In a recent case, stolen funds moved from the victim's wallet to Binance, then to Bybit, then to OKX — all within 6 hours. To recover the funds, we needed to coordinate freeze requests across all three exchanges simultaneously, sharing blockchain evidence and transaction data between them. This is cross-exchange freeze coordination — one of the most complex but effective techniques in crypto fraud recovery. When stolen cryptocurrency moves quickly across multiple exchanges, no single exchange has the full picture. Each exchange sees only the transactions that involve its own platform. To recover the funds, we must build the full picture by coordinating with all exchanges simultaneously, sharing the blockchain evidence that connects the transactions across platforms.
In this article, I explain how exchanges share data about suspicious transactions, how we coordinate freeze requests across multiple exchanges, the practical challenges of cross-exchange recovery, and the strategies we use to maximize recovery when funds are moving fast across platforms. This article builds on our chainhopping article and our AML scoring article.
How exchanges share data
Exchanges do not share customer data voluntarily — they are bound by privacy laws (GDPR in the EU, data protection laws in other jurisdictions) and their own terms of service. Sharing customer data without a legal basis would violate these obligations. However, exchanges do share data in specific circumstances:
- Law enforcement requests: When law enforcement requests information about a specific account, the exchange provides it. Law enforcement can then share the information with other exchanges through MLAT (Mutual Legal Assistance Treaty) or informal channels. This is the most formal and powerful channel for data sharing, but it is also the slowest — MLAT requests can take months.
- Travel Rule data: Under the FATF Travel Rule, exchanges share sender and recipient information for transactions above a threshold (typically EUR 1,000 in the EU, USD 3,000 in the US). See our Travel Rule article for details. This is the most systematic form of data sharing — it happens automatically for every qualifying transaction.
- Blockchain analytics providers: Exchanges use the same blockchain analytics tools (Chainalysis, TRM Labs, Elliptic). When one exchange flags an address, the flag is shared with the analytics provider, which may then propagate to other exchanges that use the same tool. This is not direct data sharing between exchanges — it is indirect sharing through the analytics provider. But it is effective: when we report an address as a scammer's address to Chainalysis, the flag propagates to all Chainalysis-using exchanges within hours. This means that even if we cannot reach an exchange's compliance team directly, the address will be flagged by the exchange's own AML system when the scammer attempts to use it. This is particularly useful for smaller exchanges where we do not have established relationships — the analytics provider does the work for us.
- Informal cooperation: Compliance teams at different exchanges sometimes communicate informally about suspicious accounts, particularly when the same scammer is targeting multiple exchanges. This is not formalized and relies on personal relationships between compliance officers, but it does happen — particularly among exchanges that share a regulator or are in the same jurisdiction.
- Regulatory coordination: Regulators (FINMA, BaFin, FCA, NYDFS) can facilitate information sharing between exchanges under their supervision, particularly in cases involving significant fraud. If multiple exchanges under the same regulator are affected by the same scammer, the regulator can coordinate the response and share information between the exchanges.
The cross-exchange freeze process
When stolen funds are moving across multiple exchanges, the freeze process follows a specific sequence of steps. Each step must be executed quickly — the funds may move to the next exchange within hours, so delays at any step can result in the funds being cashed out before the freeze is in place.
Step 1: Trace the funds
Using blockchain forensics (Chainalysis Reactor or TRM Forensics), trace the funds from the victim's wallet to the first exchange, then to the second, then to the third. At each exchange, identify the deposit address used by the scammer. See our blockchain analytics article for the tracing methodology and our chainhopping article for cross-chain tracing.
The tracing must be done as quickly as possible — ideally within 1-2 hours of the fraud being reported. Every hour of delay gives the scammer more time to move the funds further. If the funds have already moved through three exchanges by the time the tracing is complete, the freeze requests must be sent to all three simultaneously.
Step 2: Prepare freeze requests for all exchanges
Prepare a freeze request for each exchange where the funds have been identified. Each request should include:
- The scammer's deposit address at that exchange
- The transaction hash showing the deposit to that exchange
- The blockchain forensics report tracing the funds from the victim to the exchange
- A police report or case number (if available)
- A formal request to freeze the funds pending investigation
Each freeze request should be self-contained — it should not rely on the exchange having information from other exchanges. The compliance team at each exchange will review the request independently, so the evidence must be complete for each exchange.
Step 3: Send all freeze requests simultaneously
Do not send the freeze requests sequentially (wait for Exchange A to respond, then contact Exchange B). By the time Exchange A responds, the funds may have moved to Exchange B and then to Exchange C. Send all freeze requests at the same time, so that all exchanges are aware of the situation and can coordinate.
In practice, we send all freeze requests within a 30-minute window. This ensures that all exchanges receive the requests at roughly the same time and can begin their review processes simultaneously. If we waited for each exchange to respond before contacting the next, the funds would be gone before the last exchange was contacted. The parallel approach is particularly important when the funds are moving quickly — in some cases, scammers move funds from one exchange to another within 30 minutes, so any delay in contacting the next exchange can result in the funds being withdrawn before the freeze is in place. The 30-minute window is not arbitrary — it is based on our analysis of hundreds of cases, which shows that scammers typically take 30-60 minutes to move funds from one exchange to the next. By sending all requests within 30 minutes, we ensure that all exchanges are alerted before the scammer can complete the next transfer.
