# Money Laundering Related Articles

HTX News Center provides the latest articles and in-depth analysis on "Money Laundering", covering market trends, project updates, tech developments, and regulatory policies in the crypto industry.

From Theft to Re-entry: How Was $292 Million "Laundered"?

A sophisticated crypto laundering operation was executed following the $292 million hack of Kelp DAO on April 18. The attack, attributed to the North Korean Lazarus group, began with anonymous infrastructure preparation using Tornado Cash to fund wallets untraceably. The hacker exploited a vulnerability in Kelp’s cross-chain bridge, stealing 116,500 rsETH. To avoid crashing the market, the attacker used Aave and Compound as laundering tools—depositing the stolen rsETH as collateral to borrow $190 million in clean, liquid ETH. This move triggered a bank run on Aave, causing an $8 billion drop in TVL. After consolidating funds, the attacker fragmented them across hundreds of wallets to evade detection. A major breakpoint was THORChain, where over $460 million in volume—30 times its usual activity—was processed in 24 hours, converting ETH into Bitcoin. This shift to Bitcoin’s UTXO model exponentially increased tracing complexity by shattering funds into countless untraceable fragments. The final destination was Tron-based USDT, the primary channel for illicit crypto flows. From there, funds were cashed out via OTC brokers in China and Southeast Asia, using unlicensed underground banks and UnionPay networks outside Western sanctions scope. Ultimately, the laundered money supports North Korea’s weapons programs, which rely heavily on crypto hacking for foreign currency. The incident underscores structural challenges in DeFi: its openness, composability, and lack of central control make such laundering not just possible, but inherently difficult to prevent.

marsbit04/26 07:12

From Theft to Re-entry: How Was $292 Million "Laundered"?

marsbit04/26 07:12

North Korean Hackers Loot $500 Million in a Single Month, Becoming the Top Threat to Crypto Security

North Korean hackers, particularly the notorious Lazarus Group and its subgroup TraderTraitor, have stolen over $500 million from cryptocurrency DeFi platforms in less than three weeks, bringing their total theft for the year to over $700 million. Recent major attacks on Drift Protocol and KelpDAO, resulting in losses of approximately $286 million and $290 million respectively, highlight a strategic shift: instead of targeting core smart contracts, attackers are now exploiting vulnerabilities in peripheral infrastructure. For instance, the KelpDAO attack involved compromising downstream RPC infrastructure used by LayerZero's decentralized validation network (DVN), allowing manipulation without breaching core cryptography. This sophisticated approach mirrors advanced corporate cyber-espionage. Additionally, North Korea has systematically infiltrated the global crypto workforce, with an estimated 100 operatives using fake identities to gain employment at blockchain companies, enabling long-term access to sensitive systems and facilitating large-scale thefts. According to Chainalysis, North Korean-linked hackers stole a record $2 billion in 2025, accounting for 60% of all global crypto theft that year. Their total historical crypto theft has reached $6.75 billion. Post-theft, they employ specialized money laundering methods, heavily relying on Chinese OTC brokers and cross-chain mixing services rather than standard decentralized exchanges. Security experts, while acknowledging the increased sophistication, emphasize that many attacks still exploit fundamental weaknesses like poor access controls and centralized operational risks. Strengthening private key management, limiting privileged access, and enhancing coordination among exchanges, analysts, and law enforcement immediately after an attack are critical to improving defense and fund recovery chances. The industry's challenge now extends beyond secure smart contracts to safeguarding operational security at the infrastructure level.

marsbit04/23 01:49

North Korean Hackers Loot $500 Million in a Single Month, Becoming the Top Threat to Crypto Security

marsbit04/23 01:49

CertiK Releases Cryptocurrency ATM Fraud Report: Losses Reach $330 Million, AI Scams and Cross-Border Money Laundering Emerge as Major Threats

CertiK's "Skynet Cryptocurrency ATM Fraud Report" reveals that losses from such scams reached $330 million in 2025, a 33% year-on-year increase, making it one of the fastest-growing financial crimes in the U.S. The report highlights that these scams have evolved into a highly organized transnational criminal industry, leveraging social engineering and AI technologies. Cryptocurrency ATMs, with 78% located in the U.S., serve as a rapid channel for fraudsters to transfer funds. Victims, often elderly individuals who account for 86% of the losses, are manipulated via phone calls or messages to deposit cash into these machines. The funds are quickly converted into cryptocurrency and transferred to wallets controlled by criminals, making recovery nearly impossible once the transaction is on the blockchain. AI-driven scams, including voice cloning and deepfake videos, have proven 4.5 times more profitable than traditional methods. Criminal networks use automated scripts and employ "smurfing" tactics to bypass transaction limits. The illicit funds are rapidly laundered through mixing services, cross-chain bridges, and decentralized exchanges, often within minutes. The report emphasizes that the only effective intervention point is at the transaction entry level, before funds are on-chain. It calls for enhanced KYC measures, industry-wide intelligence sharing, real-time risk screening, and stronger cross-border law enforcement cooperation to combat this escalating threat.

marsbit04/02 07:36

CertiK Releases Cryptocurrency ATM Fraud Report: Losses Reach $330 Million, AI Scams and Cross-Border Money Laundering Emerge as Major Threats

marsbit04/02 07:36

活动图片