Join our Newsletter — 33% off our NHI Course
Home› FAQ› Threats, Abuse & Incident Response› When should exchanges report a hack to law…
Threats, Abuse & Incident Response

When should exchanges report a hack to law enforcement and other exchanges?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 24, 2026 Domain: Threats, Abuse & Incident Response

Immediately, as soon as the compromise is confirmed and the destination addresses are known. Rapid disclosure lets other exchanges flag or freeze associated wallets, and it gives investigators a better chance to trace funds before they are mixed or moved to low KYC services. Delayed reporting compresses the response window and usually improves the attacker’s odds of successful liquidation.

Why exchanges should treat confirmed compromise as a disclosure event, not an internal ticket

Once an exchange has confirmed a compromise and identified the destination addresses, the incident has moved from containment into coordinated response. At that point, disclosure is not just informational, it becomes a practical control that can slow cash-out, support tracing, and reduce the attacker’s ability to move through liquidity venues before monitoring teams react.

The key operational shift is that other exchanges can only act if they have something actionable: wallet addresses, transaction hashes, timestamps, or related infrastructure indicators. Reporting before the attacker has dispersed funds gives law enforcement and counterparties a better chance to correlate activity across services and preserve evidence while the trail is still coherent.

Why speed matters more than perfect certainty in the first notification

Rapid notification is valuable even when the investigation is still developing, because the response window closes quickly once funds are split, bridged, or moved into lower-friction services. The longer the delay, the more likely it is that assets will pass into channels where freezes, recalls, or tracing become much harder to execute effectively.

That does not mean publishing unverified allegations. It means reporting promptly once the compromise is confirmed and the known destination addresses are sufficiently reliable for defensive use. Exchanges and investigators can work with partial but credible intelligence far better than they can work with silence.

Notification also helps create a shared defensive picture. One exchange may see deposit activity, another may see withdrawal attempts, and law enforcement may have the broader case context. The faster those observations are linked, the less opportunity the attacker has to exploit gaps between organisations.

What information the report should contain to be useful

A useful report is concise, specific, and operational. It should include the confirmed incident summary, the relevant wallet or address set, any known transaction identifiers, time windows, and the method by which the destination was identified. If there are multiple counterparties likely to be exposed, the report should state that clearly so analysts can watch for laundering patterns and linked accounts.

Exchanges should also include enough context to support immediate action without forcing the recipient to reconstruct the incident from scratch. That usually means the assets involved, the relevant chains or networks, and any indicators that help distinguish benign activity from attempted liquidation. The goal is to enable fast triage, not to produce a full postmortem in the first message.

Where possible, reporting should go through established incident-response and law-enforcement channels rather than ad hoc contact lists. Formal paths are slower only if they are not prepared in advance. In practice, prearranged escalation routes are what make immediate disclosure operationally realistic when the clock is already running.

Risk and Threat Considerations

Delayed reporting increases the chance that stolen funds are laundered before countermeasures can land. The main threat is not only the theft itself, but the short operational window in which freezing, flagging, or tracing remains feasible across multiple exchanges and service providers.

Failure mechanism: The attacker uses speed, fragmentation, and venue hopping to break the chain of custody before counterparties are notified. Once the funds are mixed or routed through lower-visibility services, downstream tracing and recovery become materially harder.

Impact: The exchange loses response leverage, law enforcement loses evidence freshness, and other exchanges lose the chance to intervene before value exits the ecosystem.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK addresses the attack and risk surface, while CIS Controls v8, NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
CIS Controls v8CIS-8 — Audit Log ManagementIncident reporting depends on preserving traceable transaction evidence.
Recommendation — Preserve logs and transaction evidence so counterparties and investigators can trace the compromise quickly.
MITRE ATT&CKTA0009 — CollectionStolen funds are traced using adversary activity and infrastructure indicators.
Recommendation — Map observed wallet movement and laundering indicators to attacker activity to speed detection.
NIST CSF 2.0RS.CO-02 — Incidents are coordinated with stakeholders and relevant partiesPrompt exchange-to-exchange and law-enforcement notification is coordinated incident response.
Recommendation — Coordinate confirmed compromise details with affected stakeholders as soon as actionable indicators exist.
NIST SP 800-53 Rev 5IR-6 — Incident ReportingThe question is about when to report a confirmed compromise to external parties.
IR-4 — Incident HandlingReporting is part of containment and coordinated handling after compromise detection.
Recommendation — Trigger external incident reporting immediately once the compromise and actionable indicators are confirmed. Use incident-handling procedures to initiate containment and external notification without delay.

Practitioner Guidance

What to prioritise: Confirm the compromise, extract the first actionable destination set, and notify immediately through the fastest trusted channel you have. The first report should be good enough to act on, even if the investigation is not complete.

What to verify: Distinguish between confirmed destination addresses and speculative attribution. A fast alert is valuable only if recipients can safely use it for screening, freezing, or enhanced monitoring.

Practitioner takeaway: In exchange incidents, the value of reporting is measured by how much time it buys other defenders before the attacker can liquidate, not by how polished the investigation is.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 24, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org