Join our Newsletter — 33% off our NHI Course

How should exchanges detect and stop laundering attempts that rely on chain hopping and OTC brokers?

Exchanges should combine real-time transaction monitoring, blockchain attribution, and escalation paths that can freeze suspicious deposits before they are traded or withdrawn. Chain hopping can obscure provenance by moving value across assets, but it does not remove traceability when investigators can follow the flow. The practical goal is to flag hacked-fund patterns early enough to stop conversion into liquid assets.

How Exchanges Should Detect Chain-Hopping and Broker-Layer Laundering

Exchanges need to treat chain hopping and OTC brokerage as a provenance problem, not just a payment screening problem. The practical control layer is a combination of transaction analytics, address and entity attribution, and rules that can hold funds when the incoming pattern matches known laundering paths before liquidity is provided. The key is to preserve the link between source, destination, and account behaviour long enough to act.

Because chain hopping is designed to fragment traceability, exchanges should look for behaviours that are unusual in combination, not only in isolation: rapid asset swaps, repeated bridging, short holding periods, and deposits that appear to arrive from clustered infrastructure or intermediary services. Broker involvement often shows up as timing regularity, repeated counterparties, and value that is structured to avoid obvious thresholds. The detection goal is not perfect certainty, it is early confidence that warrants intervention.

For the tracing layer, exchanges should rely on blockchain analytics, internal case management, and escalation paths that can route suspicious activity to compliance or investigations before the asset is withdrawn or converted. That is especially important when the laundering attempt uses multiple hops to create distance from the original source, because the defensive question becomes whether the exchange can still prove a material relationship between the deposit and the suspected illicit origin.

What Exchange Controls Matter Most When Value Is Routed Through Multiple Hops

A useful control design separates fast automated screening from slower adjudication. Automated monitoring should score deposits for hop count, bridge usage, newly activated accounts, broker-like aggregation patterns, and prior exposure to known illicit clusters. Investigators then need enough context to decide whether to freeze, delay, or allow the transaction. That split matters because trying to resolve attribution manually after withdrawal often leaves no practical recovery path.

Exchanges should also tune controls to the asset lifecycle, not just the deposit moment. If a suspicious flow is detected after a small initial deposit but before aggregation or conversion, the exchange has a chance to stop the laundering sequence before the funds become harder to trace. That is where real-time monitoring and rapid case escalation are most effective, because the adversary depends on speed and on the exchange treating each hop as a disconnected event.

Useful practice is to maintain a playbook for when to freeze, when to request enhanced due diligence, and when to file internal escalation for suspected laundering. When the same source wallet repeatedly feeds different exchange accounts, or when OTC counterparties appear to be acting as pass-through liquidity providers, the threshold for intervention should be lower. The point is to stop the conversion into liquid assets before the laundered value is dispersed.

Risk and Threat Considerations

Chain hopping and OTC brokerage matter because they reduce the time available for interdiction and increase the chance that bad funds look routine by the time they reach the exchange. The main exposure is not that traceability disappears, but that the exchange delays action long enough for the proceeds to be converted, withdrawn, or split across additional services.

Failure mechanism: Launderers exploit fragmented visibility across chains and intermediaries, then rely on operational delays, weak escalation, or overly permissive withdrawal handling to move value before investigators can correlate the hops into one case.

Impact: If the exchange cannot hold or freeze funds quickly enough, it can facilitate cash-out, lose recovery options, and create compliance and reputational exposure from missed interdiction opportunities.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK address the attack and risk surface, while CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
CIS Controls v8 CIS 8 — Audit Log Management Continuous monitoring of suspicious deposit and hop patterns depends on reliable logs and alerting.
CIS 13 — Data Protection Attribution and chain analysis rely on protecting transaction intelligence and case evidence from tampering.
Recommendation — Centralise and review transaction and case logs to detect suspicious cross-chain laundering patterns early. Protect transaction intelligence and investigation evidence so laundering cases remain trustworthy.
NIST CSF 2.0 DE.CM — Continuous Monitoring Real-time detection of suspicious transfers and broker-like behaviour aligns with ongoing monitoring.
RS.AN — Analysis Investigators must analyse traced flows and determine whether suspicious deposits should be frozen.
RS.MI — Mitigation Freezing suspicious deposits is a mitigation action that interrupts conversion into liquid assets.
Recommendation — Monitor transfers continuously and flag anomalous hop, bridge, and broker patterns for escalation. Analyse suspected laundering flows quickly and preserve the option to freeze assets before withdrawal. Apply containment actions fast enough to stop suspicious funds from being converted or withdrawn.
MITRE ATT&CK T1090 — Proxy Chain hopping and broker layering resemble proxying value through intermediaries to obscure source.
T1020 — Data Exfiltration The underlying issue is stealthy transfer of value out of reach before controls can intervene.
Recommendation — Map intermediary hops and relays as proxy-like concealment behaviour in detection logic. Detect and interrupt attempts to move value out of reach before the exchange can act.

Practitioner Guidance

What to prioritise: Put your fastest review path on the first point where suspicious funds enter your control, because that is usually the last practical place to stop conversion. If your tooling only scores risk after withdrawal eligibility, it is too late for most chain-hopping cases.

What to verify: Confirm that investigators can see hop history, bridge activity, cluster relationships, and account-to-account reuse in one case view. If those signals live in separate tools, the control may exist on paper but still fail operationally.

Decision rule: If a deposit matches a known illicit source cluster or arrives through a pattern consistent with brokered pass-through liquidity, treat the case as freeze-eligible until human review clears it. Speed should favour containment when the objective is to prevent laundering, not merely to document it.

Practitioner takeaway: Effective exchange defence is about compressing the attacker’s conversion window, because once chain-hopped value becomes spendable or withdrawable liquidity, the probability of successful recovery drops sharply.