The Lazarus Audit: Inside the Multi-State Task Force Tracking a $2B Chain-Hop Leak
Federal and state investigators have mapped a network of non-custodial bridges used to move illicit funds across six layer-one blockchains, reopening the debate over privacy and compliance.

The task force began, as most do, with a spreadsheet. Analysts in three state financial regulators had each flagged the same cluster of deposit addresses at unrelated exchanges, and none of them could explain why the flows kept terminating at the same handful of bridge contracts.
Over eleven months, that spreadsheet grew into a coordinated review of roughly $2 billion in transfers that moved across six separate layer-one networks before re-entering the regulated system. Investigators describe the pattern as chain-hopping: a deliberate sequence of swaps designed to break the heuristics that forensic firms rely on to link addresses to a single controller.
How the pattern was found
The breakthrough was not cryptographic. It was operational. Deposits arrived in clusters within four-minute windows, and the same fee-bidding behaviour recurred across networks with entirely different mempool dynamics. That timing fingerprint, several analysts said, was far harder to disguise than the transaction graph itself.
You can obfuscate the graph. It is much harder to obfuscate the habits of the people pressing the buttons.
Bridge developers contacted for this story emphasised that their contracts are non-custodial and immutable, and that they have no ability to freeze or reverse transfers. Two of the three teams said they now publish address screening data for front-end users, a measure that does not affect direct contract calls.
What comes next
Investigators expect the first civil actions to be filed against intermediaries rather than protocol authors, a distinction that policy specialists say will define the next several years of enforcement. A separate legislative proposal would extend reporting duties to front-end operators, an approach the industry has argued is both technically unworkable and constitutionally fragile.
Bitcoin Bounty Hunter reviewed transaction records, two internal analytical memos, and interviewed nine people with direct knowledge of the review. All spoke on condition of anonymity because the matter is ongoing.
About the author
Elias Thorne is Chief Investigative Correspondent at Bitcoin Bounty Hunter. Elias Thorne has covered financial crime and illicit finance for fourteen years, including six years reporting on blockchain forensics. He previously worked as a compliance analyst at a global custody bank.
Last updated Aug 17, 2026, 01:05 PM UTC · Spotted an error? Request a correction

