Immediately, as soon as the compromise is confirmed and the destination addresses are known. Rapid disclosure lets other exchanges flag or freeze associated wallets, and it gives investigators a better chance to trace funds before they are mixed or moved to low KYC services. Delayed reporting compresses the response window and usually improves the attacker’s odds of successful liquidation.
Why exchanges should treat confirmed compromise as a disclosure event, not an internal ticket
Once an exchange has confirmed a compromise and identified the destination addresses, the incident has moved from containment into coordinated response. At that point, disclosure is not just informational, it becomes a practical control that can slow cash-out, support tracing, and reduce the attacker’s ability to move through liquidity venues before monitoring teams react.
The key operational shift is that other exchanges can only act if they have something actionable: wallet addresses, transaction hashes, timestamps, or related infrastructure indicators. Reporting before the attacker has dispersed funds gives law enforcement and counterparties a better chance to correlate activity across services and preserve evidence while the trail is still coherent.
Why speed matters more than perfect certainty in the first notification
Rapid notification is valuable even when the investigation is still developing, because the response window closes quickly once funds are split, bridged, or moved into lower-friction services. The longer the delay, the more likely it is that assets will pass into channels where freezes, recalls, or tracing become much harder to execute effectively.
That does not mean publishing unverified allegations. It means reporting promptly once the compromise is confirmed and the known destination addresses are sufficiently reliable for defensive use. Exchanges and investigators can work with partial but credible intelligence far better than they can work with silence.
Notification also helps create a shared defensive picture. One exchange may see deposit activity, another may see withdrawal attempts, and law enforcement may have the broader case context. The faster those observations are linked, the less opportunity the attacker has to exploit gaps between organisations.
What information the report should contain to be useful
A useful report is concise, specific, and operational. It should include the confirmed incident summary, the relevant wallet or address set, any known transaction identifiers, time windows, and the method by which the destination was identified. If there are multiple counterparties likely to be exposed, the report should state that clearly so analysts can watch for laundering patterns and linked accounts.
Exchanges should also include enough context to support immediate action without forcing the recipient to reconstruct the incident from scratch. That usually means the assets involved, the relevant chains or networks, and any indicators that help distinguish benign activity from attempted liquidation. The goal is to enable fast triage, not to produce a full postmortem in the first message.
Where possible, reporting should go through established incident-response and law-enforcement channels rather than ad hoc contact lists. Formal paths are slower only if they are not prepared in advance. In practice, prearranged escalation routes are what make immediate disclosure operationally realistic when the clock is already running.
Risk and Threat Considerations
Delayed reporting increases the chance that stolen funds are laundered before countermeasures can land. The main threat is not only the theft itself, but the short operational window in which freezing, flagging, or tracing remains feasible across multiple exchanges and service providers.
Failure mechanism: The attacker uses speed, fragmentation, and venue hopping to break the chain of custody before counterparties are notified. Once the funds are mixed or routed through lower-visibility services, downstream tracing and recovery become materially harder.
Impact: The exchange loses response leverage, law enforcement loses evidence freshness, and other exchanges lose the chance to intervene before value exits the ecosystem.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK addresses the attack and risk surface, while CIS Controls v8, NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CIS Controls v8 | CIS-8 — Audit Log Management | Incident reporting depends on preserving traceable transaction evidence. |
| Recommendation — Preserve logs and transaction evidence so counterparties and investigators can trace the compromise quickly. | ||
| MITRE ATT&CK | TA0009 — Collection | Stolen funds are traced using adversary activity and infrastructure indicators. |
| Recommendation — Map observed wallet movement and laundering indicators to attacker activity to speed detection. | ||
| NIST CSF 2.0 | RS.CO-02 — Incidents are coordinated with stakeholders and relevant parties | Prompt exchange-to-exchange and law-enforcement notification is coordinated incident response. |
| Recommendation — Coordinate confirmed compromise details with affected stakeholders as soon as actionable indicators exist. | ||
| NIST SP 800-53 Rev 5 | IR-6 — Incident Reporting | The question is about when to report a confirmed compromise to external parties. |
| IR-4 — Incident Handling | Reporting is part of containment and coordinated handling after compromise detection. | |
| Recommendation — Trigger external incident reporting immediately once the compromise and actionable indicators are confirmed. Use incident-handling procedures to initiate containment and external notification without delay. | ||
Practitioner Guidance
What to prioritise: Confirm the compromise, extract the first actionable destination set, and notify immediately through the fastest trusted channel you have. The first report should be good enough to act on, even if the investigation is not complete.
What to verify: Distinguish between confirmed destination addresses and speculative attribution. A fast alert is valuable only if recipients can safely use it for screening, freezing, or enhanced monitoring.
Practitioner takeaway: In exchange incidents, the value of reporting is measured by how much time it buys other defenders before the attacker can liquidate, not by how polished the investigation is.
Related resources from NHI Mgmt Group
- Why do crypto investigations still require collaboration with regulators, exchanges, and foreign law enforcement?
- Who is accountable for disrupting ransomware cash-out paths across exchanges and law enforcement?
- What happens when scam intelligence is not shared across banks, exchanges, law enforcement, and platform providers?
- How should organisations implement CJIS access controls for law enforcement data?