Cryptocurrency Exchange Seizures in Cybercrime Cases
Authorities use exchange seizures as a choke point to stop criminals from cashing out.

Cryptocurrency exchange seizures work because of one structural fact: dirty money has to surface at an exchange before a criminal can spend it. That's the choke point, and law enforcement has built its whole playbook around hitting it. Chainalysis's 2026 Crypto Crime Report found illicit addresses took in at least $154 billion in 2025, with sanctioned entities alone pulling in $104 billion. The exchange layer is where that money has to become real, and that's exactly where seizures do the most damage.
One policy shift changed the math further. The federal government now runs a Strategic Bitcoin Reserve and a Digital Assets Stockpile, changing how seized crypto is handled after forfeiture. The government retains it. That alone turns seizure from reactive cleanup into something closer to deliberate strategy. What follows is how that strategy actually plays out, case by case.
The legal architecture that gives authorities power to freeze and forfeit digital assets
Most of this runs through a handful of federal statutes, and per a 2025 analysis in the National Law Review, they carry more weight than people expect. § 981 allows civil forfeiture tied to money laundering and fraud, and here's the part that surprises people: no criminal conviction is required. The government only has to clear a preponderance-of-evidence standard, a far lower bar than "beyond a reasonable doubt." § 982 handles criminal forfeiture, which kicks in after conviction. § 853(p), the substitute-asset provision, lets the government go after equivalent-value assets once the original proceeds have been moved, spent, or hidden. A federal forfeiture fund backs the FBI, a homeland-security investigative agency, and the Secret Service, and now feeds the strategic reserve too.
The civil path is the one that actually matters. It's faster, and the bar is lower, so most exchange seizures show up as a civil forfeiture complaint long before anyone gets indicted. Prosecutors are not quietly exploiting this as a loophole. It's the tool working exactly as designed.
Digital assets, including NFTs and DeFi tokens, now count as "property" for forfeiture purposes under executive guidance and case law, per that same National Law Review analysis. The same legal machinery built decades ago for cash, cars, and houses now applies cleanly to a wallet full of Ethereum.
States are all over the map here, and the gap between them is wide enough to matter. One state legislature signed a bill on June 23, 2025 spelling out virtual currency and digital wallets as forfeitable property, though it doesn't take effect until July 2026. Texas passed Senate Bill 1498, effective September 1, 2025, widening the definition of "contraband" to cover digital currencies, NFTs, and stablecoins. Most other states are still leaning on older, general forfeiture statutes never written with crypto in mind. That gap hasn't stopped a single prosecutor.
Connecticut State Police seized over $63,500 in cryptocurrency from an alleged phishing fraudster in August 2024, before any crypto-specific law existed on the books. Houston PD traced and seized $200,000 in a 2024 fraud case where the victim had sent over $800,000 in USDT and Ethereum to a platform that turned out to be fake. Old law, new asset, same outcome. Between the substitute-asset rule and the civil forfeiture path, authorities can move on exchange-held funds well before a full criminal case gets built, and that head start is what makes everything below possible.
How blockchain transparency becomes an investigative advantage, and why criminals cannot fully neutralize it
Blockchain intelligence means digging through public ledger data to trace transactions, tie wallets to real people, and flag activity that looks off. Criminals live with a strange irony here: the ledger they use to move money is the same ledger that never forgets. Nobody can quietly delete a transaction. It sits there, permanent and public, for anyone with the right tools to read.
Blockchain data alone doesn't crack cases, though. Investigators pull from corporate filings, cyber threat intelligence, dark web monitoring, exchange KYC records, seized servers, and old-fashioned human sources, then stitch it all together across domains that don't normally talk to each other.
A Hamas fundraising infrastructure case shows how that stitching works in practice. Investigators combined human sources with on-chain tracing to execute seizures under three separate warrants, recovering roughly $560,000 combined. The public transaction record exposed wallet relationships over time, but it only turned into a case once matched against off-chain intelligence.
