Where $388 Million Went: The Path Stolen Exchange Funds Actually Take

A theft is one step; hiding it is five. Following roughly $388 million of stolen exchange funds through a split into twenty-three transactions, a cross-chain swap out of the stolen asset, a spread across four networks chosen for liquidity, cost, concealment and stablecoin depth, and an exit that is the only hop needing a willing human on the other side.

When a large theft is reported, two conversations start immediately and both are less useful than they appear. The first is about blame, and the second is about whether some protocol should have frozen the funds. Neither answers the question that a reader can actually learn from, which is how the money moved, what each hop cost the attacker, and which gates in the path were capable of closing and did not. The theft disclosed by an exchange in late September, involving roughly three hundred and eighty-eight million dollars, is unusually well documented on this last axis, because the analytics firm that traced it published the route.

What follows is that route as a sequence of five steps, with two things attached to each: what the step does for the person moving the money, and what it leaves behind for the person following it. The final sections deal with the gates, the attribution and the part of the story that never makes a headline, which is what happened to the customers.

Where $388 Million Went: The Path Stolen Exchange Funds Actually Take
The five steps. Only the first involves anything that an ordinary person would describe as breaking in; the rest is routine treasury work performed by somebody who does not want to be found.

Step one: the transfer out, which is the only break-in

The episode began with assets leaving wallets controlled by the exchange on 24 September, about three hundred and eighty-eight million dollars in total. That is the step the word “hack” describes, and it is also the step after which nothing is hidden: the movement of value on a public ledger creates a permanent record that anyone can read, and the first transaction of a theft is the beginning of the evidence, not the end of it.

The important consequence is a change in the attacker’s problem. Before the transfer, the objective was access. Afterwards, the objective is disappearance, and disappearance in a system where every movement is recorded means changing what the assets look like rather than where they came from. Every remaining step in the sequence is an attempt to break the link between a specific quantity of value and the event that produced it.

Step two: the split, and why twenty-three transactions

The tracing published afterwards described twenty-three outgoing transactions within roughly three hours. A person new to this subject reads that as panic or as clumsiness; it is neither. Splitting a balance serves three purposes at once, and all of them are defensive.

The first is threshold management. Monitoring systems and compliance rules operate with size limits, and a quantity that moves in pieces may pass under several of them rather than over one. The second is channel testing: by sending value along different routes at the same time, the attacker discovers which routes still work before committing the whole amount to any single one. The third is concentration risk in reverse: if one route is blocked or seized, only the portion sent along it is lost, and the rest of the operation continues.

None of that requires specialised infrastructure. A large seller of any asset faces the same set of constraints and solves them the same way, which is why the split is the least distinctive part of the route and the part that most resembles ordinary activity.

Step three: the swap that changes what the asset is

The step that matters most technically is the third, in which one asset is fed into a permissionless cross-chain liquidity protocol and the value is withdrawn on another network in a different asset. The tracing described the remainder of the balance being routed this way, with value coming out in bitcoin.

Two things happen in that operation and only one of them is about geography. The obvious one is a move between networks, which lets the attacker leave the chain where the stolen asset was issued. The less obvious and more important one is a change of asset, because a holding’s history is attached to the specific tokens that were taken. An issuer can freeze its own token on a specific address; it cannot freeze an unrelated asset that somebody else now holds, because as far as that asset’s ledger is concerned, nothing improper happened on it.

Bitcoin is an efficient destination for that reason, and the reasons are economic rather than ideological. It has the deepest liquidity for large conversions, the widest over-the-counter market to absorb size without moving a public price, and no issuer with a switch over its supply. The operation is not money laundering in the classic sense of commingling funds to obscure a source; it is closer to changing a serial number by melting the metal and recasting it, and the tool that makes it easy was built to let ordinary users move value between networks cheaply.

Step four: four networks, four different reasons

Where $388 Million Went: The Path Stolen Exchange Funds Actually Take
Where the value landed, and what each network offered. The distribution is deliberate: each destination is chosen for a property, not for storage.

The published split put roughly half on a general-purpose chain with the deepest liquidity, about forty percent on a payments-focused ledger whose native asset is cheap and fast to bridge, under eight percent on a chain whose transaction amounts can be hidden, and about two percent on the network with the densest market for dollar tokens. Read that distribution as a portfolio and each weight has a purpose.

The general-purpose chain is where the largest conversions can happen without disturbing a price. The payments ledger offers settlement speed and low cost, which matters when the objective is to keep moving. The privacy-capable chain offers concealment of amounts for the portion that needs it, although the transfers themselves remain visible. And the stablecoin network is useful because dollar tokens are the asset most easily exchanged for currency through venues and brokers that accept them without a banking relationship.

The pattern to note is that none of the four destinations is chosen to hold value. They are chosen for what each one can do to it, which is why the value keeps moving through the path rather than resting in it. Storage is the objective of an investor; a route is the objective here.

