How it works
eXch ran as an instant, custodial cryptocurrency swap. Users picked a pair, sent funds to a per-swap deposit address, and received the destination asset minutes later. There was no account, no email, and no password — only a swap ID and an optional refund address. The site lived on the clearnet at exch.cx and through a .onion mirror, and supported Bitcoin, Lightning, Ethereum (with ERC-20s), and Monero. Pricing came from internal liquidity and pass-through to no-KYC partner desks.
Internally, the platform was a custodial operator. eXch took possession of inbound funds during the swap window and signed the outbound transaction itself; users had no on-chain control of their deposit between confirmation and payout. Customer support was email-only — slow by users' own accounts, but generally responsive on stuck swaps.
KYC & privacy
By design, eXch collected nothing at signup, because there was no signup. The form asked for an inbound address, an outbound address, and an optional refund address. No KYC at any threshold. The operator's stated AML policy refused to freeze or share funds in response to third-party requests, and on chain the platform consistently honoured that posture even when faced with high-profile theft attribution.
That same posture is what eventually killed the project. Because eXch declined to filter incoming deposits — even after Bybit publicly tagged the addresses linked to its 21 February 2025 hack — about $200 million of the $1.46 billion stolen by the Lazarus Group flowed through the platform within weeks. Investigators at Elliptic and TRM Labs subsequently traced an estimated $1.9 billion in lifetime volume through eXch, with significant exposure to FixedFloat's February 2024 hack, sanctioned wallets, and CSAM-linked funds.
Strengths and limits
For a privacy maximalist, eXch did the things the rubric rewards: no signup, no email, onion access, native XMR alongside BTC and LN, and a hands-off operator who would not hand a transaction graph to a counterparty's lawyer. Throughput on common pairs ran in minutes, not hours. Refund handling on stuck swaps was, by the standards of no-KYC swappers, unusually consistent.
The limits were structural and proved fatal. eXch was custodial and closed-source, with no published proof of reserves and no third-party audit. Operators ran the project from a Belize-registered shell, Private Project Facilitators LTD, with a Swiss admin contact, French hosting and German servers — a geometry that gave Frankfurt prosecutors and the BKA all the jurisdiction they needed. On 30 April 2025, one day before eXch's own announced 1 May shutdown, German authorities seized the servers, roughly €34m / $38m in tokens, and 8TB of operational data. TRM Labs subsequently found the operators continued limited API access for partners after the takedown, including for CSAM-linked flows.
Verdict
eXch was the cleanest no-KYC user experience the privacy crowd had — and a money-laundering rail for North Korea's weapons programme. The clearnet domain is offline, the operators are at large, and any successor mirror is, by definition, the same crew that stayed online for CSAM customers after the seizure. Grade: D (4.2/10). Trust: SCAM.
eXch was the cleanest no-KYC user experience the privacy crowd had — and a money-laundering rail for North Korea's weapons programme. The clearnet domain is offline, the operators are at large, and any successor mirror is, by definition, the same crew that stayed online for CSAM customers after the seizure. Grade: D (4.2/10). Trust: SCAM.


