In screening vocabulary a hack is the theft of funds from an exchange, bridge, protocol or custodian through a technical compromise, as distinct from fraud that persuades a victim to send the money themselves. The attacker's addresses and the route the stolen value takes afterwards are attributable, usually within hours, because incidents of this size are investigated publicly and in real time. A wallet that shows a hack connection is holding, or has held, value from one of those events.
Large thefts are noisy. The victim protocol publishes an address list, exchanges circulate it, and the attacker's onward movements are watched by more people than any other kind of on-chain activity. That is why hack attribution tends to be fast and durable, and why value from a major incident is still recognisable long after the news cycle has moved on.
The stolen balance then has to become spendable, which means it eventually meets ordinary users: P2P sellers, small exchangers, instant swap services, over-the-counter buyers. That is the point at which a category most people would consider distant becomes their deposit review.
Because you can inherit it without doing anything. A trader who sells USDT to a stranger, an exchanger who fills a routine order, a merchant accepting payment — any of them can receive value that traces back to an incident they read about. The receiving exchange applies its own policy to that deposit, and the honest explanation ("someone paid me") does not carry a document.
Screening the counterparty address before you accept is the only step that prevents this rather than explaining it afterwards. Three free checks a day in the Telegram bot, verdict in seconds, no signup.
The result names the category in plain words and separates a connection on the address itself from one in the path that funded it. Beside it you see the verdict — CLEAN, LOW, MEDIUM, HIGH or CRITICAL — a recommendation of Proceed, Caution, Review or Reject, and the decision drivers written out, so the finding can be read by someone who was not there when you ran it.
Where stolen value has moved across chains, the connection is reported for what it is rather than lost at the boundary; that matters because large thefts move quickly and rarely stay on the chain they started on. Desks work these cases in the workspace, filter the queue by category and export a signed report per case. Plans are on the pricing page.
A hack names the event — a compromise of a protocol, bridge, exchange or custodian. Stolen funds names the value that came out of one, including thefts from individuals. The same transfer can carry both.
Usually fast, because the victim publishes addresses and the incident is watched publicly. Attribution then persists as the value moves, which is why old incidents still surface on checks.
Yes. Moving value between chains creates two visible legs rather than erasing one, and screening reports the connection instead of stopping at the boundary.
Also available in: · · ·
That depends on your jurisdiction and on what you can show about your own conduct. Documentation is what protects you, which is why the check result and the counterparty record matter more than the explanation.
Send any wallet to the Telegram bot and get a verdict in seconds. Three checks a day, free, no signup. Desks that screen every deposit run it on plans from $199/mo.