Follow the money quickly and focus on the services that concentrate cash-out activity. Centralised exchanges, high-risk exchanges, and mixers can reveal where attackers convert proceeds or obfuscate tracing. Investigators should map intermediary wallets, identify repeated service use, and preserve transaction evidence early. The goal is to constrain laundering options and strengthen the chances of seizure, attribution, and disruption.
Tracing exchanges and mixers in a ransomware follow-the-money investigation
When extortion proceeds start moving through exchanges and mixers, the investigation becomes a race against time and service availability. The useful question is not only where the funds went, but which services repeatedly absorb, split, consolidate, or cash out the trail. That is where attribution, seizure opportunity, and the remaining chance to freeze funds are often won or lost.
Start by treating each wallet hop as evidence of intent as well as movement. Exchange deposits can expose conversion points, account reuse, and timing patterns; mixers can indicate deliberate obfuscation and break the simple transaction path. A sound workflow preserves the transaction graph early, then narrows to the services most likely to hold identifiers, logs, or withdrawal links.
Investigators should also distinguish between endpoints that only relay value and services that create operational choke points. A repeated deposit address at a centralised exchange, for example, may be more actionable than a long chain of intermediary wallets because the service may have KYC records, internal logs, or a compliance team that can respond to preservation requests. Mixers are usually different: they reduce traceability, so the main value is often in correlation, clustering, and identifying pre- or post-mix touchpoints.
How to map intermediary wallets, repeated service use, and cash-out paths
The practical objective is to build a defensible chain of custody for the funds while still the trail is fresh. Map the full path from the victim payment address through intermediary wallets, then mark where the same service is reused across multiple transactions, because repeated service use can reveal the operator’s preferred laundering route or an infrastructure pattern shared across campaigns. For background on broader NHI and credential risk patterns that often feed extortion activity, see Ultimate Guide to NHIs and Top 10 NHI Issues.
Service attribution matters most when you can tie deposits to a platform that concentrates activity. A high-risk exchange, a custodial wallet provider, or a mixer endpoint may not reveal the operator immediately, but each can still support subpoenas, exchange notifications, blockchain analytics, and operational correlation with other incidents. When a specific service has already appeared in related extortion investigations, investigators should treat that service as a priority lead rather than a generic waypoint. In cloud-enabled extortion cases, weak identity controls and exposed credentials often amplify the initial compromise, which is why the 230M AWS environment compromise and the Codefinger AWS S3 ransomware attack are useful analogues for how access and monetisation chains can intersect.
Preservation should be immediate and specific. Capture wallet addresses, transaction IDs, timestamps, service names, deposit memo fields where available, and the analytical rationale for any wallet clustering or service linkage. Preserve the evidence in a way that supports later legal action, because once the funds are withdrawn or further layered, the practical value of the trace drops sharply even if the original blockchain record remains immutable.
What investigators should prioritise before the laundering trail cools
The highest-value work is usually the shortest-window work: identify the services most likely to hold actionable records, then move fast on notices and internal escalation. If a service is a known centralised exchange, high-volume cash-out point, or repeated laundering venue, it should rise above low-signal wallet-to-wallet tracing. If the trail enters a mixer, the next best move is often to bracket the mixer with pre-mix and post-mix activity rather than waiting for a perfect attribution that may never arrive.
Investigators should also coordinate across technical and legal teams early, because timing determines whether records still exist and whether funds can be frozen. A rapid request that reaches the right exchange compliance contact can matter more than a deeper analysis delivered too late. Where the trail intersects with infrastructure identity or account compromise, related case studies such as GitLocker GitHub extortion campaign and Cisco Active Directory credentials breach show how stolen access and monetisation can reinforce one another across the intrusion lifecycle.
Risk and Threat Considerations
Ransomware proceeds are often moved quickly because delays increase the chance of tracing, freezing, or recovery. Exchanges and mixers create different risks: exchanges can be actionable choke points, while mixers are designed to break visibility and delay attribution, which makes early preservation and correlation essential.
Failure mechanism: The investigation loses leverage when funds are allowed to pass through multiple services before wallets, deposit points, and service interactions are documented. Repeated use of the same exchange or mixer can also hide a broader laundering pattern if investigators track only the final cash-out address.
Impact: Late tracing reduces seizure opportunities, weakens attribution, and increases the likelihood that proceeds are converted, dispersed, or withdrawn before enforcement can intervene.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK addresses the attack and risk surface, while NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| MITRE ATT&CK | TA0010 — Exfiltration | Tracks how attackers move value and conceal proceeds after extortion. |
| Recommendation — Map post-extortion fund movement patterns and hunt for linked laundering infrastructure. | ||
| NIST CSF 2.0 | RC.CO-03 — Public communications are coordinated with internal and external stakeholders | Supports rapid coordination with exchanges, counsel, and enforcement during recovery. |
| RS.MI-01 — Incidents are contained | Covers constraining ongoing loss once laundering services are identified. | |
| Recommendation — Coordinate preservation requests and recovery actions across stakeholders without delay. Contain the financial trail by targeting service points that can still be frozen or disrupted. | ||
| NIST SP 800-53 Rev 5 | AU-6 — Audit Record Review, Analysis, and Reporting | Applies to reviewing transaction evidence, wallet patterns, and service activity for investigative leads. |
| IR-5 — Incident Monitoring | Supports rapid monitoring of the extortion-to-cash-out path while evidence is still actionable. | |
| Recommendation — Review and correlate transaction evidence to identify repeat service use and cash-out points. Monitor the laundering path continuously and escalate when a service becomes actionable. | ||
Practitioner Guidance
What to prioritise: Focus first on the service nodes most likely to hold records or control the cash-out path, not on exhaustively tracing every intermediate hop. A limited number of well-supported links to an exchange or mixer is usually more valuable than a large but shallow transaction map.
What to verify: Confirm whether the same service appears across multiple extortion cases, whether the wallet cluster shows repeated routing behaviour, and whether the service is likely to retain logs or KYC-linked data long enough for legal process.
Practitioner takeaway: The best recovery opportunity is often created by speed, precision, and service targeting, because once ransomware funds are layered through multiple venues, the investigation shifts from recovery to reconstruction.
Related resources from NHI Mgmt Group
- Who is accountable when ransomware operators move from access to extortion?
- How should investigators handle crypto tracing when funds pass through exchanges or deposit addresses?
- How should security teams respond when ransomware operators gain initial access through stolen credentials and then move laterally across endpoints?
- How should investigators trace stolen cryptocurrency when hackers use decentralized exchanges to move funds?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 24, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org