Step five: the exit, which is the only step needing a counterparty

The final step in any route is conversion into something spendable, and it is the only step that cannot be completed by software alone. A chain can move value between addresses; it cannot pay a salary, settle an invoice or buy a building. That requires a venue or a broker willing to take the asset and deliver currency, and a willing counterparty is exactly what a person trying to be invisible does not have.

That is why the last stage of every case looks the same and why it is where arrests and seizures concentrate. Everything upstream of it is a technical problem solved by code. The final hop is a human problem, and the humans on the other side of it are regulated, identifiable and increasingly automated in their screening. The published record of this case ends at the point where the funds were consolidated and beginning to be distributed, which is precisely the doorway.

The four gates, and what each can actually do

Where $388 Million Went: The Path Stolen Exchange Funds Actually Take
Four gates and their powers. The asymmetry between the two columns is the entire story of why recovery attempts stall.

A token issuer can freeze its own token on a given address, and that power is real: it works on a balance whether the holder agrees or not. Its limitation is scope. A freeze reaches only the liability that issuer created, which is why the change of asset in step three is the attacker’s most valuable move — it steps out from under the only switch in the system that is designed to be pulled.

A regulated venue can refuse a deposit, can request information, and is obliged to report suspicious activity. That is the most consequential gate in practice, and it operates by attrition: it forces the person moving the funds to find a venue with weaker controls, which narrows the available routes with every refusal. A permissionless protocol has no such capability and does not want one; its inability to block a specific user is the same property that lets it serve a user whose government dislikes them. A chain’s validators could censor or reorg, and have no obligation to, which makes that gate technically available and politically improbable.

The asymmetry produces the pattern of every large case: the swifter the response, the more value is caught at the first two gates, and the longer the delay, the more the funds have already passed into the layers that have no mechanism at all.

Why the gate with no switch was built that way

The refusal that drew attention in this case is worth understanding on its own terms. A permissionless cross-chain exchange declined to block addresses associated with the theft, explaining that blocking would require an authority the protocol does not have and was not designed to have. That statement is accurate and is also the honest description of a trade-off that every protocol in this category has made.

If such a protocol could block a specific address, it could block any address, and the set of reasons for blocking would be set by whoever controls the switch. The design choice to remove that capability is what allows the protocol to operate without permission, without identity checks and without jurisdiction. The cost of the choice appears in exactly this situation: an asset moving between networks through a mechanism that cannot distinguish a merchant from a thief.

Neither side of the argument is dissembling. The protocol’s defenders are describing its architecture, and its critics are describing the consequence of that architecture. What is not available is a version of the same mechanism that keeps the permissionless property and gains a blocking power, because the second property is the first one applied to somebody.

The trail that survives anyway

Against the impression that a chain-hopping route makes funds untraceable, the evidence in this case runs the other way: the route was reconstructed from public data and published with the proportions and the intermediate steps. Three features of the record make that possible.

The first is that every transfer is permanent and timestamped, so a sequence can be ordered without asking anyone. The second is that the split at step two creates relationships: funds that move together, or rest in the same place at the same moment, or arrive at a pool within seconds of each other, cluster into groups that an automated analysis can assemble into a route. The third is that the exit is visible, because the venues that convert assets into currency keep records precisely so that the first two features can be used against their own customers when required.

A common misunderstanding belongs here. An unspent-output model — the design bitcoin uses — is not anonymous; it is pseudonymous, and the distinction is large. Amounts and destinations are public, and the only thing standing between a chain of transactions and a name is an identity check at some venue. Privacy features on other networks change what is visible in specific transactions, and they do not remove the fact that a hop between networks creates a link that has to be explained rather than erased.

Attribution, and what it is worth

The firm that traced the route attributed it to a state-linked group, and the total attributed to that actor over the course of the year passed a billion dollars. The exchange’s chief executive publicly connected the incident to the same actor within hours, citing network-level evidence, which is a faster conclusion than most attribution work supports.

The technique behind such attributions is pattern recognition rather than proof: the reuse of infrastructure, the timing of activity, the choice of tooling, the habit of routing through a particular protocol, and in this case network identifiers consistent with a characteristic cluster. That is strong evidence in aggregate and is not the same as a signed confession. Its value is practical rather than forensic: it drives sanctions, it shapes how venues screen deposits, and it changes the political priority of an investigation.

The limit is worth stating because it is where expectations go wrong. Attribution does not recover assets, and it does not produce a defendant. It moves the problem from a technical puzzle to a diplomatic one, where the available instruments are sanctions and the willingness of third-country venues to cooperate, and it is the only path available once the funds have left the networks whose issuers have switches.

What a hack costs after the hack

The rest of the story belongs to the customers, and the sequence is instructive about what a venue actually sells. Withdrawals were restored asset by asset over about a week, beginning with bitcoin a few days after the incident, then ether, then the largest dollar token, with the remaining tokens, fiat and peer-to-peer services following into the next week.

