasi. - Meringankan tekanan pada jaringan listrik dengan mendistribusikan kebutuhan energi. - Memberi peluang bagi negara dan bisnis kecil untuk berpartisipasi. - Meningkatkan transparansi melalui verifikasi kriptografis. Meski masih dalam tahap awal dan menghadapi tantangan kinerja, dukungan dari investor ventura dan eksplorasi oleh beberapa pemerintah menunjukkan minat yang tumbuh. Nilai utama DeAI bukanlah untuk segera mengungguli sistem terpusat, tetapi untuk menyediakan arsitektur alternatif yang menolak monopoli dan menyebarkan kekuasaan. Keberadaan pilihan itu sendiri sudah merupakan bentuk penyeimbang.

marsbit1j yang lalu

Negara Besar Memblokir Chip, Raksasa Membeli Pembangkit Nuklir: Mengapa Sekarang Waktunya Serius Mencermati DeAI

marsbit1j yang lalu

Ulasan Outpoll: Sebuah Platform Pasar Prediksi yang Dibangun untuk Trader Aktif

Outpoll adalah platform pasar prediksi yang dirancang khusus untuk trader aktif. Platform ini menyediakan pengalaman dan alat perdagangan tingkat lanjut yang sebelumnya kurang umum di sektor pasar prediksi. Outpoll beroperasi dengan logika standar pasar prediksi, di mana pengguna memperdagangkan kemungkinan suatu peristiwa terjadi, menggunakan USDC sebagai aset penyelesaian dan menerapkan sistem jaminan penuh. Biaya transaksi dikenakan sekitar 0,1% per perdagangan. Fitur utama Outpoll termasuk: * **Alat Perdagangan Canggih:** Mendukung order limit, order pasar, serta pengaturan take-profit dan stop-loss untuk posisi yang terbuka. * **API Publik Lengkap:** Menyediakan REST API dan WebSocket API untuk memungkinkan otomatisasi, pemantauan, dan integrasi dengan alat trader lainnya. * **Pasar yang Dipimpin Kreator:** Memungkinkan pakar komunitas dan pemimpin opini untuk membuat dan mengelola pasar di topik khusus, dengan pengawasan platform. * **Integrasi Berita dan Perdagangan:** Panel berita terintegrasi langsung dalam antarmuka perdagangan untuk akses informasi yang lancar. * **Aplikasi Seluler Asli:** Sudah tersedia aplikasi Android (di Google Play), dengan versi iOS direncanakan rilis tahun ini. Outpoll berfokus pada peningkatan infrastruktur perdagangan untuk pengguna yang lebih profesional melalui alat yang kuat, transparansi, dan jangkauan pasar yang luas melalui program kreatornya. Platform ini kini terbuka untuk pengguna global.

marsbit1j yang lalu

Ulasan Outpoll: Sebuah Platform Pasar Prediksi yang Dibangun untuk Trader Aktif

marsbit1j yang lalu

Bitwise: Crypto Berubah Menjadi Investasi Kontrarian, Tiga Logika untuk Memahami Pasar Saat Ini

