Exchanges should trace the path of stolen funds across intermediary wallets, mixers, swaps, and nested service deposit addresses, then prioritize controls that spot repeated structured transfers and rapid service hopping. The key is not only knowing where funds land, but understanding how they are fragmented and reassembled. That gives investigators better chances to freeze assets before criminals disperse them across multiple services.
Tracing laundering paths through nested services and DeFi
After a high-value theft, the first analytic task is to rebuild the transaction chain in order, not just identify the final receiving wallet. Exchanges should segment the flow into hops, correlate timing and amount patterns, and flag when funds move through nested service deposit addresses, swaps, bridges, and other high-velocity conversion points. The objective is to expose the laundering structure, not merely the destination.
That distinction matters because nested services often fragment a large theft into smaller, more ordinary-looking movements before recombining value elsewhere. Exchanges that can reconstruct the path across multiple services are better positioned to prioritise freezes, alerts, and outreach before the trail becomes too distributed to act on.
What makes nested-service and DeFi laundering harder to spot
Nested services complicate detection because they introduce layers of aggregation and redistribution between the theft and the eventual cash-out point. A single source wallet may fan out into many deposit addresses, then re-enter through different services or DeFi protocols, which makes the provenance harder to follow if monitoring only looks for direct deposit into a known bad address. The practical problem is chain continuity: once continuity is lost, containment gets slower and less reliable.
DeFi adds another layer of difficulty because swaps, routing, and liquidity interactions can rapidly change the visible form of the asset while preserving value. That means investigators need analytics that tolerate asset transformation, address churn, and timing noise, while still preserving the link back to the original theft. NIST Cybersecurity Framework 2.0 is useful here as a broad detection and response lens for building repeatable monitoring and containment workflows.
Detection signals exchanges should prioritize
The strongest signals are usually behavioural rather than isolated. Repeated structured transfers, rapid service hopping, cyclical movement between a small set of services, and sudden re-aggregation after fragmentation are all useful indicators that the flow is being managed for concealment rather than ordinary trading. Exchanges should also watch for patterns that mirror laundering operations, such as bursts of similar-sized transfers, short dwell times, and address reuse across apparently unrelated paths.
Containment works best when investigators treat the flow as a graph problem and update risk as new hops appear. A deposit that looks benign in isolation can become high priority once it is linked to known theft sources, repeated intermediary routing, or rapid conversion across multiple venues. MITRE ATT&CK Enterprise Matrix is not a crypto-specific playbook, but it is useful for structuring how teams think about adversary movement, chaining behaviours, and evidence-driven detection logic. NIST Cybersecurity Framework 2.0 also supports the response side by keeping detection and containment tied to measurable operational outcomes.
Containment depends on speed, attribution quality, and coordination
Once the path is reconstructed, the response goal is to narrow the window in which the stolen value can be dispersed. That usually means fast internal escalation, clear confidence thresholds for freezing or reviewing linked accounts, and rapid sharing of actionable indicators with counterparties and service operators. The faster the exchange can distinguish high-confidence linkages from weak correlations, the more likely it is to contain the flow before it is split again.
Exchanges should also preserve evidence as they act, because laundering investigations often become cross-platform and cross-border very quickly. Good containment is not just blocking an address, it is maintaining a defensible record of why a path was considered linked, what signals triggered action, and what follow-up checks were performed when the flow re-emerged through another service.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK addresses the attack and risk surface, while NIST CSF 2.0 sets the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | DE.CM-01 — Monitoring for Unauthorized Activities | Detect laundering-like transfer patterns and service hopping in transaction monitoring. |
| RS.MI-01 — Incidents are contained | Containment is the core operational need after theft-linked laundering activity is identified. | |
| RS.AN-01 — Incident analysis | Reconstructing fragmented transaction chains requires structured incident analysis. | |
| Recommendation — Instrument monitoring to surface repeated structured transfers and rapid cross-service movement. Contain linked accounts and paths as soon as high-confidence laundering indicators emerge. Correlate hop-by-hop evidence to rebuild the laundering path before taking action. | ||
| MITRE ATT&CK | TA0010 — Exfiltration | Stolen value is being moved out through successive services and protocols. |
| TA0011 — Command and Control | Nested services can function as relay infrastructure that obscures transactional control paths. | |
| Recommendation — Map observed transfer chains to exfiltration-style movement and trigger focused tracing. Look for relay-like service chaining that hides the origin and continuity of the flow. | ||
Practitioner Guidance
What to prioritise: Prioritise graph continuity over destination certainty. If a flow shows repeated fragmentation, short-hop routing, and re-aggregation across services, treat the path itself as the investigative object even before every endpoint is fully identified.
What to verify: Verify that your monitoring can correlate time, value, and address relationships across custody boundaries, including service deposit addresses and protocol-mediated swaps. If it cannot, the control gap is in path reconstruction, not alert volume.
Decision rule: If the flow is both high-value and rapidly moving across multiple nested services, escalate containment actions on partial attribution rather than waiting for perfect proof. In these cases, delay usually helps the launderer more than the investigator.
Practitioner takeaway: The most effective teams do not ask only where stolen funds ended up, they ask how the movement pattern was assembled, because that is what creates the best chance to freeze value before it is broken apart again.
Related resources from NHI Mgmt Group
- Why do digital asset exchanges create sanctions and money laundering risk when they sit between high-volume wallets and cross-border flows?
- How should compliance teams respond when illicit crypto flows become more diffuse across exchanges and nested services?
- Why do nested cryptocurrency services create sanctions and money-laundering risk for exchanges that host them?
- Why do still-valid secrets matter after public disclosure?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 26, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org