In parallel, the venue reported that its protection fund had been restored above three hundred million dollars and published a reserve ratio of about one hundred and thirty-one percent across nineteen asset classes. Those two numbers are a solvency statement, and what holders actually needed was a liquidity statement. Being solvent while being unable to process withdrawals is the failure mode that has closed exchanges in the past, and the interval between the theft and the restoration of withdrawals is the metric that depositors feel, regardless of what the reserve ratio says.

The third-party losses in the same window are worth noting for scale. A separate exploit against an adapter used by a lending market drained a few hundred thousand dollars from two multisignature wallets, and several other incidents in the same fortnight involved compromised tooling rather than protocols. The category’s loss record is not dominated by sophisticated attacks on cryptography; it is dominated by the operational security of the entities holding keys.

The pattern across cases

Compare this route with the one used by large thefts five years ago and the professionalisation is visible. The standard route then was a direct deposit to a venue with weak controls, followed by conversion, followed by an attempt to withdraw before anyone noticed. That route now fails almost immediately, because deposit screening improved and because venues learned to watch for the specific pattern.

The current route has three parts: a cross-chain swap into a different asset, a spread across networks chosen for specific properties, and an exit negotiated through brokers and over-the-counter desks rather than through retail deposit channels. Each part compensates for a defence that was added after the previous generation of cases, which is why the attribution rate stays roughly flat even as the loss amounts grow.

What defenders can actually change

Four levers are available and the first is the most powerful of them. Issuers can freeze their own liabilities, and in cases where the stolen asset is still the token that was stolen, that power recovers value while it is moving. Everything downstream of the swap falls outside its reach, which suggests where response time matters most: the first hours, before the second hop.

The second lever belongs to venues, and it is screening with a delay rather than screening alone. A deposit that is credited after a wait is a deposit that can still be reversed when the analysis catches up. The third belongs to the protocols, and taking it means giving up the property that makes them useful; that is a choice for their communities rather than a flaw to be patched. And the fourth is the least discussed and most important: reduce the number of places where a single key can move a large balance, through multi-party signing, threshold schemes and the separation of duties that ordinary treasury operations have used for a century.

The uncomfortable implication is that the layers doing the most to reduce this category of loss are the ones with the least interesting architecture. A multisignature policy is not a protocol upgrade, and an enforced delay between request and transfer is not a consensus mechanism, and both make the theft itself harder than any downstream measure can.

Two things this case did not involve

What is missing from the route is as informative as what is in it, and two absences are worth naming for anyone trying to place the right defences.

The first is a bug. Nothing in the published account describes a flaw in a contract that was exploited, a signature scheme that was broken, or a consensus rule that was violated. The assets left wallets controlled by an organisation because access to those wallets was obtained, which places the entire episode in the category of operational security rather than in the category of protocol security. That distinction determines who has to change behaviour after it: auditors reviewing code cannot find an access path, and a firm reviewing its key management can.

The second is a chain-level intervention. No reorganisation was attempted, no validator set was asked to censor, and no coordinated rollback was proposed. The networks behaved exactly as designed throughout, which means the recovery options available in this case were the ones available in every case: what an issuer can freeze, what a venue can refuse, and what an investigator can reconstruct. A theft that required a chain to do something unusual would be a different story with different politics.

Those two absences explain the shape of the response. When the failure is access rather than code, the remedies are procedural: multi-party signing, delays between request and transfer, segregation of duties, and the unglamorous review work that no product announcement describes. Every one of those measures is older than the industry and none of them requires a protocol change, which is why the losses in this category keep happening to organisations that have not adopted them.

Three questions for the next report of this kind

The value of following a route is that it converts a large number into three answerable questions. Which networks did the value pass through, and were any of them issuers with a switch over their own token? What asset did it become, and how many hops were required before it was no longer the thing that was stolen? And how long was the interval, which is the variable that decides whether any of the answers still matter by the time they are found.

A theft of this size is a failure of custody before it is anything else, and everything in the sequence after the first step is the consequence of that failure becoming public. The route described here is not a sophisticated exploit of cryptography; it is a set of ordinary operations performed in a deliberate order by somebody who understood which parts of the system have switches and which do not. That understanding is available to anyone who reads the same public data, which is the reason the trace exists at all and the reason the next case will follow a similar shape with different names.

Blockchain

Why Blast Is Shutting Down: The Economics of an L2 That Couldn't Pay for Itself

2026-10-3 10:10:02

Blockchain

What Is Web3? A Claim About Ownership, Tested One Layer at a Time

2026-10-3 12:34:44

0 comment A文章作者 M管理员
    No Comments Yet. Be the first to share what you think
❯
Profile
Cart
Coupons
Check-in
Message Message
Search