Step 4: Share information between exchanges
When one exchange confirms that the funds were at their exchange (and provides the withdrawal address or the account holder's information), share this information with the other exchanges. This helps the other exchanges trace the funds within their own systems and identify the scammer's accounts.
The exchanges cannot share customer data directly (due to privacy laws), but they can share blockchain evidence (wallet addresses, transaction hashes) that helps each exchange identify the relevant accounts. We act as the intermediary — we receive information from one exchange and share the blockchain evidence with the other exchanges, without sharing any customer data.
Step 5: Coordinate with law enforcement
If the loss is significant (typically over $100,000), involve law enforcement. Law enforcement can compel exchanges to share customer data and can coordinate across jurisdictions through MLAT and other international legal assistance channels. A law enforcement request to freeze funds is more powerful than a private freeze request — exchanges are legally required to comply with law enforcement requests, while private requests are voluntary (though most reputable exchanges will comply with well-documented private requests). Law enforcement can also execute search warrants, arrest suspects, and seize assets — powers that private parties do not have.
Law enforcement can also execute search warrants and seizure orders, which private parties cannot. If the scammer is identified through the exchange's KYC records, law enforcement can arrest the scammer and seize the stolen funds — something that private legal action alone cannot achieve. Law enforcement can also coordinate with foreign law enforcement through Interpol and Europol, which is particularly important in cases where the scammer is in a different country than the victim. However, law enforcement investigations take time — typically weeks to months — and may not produce results quickly enough to recover the funds before they are cashed out. This is why we pursue private freeze requests in parallel with law enforcement involvement — the private requests can produce results within hours, while the law enforcement investigation provides the longer-term framework for prosecution and asset seizure.
The challenges of cross-exchange coordination
Cross-exchange freeze coordination is effective but challenging. The main challenges are:
- Different response times: Each exchange has a different response time. Binance may respond in 2 hours, while OKX may take 12 hours. The slowest exchange determines the overall timeline. If the funds are at the slowest exchange, they may be withdrawn before the freeze is in place.
- Different jurisdictions: Each exchange is in a different jurisdiction, with different legal requirements for freeze requests. Binance has entities in multiple jurisdictions (BVI, Ireland, Dubai), Bybit is in Dubai, OKX has entities in Seychelles and Dubai. Each requires a different legal approach, and some jurisdictions are more cooperative than others.
- Privacy restrictions: Exchanges cannot share customer data without a legal basis. Sharing blockchain evidence (wallet addresses, transaction hashes) is generally permissible, but sharing customer names, emails, or KYC documents requires a law enforcement request or a court order (like a Norwich Pharmacal order — see our Norwich Pharmacal article).
- Language barriers: Compliance teams at different exchanges may speak different languages. English is the lingua franca of crypto compliance, but some exchanges (particularly in Asia) have limited English capabilities. Miscommunication can lead to delays or misunderstandings.
- Time zones: Compliance teams work in different time zones. A freeze request sent at 9 AM in Switzerland arrives at 5 PM in Singapore, where the compliance team may have already gone home. We account for this by sending requests during the business hours of the destination exchange, or by sending to 24/7 compliance teams (which the largest exchanges have).
- Unregulated exchanges: If the funds reach an unregulated exchange (MEXC, Gate.io, or a smaller offshore exchange), the freeze request may be ignored. Unregulated exchanges are not required to comply with private freeze requests and may not respond even to law enforcement requests from foreign jurisdictions.
The role of blockchain analytics in cross-exchange coordination
Blockchain analytics tools (Chainalysis, TRM Labs) play a critical role in cross-exchange coordination. When we trace funds through multiple exchanges, we share the analytics report with each exchange. The report shows the flow of funds from the victim to each exchange, and each exchange can use the report to identify the relevant account at their exchange.
Additionally, when we flag an address with one analytics provider (e.g., by reporting it as a scammer's address to Chainalysis), the flag propagates to all exchanges that use that provider. This means that when the scammer attempts to use the flagged address at another exchange, the exchange's AML system will automatically flag it. This is a passive form of cross-exchange coordination — it does not require active communication between exchanges, but it does help prevent the scammer from cashing out at other exchanges.
The analytics report also serves as a common language between exchanges. Each exchange's compliance team is familiar with Chainalysis or TRM reports — they use the same tools internally. When we provide a Chainalysis report to a Binance compliance officer and the same report to a Bybit compliance officer, both officers can read and understand the report without any translation or explanation. This accelerates the review process at each exchange, because the compliance team does not need to spend time understanding the format or methodology of the report — they can focus immediately on the specific addresses and transactions that are relevant to their exchange. In some cases, the analytics report also includes pre-computed risk scores for each address, which the compliance team can use to make a quick decision without running their own analysis.
