A stolen-funds check traces whether a wallet received crypto linked to hacks, exploits or thefts; Plastron flags stolen-fund exposure free across seven EVM chains, showing the specific counterparties behind the link.
Stolen Funds Exposure Check
Billions in stolen crypto still circulate through DeFi. Your wallet may have received exploit funds without knowing.
Cryptocurrency exchange and protocol hacks have produced billions of dollars in stolen assets that continue to circulate through the ecosystem years after the original theft. The Ronin bridge hack produced $625 million in stolen ETH and USDC in 2022; the Bybit hack in 2025 produced $1.5 billion; Mt. Gox, Bitfinex 2016, and dozens of DeFi protocol exploits add further billions to the total. Hackers move stolen funds through complex paths: multiple intermediary wallets, DEX swaps, bridge crossings, and mixing services are all employed to obscure the origin. These funds eventually reach ordinary wallets through liquidity pools, yield farming rewards, P2P trades, and token purchases. A wallet that received ETH from a pool where a hacker deposited funds may carry stolen fund exposure that appears in blockchain analytics — even though the recipient had no knowledge of the hack. This indirect exposure creates real compliance risk. Exchanges including Binance, Coinbase, and Kraken have frozen accounts with stolen fund exposure following major hacks as they work through the trace analysis. The Ronin hack in particular resulted in widespread account holds because Lazarus Group funds moved rapidly through mainstream DeFi protocols before exchanges could identify and block the addresses. Screening your wallet against known exploit and hack fund addresses is the essential step in understanding this exposure.
How Plastron Helps
Hack Fund Database Coverage
Plastron's known-address database includes exploit and hack fund addresses from Forta's labelled datasets, covering Ethereum mainnet hack contracts, heist addresses, and phish-hack-related wallets. This is one of the most comprehensive freely available hack fund address databases, covering hundreds of major protocol exploits. Direct counterparty matches flag at High or Critical severity depending on the hack's OFAC status.
Lazarus Group and DPRK Exposure Detection
North Korean hacking group Lazarus is responsible for several billion-dollar thefts including Ronin and Bybit. Their addresses are OFAC-designated, meaning any wallet with direct Lazarus exposure carries both a stolen fund flag and a sanctions flag simultaneously. We maintain updated Lazarus-associated addresses and flag them at Critical severity with specific OFAC SDN references.
Indirect Exposure Tracing
Hack funds move through intermediary wallets before reaching ordinary users. Plastron traces your counterparty graph and flags any addresses in your transaction history that are directly linked to known hack addresses. The report shows the specific exploit source, the volume of your indirect exposure, and how many hops separate your wallet from the original theft.
Risk Categories We Screen
See It in Action
Real public wallets relevant to this topic. Click any to run a live scan.
Frequently Asked Questions
Related Screening Tools
Screen Your Wallet Now
Connect your wallet and get a full risk report in under 30 seconds. Free, non-custodial, and completely private.