Curriculum·G405 Blockchain Analytics from the Compliance Side·about 32 min

Tracing for a suspicious activity report

By the end of this lesson you can

  • Explain how stolen Upbit funds were traced across the chain after the 2019 theft
  • Trace an inbound deposit backward through the transfer graph to judge its origin
  • State when a traced origin obliges a suspicious activity report rather than a private decision
  • Distinguish tracing that informs a decision from tracing that produces a filed report

Graduate · enrolled learners

This lesson opens with The Upbit hot-wallet theft, November 2019.

What happened
In November 2019 about 342,000 ether, worth roughly 50 million dollars at the time, was taken from the hot wallet of Upbit, a South Korean cryptocurrency exchange. Because the theft moved on a public ledger, the stolen ether did not vanish; it was traceable, and analysts and investigators followed it as the thieves split it across many addresses and pushed it through mixers and dozens of other exchanges to try to break the trail. Years later authorities attributed the theft to a state-linked group and, through that tracing and cooperation between exchanges, recovered a portion of the funds. The lesson for a compliance desk is on the receiving side: when some of those funds arrived at another exchange, that exchange could trace an inbound deposit backward through the transfer graph and discover it led to the Upbit theft, which is exactly the situation that obliges a suspicious activity report rather than a quiet decision to keep or refuse the funds.
The decision point
Screening asks whether a counterparty looks risky before you deal with it; tracing goes further, following funds backward through the transfer graph to establish where a specific deposit actually came from, hop by hop, even after thieves have split and mixed it to obscure the path. The Upbit theft is the demonstration that stolen funds moving on a public ledger stay traceable through those obfuscation steps, which is why a receiving institution can discover that an inbound deposit leads back to a known theft. That discovery is not merely information to act on privately: when tracing reveals that funds are connected to crime, the regulated institution is generally obliged to file a suspicious activity report, a formal report to the authorities, rather than simply keeping or returning the funds on its own judgment. So the decision an institution makes is that tracing has a required output when it surfaces criminal proceeds: the trace informs the report, and the report is filed, because a desk that traces a deposit to a theft and then handles it quietly has done the analysis and skipped the obligation the analysis triggered.
Recorded loss
$50,000,000

What you will be able to answer

  • Why did the stolen Upbit funds stay traceable?
  • What is tracing, versus screening?
  • When tracing reveals a deposit is connected to crime, what is required?
  • What distinguishes tracing that meets the obligation?

Orientation and Year One are open: anyone can read them without an account. From Year Two onward the lessons are for enrolled learners, because progress through the later years only means anything if it is tracked against a record.

It is free. We do not sell the list and there is nothing to buy at the end of it.

Sources and review

Confidence medium·Volatility low·Reviewed 2026-09-16·Owner unassigned

Contested

The roughly 50 million dollar figure is the value of the stolen ether at the time of the November 2019 theft; its value changed substantially afterward, and only a portion was recovered. The lesson uses the theft to illustrate receiving-side tracing and the reporting obligation, not to measure the ultimate loss.

Attribution of the Upbit theft to a specific state-linked group was confirmed by authorities years later; the tracing-and-report lesson does not depend on the attribution, only on the fact that stolen funds moving on a public ledger stay traceable to a receiving institution.