Penulis Asli: Matt Hougan, CIO Bitwise Kompilasi Asli: Chopper, Foresight News Artikel ini menganalisis kondisi pasar kripto saat ini dari tiga dimensi utama: 1) **Aset Kripto Berubah Menjadi Pilihan Investasi Kontrarian.** Pasar kripto sedang lesu, dengan penurunan harga utama seperti Bitcoin dan Ethereum. Hal ini terjadi karena perhatian modal global kini terfokus pada sektor seperti AI, mengubah kripto dari investasi tren menjadi investasi kontrarian yang memerlukan kesabaran dan analisis fundamental. Dana kini beralih ke proyek dengan dasar fundamental yang kuat, seperti Hyperliquid. 2) **Pasar Menunggu Kepastian Regulasi, tapi RUU CLARITY Kemungkinan Besar Tidak Akan Disahkan.** Ketidakpastian regulasi, terutama terkait RUU CLARITY di AS, menghambat aliran modal institusional. Meskipun RUU ini bertujuan menciptakan kerangka hukum yang jelas, kemungkinan disahkannya tahun ini diragukan (sekitar 30-55%). Ketidakpastian ini membuat investor institusi lebih memilih aset seperti saham AI. Pasar kripto sulit pulih sebelum kejelasan regulasi tercapai. 3) **Modal Beralih ke Aset Fundamental Generasi Baru.** Berbeda dengan siklus bearish sebelumnya, dana tidak hanya lari ke Bitcoin. Beberapa aset dengan fundamental unik dan kapitalisasi pasar lebih kecil, seperti Hyperliquid, Zcash, dan XLM, justru menunjukkan kinerja positif yang kuat pada Mei 2026. Pergeseran ini mencerminkan logika investasi kontrarian dan menandakan bahwa pasar kemungkinan memasuki fase akhir siklus bearish. **Kesimpulan:** Tekanan jangka pendek diperkirakan berlanjut karena ketidakpastian regulasi dan dominasi narasi AI. Namun, periode ini justru menawarkan peluang investasi kontrarian. Kunci kesuksesan terletak pada kesabaran, disiplin, dan fokus untuk mengidentifikasi serta berinvestasi pada proyek-proyek bernilai dengan fundamental yang kuat untuk imbal hasil jangka panjang yang substansial.

marsbit1j yang lalu

Bitwise: Crypto Berubah Menjadi Investasi Kontrarian, Tiga Logika untuk Memahami Pasar Saat Ini

marsbit1j yang lalu

Trading

Spot
Futures

Artikel Populer

Cara Membeli DAO

Selamat datang di HTX.com! Kami telah membuat pembelian DAO Maker (DAO) menjadi mudah dan nyaman. Ikuti panduan langkah demi langkah kami untuk memulai perjalanan kripto Anda.Langkah 1: Buat Akun HTX AndaGunakan alamat email atau nomor ponsel Anda untuk mendaftar akun gratis di HTX. Rasakan perjalanan pendaftaran yang mudah dan buka semua fitur.Dapatkan Akun SayaLangkah 2: Buka Beli Kripto, lalu Pilih Metode Pembayaran AndaKartu Kredit/Debit: Gunakan Visa atau Mastercard Anda untuk membeli DAO Maker (DAO) secara instan.Saldo: Gunakan dana dari saldo akun HTX Anda untuk melakukan trading dengan lancar.Pihak Ketiga: Kami telah menambahkan metode pembayaran populer seperti Google Pay dan Apple Pay untuk meningkatkan kenyamanan.P2P: Lakukan trading langsung dengan pengguna lain di HTX.Over-the-Counter (OTC): Kami menawarkan layanan yang dibuat khusus dan kurs yang kompetitif bagi para trader.Langkah 3: Simpan DAO Maker (DAO) AndaSetelah melakukan pembelian, simpan DAO Maker (DAO) di akun HTX Anda. Selain itu, Anda dapat mengirimkannya ke tempat lain melalui transfer blockchain atau menggunakannya untuk memperdagangkan mata uang kripto lainnya.Langkah 4: Lakukan trading DAO Maker (DAO)Lakukan trading DAO Maker (DAO) dengan mudah di pasar spot HTX. Cukup akses akun Anda, pilih pasangan perdagangan, jalankan trading, lalu pantau secara real-time. Kami menawarkan pengalaman yang ramah pengguna baik untuk pemula maupun trader berpengalaman.

233 Total TayanganDipublikasikan pada 2024.12.11Diperbarui pada 2026.06.02

Cara Membeli DAO

Diskusi

Selamat datang di Komunitas HTX. Di sini, Anda bisa terus mendapatkan informasi terbaru tentang perkembangan platform terkini dan mendapatkan akses ke wawasan pasar profesional. Pendapat pengguna mengenai harga DAO (DAO) disajikan di bawah ini.

活动图片