Picture a thief who robs a bank and hides the money in a glass safe in the middle of a town square. Everyone can see the safe. Everyone can see how much is inside. But it cannot be opened without the key — and for six years the thief walks past it, afraid to touch the loot. That is exactly what the largest seizure in crypto history looked like: 119,754 stolen bitcoin that lay in plain sight of the whole world for years and still led investigators back to their owners. This case is the perfect textbook on why the blockchain remembers everything and why the weak link in any laundering scheme is the moment of cashing out.
▶ Video case study of the Bitfinex case (English narration).
On 2 August 2016 one of the largest crypto exchanges in the world at the time — Bitfinex — was hacked. The attackers gained access to the exchange's hot wallets and drained roughly 119,754 BTC. At that day's exchange rate this was about 71 million dollars — an enormous sum even then, one that crashed the price of bitcoin on the market.
But the most interesting part began after the theft. The stolen coins did not leave in a single transfer to a single address — they were scattered across 2,075 addresses. This is a classic technique: break the loot into a multitude of "container wallets" to complicate visual analysis and avoid keeping all your eggs in one basket. A clever move, it would seem. But this move had a fatal flaw that, in 2016, the thief may not yet have taken seriously: each of these 2,075 addresses remained forever in the public ledger of the blockchain. They could be tracked. They could be watched. And they were watched — for years.
The permanence of the blockchain is a permanent record that ultimately helped recover the stolen funds.
— this is how the essence of the case was framed at the U.S. Department of Justice (paraphrase, not a verbatim quote)
After the theft, something happened that looks strange to a beginner but is entirely logical to an analyst. The stolen coins barely moved. For years a gigantic sum simply sat untouched on 2,075 addresses. Why didn't the thief spend the loot?
Because this is precisely the fundamental problem with stolen crypto. Stealing bitcoin is not technically hard — it is enough to gain control of the keys. But turning stolen bitcoin into real money — an apartment, a car, a bank account — is practically impossible without "lighting up." The moment the coins move toward an exchange or a swap service, toward a point of contact with the fiat world, they fall under the crosshairs of KYT systems and investigators. Any movement across these flagged addresses is an alarm signal for the entire industry.
And so a stalemate arose that we call the "glass safe." The wealth exists — on paper, or rather, on the blockchain. But it cannot be used. This is exactly why a huge share of major thefts sits "frozen" for years: thieves wait for attention to fade, look for laundering routes, and cautiously test cash-out paths. And it was on those cash-out attempts that the investigation "got a grip."
Movement began later. When the owners of the stolen funds started trying to move money into the banking system — through chains of intermediate addresses, swap services, and accounts — investigators picked up threads. Every attempt to legitimize the money left a new trail: a link between a "dirty" blockchain address and a very specific real-world service or account.
Here lies the central lesson of the whole case, which we repeat throughout the course: the weak link of laundering is cashing out. As long as the money stays inside the blockchain, it is only conditionally anonymous (addresses are pseudonymous, but traceable). But at the moment of exit into fiat — onto a KYC-requiring exchange, into a bank account, to a payment provider — the pseudonym inevitably gets linked to an identity. It is at this border between the two worlds that almost everyone is caught.
In February 2022 the story reached its climax. The U.S. Department of Justice announced the seizure of roughly 94,000 BTC — about 3.6 billion dollars. Over six years the price of bitcoin had risen many times over, and the "frozen" $71M had turned into billions. At the time this became the largest financial seizure in the agency's history.
But how were investigators able to take the bitcoin at all? After all, the blockchain cannot be "undone," and without the private keys the coins are inaccessible to anyone, the state included. The answer is in the details, and it beautifully illustrates another principle of the course: "Not your keys, not your coins".
Two people were arrested: Ilya Lichtenstein (known online by the handle "Dutch") and his wife Heather Morgan (an eccentric rap performer under the alias "Razzlekhan"). The key moment of the investigation: the private keys to the wallet holding the stolen funds were found in Lichtenstein's cloud account. Having gained access to this digital vault, investigators obtained the keys — and with the keys, control over the coins. In 2023 the couple pleaded guilty.
An ordinary person, on hearing about a theft, thinks: "The money was stolen and spent, good luck chasing the wind." In traditional finance, cash really does dissolve. But the blockchain is built on a fundamentally different principle, and therein lies its greatest feature for AML.
Every bitcoin transaction is recorded forever in a public, distributed, immutable ledger. A transfer cannot be "erased." History cannot be "rewritten." The address that received the stolen coins in 2016 will still be visible a hundred years from now — as will the entire chain of subsequent movements. For the criminal this is a delayed-action trap: he may avoid exposure for years, but the second he tries to use the loot, the whole preserved history unfolds against him.
This is exactly why the U.S. Department of Justice, commenting on the case, emphasized a simple idea: the permanence of the blockchain is a permanent record, and it is precisely this record that ultimately helped recover the funds. Investigators did not need to catch the thief "red-handed" in 2016. It was enough for them to patiently watch the flagged addresses and wait for the owner to make a mistake himself in an attempt to cash out.
In the next case study we will see how the same principle of traceability worked even more strikingly — and in just a month: how the FBI recovered the ransom paid to extortionists after the attack on the Colonial Pipeline fuel line.
The facts are presented from open sources. The materials are for educational purposes.