THORChain is being flagged as a key route for hackers to move stolen funds
THORChain has become a primary conduit for laundering hundreds of millions in stolen cryptocurrency, with the latest KelpDAO exploit alone generating nearly $1 million in protocol fees in 36 hours. For institutional investors, the protocol’s role as a cross-chain bridge without identity verification creates regulatory risk and raises questions about whether decentralized finance platforms can operate at scale without compliance infrastructure.
- KelpDAO attacker moved all 75,701 ETH ($175 million) through THORChain within 36 hours, generating $910,000 in protocol fees
- Recent major exploits totaling over $1.6 billion from FTX, Bybit, Balancer, and KelpDAO have all routed stolen funds through THORChain
- THORChain’s lack of know-your-customer checks and intermediaries enables rapid cross-chain asset transfers from Ethereum to Bitcoin, where tracing becomes more difficult
- $910,000 Fees earned by THORChain from KelpDAO incident alone in 36 hours
- $1.6B+ Stolen funds from multiple exploits routed through protocol this year
- $540M Swap volume on THORChain in single 24-hour period during recent attack
THORChain, a decentralized cross-chain bridge protocol, has emerged as a primary exit route for hackers moving stolen digital assets across blockchain ecosystems.
On-chain analysis reveals that multiple high-profile exploits, including the FTX attacker ($124 million), Bybit hacker ($1.2 billion+), Balancer exploiter ($120 million), and most recently the KelpDAO attacker ($175 million), have systematically funneled illicit funds through THORChain’s rails.
The pattern reflects a deliberate operational choice by attackers seeking to exploit the protocol’s defining feature: the ability to swap assets across chains without intermediaries, identity verification, or traditional financial controls.
The financial incentives have aligned perfectly. During the KelpDAO incident alone, THORChain generated approximately $910,000 in protocol fees within 36 hours, nearly surpassing its entire previous month’s fee generation of $709,000. Daily swap volume on the protocol hit $540 million during peak attack activity, generating an additional $660,000 in fees during that 24-hour window.
The protocol continues to maintain an operational stance of neutrality, collecting fees while hundreds of millions in demonstrably stolen funds transit its infrastructure.
KelpDAO attacker splits 75,701 ETH across wallets to obscure transaction trail
According to Arkham Intelligence data, the KelpDAO attacker adopted a deliberate fragmentation strategy to complicate on-chain forensics. The stolen funds were split across three separate Ethereum wallets, each holding approximately 25,000 ETH worth $57-59 million.
By distributing the assets rather than holding them in a single address, the attacker reduced the visibility of the total haul and created multiple entry points into laundering infrastructure.
Only one of the three wallets has actively initiated the cash-out process. That wallet’s balance declined rapidly from 25,000 ETH to approximately 3,800 ETH as assets were moved onward, with on-chain data showing nearly 99% of the funds have already transited out of that address.
A substantial portion of those proceeds have already been bridged into Bitcoin using THORChain’s cross-chain swap functionality. The attacker completed the full swap of all 75,701 ETH through THORChain, demonstrating both the speed and volume capacity of the protocol to process large illicit transactions without friction.
This exit velocity stands in stark contrast to traditional financial system latency. A conventional wire transfer or banking sanction typically involves multiple verification steps and clearing periods. THORChain processed the entire KelpDAO transfer in hours, with minimal on-chain delays between detection and asset dispersal.
For institutional investors managing custodial assets or evaluating counterparty risk, the protocol’s efficiency as a laundering vehicle has begun to factor into broader concerns about cross-chain bridge security and regulatory compliance frameworks.
Arbitrum Security Council’s $71 million asset freeze accelerates attacker’s laundering timeline
The Arbitrum Security Council’s decision to freeze 30,766 ETH (approximately $71 million) linked to the exploit created immediate pressure on the attacker’s operational strategy. The freeze, though only partial relative to the total theft, required governance votes for any potential recovery and effectively removed that portion of stolen funds from immediate access.
The attacker responded by accelerating its use of THORChain and other laundering routes rather than waiting for market conditions or attention to fade.
This dynamic reveals an ongoing structural tension in decentralized finance between protocol-level intervention and the decentralization principle. When individual chains or protocols take defensive action, whether through freezes, governance votes, or asset locks, attackers respond by shifting to less transparent channels and faster execution timelines.
The more sophisticated laundering infrastructure becomes, the more it pressures protocols like THORChain that offer speed and anonymity as core features. Attackers facing partial asset seizure have strong incentive to move remaining funds immediately rather than risk further freezes.
Historically, attackers have demonstrated patience, allowing compromised wallets to remain dormant for months before activating them when market attention wanes. The Arbitrum intervention appears to have collapsed that timeline in this case, forcing the attacker into immediate action and rapid routing through THORChain’s cross-chain bridges.
For institutional investors operating on Arbitrum or other Layer 2 networks, the precedent suggests that security interventions may inadvertently accelerate criminal cash flow to more opaque protocols rather than containing it.
THORChain’s Bitcoin exit route exploits UTXO model to fragment transaction tracing
The attacker’s choice to route Ethereum assets into Bitcoin via THORChain reflects a deliberate exit strategy grounded in blockchain architecture. Bitcoin’s UTXO (unspent transaction output) model creates fundamentally different transaction tracing patterns than Ethereum’s account-based system.
While Ethereum transactions leave clear on-chain footprints connecting addresses and fund flows, Bitcoin transactions can be fragmented and mixed more easily due to the nature of UTXO mechanics and the maturity of Bitcoin privacy infrastructure.
THORChain’s role as the bridge between these ecosystems matters precisely because it eliminates intermediary review at the conversion point. Traditional centralized exchanges require identity verification and sanctions screening before converting between major assets. They maintain compliance teams and freeze accounts linked to exploits.
THORChain, by design, performs none of this work. The protocol treats all transactions as equivalent and operates without customer identification requirements or transaction review.
This architectural choice has made THORChain the preferred exit mechanism for high-value theft. The combination of speed, scale ($540 million daily volume during the attack), lack of intermediaries, and direct access to Bitcoin liquidity creates an efficient funnel from detected exploits to fragmented, harder-to-trace assets.
For institutional custodians and compliance teams, THORChain’s rapid processing of known stolen funds raises direct questions about whether the protocol should face regulatory pressure, asset freezes, or whether its business model remains sustainable if major protocols begin routing users away from it pending compliance upgrades.
The question facing THORChain and similar decentralized protocols is whether operational neutrality remains viable at scale when hundreds of millions in stolen funds flow through in weeks. Mantle’s pending proposal to contribute 30,000 ETH to Aave as a loan, alongside Lido’s separate 2,500 stETH donation announcement, suggests ecosystem projects remain engaged with protocol development despite the laundering activity. The concrete test will be whether major protocols like Ethereum, Arbitrum, or Layer 2 ecosystems implement additional bridge filtering, whether U.S. regulators issue guidance on cross-chain DEX compliance obligations, or whether THORChain’s fee model ultimately attracts regulatory intervention that forces architectural changes to its verification requirements.