Curriculum·G102 Wallet Clustering and Heuristics·about 31 min
Clustering across services and chains
By the end of this lesson you can
- →Explain why address-level clustering heuristics do not carry across a bridge or an exchange
- →Explain how Lazarus laundering was followed across chains and mixers by correlating deposits and withdrawals
- →Compute a cross-chain match from amount, timing, and sequence when the addresses do not connect
- →Bridge a cluster across a service by evidence of correspondence rather than by a shared key
Graduate · enrolled learners
This lesson opens with Lazarus cross-chain laundering, 2022 onward.
- What happened
- The North Korea-linked Lazarus Group has stolen billions, including about 625 million dollars from the Ronin bridge in March 2022, and it launders across chains on purpose. Stolen Ethereum is passed through the Tornado Cash mixer, swapped, and moved over cross-chain bridges into Bitcoin and back, because each hop through a service breaks the direct address trail: the bridge or mixer takes funds in at one address and pays out from a different pool, so common-input-ownership and change detection, which work within one chain's address graph, do not carry across the gap. Investigators at firms like Chainalysis and Elliptic followed it anyway, by correlating the deposits into a service with the withdrawals out of it, matching amounts, timing and sequence to link an entity's funds across the break, and by cross-referencing with sanctions data and known Lazarus infrastructure. The trail across chains was reconstructed not by a shared key but by evidence of correspondence.
- The decision point
- Address-level clustering has a hard edge: it lives inside one chain's transaction graph, and a service, a mixer, an exchange, a bridge, is a wall the graph does not cross. Funds go in as inputs to the service and come out as unrelated outputs from the service's own pool, so the co-spending and change signals that clustered an entity stop at the door. Following an entity across that wall is a different move: not proving one owner signed, but showing that the funds out correspond to the funds in, by amount, by timing, by sequence, by any pattern the launderer could not fully scramble. This is clustering across services and chains, and it is both weaker and unavoidable, because every serious launderer routes through exactly these walls. The analyst who stops at the mixer has followed the money to the edge of one graph; the analyst who can argue a correspondence across it keeps the trail alive.
- Recorded loss
- $625,000,000
What you will be able to answer
- →Why do address-level heuristics fail across a mixer or bridge?
- →How is an entity followed across a service?
- →How did investigators track Lazarus across chains?
- →Does obfuscation (splitting, odd timing) kill correspondence matching?
Orientation and Year One are open: anyone can read them without an account. From Year Two onward the lessons are for enrolled learners, because progress through the later years only means anything if it is tracked against a record.
It is free. We do not sell the list and there is nothing to buy at the end of it.
Sources and review
- https://www.chainalysis.com/blog/lazarus-group-north-korea-crypto-hacking/
- https://www.elliptic.co/blog
- https://home.treasury.gov/news/press-releases/jy0916
Confidence high·Volatility medium·Reviewed 2026-09-15·Owner unassigned
Contested
The Ronin theft attributed to Lazarus was about 625 million dollars; the cross-chain laundering through Tornado Cash and bridges is documented by multiple firms and by US Treasury sanctions actions. Specific correspondence matches are probabilistic and, in adversarial settings, contestable.
Correspondence matching across mixers depends on the mixer's design and volume; high-volume, well-mixed pools degrade matching more than thin ones. The lesson teaches the method, not a guaranteed result.
