An institution that discovers a theft, of its own assets or a client's, usually wants one answer first: is it coming back? That depends on size, speed and where the funds land, and on the dated figures below, most stolen crypto does not come back. What follows takes the routes in the order an institution meets them: tracing, freezing, seizure, civil action and negotiation. None of it is legal advice.
Tracing: what the ledger can and cannot show
Every transfer of stolen funds is visible on a public ledger. What analytics firms add is clustering: grouping addresses that are likely controlled by one actor, using heuristics such as common transaction inputs and change-address detection. The heuristics are useful and fallible, and, as a 2024 English judgment below shows, a trace has to survive a court's scrutiny, not just look persuasive in a report. The method itself is covered in what blockchain data can tell you.
Mixers and cross-chain bridges are the main obstacle, not because they make funds invisible but because they break the simple heuristics and force address-by-address reconstruction. The Bybit theft shows the pattern. On 21 February 2025 nearly $1.5 billion in ether was taken from the exchange's Ethereum cold wallet, an attack Chainalysis attributed to actors linked to North Korea. On 4 March 2025 Bybit reported that 77% of the stolen funds were still traceable and about 20% had gone dark. Its update of 21 April 2025 read 68.57% traceable, 27.59% gone dark and 3.84% frozen, with the untraceable share having flowed mainly into mixers and then across bridges.
Traceable is not recoverable. Tracing tells an institution where funds went; on its own it brings nothing back.
Who can freeze funds
Freezing power sits with a small number of actors, and it varies by asset.
Stablecoin issuers hold the most direct lever, because they can stop a balance at a given address from moving. On 23 April 2026 Tether announced a freeze of more than $344 million in USD₮ across two addresses, in coordination with OFAC and US law enforcement, and said it had frozen more than $4.4 billion in total across more than 2,300 cases globally, over $2.1 billion of it connected to US authorities. Circle can do the same with USDC: on 9 August 2022 it froze more than 75,000 USDC at 81 addresses after OFAC designated the Tornado Cash mixer. In both cases the freeze was the issuer's own act, not a court order.
Exchanges can freeze a customer's balance when law enforcement or a court asks, and can hold deposits that analytics tools flag, but only inside their own walls. Once funds reach a venue that will not cooperate, that power ends. Bybit's own figures make the point: most of the stolen ether stayed traceable for months, yet the frozen share was under 4% in April 2025, and a one-year retrospective published in March 2026 put it at about 3–4%.
Protocols can usually freeze very little. Many DeFi contracts have no admin key or pause function that could reverse a theft, which is why negotiation, covered below, exists as a route at all. Where a protocol does have an emergency pause, it can stop further loss; it cannot undo a transfer that has already settled. How design choices shape what can go wrong is set out in the institutional threat model for DeFi.
Law enforcement: seizure and forfeiture
State seizure is the most powerful route when it works, and the slowest.
In August 2016 about 119,754 bitcoin were taken from the Bitfinex exchange, coins CoinDesk valued at roughly $60 million at the time. On 8 February 2022 the US Department of Justice announced the seizure of more than 94,000 of them, by then worth about $3.6 billion. The criminal case ended in guilty pleas on 3 August 2023. Nearly six years passed between theft and seizure.
Ransom payments have been clawed back faster. Colonial Pipeline paid a ransom of about $4.4 million in May 2021; on 7 June 2021 the Department of Justice announced it had seized 63.7 bitcoin of that payment, worth about $2.3 million, after following it on the public ledger.
The largest recent actions show how long the tail is. On 14 October 2025 the Department of Justice filed a civil forfeiture complaint against approximately 127,271 bitcoin, then worth about $15 billion, which it called the largest forfeiture action in its history; it alleges the coins are proceeds of forced-labour scam compounds run by a Cambodia-based conglomerate. A forfeiture complaint is an allegation the government must prove, not a finding. In the UK, the Metropolitan Police seized 61,000 bitcoin in 2018, in an investigation opened that year into the proceeds of an investment fraud in China between 2014 and 2017 with more than 128,000 victims. The force describes it as the single largest cryptocurrency seizure in the world, worth more than £5.5 billion when the criminal case ended in guilty pleas in September 2025, and the Crown Prosecution Service said it would use criminal confiscation and civil proceedings to keep the assets beyond the fraudsters' reach. In both cases seizure opened a long legal process over the assets rather than delivering a payout to victims.
Civil routes: freezing injunctions and forced disclosure
An institution does not have to wait for a prosecutor. In AA v Persons Unknown, decided on 13 December 2019, the English Commercial Court treated bitcoin as property capable of protection by a proprietary injunction, and granted one over 96 bitcoin from a ransomware payment that had been traced to an address at the Bitfinex exchange. The order ran against unidentified persons as well as the exchange's operators. Disclosure orders address the other gap, identity. In April 2025 the Commercial Court granted a Norwich Pharmacal order, which compels a third party caught up in someone else's wrongdoing to disclose what it knows, against four exchanges, Binance, Paxful, HitBTC and Bybit, after a £500,000 theft that followed a phone snatch.
Civil tracing has limits. In a September 2024 High Court judgment, a claimant who said about £2.5 million in USDT had been taken by fraudsters took a claim against the Thai exchange Bitkub to trial. The court accepted that USDT is property and that the fraudsters held it on constructive trust, but dismissed the claim against the exchange, mainly because the evidence did not prove that the claimant's funds had reached it, and also because of deficiencies in the pleadings. Tracing evidence has to survive cross-examination.
Negotiated returns
Where a hack exploits a public smart contract rather than a custodian, the attacker is usually anonymous but not out of sight: the address is visible and every later move can be watched. On 10 August 2021 an attacker took about $612 million from Poly Network, a cross-chain protocol; by 12 August, Chainalysis reported, everything had been returned except 33.4 million USDT that Tether had frozen. Poly Network then offered a $500,000 bug bounty, payable once the refund was complete. In March 2023 Euler Finance lost about $200 million to an exploit; the attacker returned the bulk over the following weeks, and on 3 April 2023 Euler said all recoverable funds had come back. Neither outcome was compelled by law. Both depended on an attacker who chose to return the funds.
What actually gets recovered
Against those individual outcomes, the aggregate is poor. Two vendor trackers, cited here as such, measure recovery directly. Immunefi reported on 27 March 2025 that of $1.64 billion lost to hacks in the first quarter of 2025, the quarter of the Bybit theft, $6.5 million, or 0.4%, had been recovered, against 21.2% in the same quarter of 2024. PeckShield's annual report, published on 13 January 2026, put 2025 theft at $4.04 billion and the amount recovered or frozen at $334.9 million, about 8%, down from $488.5 million in 2024, when $3.01 billion was stolen. The dollar amount recovered fell while losses rose by about a third. The two firms count incidents differently, but they agree that most stolen value is not recovered and that a single large exchange theft can drag a year's recovery rate towards zero.
What the record suggests
Three things recur. Speed: in the second week after its theft, Bybit said the days ahead were critical for freezing because the funds were about to clear through exchanges, OTC desks and peer-to-peer venues. Choke points: the freezes that worked, by Tether in the Poly Network case and by exchanges in the Bybit case, happened where funds touched a firm able to act. Time: state seizure, when it comes, is measured in years. The record therefore puts most of the weight on what exists before a theft, custody design, what is insurable and working relationships with issuers and exchanges, rather than on analysis afterwards. Freezes made to comply with sanctions follow their own rules, set out in sanctions compliance onchain.