OAK — OnChain Attack Knowledge

Worked example · 2025-02

Bybit aftermath — $1.4B THORChain laundering — Ethereum → BTC / DAI — 2025-02 to 2025-03

Loss
indirect — the Bybit theft (~$1.5B) is the primary extraction event (see examples/2025-02-bybit.md). This example characterizes the downstream laundering flow: ~$1.4B of the Bybit-extracted ETH was laundered through THORChain's cross-chain swap infrastructure, converting ETH to BTC and DAI, over approximately 10 days.
Attribution
pseudonymous — no public actor attribution at OAK v0.1 cutoff.
Volume laundered
~$1.4B (the full Bybit-extracted ETH amount).
Time-to-launder
approximately 10 days from extraction to full conversion.
THORChain operator economics
node operators collectively earned at least ~$12M in fees from the laundering operation. The figure originates with Chainalysis ([chainalysisbybitthorchain]), with CoinDesk's reporting ([coindeskthorchainlazarus2025]) wrapping the Chainalysis number; cite Chainalysis as the primary source and CoinDesk as secondary. As of v0.1 the ~$12M figure rests primarily on the Chainalysis attribution; corroboration from Elliptic / TRM Labs has been published at the broader-volume level but not at the precise $12M-fee-accrual level. Status: verified-with-caveat — single primary source for the precise dollar figure, multi-source for the surrounding facts (Bybit attribution, ETH → BTC / DAI chain-hop pattern, ~10-day window).
OAK Techniques observed
OAK-T7.003 (Cross-Chain Bridge Laundering) — primary; OAK-T7.001 (Mixer-Routed Hop) — partial / earlier-stage hops where applicable + OAK-T7.007 (DEX-Aggregator Routing Laundering).
OAK-Gnn
OAK-G01 Lazarus Group / DPRK-attributed. Confirmed attribution: FBI IC3 PSA published 2025-02-26; corroborating industry forensic provider attributions.
Predicate
examples/2025-02-bybit.md — the original ~$1.46B Bybit extraction event.
Key teaching point
This case operationalises several of OAK's structural design choices. The Threat Actors axis (actors/OAK-G01-lazarus.md) lets the laundering case study link cleanly back to the predicate-extraction case study (examples/2025-02-bybit.md); the OAK-T7.003 Technique page captures the cross-chain bridge laundering pattern at the methodology layer; this worked example documents the headline-magnitude operational deployment of the methodology. Contributors writing future T7.003 cases should expect to follow the same predicate-event → Group-attribution → laundering-chain template, particularly for OAK-G01 cases where the same operator profile recurs across many predicate events.

Summary

This worked example covers the laundering chain downstream of the Bybit February 2025 extraction (the largest single crypto-theft event on the public record; see examples/2025-02-bybit.md for the extraction itself). Per Chainalysis ([chainalysisbybitthorchain]) — wrapped by CoinDesk's investigative reporting in [coindeskthorchainlazarus2025] — the OAK-G01 Lazarus Group laundered approximately $1.4B in Bybit-extracted ETH through THORChain over roughly 10 days following the February 21, 2025 extraction. The operational pattern is the canonical T7.003 cross-chain laundering chain: ETH on Ethereum was swapped through THORChain to Bitcoin or to bridge-redeemed stablecoins (DAI, USDC), with the canonical chain-hop being ETH → BTC → DAI within hours-to-days windows.

The case is OAK's modern canonical T7.003 example because the volume is unambiguous, the speed metric is published, the protocol-economics impact ($12M in fees to THORChain node operators) is on the public record, and the OAK-G01 attribution is confirmed at the FBI / Treasury / industry-corroboration level.

Timeline (UTC)

When Event OAK ref
2025-02-21 Bybit extraction event (~$1.46B ETH); see examples/2025-02-bybit.md for the on-chain manifestation and off-chain entry vector (predicate event — see linked example)
2025-02-21 onward (hours) Initial outbound hops from extraction-recipient addresses; some early-stage T7.001 mixer-routed hops where geographic / operational considerations applied T7.001 (partial)
2025-02-21 to 2025-03-03 (~10 days) Bulk of the ~$1.4B routed through THORChain in the canonical ETH → BTC → DAI / USDC chain-hop pattern T7.003 primary
2025-02-26 FBI IC3 PSA attributing the extraction to OAK-G01 Lazarus Group (which catalysed accelerated forensic attribution of the laundering chain) G01 confirmed attribution
2025-03-03 onward Downstream T7.002 CEX-deposit-address layering for the off-ramp from settlement assets back to fiat; outside the scope of this example but documented in industry tracking T7.002 (downstream)

