Accountability sits with the operators, the investigators, and any counterparties touching the funds. The exchange must preserve evidence and provide accurate disclosures. Investigators must validate claims against blockchain data. Regulators and sanctions bodies may also need to assess whether the event was a genuine compromise, an exit scam, or a coordinated cover story.
Why This Matters for Security Teams
When a crypto exchange says it was “hacked,” the label can hide very different accountability paths: an external intrusion, an insider drain, a staged false flag, or a sanctions-evasion cover story. Security teams cannot treat those as interchangeable because each one changes evidence preservation, disclosure duties, asset tracing, and whether the incident implicates control failure, fraud, or legal exposure. The operational question is not just who lost funds, but who controlled the systems, who moved the assets, and who can prove what happened.
That distinction matters because blockchain visibility does not automatically equal truth. Attackers and insiders can fragment transfers, use mixers, or time activity to mimic compromise. Current guidance suggests pairing forensic host evidence with on-chain tracing and internal access records before making public claims. NIST’s NIST SP 800-53 Rev 5 Security and Privacy Controls remains relevant here because incident response, audit logging, and evidence integrity are foundational, but the control set only works if operators actually preserve telemetry early.
NHI Management Group has repeatedly shown how quickly credential exposure turns into real-world abuse, including in DeepSeek breach analysis and the JetBrains GitHub plugin token exposure case, where leaked access material became an operational foothold rather than a theoretical risk. In practice, many security teams learn that an “exchange hack” was something else only after the funds have already been routed through multiple wallets.
How It Works in Practice
Accountability starts by separating three questions: what happened technically, who authorized the movement of value, and whether the public narrative matches the evidence. Investigators should correlate wallet tracing, exchange logs, IAM events, employee access paths, and infrastructure telemetry. If the alleged breach came from a privileged wallet, the central issue may be insider misuse or weak segregation of duties. If the story changes repeatedly, preserve communications, approvals, and key-management records as potential evidence of deception.
A practical workflow usually includes:
- Freeze and export logs before rotation, retention expiry, or tampering.
- Map fund flows against authenticated user and admin actions.
- Check whether the same operator, wallet cluster, or endpoint appears across prior incidents.
- Validate external claims against chain data, exchange controls, and custody records.
- Escalate to sanctions and legal review if routing suggests concealment or prohibited counterparties.
For identity assurance, investigators should treat NIST SP 800-63 Digital Identity Guidelines as a reminder that authentication strength is only part of the trust picture; proof of session, device, and administrative action matters just as much. On the threat side, the MITRE ATLAS adversarial AI threat matrix is useful when analysis includes automated laundering detection, anomaly scoring, or other AI-assisted triage that can itself be manipulated.
Operationally, this means the exchange is accountable for preserving evidence and telling the truth, investigators are accountable for validating the narrative, and counterparties are accountable for due diligence before accepting or routing suspect funds. These controls tend to break down when logs are incomplete, keys are shared across teams, or custody and trading functions are too tightly coupled to prove who initiated the transfer.
Common Variations and Edge Cases
Tighter forensic control often increases response friction, requiring organisations to balance rapid containment against evidentiary integrity. That tradeoff becomes harder in custody-heavy environments where hot wallets, admin consoles, and customer support tooling overlap. There is no universal standard for classifying these events yet, so best practice is evolving: some cases are genuine compromise, some are insider drains, and some are engineered disclosures intended to obscure sanctions exposure or prior insolvency.
One common edge case is the “false flag” claim used after suspicious wallet movement is already visible on-chain. Another is a staged hack narrative designed to slow withdrawal requests or redirect attention from poor treasury controls. A third is a sanctions-evasion attempt where attribution is intentionally muddied by mixers, cross-chain hops, or third-party intermediaries. In these situations, accountability may extend beyond the exchange to forensic providers, custodians, liquidity venues, and any compliance function that failed to challenge implausible explanations.
The most useful test is evidentiary consistency: do access logs, signed transactions, employee actions, and external blockchain movements tell the same story? If they do not, the incident should be treated as an open allegation, not a confirmed hack. NHI Management Group’s research on the State of Secrets in AppSec shows how fragmented secret handling and delayed remediation create the exact conditions where operators lose control of attribution. That is why current guidance suggests documenting custody, key ownership, and disclosure decisions as soon as the first anomaly appears.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10, OWASP Agentic AI Top 10 and CSA MAESTRO address the attack and risk surface, while NIST AI RMF and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 | Identity proofing and lifecycle control are central when wallet control is disputed. |
| OWASP Agentic AI Top 10 | A1 | Autonomous or scripted fund movement can obscure whether an action was authorized. |
| CSA MAESTRO | GO-2 | Governance must preserve evidence and assign decision accountability across agentic workflows. |
| NIST AI RMF | AI-assisted tracing and classification need oversight to avoid false confidence. | |
| NIST CSF 2.0 | RS.AN-3 | Incident analysis must correlate technical evidence before accountability is assigned. |
Verify operator and wallet ownership continuously, then tie every transfer to a managed NHI lifecycle.
Related resources from NHI Mgmt Group
- Who is accountable when crypto rails are used for sanctions evasion?
- Who is accountable when stolen crypto is tied to sanctions evasion or state-sponsored theft?
- When do IAST and RASP create a false sense of coverage for NHIs?
- Who is accountable when a crypto exchange account is taken over through recovery abuse?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 24, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org