Where’s my crypto, Dude? The Ultimate Guide to Crypto Money Laundering

2025-08-09 Microsoft

https://media.defcon.org/DEF%20CON%2033/DEF%20CON%2033%20presentations/Thomas%20Roccia%20-%20Where%E2%80%99s%20My%20Crypto%2C%20Dude%20The%20Ultimate%20Guide%20to%20Crypto%20Money%20Laundering%20%28and%20How%20to%20Track%20It%29.pdf

Attachments

Thomas20Roccia20-20WhereE28099s20My20Crypto2C20Dude20The20Ultimate_DRjKi72.pdf (56 MB)

The DEF CON material uses the February 2025 Bybit theft as a case study for tracing large-scale cryptocurrency laundering after a manipulated transaction changed the Safe wallet execution path and enabled attacker-controlled transfers. It describes rapid conversion of tokenized assets into ETH, dispersal across dozens and then thousands of wallets, cross-chain movement into Bitcoin and Tron, and use of DEXs, bridges, no-KYC exchanges, mixers, CoinJoin, and OTC networks. The excerpt highlights investigative opportunities such as clustering similar gas and timing patterns, monitoring bridge events, reconstructing DEX swap paths, matching eXch deposit and withdrawal flows, and correlating ETH-to-BTC movements. DPRK-specific content is limited to tracking guidance that recommends labeling known DPRK wallets and watching bridge activity, so the material is most useful as laundering tradecraft context rather than a standalone attribution source.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN lukka.tech 2025-08-09 2025-08-09

Related Reports

« Back