The Colonial Pipeline ransomware recovery is the one most people remember. The DOJ traced about $2.3 million in Bitcoin paid as ransom, following the money through a chain of wallets before seizing the private keys outright. That case demonstrated how on-chain tracing could follow funds through layered wallets to a successful seizure.
The Southeast Asia pig butchering case involved Chainalysis, Tether, and the DOJ and the Secret Service. Investigators traced the illicit flows, and Tether froze around $225 million in USDT, the largest USDT freeze on record. Nobody seized a private key here. Tether just flipped the switch on its own token. Either the government seizes the keys, or a private issuer freezes the asset at the government's request. Criminals trying to dodge one method walk straight into the other.
What a coordinated exchange takedown looks like in practice, the Garantex case
Garantex is the clean example of how all of this comes together. Founded in late 2019 and originally registered in Estonia, the Russia-based exchange processed at least $96 billion in transactions before it went down. Per Chainalysis and OFAC, it served ransomware groups including Conti, Black Basta, LockBit, NetWalker, Phoenix Cryptolocker, and Ryuk, plus drug traffickers and sanctioned entities. In 2024 alone, Garantex and a second exchange, Nobitex, accounted for more than 85% of crypto inflows to sanctioned entities and jurisdictions, according to TRM Labs.
The takedown ran on a tight schedule. In early March 2025, a coordinated law enforcement action seized Garantex's web domain and froze more than $26 million in crypto. The next day, the DOJ unsealed indictments against executives Aleksandr Mira Serda and Aleksej Besciokov. Besciokov was arrested in India shortly after.
Getting there took multiple national jurisdictions working in sync, involving the DOJ, FBI, Europol, the Dutch National Police, Germany's BKA, the Frankfurt General Prosecutor's Office, Finland's National Bureau of Investigation, and Estonian National Criminal Police. No formal task force ran this. Call it a small international coalition instead, stitched together case by case.
None of it happened overnight, either. OFAC had designated Garantex back in April 2022, so the March 2025 action capped three years of documented sanctions before the physical strike landed. A follow-up re-designation on August 14, 2025 added cyber-authority charges under a separate executive order. The State Department backed the case with reward money too: up to $5 million for information leading to Mira Serda's arrest or conviction, up to $1 million for other Garantex leaders.
The sequencing is the part most writeups skip past. Domain seizure first, then freeze the funds, then make the indictments public. That order matters because it left Garantex's operators no warning window to move assets before the case became public knowledge.
The successor-entity problem, how criminal networks reconstitute after takedowns
Garantex didn't stay dead, and pretending otherwise misses the entire point of the case. Within days of the March 2025 takedown, Telegram channels tied to Garantex started promoting a near-identical replacement called Grinex. Per TRM Labs, Grinex had been registered in Kyrgyzstan back in December 2024, months before the takedown even happened. That's not coincidence. That's planning. OFAC designated Grinex and three Garantex executives on August 14, 2025, but by then, more than $100 million in transactions had already run through the rebranded Grinex operation alone, sanctions notwithstanding.
This pattern, repeating everywhere, is the strongest evidence that dollar-figure press releases oversell what a single takedown actually accomplishes. When Hydra Market got taken down in 2022, twelve Russian-language marketplaces sprang up to fill the gap, and within five months they'd collectively moved more volume than Hydra had moved in the same stretch before its own seizure, according to TRM Labs. Demand doesn't disappear when the platform does. It just finds a new address.
Xinbi Guarantee Marketplace saw the writing on the wall even earlier. Around June 2025, as law enforcement scrutiny built up, it started shifting parts of its merchant and money-laundering network onto SafeW, an encrypted messaging app, well before any seizure warrant showed up.
