On 21 February 2025, approximately $1.46 billion in cryptocurrency left a Bybit cold wallet, marking the largest theft in the digital assets market.

Within minutes, the stolen assets started moving between wallets. Elliptic identified and labelled the initial addresses within 18 minutes of Bybit confirming the attack. Chainalysis and other blockchain intelligence firms subsequently tracked the assets through multiple addresses, assets and networks.

The initial theft was easy to identify, but with each subsequent transaction, the value became increasingly harder to attribute. In this article, you will follow the stolen funds after the initial theft and look at how investigators trace their value across wallets, assets, chains and services.

Following the value

A direct transfer from a victim's wallet provides a clear starting point. The sender, recipient, amount and time are all recorded on-chain.

But then the trail becomes more complicated after an asset is exchanged or moved to another network. Stolen ETH becomes another token. That token is then bridged and distributed across several wallets and exchanged again. Some funds will later be combined with assets from unrelated transactions.

While after theft, every transaction remains visible on-chain, the relationship between the original theft and the funds several steps later becomes less and less direct.

That distinction drives most large-scale crypto tracing investigations. Analysts, during work both follow tokens and addresses, as well as do a much harder job reconstructing the movement of value and assets. A separate track of work is judging how strongly each subsequent transaction can be linked to the original source.

In Bybit's case, Hacken's forensic investigation first established how the assets were stolen. It found no vulnerability in Ethereum or the underlying multisig contract. Instead, an adversary used malicious JavaScript introduced into resources used by the Safe signing interface, causing authorised signers to approve a transaction whose underlying instruction transferred control to the attacker.

Once the assets had left the wallet, the investigation became a different problem. Elliptic traced them through multiple chains, decentralised exchanges, and other services, later reporting that approximately $200 million in stolen funds had passed through eXch, a no-KYC exchange service, before it was shut down.

The first hours create the best opportunities

Researchers reported identifying the initial Bybit-related addresses within 18 minutes. In one case, approximately $150,000 in stolen funds reached an exchange and was subsequently frozen and seized after the exposure was identified.

Other portions of stolen value continued to be laundered. Chainalysis later described a separate investigation in Greece that traced and froze a portion of the stolen Bybit assets, resulting in the country's first cryptocurrency seizure.

But time also plays against the defenders, as the funds move through more wallets, assets and chains. Each conversion creates another relationship to reconstruct, while each new service introduces another point at which investigators may need cooperation.

Five ways to make assets harder to follow

Attackers cannot simply disappear on-chain. Even when funds pass through mixers and other services, the transactions remain visible. What attackers can do is make the connection between the original theft and the eventual destination increasingly difficult and time-consuming to reconstruct.

They use several services to do so:

  • A DEX can change the asset.
  • A bridge can move it to another chain.
  • New wallets can split the funds across separate paths.
  • An OTC transaction can introduce counterparties whose details are not visible on-chain.
  • An exchange can pool deposits from multiple users, while a mixer can obscure the direct relationship between deposits and withdrawals.

The investigator, therefore, has to follow the value rather than wait for the original asset to reappear.

Hacken's analysis of the 2026 Abracadabra exploit shows how quickly that distinction matters. Approximately $1.79 million in MIM was exchanged for around 395 ETH, after which the funds were split across 46 Tornado Cash deposits over approximately 22 hours. Following the original MIM transactions alone would no longer describe where the stolen value had gone.

The same problem limits static address screening. A known attacker address is useful, but funds can move into new wallets before that address is identified or added to an industry-wide AML blocklist. The behaviour of those wallets then becomes part of the investigation: how quickly did the funds arrive, were they split, which assets did they become, and which services did they reach?

That context also prevents a simple conclusion that every exposed address belongs to a criminal operation. Bridges, exchanges, and DEXs process legitimate activity at scale, and a wallet can receive assets with some historical connection to a theft without knowing their origin.

Sometimes investigations point to the wrong wallet

A wallet can receive stolen funds without belonging to the attacker. An exchange can hold both illicit and legitimate assets. A bridge can connect thousands of unrelated transactions. Even a direct exposure can be the result of an intermediary rather than intent.

That makes misattribution one of the risks of on-chain investigation. Treating every connection as proof can turn a useful lead into a false positive, divert attention from the actual flow of funds, and trigger compliance action against the wrong counterparty.

Experienced investigators, therefore, separate exposure from attribution. They look at transaction proximity, timing, asset movements, and wallet behavior before deciding what a connection means.

The investigation continues after the exploit

Tracing stolen funds is painstaking work. Every swap, bridge, new wallet and intermediary adds another relationship to reconstruct. In the first minutes and hours, however, that work can make the difference between watching funds move and stopping them.

The Bybit investigation shows how quickly that window can close. Within minutes of the attack being confirmed, investigators had identified the initial addresses, and real-time intelligence helped an exchange freeze and seize approximately $150,000 in stolen funds. Other portions took a very different route: more than $1 billion had been laundered within six months, with portions eventually reaching Tron, being converted to USDT, and cashed out through suspected Chinese OTC services.

Obviously, teams do not track these transactions in explorers by hand. They use on-chain monitoring and risk intelligence to follow activity at scale, identify suspicious patterns and flag transactions while there is still time to act. And the same logic applies before an exploit: security testing, code review and operational controls can reduce the number of ways an attacker can get in or move laterally once they do.

This is where the different parts of security start to overlap. Smart contract audits, penetration testing, and secure code review address technical attack vectors. Governance and operational security, including frameworks such as NIS 2, SOC 2, and ISO 27001, address how organisations manage security beyond the code. Monitoring and risk intelligence, through tools such as Extractor and CORE3 Enterprise, help teams spot and respond to on-chain activity.

The better outcome is not to have to trace the funds in the first place.

Sources used:

Hacken, Bybit Hack Investigation: The Biggest Crypto Heist in History; Hacken, Q2 2026 Security and Compliance Report; Hacken, Abracadabra (MIM) $1.8M Hack Explained; Chainalysis, 2025 Crypto Theft Reaches $3.4 Billion and its analysis of the Bybit fund flows; and Elliptic, Bybit Exploit Six Months On.

By Popoola Kayode (Popeblack)

Popoola Kayode, known professionally as Popeblack, works across Web3 business development, blockchain intelligence, and financial crime. His interests include AML, crypto investigations, digital asset compliance, blockchain infrastructure, and the evolving relationship between cybersecurity and financial crime.