Case study: the three-exchange chase
In the case I described at the beginning of this article, stolen funds (120 ETH, worth $390,000) moved from the victim's wallet to Binance, then to Bybit, then to OKX — all within 6 hours. We traced the funds using Chainalysis Reactor and identified the deposit addresses at all three exchanges.
We prepared freeze requests for all three exchanges simultaneously. Each request included the full blockchain forensics report (showing the flow of funds from the victim to all three exchanges), the police report, and a formal request to freeze. We sent all three requests within a 30-minute window.
Binance responded first (within 2 hours) and confirmed that the funds had already been withdrawn to Bybit. We shared Binance's withdrawal address with Bybit, which helped Bybit identify the scammer's account. Bybit froze the funds (approximately 80 ETH remained — the scammer had already withdrawn 40 ETH) within 4 hours of receiving our request.
OKX confirmed that the scammer had an account but had not yet received funds from Bybit. We asked OKX to monitor the account for incoming deposits from Bybit. When the scammer attempted to withdraw the remaining 80 ETH from Bybit to OKX, Bybit blocked the withdrawal (because the account was frozen) and OKX was prepared to freeze the funds if they arrived.
Total recovery: 80 ETH (67% of the loss). The remaining 40 ETH had been cashed out at Binance before the freeze was in place. The key to the partial recovery was speed (all three freeze requests sent within 30 minutes) and coordination (sharing information between exchanges to help each identify the scammer's account). If we had contacted the exchanges sequentially, the funds would have been fully cashed out before the last exchange was contacted. The parallel approach — sending all requests simultaneously — is what made the partial recovery possible. This case also demonstrates the importance of having the blockchain analytics report ready before contacting the exchanges. If we had needed to trace the funds after contacting each exchange, the delays would have been fatal. The tracing was completed before the first freeze request was sent, so all three requests included the complete forensic report from the start.
The importance of pre-existing relationships with exchanges
Cross-exchange coordination is significantly more effective when the recovery team has pre-existing relationships with the exchanges' compliance teams. At Valken, we have established relationships with compliance teams at Binance, Coinbase, Kraken, Bybit, OKX, and other major exchanges. These relationships mean that our freeze requests are taken more seriously, reviewed faster, and given priority over requests from unknown parties.
This is not about favoritism — it is about trust. Compliance teams receive hundreds of freeze requests per day, many of which are fraudulent or baseless (some "recovery firms" send mass freeze requests on behalf of clients who have not actually been scammed, clogging the compliance team's review queue). When a request comes from a known, trusted source (a licensed law firm with a track record of legitimate requests), the compliance team can process it faster because they do not need to verify the requester's identity or assess the legitimacy of the request — they know from past experience that this source sends legitimate requests. When a request comes from an unknown source, the compliance team must verify the requester, assess the legitimacy of the request, and then begin the review — all of which takes time. Time is the enemy in cross-exchange coordination, so any factor that speeds up the compliance team's response is critical.
The bottom line
Cross-exchange freeze coordination is one of the most effective techniques for recovering stolen cryptocurrency that has been moved across multiple exchanges. In an era where scammers can move stolen funds through Binance, Bybit, and OKX within hours, the ability to coordinate freeze requests across all three simultaneously is often the only way to intercept the funds before they are cashed out. The key is speed (send all freeze requests simultaneously, within a 30-minute window), evidence (provide a comprehensive blockchain forensics report to each exchange), and coordination (share blockchain evidence between exchanges to help each identify the scammer's account). With the right approach, partial or full recovery is possible even when funds have moved through three or more exchanges. The key factors are speed (sending all freeze requests within a 30-minute window), evidence (providing a comprehensive blockchain forensics report to each exchange), coordination (sharing blockchain evidence between exchanges), and relationships (having pre-existing contacts with each exchange's compliance team). When all four factors are present, the recovery rate in our practice is approximately 50-70%. When any factor is missing — particularly speed — the recovery rate drops dramatically.
If you need help coordinating freeze requests across multiple exchanges, contact us immediately. We have experience coordinating freezes across Binance, Bybit, OKX, Kraken, Coinbase, and other major exchanges, and we can act quickly to maximize your chances of recovery. We have established relationships with compliance teams at all major exchanges, which means our requests are processed faster than requests from unknown parties. The first 6 hours after the fraud are critical — if we can begin the tracing and freeze process within that window, the recovery rate is significantly higher. After 6 hours, the funds have typically been moved through multiple exchanges and the trail is much harder to follow. After 24 hours, the funds are typically cashed out and recovery is extremely difficult. This is why we emphasize speed above all else — every hour counts, and the difference between acting in hour 1 versus hour 6 can be the difference between full recovery and total loss. After 6 hours, the funds have typically been moved through multiple exchanges and the trail is much harder to follow. After 24 hours, the funds are typically cashed out and recovery is extremely difficult. This is why we emphasize speed above all else — every hour counts, and the difference between acting in hour 1 versus hour 6 can be the difference between full recovery and total loss.