Technology

Cross-chain bridges and decentralised-finance protocols

Cross-chain bridges move assets or messages between blockchain environments. Decentralised-finance protocols use smart contracts to provide exchange, lending, liquidity and related functions. These technologies are neutral infrastructure. Their strategic relevance arises from documented DPRK-linked theft and laundering, and from the control points that states and regulated intermediaries can use to trace, restrict or recover assets.

Architecture and control

A bridge may lock an asset on one chain and mint a representation on another, burn and release assets, verify cross-chain messages, or transfer value through liquidity pools. Security therefore depends on the particular design: administrator and upgrade keys, validators, relayers, oracles, smart contracts, front ends and liquidity arrangements can each fail or be compromised.

The label decentralised does not settle who controls a protocol. A component-level test asks who can alter parameters, upgrade code, select validators, operate an interface, collect fees, block addresses or influence governance. The Financial Action Task Force distinguishes publishing software from providing a regulated service, while treating owners or operators with control or sufficient influence as potential virtual-asset service providers.

Statecraft pathways

Three pathways must be separated. First, a state-directed actor can compromise a bridge or related custodian to acquire assets. Second, it can use bridges, exchanges, mixers or decentralised services to move and obscure proceeds acquired elsewhere. Third, states can regulate, sanction or disrupt operators, interfaces, issuers and off-ramps. A bridge may be a theft target, a transfer route, or both, but those are different mechanisms.

US authorities attributed the 2022 Harmony Horizon Bridge theft and subsequent laundering activity to DPRK-linked Lazarus actors. Treasury also associated a designated wallet with the Ronin bridge theft. In 2025 the FBI attributed the Bybit exchange theft to North Korea and described rapid movement across multiple blockchains and services. These records establish direct state-linked use at the application layer. They do not prove that the technology itself is a state instrument, that one actor controlled every traced address, or that the full nominal value was converted into usable state revenue.

Regulation and disruption

Public ledgers can support tracing even where contractual controls are dispersed. Asset issuers may freeze tokens, intermediaries may block wallets or refuse conversion, authorities may seize assets, and protocol teams may harden code or restrict front ends. Each response reaches a different component and jurisdiction.

The Fifth Circuit's 2024 Van Loon decision concerned a specific statutory question involving the immutable Tornado Cash contracts before it. The US Treasury removed Tornado Cash sanctions on 21 March 2025 while maintaining concern about DPRK activity. Neither development makes other protocols immune from sanctions, regulation or enforcement. Legal treatment still turns on the relevant person, property, service, authority and control facts.

Effects and limits

Address tracing is not actor attribution. Moving assets is not the same as converting them, receiving them for state use or funding a particular programme. Valuation must separate the amount taken at the time of a compromise, later transfers, freezes, recoveries, seizures and realised proceeds. Claims about state benefit therefore require evidence across the full chain, not a transaction cluster alone.

See also

[State-directed cryptocurrency theft](../instrument/cryptocurrency-theft-as-state-finance.md) | [Digital identity and conditional-payment controls](digital-identity-and-programmable-money-controls.md) | [Tokenised deposits and distributed-ledger settlement](distributed-ledger-settlement-and-tokenised-deposit-systems.md)

Sources

  1. US Department of the Treasury, Illicit Finance Risk Assessment of Decentralized Finance (April 2023). https://home.treasury.gov/system/files/136/DeFi-Risk-Full-Review.pdf
  2. Financial Action Task Force, Updated Guidance for a Risk-Based Approach to Virtual Assets and Virtual Asset Service Providers (October 2021). https://www.fatf-gafi.org/content/dam/fatf-gafi/guidance/Updated-Guidance-VA-VASP.pdf
  3. Financial Action Task Force, Targeted Update on Implementation of the FATF Standards on Virtual Assets and Virtual Asset Service Providers (June 2023). https://www.fatf-gafi.org/content/dam/fatf-gafi/guidance/June2023-Targeted-Update-VA-VASP.pdf.coredownload.inline.pdf
  4. Financial Action Task Force, Targeted Report on Stablecoins and Unhosted Wallets: Peer-to-Peer Transactions, 3 March 2026. https://www.fatf-gafi.org/en/publications/Virtualassets/targeted-report-stablecoins-unhosted-wallets.html
  5. Federal Bureau of Investigation, 'FBI Confirms Lazarus Group Cyber Actors Responsible for Harmony's Horizon Bridge Currency Theft', 23 January 2023. https://www.fbi.gov/news/press-releases/fbi-confirms-lazarus-group-cyber-actors-responsible-for-harmonys-horizon-bridge-currency-theft
  6. US Department of the Treasury, Office of Foreign Assets Control, 'North Korea Designations and Designation Update', 14 April 2022. https://ofac.treasury.gov/recent-actions/20220414
  7. United Nations Security Council Panel of Experts, Final report submitted pursuant to resolution 2680 (2023), S/2024/215, 7 March 2024. https://digitallibrary.un.org/record/4041323/files/S_2024_215-EN.pdf?version=1
  8. Federal Bureau of Investigation, 'North Korea Responsible for $1.5 Billion Bybit Hack', 26 February 2025. https://www.fbi.gov/investigate/cyber/alerts/2025/north-korea-responsible-for-1-5-billion-bybit-hack
  9. US Court of Appeals for the Fifth Circuit, Van Loon v. Department of the Treasury, No. 23-50669, 26 November 2024. https://www.ca5.uscourts.gov/opinions/pub/23/23-50669-CV0.pdf
  10. US Department of the Treasury, 'Tornado Cash Delisting', 21 March 2025. https://home.treasury.gov/news/press-releases/sb0057
  11. Mengya Zhang, Xiaokuan Zhang, Josh Barbee, Yinqian Zhang and Zhiqiang Lin, 'SoK: Security of Cross-chain Bridges: Attack Surfaces, Defenses, and Open Problems' (2023). https://arxiv.org/abs/2312.12573
  12. Hanyu Mao, Tiezheng Nie, Hao Sun, Derong Shen and Ge Yu, 'A Survey on Cross-Chain Technology: Challenges, Development, and Prospect', IEEE Access 11 (2023): 45527-45546. https://doi.org/10.1109/ACCESS.2022.3228535

Recommended citation

Cite this entry

Tennant, James J., ed. 'Cross-chain bridges and decentralised-finance protocols.' The Encyclopedia of Economic Statecraft, version 2.0, last reviewed 29 July 2026. https://jamesjtennant.com/entries/cross-chain-bridges-and-defi-protocols/.

Suggest an edit