A report from blockchain analytics firm Chainalysis argues that cryptocurrency exchange hacking is far more concentrated than many in the industry may assume. According to the company, just two prominent hacker groups are tied to at least 60% of all publicly reported exchange hacks, and together they have stolen roughly $1 billion in cryptocurrency to date.
The findings, originally presented as part of Chainalysis’ broader crypto crime research, suggest that exchange-related cybercrime has become the most lucrative category in the digital asset ecosystem. By tracing the behavior of stolen funds and comparing laundering patterns across incidents, the researchers concluded that a relatively small number of professional actors appear to dominate the most damaging attacks on trading platforms.
Two groups, different methods
Chainalysis said the incidents attributed to the two groups averaged about $90 million per hack, underscoring the scale of losses a single successful breach can inflict on the market. While the report does not publicly name the actors, it distinguishes them by organizational behavior and likely motivation.
The first group is described as a “giant, tightly controlled organization,” one that may be motivated by more than financial gain alone. That characterization implies a higher degree of operational discipline and coordination, as well as the possibility that some attacks could serve strategic or political objectives in addition to profit.
The second group, by contrast, is portrayed as smaller and less structured, but highly focused on making money. Chainalysis said this group appears less concerned with avoiding detection, suggesting a more opportunistic operating style centered on speed and monetization rather than deep concealment.
Even with those differences, the report’s central conclusion is the same: exchange hacks are not a diffuse threat coming from countless unrelated actors. Instead, a substantial share of major thefts appears to be driven by a narrow set of sophisticated offenders with repeatable methods.
Hacking remains the most lucrative crypto crime
Chainalysis’ report frames hacking as the dominant form of crypto crime by economic impact. The company said hacking “dwarfs” other categories of digital asset crime and remains the most profitable avenue for illicit actors. The combination of large custodial pools, uneven security practices, and cross-border settlement rails continues to make exchanges especially attractive targets.
That conclusion matters because it shifts the policy and compliance conversation. Rather than viewing exchange hacks as isolated technical failures, the report suggests they should also be seen as part of a mature criminal economy, one in which a small number of professional groups repeatedly exploit the ecosystem and then funnel proceeds through conversion channels.
Chainalysis also warned that, given the level of potential reward, there is little reason to expect the activity to fade on its own. As long as attackers can extract significant value and find paths to liquidate stolen assets, the incentive to continue will remain strong.
Where stolen crypto goes after the hack
One of the report’s most important findings concerns the post-theft lifecycle of stolen cryptocurrency. Chainalysis said that at least 50% of stolen funds were cashed out through some form of conversion service within 112 days of the hack. That indicates a relatively compressed monetization window, with attackers often moving to convert or reposition assets within months rather than years.
Among the destinations identified by the researchers, 64.3% of stolen funds were sent to centralized cryptocurrency exchanges. Another 11.9% moved to peer-to-peer exchanges, while the remaining 23.8% flowed through other services, including mixing tools, bitcoin ATMs, and gambling platforms.
Those figures reinforce an uncomfortable reality for the industry: centralized exchanges are not only prime hacking targets, they are also major exit points for laundering stolen crypto. In practice, that means exchange compliance teams sit at a critical chokepoint in the movement of illicit funds.
Why exchanges keep processing stolen funds
Chainalysis explained that exchanges often process stolen assets not necessarily because they are ignoring illicit activity, but because the provenance of those funds can be difficult to identify without specialized monitoring tools. Unless the receiving platform is the one that was directly hacked, the incoming coins may appear to come from legitimate owners on-chain.
That challenge is structural. Blockchain transactions are transparent, but transparency alone does not equal easy attribution. A token transfer can look ordinary unless it is enriched with investigative data, heuristics, and clustering analysis that reveal links to a known breach. Without that layer of intelligence, distinguishing compromised assets from ordinary customer activity can be difficult in real time.
The report therefore points to a broader compliance gap in the market: many services may be touching stolen funds before they fully understand their origin. For exchanges, that creates legal, reputational, and operational risk, especially in a climate of increasing regulatory scrutiny around anti-money-laundering controls.
Compliance tools move to the forefront
Against that backdrop, Chainalysis highlighted its push into transaction monitoring. The company recently announced Know Your Transaction, or KYT, for stablecoins, a compliance product designed to track transactions from issuance to redemption. While that launch was mentioned separately from the hacking findings, the connection is clear: as illicit flows increasingly move through mainstream digital asset infrastructure, monitoring tools are becoming central to exchange risk management.
The report does not claim that analytics alone can stop exchange hacks. Security architecture, custody design, internal controls, and incident response all remain essential. But Chainalysis makes the case that tracing and monitoring technology are now indispensable in limiting how effectively attackers can launder stolen funds after a breach.
A warning for the crypto industry
The broader takeaway from the report is that the exchange sector remains under sustained pressure from highly capable adversaries. If two groups can account for a majority of publicly reported hacks, then the industry is facing not just a cybersecurity challenge, but a concentration of adversarial expertise that can repeatedly target weak points across platforms.
For exchanges, the implications are immediate: stronger defenses are necessary, but so are better detection systems for suspicious inflows after an incident occurs elsewhere. For regulators and compliance teams, the findings support closer attention to conversion services, especially centralized trading venues that continue to serve as key gateways between stolen crypto and broader liquidity.
Ultimately, the Chainalysis report presents a stark picture. A small set of organized actors has allegedly extracted about $1 billion from the exchange ecosystem, and much of that value has moved through services designed for legitimate financial activity. That combination of concentrated criminal capability and accessible laundering routes helps explain why exchange hacking remains one of the defining risks in crypto.

