Posts  / #POST-212666
REDDIT

How CEX KYC Failed to Stop a DeFi Theft Operation

A
Nov 20, 2025 · 19:18

This is a warning about how centralized exchanges enable DeFi crimes despite having full KYC on criminals.

**The Attack Vector:** On November 16, my locked Team Finance position (wBTC locked until 2028) was stolen through compromised private key. Standard DeFi risk, I accept that.

**The CEX Connection:** Here's where it gets interesting - I traced the criminal's wallet back to direct funding from Bybit (centralized exchange) on October 29. Full KYC required exchange → Criminal wallet → Theft execution.

**The Money Laundering:** Post-theft, the criminal used:

* 1inch DEX aggregator for swaps
* Multiple wallet hopping
* Cross-chain bridging
* Classic DeFi laundering playbook

**The Failure Point:** Bybit has:

* Criminal's KYC documents
* Proof of theft (I provided everything)
* Clear money laundering evidence
* Ability to freeze the source account

Their response? "Contact law enforcement" while the criminal operates freely.

**Criminal Wallet:** 0x606311856266bb715cd8c15aaa28722f47c37df2 **Bybit Case:** \#22819689

**Why This Matters for DeFi:** We always talk about "not your keys, not your crypto" but what about when CEXs actively enable criminals who attack DeFi users? The on/off ramp problem isn't just about regulation - it's about exchanges refusing to act even with proof.

This criminal is still active. Still has access to Bybit. Still hunting for victims.

**Question for the community:** How do we pressure CEXs to actually use their KYC for crime prevention instead of just compliance theater?

Not seeking funds or sympathy. Just awareness that the CEX/DEX bridge is being exploited and exchanges don't care.