Here's the real measuring stick for these operations, and it's not the one that makes headlines. Dollar figures recovered look good in a press release, but the number that actually matters is how much damage got done to the underlying network. Seizures land hardest when they're paired with arrests of the people running things, because a website gets rebuilt over a weekend. A criminal's contact list takes a lot longer to replace, a gap enforcement should be chasing instead of the headline number.
The range of criminal ecosystems that exchange seizures now reach
Exchange seizures aren't limited to big-name platforms serving ransomware gangs anymore. In December 2025, federal prosecutors, working with international partners and a national police force, shut down E-Note, an exchange used to launder money for transnational cybercriminal groups targeting healthcare systems and critical infrastructure. The FBI traced more than $70 million in illicit proceeds from ransomware attacks and account takeovers flowing through E-Note since 2017. A Russian national, Mykhalio Petrovich Chudnovets, 39, was indicted on money laundering conspiracy charges.
Xinbi Guarantee Marketplace, hit with a DOJ seizure warrant in 2026, ran as a Chinese-language marketplace on Telegram where vendors sold custom scam investment websites, laundering services, and even recruited trafficking victims to staff scam compounds in Southeast Asia. OFAC sanctioned Xinbi as a transnational criminal organization. It had processed more than $24 billion in digital assets and traditional currency since roughly 2022, a scale that puts it in a different category entirely from a single rogue exchange.
Xinbi's takedown fell under a task force launched in 2025 by Attorney Jeanine Ferris Pirro, which has recovered more than $800 million total. Per the Secret Service, the launderers behind these networks mostly operate out of Southeast Asia, with IP addresses tracing back to China, Malaysia, and Cambodia.
The DOJ's Phoenix pig butchering case pulled in $112 million through warrants across the District of Arizona, the Central District of California, and the District of Idaho, coordinated by FBI Phoenix alongside the Criminal Division's National Cryptocurrency Enforcement Team, the Fraud Section, and the Money Laundering and Asset Recovery Section.
On July 21, 2026, the DOJ's Cyber Fraud Task Force filed five civil forfeiture complaints seeking more than $25 million total. One case tied roughly $10.4 million to a network flagged by Canadian authorities involving more than 270 suspected victims. Another linked about $12 million to online romance scams affecting more than 200 victims. Smaller complaints, in the range of $1.2 million to $2.4 million, covered separate victim-reported schemes.
Whether it's a formal exchange, a Telegram marketplace, or a network of money mules, the pattern doesn't change. The exchange layer is where illicit money has to surface before a criminal can spend it, and that's exactly where investigators plant their flag.
How the public-private intelligence model accelerates seizures that agencies could not execute alone
None of this runs on government horsepower alone, and pretending it does gives agencies too much credit. Operation Spincaster, a Chainalysis-led series of coordinated sprints pairing law enforcement with private sector partners to dismantle crypto scam networks, including approval phishing and pig butchering operations. In 2024 it ran across six countries, including the US, Canada, the UK, Spain, the Netherlands, and Australia, with Chainalysis providing investigative training on its own blockchain analysis tools.
The Tether freeze in the Southeast Asia pig butchering case is maybe the cleanest example of what this partnership actually buys investigators. Chainalysis and Tether worked directly with the DOJ and Secret Service, and Tether froze roughly $225 million in USDT at investigators' direction. A private company acted as the enforcement mechanism for an asset the government doesn't own and can't unilaterally touch. That's the arrangement in one sentence.
By the end of 2025, Chainalysis says it had helped partners seize or freeze around $34 billion worth of cryptocurrency. That's the return on years of this exact model running case after case, and it's a number the DOJ couldn't have hit working alone.
A lot of these cases start with a tip from the private side, not a government lead. In the DOJ Cyber Fraud Task Force's romance-scam investigation, a private sector partner flagged suspicious transactions that led directly to the $12 million complaint. Canadian authorities did the same for the network behind the $10.4 million complaint. Government brings subpoena power and the legal authority to freeze accounts. Private firms bring the analytical depth and the real-time data feeds that spot the pattern in the first place. Neither side gets there alone, not at this scale.
