An exchange-hack check traces whether a wallet received crypto stolen in exchange breaches such as Mt. Gox or FTX-era thefts; Plastron flags exchange-hack fund exposure free across seven EVM chains.
Exchange Hack Funds Exposure Check
Stolen funds from Mt. Gox, Bitfinex, KuCoin, and Bybit still circulate on-chain. On-chain traces are permanent and visible to every exchange.
The history of cryptocurrency exchange hacks spans over a decade, from Mt. Gox's collapse in 2014 through the Bybit hack in 2025. Mt. Gox alone resulted in 850,000 BTC stolen, most of which has never been recovered and continues to generate compliance concerns as partial distributions to creditors occur. The 2016 Bitfinex hack produced 119,756 BTC in stolen funds that moved slowly through laundering operations until the 2022 DOJ seizure. The 2020 KuCoin hack produced $281 million in stolen tokens distributed through DEX protocols. The 2025 Bybit hack produced $1.5 billion attributed to Lazarus Group. Each of these hacks left on-chain traces that persist in blockchain analytics databases. Funds from exchange hacks move differently from DeFi exploit funds: exchange hackers often hold stolen assets for years before attempting to launder, making the exposure distribution slower and more diffuse. Stolen exchange funds that have been in circulation long enough to reach ordinary DeFi protocols, P2P trades, or exchange deposits create compliance exposure that can surface years after the original hack. Understanding whether any of your counterparties trace back to major exchange hacks is important for anyone who has been active in DeFi or peer-to-peer trading over the past decade.
How Plastron Helps
Multi-Exchange Hack Coverage
Plastron's database covers known wallet addresses associated with major exchange hacks including Bitfinex 2016, KuCoin 2020, and Bybit 2025, sourced from Forta labelled-datasets and community threat intelligence. Counterparties matching these addresses are flagged as stolen fund exposure with severity reflecting the hack's scale and OFAC designation status.
Lazarus-Linked Exchange Hack Priority
The Bybit 2025 hack and portions of the Ronin Bridge hack involved Lazarus Group — OFAC-designated addresses. Exchange hack exposure linked to DPRK-attributed addresses receives a dual classification: stolen funds and OFAC sanctions. These are the highest-severity cases because they create mandatory compliance obligations beyond ordinary AML risk.
Historical Fund Flow Analysis
Exchange hack funds can take years to reach ordinary wallets through laundering operations. Plastron analyzes your full available transaction history — up to 1,000 transactions — and checks all counterparties against hack fund databases regardless of when those transactions occurred. Historical exposure to hack funds that was once obscure may become a compliance issue as analytics tools improve.
Risk Categories We Screen
Frequently Asked Questions
Related Screening Tools
Screen Your Wallet Now
Connect your wallet and get a full risk report in under 30 seconds. Free, non-custodial, and completely private.