What defenders observed

  • Speed metric: 10 days for $1.4B through a single primary laundering rail is operationally extraordinary. The pre-event THORChain compliance integration was minimal; post-event, the protocol-level reaction was constrained both by THORChain's decentralised architecture and by node-operator economic incentives (the $12M in fees was earned by the operators during the laundering, not penalised after).
  • Protocol-economics signal: the fee-accrual-correlated-with-attribution detection signal flagged in the OAK-T7.003 page is unambiguously visible here. A protocol-level monitoring posture that watched THORChain fee accrual against a known illicit-cluster watchlist would have surfaced the laundering activity within hours of extraction; the forensic attribution to OAK-G01 was already confirmed by day 5 (FBI IC3 PSA).
  • Post-event: industry reporting and academic write-ups on this case are still being published as of OAK v0.1 publication; the consolidated record is expected to be documented further in the Chainalysis 2026 Crypto Crime Report and in subsequent TRM and Elliptic investigative releases.

What this example tells contributors writing future Technique pages

  • T7.003 is now the dominant Lazarus laundering rail. Contributors writing post-2022 OAK-G01-attributed examples should expect cross-chain bridge laundering as the primary post-extraction path, with T7.001 mixer-routed hops as a partial / earlier-stage component rather than the dominant rail. The OAK-T7.001 page reflects this shift in its Discussion section.
  • Protocol-economics signals are real detection signals. When a laundering rail processes $1.4B in 10 days and the node operators earn $12M, the protocol-economics impact is itself an attribution-grade indicator that the protocol is being used as a laundering rail at the present moment. Contributors writing T7.003 examples should make the protocol-economics-signal angle explicit when the data is available.
  • OAK-Gnn attribution accelerates downstream forensic tracking. The five-day FBI attribution of Bybit to OAK-G01 catalysed accelerated forensic attribution of the laundering chain across forensic providers; without the attribution, per-transaction tracing would have been substantially slower. The compounding effect — confirmed attribution at the predicate event accelerates attribution at the downstream laundering events — is a structural argument for the Threat Actors axis.

Detection chain — forensic providers, government attribution, dollar accounting

This section makes the detection chain explicit so future T7.003 contributors can use it as a template for laundering-chain forensic write-ups. The Bybit case is the densest 2025 detection chain on the public record: FBI / OFAC / industry forensic providers all published attributions within roughly five days of extraction, and the per-hop dollar accounting is on the public record at sufficient granularity to ground a worked example.

  • Predicate-event attribution (2025-02-26, T+5). FBI Internet Crime Complaint Center (IC3) Public Service Announcement attributing the Bybit extraction to "TraderTraitor" (the FBI designation for DPRK / Lazarus cluster operating against crypto custodians). Published within five days of the extraction — one of the fastest authoritative attributions in the public record. The IC3 PSA is the load-bearing government-attribution document for the predicate event, and is the upstream that the laundering-chain attribution rests on.
  • Industry-forensic corroboration (T+0 to T+10). Chainalysis ([chainalysisbybitthorchain]), TRM Labs, Elliptic, and NCC Group all published independent forensic confirmations within the laundering window. TRM Labs's published number — at least ~$160M processed through illicit channels within 48 hours of extraction — provides the per-window dollar accounting that grounds the speed metric. Chainalysis's ~$12M THORChain operator-fee figure is the protocol-economics signal. Elliptic and NCC Group's wallet-cluster attribution provides the forensic-provider triangulation that supports the FBI attribution at the on-chain layer.
  • Investigative-journalism record. ZachXBT (community on-chain analyst) published continuous tracking through the laundering window, with per-transaction wallet-cluster attribution feeding into the broader forensic-provider record. CoinDesk's investigative reporting ([coindeskthorchainlazarus2025]) wraps the Chainalysis and TRM numbers into the consolidated public record. The ZachXBT-and-CoinDesk surface is the canonical 2025 investigative-journalism triangulation pattern; future T7.003 contributors should expect the same shape — community on-chain analyst surfaces per-transaction detail, mainstream investigative-journalism wraps the forensic-provider numbers into the public record.
  • Per-hop dollar accounting. The published numbers segment cleanly: ~$1.46–$1.5B extracted on 2025-02-21 (predicate); ~$160M+ moved through illicit channels within 48 hours per TRM Labs; ~$1.4B routed through THORChain in the canonical ETH → BTC → DAI / USDC chain-hop pattern over ~10 days; ~$35M routed through eXch (the non-KYC instant-exchange that subsequently shut down on 2025-05-01 — see examples/2025-04-exch-shutdown.md); ~$12M aggregate fee-accrual to THORChain node operators (Chainalysis). The detection signal is the protocol-economics correlation between THORChain fee accrual and DPRK-cluster wallet activity; a compliance posture watching this correlation against an OAK-G01-attributed watchlist would have surfaced the laundering activity within hours.
  • Recovery outcomes. No on-chain recovery of consequence at v0.1 freeze. The downstream OFAC SDN / civil-forfeiture surface is bounded by the laundering rail's structural properties: THORChain's decentralised architecture meaningfully constrains protocol-level intervention; eXch's non-KYC posture provided no compliance surface for tracing-then-freezing during the active laundering window. The recovery posture is therefore attribution-as-deterrence — the FBI / OFAC / industry-forensic record is sufficient to support downstream sanctions designations on laundering-rail infrastructure (eXch shutdown announcement on 2025-04-17 cites the U.S. DOJ whistleblower information referencing this case), but not sufficient to recover the laundered assets at the on-chain layer.

