Join our Newsletter — 33% off our NHI Course
Home FAQ Identity Beyond IAM What happens when illicit actors move funds through…
Identity Beyond IAM

What happens when illicit actors move funds through cross-chain bridges instead of centralized services?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 16, 2026 Domain: Identity Beyond IAM

When criminals use bridges, they can move value between blockchains without a central custodian taking control of the funds. That makes the activity harder to interrupt operationally, but it remains visible on chain and can still be traced. In practice, bridges can help obscure the laundering path while also creating an analyzable trail for investigators who follow token movements across chains.

Why This Matters for Security Teams

Cross-chain bridges change the laundering problem from a single-platform transfer into a multi-ledger movement problem. That matters because the actor no longer depends on a centralized service to hold or delay funds, so operational interruption becomes harder even when investigators can still see the transfers. The core security value is not that bridges make activity invisible, but that they fragment the path and add reconciliation complexity across chains.

That complexity is where investigators and compliance teams often lose time. A bridge hop can create the appearance of a fresh asset origin on the destination chain, while the underlying movement remains connected through transaction metadata, contract interaction, and timing. In practice, the challenge is less about proving that money moved and more about proving that the movement is part of a coordinated laundering sequence.

Analysts therefore need to treat bridge usage as an escalation signal, not a conclusion. A bridge can be part of ordinary treasury movement, cross-chain arbitrage, or protocol usage, but illicit actors deliberately exploit the same mechanism to make tracing slower and interdiction less straightforward. In practice, many teams notice the bridge only after the trail has already been split across multiple networks.

How It Works in Practice

In a bridge-based laundering flow, value is typically locked, burned, or otherwise committed on the source chain and then reissued or released on the destination chain through the bridge’s contract logic. The bridge itself becomes the coordination point, but it does not behave like a centralized custodian that can simply freeze the funds on behalf of an investigator. That distinction matters because the attacker is exploiting protocol mechanics, not a single service account or payment processor.

From an investigative perspective, the bridge event is still highly useful. The source-chain transaction, contract address, token amount, and timestamp can often be correlated with destination-chain minting or release events. Cross-chain tracing therefore depends on assembling a timeline across multiple ledgers rather than following one wallet in isolation. Good analysis usually focuses on:

  • the initiating wallet and its funding source,
  • the exact bridge contract or route used,
  • the destination chain and receiving address cluster,
  • the timing between source and destination events, and
  • any subsequent swaps, peel chains, or consolidation steps.

Because bridges are public infrastructure, they can support both concealment and attribution. They help illicit actors break up custody and route funds through more than one ecosystem, but they also create a durable on-chain record that can be reconstructed with the right tooling. That is why bridge activity is usually most valuable to investigators when it is combined with address clustering, contract analysis, and follow-on transaction monitoring rather than treated as a stand-alone indicator.

These controls tend to break down when bridge activity is followed by rapid swaps into highly liquid assets and then repeated across several chains, because attribution depends on correlating many small events before the trail fragments further.

Common Variations and Edge Cases

Tighter monitoring of bridge activity often increases false positives, so organisations have to balance visibility against alert fatigue. Not every bridge transfer is suspicious, and some legitimate users rely on bridges for normal cross-chain operations. The practical question is whether the transfer pattern matches known laundering behaviour, such as rapid chaining, repeated small splits, or movement into jurisdictions and venues that reduce recovery options.

Bridge design also matters. Some bridges use canonical mechanisms that are easier to trace, while others rely on liquidity pools, wrapped assets, or intermediary hops that make the path harder to interpret. Current guidance suggests the tracing burden rises when the bridge is only one step in a broader layering sequence, especially if the next step is a swap into privacy-enhancing or high-churn assets.

Another edge case is that bridge usage can look identical for legitimate and illicit actors at the transaction level. That means the best discriminator is usually context, not the bridge alone, source of funds, historical wallet behaviour, and what happens immediately after the transfer all matter more than the existence of the bridge hop itself. The bridge is a mechanism, not proof of laundering.

Risk and Threat Considerations

Bridge-based movement introduces tracing risk, interdiction delay, and cross-chain visibility gaps. For defenders, the exposure is not that the funds disappear, but that the laundering path becomes operationally harder to pause once value has moved into another ledger environment.

Failure mechanism: The actor uses bridge contracts to separate source-chain custody from destination-chain control, then layers swaps or additional transfers to fragment the trail. That defeats single-platform monitoring and forces investigators to correlate multiple on-chain events across networks.

Impact: Recovery time increases, attribution becomes slower, and suspicious funds may exit into more liquid or harder-to-seize environments before a response is coordinated.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK address the attack and risk surface, while CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
MITRE ATT&CKT1020 — Data ExfiltrationCross-chain bridges can be used to move illicit value out of a monitored environment.
Recommendation — Track bridge-linked transfers as exfiltration-like movement and correlate follow-on wallet activity.
CIS Controls v88 — Audit Log ManagementBridge transfers require durable transaction records to reconstruct multi-chain movement.
Recommendation — Retain and correlate source-chain and destination-chain transaction logs for bridge events.
NIST CSF 2.0DE.CM — Security Continuous MonitoringBridge activity needs continuous monitoring across ledgers to detect laundering patterns.
Recommendation — Monitor cross-chain transfers continuously and alert on unusual bridge-and-swap sequences.

Practitioner Guidance

What to prioritise: Treat bridge activity as a correlation problem, not just a compliance flag. The first step is to preserve source-chain transaction context, bridge contract details, destination-chain receipt events, and any post-bridge swaps so the full sequence remains reconstructable.

What to verify: Confirm whether the destination wallet is newly active, whether funds are split immediately after the bridge hop, and whether the route matches normal customer behaviour for that asset and chain pair. A bridge transfer that is followed by rapid fan-out deserves a different response than one that ends in a stable, known operational wallet.

What practitioners underestimate: The bridge itself is rarely the end of the laundering chain. The important judgement is whether the bridge hop is part of layering, because that determines whether the response should focus on tracing, escalation, or coordination with counterpart venues.

Practitioner takeaway: The most effective response is to preserve chain-to-chain continuity early, because once bridge activity is combined with swaps and repeated hops, the cost of reconstructing the laundering path rises sharply.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 16, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org