
Less than 5% of the $1.5 billion Bybit hack was recovered. Here is how the 45-day laundering cycle works and why the freeze window is shrinking.
Hackers stole $3.4 billion in crypto last year and another $1.1 billion in the first half of 2026. Once the coins leave the victim's wallet, investigators have about 45 days before the trail becomes unworkable.
The Bybit hack in February 2025 accounted for nearly half of 2025's total. Attackers compromised the exchange's cold-wallet signing process and walked away with $1.5 billion, the largest single crypto theft on record. Less than 5% of those funds were ever recovered, even with the exchange's white‑hat team tracking every hop.
That low recovery rate is not an accident. Security firms Chainalysis, TRM Labs and Blockaid have all documented a distinctive laundering cycle that runs roughly 45 days in three waves, and it has become the industry standard among sophisticated thieves.
Days zero through five are about speed. Stolen tokens hit DeFi protocols first. Activity spikes as much as 370% in these hours, according to on‑chain data. Attackers swap the haul through liquidity pools and push it into mixing services that shuffle coins to break the link between source and destination.
Days six through ten the funds hop blockchains via cross‑chain bridges. From there they flow into exchanges that require minimal know‑your‑customer checks. The goal is to move the money through enough venues that any single freezing attempt is useless.
From day 20 to day 45 the coins are cashed out in small tranches, typically under $500,000 to stay beneath reporting thresholds. No‑KYC instant exchangers, Chinese‑language over‑the‑counter networks, and guarantee services like the sanctioned Huione marketplace handle the final leg. By day 45 the funds have crossed so many chains, mixers and jurisdictions that attribution remains possible – blockchains never forget – but recovery rarely is.
The cycle explains why the industry's freeze lever is the only tool that reliably works. Tether and Circle can blacklist addresses at the contract level, instantly stranding any USDT or USDC still in thief wallets. Sophisticated attackers know this. They swap stolen stablecoins into ether or bitcoin within minutes of a breach, accepting price risk to escape the freeze radius. The most censorship‑resistant assets are the easiest to launder; the most freezable ones are the easiest to recover.
North Korean‑linked Lazarus crews were behind about 55% of first‑half losses, TRM Labs said. April alone set a monthly record with $641.67 million stolen across multiple exploits. The largest single event was the KelpDAO restaking protocol exploit on April 19, which cost $293 million.
A separate Coldcard hardware‑wallet exploit showed how the playbook works for bitcoin too. An attacker drained roughly $116 million from weak‑seed wallets, then began consolidating coins while onlookers watched every transaction. Bitcoin's transparency let everyone see the stolen coins move. Its irreversibility meant nobody could move them back.
For exchanges and analytics firms, the practical takeaway is that prevention is nearly the whole game. Funds that touch compliant platforms can be frozen, which is why launderers front‑load DeFi and mixers, where no freeze mechanism exists. Sanctions on mixers and on Huione raise the attackers' costs but push flows to successors rather than stopping them. The 45‑day clock means that by the time cross‑border legal process gets underway, the coins have usually finished their journey.
The blockchain records everything. It returns almost nothing.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.