TRM Labs points to the friction underneath all of it: investigators need to search across blockchain data, corporate records, dark web forums, and threat intelligence in something close to plain language, with an audit trail preserved the whole way through. Building that kind of search tool inside a government agency, from scratch, is a heavy lift few agencies can pull off on their own. That gap is exactly what keeps the public-private arrangement necessary rather than optional.
What the volatility of seized assets means for victims, governments, and the integrity of enforcement
Before the Strategic Bitcoin Reserve existed, seized crypto usually got liquidated at auction and converted to cash. Now, under the SBR and Digital Assets Stockpile policy, the government holds onto it as a long-term asset instead. Per Blank Rome's National Law Review analysis, that means the government carries market exposure it never had before. If Bitcoin drops 30% while sitting in custody, that's the government's problem to manage, not a buyer's.
Victims sit in the middle of that risk, and this is the part policymakers seem to keep skipping over. Statutory rules require restitution and law enforcement funding to get paid before any asset goes into the reserve, but a case can drag on for months or years. If the crypto's value tanks while it's parked in government custody awaiting resolution, victims can end up with restitution that covers a lot less than what they actually lost, even though the seizure itself worked exactly as intended.
Most states haven't caught up to this problem at all. Per the National Association of Attorneys General, the bulk of states still lack legislation that deals with crypto forfeiture directly, which leaves the question of how to make victims whole when asset values swing wildly in custody unresolved across most of the country.
The substitute-asset provision under § 853(p) offers a partial fix, letting the government chase equivalent-value property when the original proceeds are gone or unrecoverable. But that only works if recoverable property exists somewhere to go after, and often it doesn't. The law is still catching up to an asset class that can lose a quarter of its value in a bad week, and that tension isn't closing anytime soon.
What security practitioners and vendors need to understand about how enforcement shapes the threat landscape they defend against
Enforcement doesn't erase criminal infrastructure. It reshapes it, and treating a takedown as a clean ending is the mistake most security teams still make. Every case above shows the same cycle: seize the exchange, and a near-identical successor shows up within weeks, sometimes registered months in advance. Security teams tracking wallet clusters, exchange flows, or ransomware payment infrastructure need to build that expectation into their models rather than closing the file the day a headline breaks.
Watch designation timelines, not just seizure headlines. OFAC sanctioned Garantex in 2022, and the physical action didn't land until 2025. That three-year gap is exactly the window operators used to stand up Grinex as a replacement. A sanctioned entity that's still technically operating doesn't mean enforcement failed. It usually means enforcement is mid-sequence, and the raid hasn't come yet.
The public-private intelligence model matters directly to any vendor building fraud detection or blockchain analytics tools. Cases succeed when siloed data (corporate records, KYC data, dark web chatter, on-chain flows) gets connected into one searchable picture. TRM Labs and Chainalysis have built entire businesses around closing that exact gap. Vendors serving this market aren't selling blockchain analysis alone anymore. They're selling the connective tissue between data sources that were never built to talk to each other, a capability enforcement agencies keep leaning on, case after case.
Sources
- Understanding Cryptocurrency Forfeiture: A Guide to Digital Asset Seizure
- Treasury Sanctions Cryptocurrency Exchange and Network Enabling Sanctions Evasion and Cyber Criminals
- District of Columbia | Investigations into Cryptocurrency Scams Result in Seizure of More Than $25 Million | United States Department of Justice
- Crypto-Crackdown: Criminal Forfeiture of Cryptocurrencies by States - National Association of Attorneys General
- U.S. Secret Service Washington Field Office Investigations Result in Seizure of more than $25 million taken in Cryptocurrency Scams | United States Secret Service
- Asset Seizure and Cryptocurrency - Chainalysis
- The Landscape of Seizable Crypto Assets in 2025 - Chainalysis
- chainalysis.com