The detection chain's compounding effect — predicate-event attribution at T+5 catalysed accelerated forensic attribution of the laundering chain across forensic providers; the laundering-rail infrastructure attribution catalysed downstream sanctions / shutdown action against eXch and (subsequently) other laundering-rail operators — is the structural argument for the Threat Actors axis and for cataloguing laundering-rail operators (eXch, Sinbad, Garantex / Grinex) as first-class entities in the OAK corpus rather than merely as adjacent infrastructure to predicate events.

Public references

  • [chainalysisbybitthorchain] — Chainalysis primary attribution for the ~$12M THORChain node-operator fee-accrual figure during the Bybit-laundering window. Cite Chainalysis directly for the precise dollar figure rather than relying on the secondary CoinDesk wrap-up.
  • [coindeskthorchainlazarus2025] — CoinDesk investigative reporting on THORChain as Lazarus's preferred post-Bybit laundering rail; documents the 10-day full-laundering metric. CoinDesk wraps Chainalysis's underlying numbers; cite as secondary corroborating source for narrative facts.
  • [chainalysis2024laundering] — broader 2023–2024 evolution context (cross-chain bridges as a laundering category).
  • [fbiic3bybit2025] — FBI Internet Crime Complaint Center Public Service Announcement (2025-02-26) attributing the Bybit theft to "TraderTraitor" (DPRK / Lazarus cluster). Load-bearing government-attribution document for the predicate event; the upstream that the laundering-chain attribution rests on.
  • [trmlabsbybit2025] — TRM Labs investigative blog post on the Bybit laundering chain; primary source for the ~$160M-in-48-hours speed metric and the per-instant-exchange / per-mixer hop accounting.
  • [trilateraldprkstatement2025] — U.S.–Japan–ROK trilateral statement (2025-01-14, predating Bybit but establishing the multi-government attribution baseline that Bybit subsequently entered).
  • Cointelegraph — Crypto laundering evolves with Lazarus Group's bridge tactics — companion industry framing.

Discussion

This case operationalises several of OAK's structural design choices. The Threat Actors axis (actors/OAK-G01-lazarus.md) lets the laundering case study link cleanly back to the predicate-extraction case study (examples/2025-02-bybit.md); the OAK-T7.003 Technique page captures the cross-chain bridge laundering pattern at the methodology layer; this worked example documents the headline-magnitude operational deployment of the methodology. Contributors writing future T7.003 cases should expect to follow the same predicate-event → Group-attribution → laundering-chain template, particularly for OAK-G01 cases where the same operator profile recurs across many predicate events.

The unresolved policy question — whether T7.003 mitigation responsibility lives at the cross-chain bridge protocol layer or at the receiving-venue layer — is illustrated starkly by this case. THORChain's decentralised architecture meaningfully constrains protocol-level intervention; the dollar-loss-prevented metric in this case is bounded primarily by what the receiving CEXes did at off-ramp time. OAK does not opine; it documents that both layers had defensive surface and that whichever layer would have moved first would have prevented some fraction of the laundering.

Techniques demonstrated (3)