Blockchain analytics firm Chainalysis says just two hacking groups account for the majority of cybercrime targeting cryptocurrency exchanges, with combined thefts reaching roughly $1 billion so far. According to the report, those groups are linked to at least 60% of all publicly reported crypto exchange hack losses, underscoring how concentrated and professionalized exchange-focused attacks have become.
Two groups, outsized impact
Chainalysis said its conclusions were based in part on analyzing the laundering behavior used after thefts took place. By studying how stolen assets moved through the crypto ecosystem, researchers were able to identify patterns that pointed to two distinct groups operating behind a large share of major incidents.
On average, the hacks attributed to these two groups involved around $90 million per incident. The report describes one of the groups as a large, tightly controlled organization that may not be motivated purely by profit. The second group is portrayed as smaller and less organized, but intensely focused on making money and less concerned about avoiding detection.
In Chainalysis’ view, hacking remains the most lucrative category of crypto-related crime. The company argues that the scale of returns available from exchange breaches means such attacks are unlikely to stop anytime soon. For the broader market, that conclusion is significant: the threat is not diffuse or random, but concentrated among a small number of highly capable actors.
Most stolen crypto is cashed out through exchanges
The report also highlights what happens after an exchange is hacked. Chainalysis found that at least 50% of stolen funds were converted into other assets or cashed out through some kind of conversion service within 112 days of the theft.
Among those flows, centralized cryptocurrency exchanges were the dominant destination. Chainalysis said 64.3% of stolen funds were sent to centralized exchanges, while 11.9% went to peer-to-peer exchanges. The remaining 23.8% passed through other conversion channels, including mixing services, bitcoin ATMs, and gambling sites.
That finding places centralized platforms at the center of the post-hack laundering process. In practical terms, exchanges often become the point where illicit crypto can be swapped into fiat currency or into other digital assets. This does not necessarily mean exchanges are knowingly facilitating criminal activity; rather, the report suggests that, without specialized tools, distinguishing stolen funds from legitimate holdings can be extremely difficult.
Chainalysis notes that unless a platform is the exchange that was directly hacked, the stolen assets may appear to originate from legitimate owners. On-chain movements alone do not always make the theft obvious. That ambiguity is one reason compliance systems and forensic blockchain analysis have become increasingly important for crypto businesses.
Why detection remains difficult
The report points to a structural challenge in crypto investigations: stolen assets can move quickly, and they often enter mainstream venues before red flags are fully identified. When funds are routed through major exchanges, peer-to-peer markets, or ancillary services such as mixers and gambling platforms, tracing and interdiction become more complex.
For exchanges, this creates both an operational and regulatory problem. If illicit proceeds can resemble ordinary customer deposits, then platforms need stronger transaction monitoring to identify suspicious behavior in time. The issue is especially acute in a cross-border market where funds can be shifted across services and jurisdictions within hours.
Chainalysis’ broader message is that exchange security cannot be viewed only as a matter of preventing the initial breach. The downstream movement of stolen funds is equally important. Once assets leave the hacked venue, the ability of the wider ecosystem to detect, freeze, or flag those funds becomes a central line of defense.
Compliance tools gain importance
The report arrives as monitoring and anti-money laundering tools are becoming more embedded in digital asset markets. Chainalysis recently announced Know Your Transaction, or KYT, for stablecoins, an AML compliance solution designed to monitor stablecoin transactions from issuance to redemption.
While that product announcement is separate from the exchange hacking findings, it reflects the same broader industry trend: the need for more granular visibility into how funds move on-chain. As stolen assets increasingly pass through conventional crypto infrastructure, analytics and compliance tools are no longer optional additions for major platforms. They are becoming core components of exchange risk management.
For market participants, the report is a reminder that crypto crime is not only about anonymous wallets or obscure dark-market activity. A large share of illicit proceeds ultimately intersects with regulated or semi-regulated services. That means exchanges, investigators, and compliance teams are all part of the response network.
A concentrated threat to the exchange sector
Perhaps the most striking conclusion from the report is the concentration of responsibility. If two organized groups truly account for the bulk of major exchange thefts, then the exchange-hacking problem is less a story of countless isolated attackers and more a story of a few repeat offenders operating at scale.
That concentration cuts both ways. On one hand, it shows how dangerous skilled and persistent groups can be in a market where a single successful intrusion can produce enormous returns. On the other hand, it suggests that better intelligence-sharing, pattern recognition, and coordinated monitoring may have an outsized impact if those same groups continue to reuse laundering pathways or operational habits.
Overall, the Chainalysis findings present a stark picture of the crypto security landscape: exchange hacks remain the most profitable form of crypto crime, the sums involved are enormous, and the laundering process frequently runs through familiar market infrastructure. For exchanges and service providers, the message is clear—security, surveillance, and transaction monitoring must evolve as quickly as the attackers targeting the sector.

