Answer

A stolen-funds check traces whether a wallet received crypto linked to hacks, exploits or thefts; Plastron flags stolen-fund exposure free across seven EVM chains, showing the specific counterparties behind the link.

Stolen Funds Exposure Check

Billions in stolen crypto still circulate through DeFi. Your wallet may have received exploit funds without knowing.

Cryptocurrency exchange and protocol hacks have produced billions of dollars in stolen assets that continue to circulate through the ecosystem years after the original theft. The Ronin bridge hack produced $625 million in stolen ETH and USDC in 2022; the Bybit hack in 2025 produced $1.5 billion; Mt. Gox, Bitfinex 2016, and dozens of DeFi protocol exploits add further billions to the total. Hackers move stolen funds through complex paths: multiple intermediary wallets, DEX swaps, bridge crossings, and mixing services are all employed to obscure the origin. These funds eventually reach ordinary wallets through liquidity pools, yield farming rewards, P2P trades, and token purchases. A wallet that received ETH from a pool where a hacker deposited funds may carry stolen fund exposure that appears in blockchain analytics — even though the recipient had no knowledge of the hack. This indirect exposure creates real compliance risk. Exchanges including Binance, Coinbase, and Kraken have frozen accounts with stolen fund exposure following major hacks as they work through the trace analysis. The Ronin hack in particular resulted in widespread account holds because Lazarus Group funds moved rapidly through mainstream DeFi protocols before exchanges could identify and block the addresses. Screening your wallet against known exploit and hack fund addresses is the essential step in understanding this exposure.

How Plastron Helps

Hack Fund Database Coverage

Plastron's known-address database includes exploit and hack fund addresses from Forta's labelled datasets, covering Ethereum mainnet hack contracts, heist addresses, and phish-hack-related wallets. This is one of the most comprehensive freely available hack fund address databases, covering hundreds of major protocol exploits. Direct counterparty matches flag at High or Critical severity depending on the hack's OFAC status.

Lazarus Group and DPRK Exposure Detection

North Korean hacking group Lazarus is responsible for several billion-dollar thefts including Ronin and Bybit. Their addresses are OFAC-designated, meaning any wallet with direct Lazarus exposure carries both a stolen fund flag and a sanctions flag simultaneously. We maintain updated Lazarus-associated addresses and flag them at Critical severity with specific OFAC SDN references.

Indirect Exposure Tracing

Hack funds move through intermediary wallets before reaching ordinary users. Plastron traces your counterparty graph and flags any addresses in your transaction history that are directly linked to known hack addresses. The report shows the specific exploit source, the volume of your indirect exposure, and how many hops separate your wallet from the original theft.

Risk Categories We Screen

Stolen Funds
Wallets linked to hacks, exploits, and bridge attacks. Even receiving a fraction taints your address.
Sanctions
OFAC SDN, EU, and UN sanctioned addresses. Direct or indirect exposure flags your wallet instantly.
Darknet
Addresses associated with darknet marketplaces. Any connection triggers heightened scrutiny at exchanges.
$3.8B
Crypto stolen in hacks in 2022 alone
Source: Chainalysis 2023 Crypto Crime Report
$1.5B
Stolen in the Bybit 2025 Lazarus hack
Source: Bybit and on-chain analysis
668
Exploit and heist addresses in Plastron's database from Forta
Source: Forta labelled-datasets

See It in Action

Real public wallets relevant to this topic. Click any to run a live scan.

Ronin Bridge Exploiter
0x098b716b8aaf21512996dc57eb0615e2383e2f96
Stole $625M from the Ronin bridge in March 2022. OFAC-attributed to North Korea's Lazarus Group. One of the largest DeFi hacks on record.
Scan this wallet
Wormhole Bridge Exploiter
0x629e7da20197a5429d30da36e77d06cdf796b71a
Exploited the Wormhole bridge for $325M in February 2022. Flagged as a critical-severity hack exploit address in the stolen funds category.
Scan this wallet

Frequently Asked Questions

Related Screening Tools

Exchange Hack Funds Check — Hack Exposure ScreeningNorth Korea Crypto Check — Lazarus Group ScreeningDeFi Hack Exposure Check — Protocol Exploit DetectionFree AML Screening for Crypto Wallets | PlastronEthereum Wallet Check — Screen ETH for Risk

Screen Your Wallet Now

Connect your wallet and get a full risk report in under 30 seconds. Free, non-custodial, and completely private.

Explore More

Free AML Screening for Crypto Wallets | PlastronWallet Risk Check — Scan Before You DepositCrypto Compliance Check — Free Wallet ScanKYC Wallet Check — Screen Your Address FreeWallet Address Checker — Verify Any ETH Address