/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Elliptic: cross-chain bridge RenBridge has been used to launder $540M+ in crime-related crypto cash since 2020, including 53M+ by the Conti ransomware group

MacKenzie Sigalos / CNBC : Source: Elliptic Connect .

CNBC MacKenzie Sigalos

Context & Ripple Effects

Elliptic's report lands at the center of a two-sided bridge problem: the same week [[a:981475|Chainalysis counted $2B stolen from cross-chain bridges across 13 hacks in 2022 — 69% of all funds stolen that year]], Elliptic is showing bridges also serve as the cash-out layer for what was stolen elsewhere. Its finding that RenBridge moved $540M+ in crime-linked crypto since 2020, including $53M+ from Conti, extends the firm's earlier work tracing ransomware proceeds.

The Conti link matters because the group's successors kept the playbook: Elliptic later tied Black Basta, widely seen as a Conti offshoot, to $107M+ in extorted bitcoin. A year on, Elliptic's ledger had grown to $7B laundered through DEXs, bridges, and coin swaps with Lazarus Group on top — making this RenBridge report an early, named data point in that escalation.

First-order effects

  • RenBridge now carries a documented laundering record attached to its name, putting direct compliance pressure on the protocol and on any exchange accepting its outbound flows.
  • Conti and similar ransomware operations lose a mapped cash-out route: once Elliptic Connect flags the wallet clusters, downstream exchanges can freeze or reject those transfers.

Second-order effects

  • Other bridge operators face a forced choice between adding transaction screening — raising costs and friction — or inheriting the same illicit-finance label that analytics firms can attach to RenBridge.
  • Chainalysis and Elliptic's findings make bridges the highest-risk node in crypto infrastructure on both sides of the ledger (exploit target and laundering conduit), pushing institutional liquidity toward bridges with audited, monitored rails.

Third-order effects

  • The enforcement arc runs from analytics reports to action: Europol's later dismantling of the AudiA6 mixing service, which allegedly laundered $380M+ for ransomware actors, shows the reporting-to-takedown pipeline this kind of research feeds.
  • If regulators treat bridges as they treated mixers, cross-chain infrastructure splits into compliant, KYC'd services and a shadow tier — deepening the legitimacy gap between institutional crypto and its criminal-use fringe.

The trend: Crypto laundering is migrating toward cross-chain infrastructure as analytics firms map mixers and bridges, setting up bridges as the next target for both compliance tooling and law-enforcement takedowns.