The KuCoin thief's exploits reveal the cutting edge of digital money laundering

Quick Take
- After getting blocked by centralized exchanges, the KuCoin thief turned to DEXs to convert stolen tokens into ETH.
- In recent days the thief has used a second decentralized tool to throw investigators off the money trail.
We'd love your feedback.
Late in the evening of September 25, a hacker gained access to hot wallets owned by KuCoin, a Singapore-based cryptocurrency exchange. The attacker stole roughly $280 million worth of digital money, making it the third-largest theft from a crypto exchange in history.
What is most interesting is not the amount that was stolen, however. It’s the way the thief has attempted to launder a portion of it.
Shortly after the heist, the attacker began trying to use centralized exchanges to trade stolen Ethereum-based tokens — many of which were at risk of being frozen by their issuer — for other tokens, like Ether, that could not be frozen. But those exchanges were able to detect that the tokens came from the KuCoin hack, and immediately threw up roadblocks, according to Tom Robinson, chief scientist and co-founder of blockchain analytics firm Elliptic.
So the thief turned to so-called decentralized exchange (DEX) platforms — Uniswap, Kyber Network, DEX.AG, 1inch.exchange, and Tokenlon — where they sold $19.5 million worth of the stolen tokens for Ether, according to Elliptic.
At least one individual with access to those funds is still on the loose, and in recent days they’ve used yet another decentralized tool to throw investigators completely off their trail.
In the process, the KuCoin thief has shown that using decentralized platforms to launder money now works almost as well as using real cash.
What is Uniswap?
In the context of traditional law, money laundering refers to the execution of one or more financial transactions that conceals the identity, source, or destination of illegally obtained funds.
In the U.S., the main anti-money-laundering law is the Bank Secrecy Act (BSA), which was created in 1970. The goal of the BSA is to prevent financial institutions from helping criminals hide, obscure, or launder ill-gotten money. It works by requiring financial institutions to flag certain large transactions — for instance, a cash transaction of over $10,000. It also requires institutions to report “suspicious” activity to the Financial Crimes Enforcement Network (FinCEN), a bureau or the Treasury Department, which can then follow-up and investigate.
The KuCoin thief has used a two-step process to launder the stolen Ethereum-based tokens. The first step entailed converting stolen tokens into ETH using DEXs. But are DEXs financial institutions? That’s a complicated question. The short answer is that they don’t exactly fit the legal definition.
Take Uniswap, for instance. What is Uniswap? In fact, it’s two things, and neither of them seems to fall within the scope of the Bank Secrecy Act.
First, it’s a set of smart contracts on the Ethereum blockchain — one for each of the many ERC20 tokens for which the platform supports trading. The contracts hold reserves, called “liquidity pools,” for given trading pairs. The money in the pools comes from individuals called liquidity providers, who put up the money for a cut of the transaction fees. Users can trade against reserves at any time rather than waiting to get matched via a traditional order book model.
Uniswap is also a company, based in Brooklyn, that employs the software developers who built those smart contracts. In fact, each of the five DEXs the KuCoin hacker used is associated with a legal entity — shouldn’t those entities be subject to anti-money laundering law enforcement?
Not if they don’t take custody of the users’ assets, says Juan Llanos, a cryptocurrency and financial compliance expert. “Platforms, marketplaces, and platforms are technology providers. They are not financial institutions,” says Llanos. “Hayden Adams, who is the founder of Uniswap, is not liable because he is not in control of those assets.”
Uniswap’s developers should not be held accountable for illegal actions of people using the tool they developed, argues Peter Van Valkenburgh, director of research at the cryptocurrency policy advocacy group Coin Center. Now that the tool is in the wild, they have no more control over the way people use it than a hammer manufacturer has over how people use a hammer, he says. Hammer manufacturers cannot be held accountable if a hammer they made is used to harm someone.
Van Valkenburgh says it would be a mistake for regulators to try to ban decentralized exchange platforms. But if people keep exchanging large sums of stolen money via DEXs, policymakers are bound to respond somehow. Earlier this month, in a report entitled “Cryptocurrency: An Enforcement Framework,” the U.S. Department of Justice made it clear that DeFi is on its radar.
“The ICO boom from a few years ago has given way to the exponential growth of Decentralized Finance markets in recent months — with all the associated complexities and difficulties for enforcers seeking to stay ahead of the curve and keep investors safe,” the report said.
You can run, and now you can also hide
The reality is that such complexities and difficulties — particularly those pertaining to decentralized money laundering — will likely keep relevant legal and policy questions from being resolved any time soon.
But in the meantime, what about the actual KuCoin hacker?
On October 4, KuCoin CEO Johnny Lyu tweeted that the “suspects” had been “found,” adding that “law enforcement officials and police are officially involved to take action.” But at least one individual with access to the stolen funds seems to still be on the loose.
In recent days, they’ve initiated the second step of the laundering process: passing the ETH through a “mixing” service called Tornado Cash.
Mixers pool funds from multiple users before mixing them up and redistributing them — generally, for the purpose of making it harder to trace the movement of these funds. Tornado Cash is essentially a smart contract that employs sophisticated cryptography based on zero-knowledge proofs to break the association between the address that deposit the funds and the address that withdraws them on the other side. (The thief has also started using a different mixer to launder bitcoin stolen via the hack.)
“We can't trace it beyond that,” Robinson says. “And so that is pretty much the end of the line when it comes to blockchain analysis.”
Whether the KuCoin thief can truly get away with the funds will depend on if they can find a way to spend or exchange it without being detected. Robinson says Elliptic has built tools that exchanges can use to spot whether a deposit came through a mixer. But there are plenty of exchanges with lax anti-money laundering policies.
“If they [exchanges] are really doing proper comprehensive blockchain analytics on all customer deposits, then they should identify this is coming from Tornado Cash, but some exchanges don't do that,” Robinson says.
Given the growing availability of decentralized tools like Uniswap and Tornado Cash and the persistence of centralized exchanges with lax oversight, we are likely to see more incidents like the KuCoin case.
The law has yet to catch up to the technology, Van Valkenburgh says. But it should not be forgotten that “far more” money is laundered using physical cash, he says — and digital currency money laundering, by its nature, leaves more traces for investigators to follow.
© 2026 The Block. All Rights Reserved. This article is provided for informational purposes only. It is not offered or intended to be used as legal, tax, investment, financial, or other advice.

