Cybercrime DB

Seized Cybercrime Asset Forfeiture Outcomes

Most seized cybercrime money never reaches the victims who lost it.

Staff Writer · · 11 min read
Cover illustration for “Seized Cybercrime Asset Forfeiture Outcomes”
cybercrime takedowns and seizures · September 17, 2026 · 11 min read · 2,404 words

The FBI's IC3 report put cybercrime losses at $20.877 billion in 2025, and complaints crossed 1 million for the first time ever. Both are records, and neither is the interesting part. The interesting part is what happens after: how much of that money actually gets clawed back, who it goes to, and whether the machinery of seizure and forfeiture works the way most people assume it does. Spoiler: it doesn't, not entirely, and the gap between "we seized it" and "you got your money back" is where this story actually lives.

The scale keeps climbing, too. That $20.877 billion figure is up 26% from 2024's $16.6 billion, which was itself a 33% jump over 2023. That's a trend line the article treats as sustained growth rather than a spike. That's a trend line with a bad attitude. Investment fraud alone accounted for the larger share of 2025 losses, with business email compromise adding a substantial sum on top of that. Digital assets were involved in nearly 150,000 complaints in 2024, totaling $9.3 billion, a 66% jump year over year. And all of that is just what got reported. IC3 numbers only capture people who filed a complaint, so the real total is bigger, possibly a lot bigger.

What seizure and forfeiture mean, and why the distinction matters

Seizure and forfeiture get used like synonyms in headlines, but they're not the same thing, and the difference matters if you're trying to figure out who actually ends up owning the money.

Seizure is temporary. It's the government taking control of an asset it suspects is tied to a crime, sort of like impounding a car until someone sorts out whose name is actually on the title. Forfeiture is permanent: it's the legal process that transfers ownership to the government for good, after a judge signs off. Civil forfeiture goes after the asset itself, not the person attached to it, which means prosecutors don't need a criminal conviction to keep the money. Criminal forfeiture, by contrast, only kicks in after someone's actually been convicted.

Crypto adds its own wrinkle. Investigators use five tools in combination: freezing, seizing, burning, reissuing, and forfeiting. Stablecoin issuers Tether and Circle have both frozen and burned tokens at law enforcement's request, and when tokens get burned, an equivalent amount can be reissued, minted fresh and handed to the government or to victims. It's a strange kind of alchemy: destroy the coin, mint a replacement, hand it over. Most states still don't have laws written specifically for digital asset seizure, so officers have been stretching old forfeiture statutes to cover new technology, which creates exactly the kind of legal patchwork you'd expect. Texas closed part of that gap with Senate Bill 1498, effective September 1, 2025, which classifies digital currencies, digital collectibles, and stablecoins as "contraband" when tied to criminal activity. Connecticut followed with House Bill 6990, signed June 23, 2025, taking effect July 1, 2026.

None of this happens fast. The pipeline from seizure to final forfeiture can take months, sometimes years, and during that whole stretch the asset sits in government custody. For crypto, where prices can swing wildly, that waiting period functions as a financial variable all its own. It's a financial variable all its own.

How the Treasury and DOJ forfeiture funds work

Money seized in cybercrime cases doesn't just vanish into a government vault somewhere. It flows into specific funds with specific rules, and those rules shape what enforcement prioritizes.

The Treasury Forfeiture Fund pulled in $2.263 billion in gross non-exchange revenues in fiscal year 2024, up from $1.619 billion the year before. The Fund has a stated performance target: 80% of forfeitures should be "high-impact" cases, meaning currency seizures of $100,000 or more. In FY 2024, participating bureaus blew past that target, hitting 95%. That's what the incentive structure produces. It's what the incentive structure produces.

The Fund also handed out $124 million in Strategic Support funding to member agencies in FY 2024, aimed at things like cyber investigative capabilities and analytical tools. Meanwhile, the DOJ's Asset Forfeiture Program reports to Congress every year, a requirement baked into the Civil Asset Forfeiture Reform Act of 2000, and those reports are public.

Forfeited money doesn't automatically go back to victims, which surprises people. It gets reinvested in law enforcement infrastructure, funds future investigations, and gets shared with state and local agencies through equitable sharing arrangements. Victims are last in line behind law enforcement infrastructure, future investigations, and state and local agencies through equitable sharing arrangements. They're not even guaranteed a line. And because the whole system is built around chasing high-impact, six-and-seven-figure seizures, smaller victims, the ones who lost far less rather than a sum many multiples larger, are simply less likely to be part of a case big enough to generate a large single forfeiture in the first place.

Diagram: Cybercrime Losses: Three Years of Sustained Growth. Visualizes: Show the year-over-year escalation in IC3-reported cybercrime losses across three years: $16.6 billion in 2024 (a 33% jump over 2023) rising to $20.877 billion in 2025 (a 26%…

What landmark seizures show about enforcement capability, and its ceiling

Enforcement can trace crypto now. That much is settled. Whether tracing translates into recovery for the people who actually lost money is a separate question, and the landmark cases from the past few years answer both at once.

Take June 2025: a federal prosecutor's office. Attorney's Office filed a civil forfeiture complaint against more than $225.3 million in cryptocurrency tied to confidence scams, the largest seizure in Secret Service history, with over 400 suspected victims identified. Investigators used TRM Labs' blockchain intelligence tooling to trace more than $263,000 in proceeds from just six victims through 42 intermediary wallets before it landed in an OKX account. Forty-two hops. That's not a paper trail, that's a maze, and investigators walked the whole thing.

Then October 2025 delivered something bigger still: authorities seized 127,271 Bitcoin connected to Chen Zhi and the Cambodian Prince Group, valued around $15 billion. Prince Group stands accused of running scam compounds involving forced labor and human trafficking, which makes this less a financial crimes case and more something closer to organized crime with a crypto wallet attached. Reports emerged, however, that DOJ had rejected numerous victim claims and hadn't provided claimants enough information about where the Bitcoin came from or how it moved. Fifteen billion dollars seized, and the people it was stolen from still can't get straight answers.

Other cases follow the same pattern of technical success paired with an uncertain payout. In 2023, FBI Phoenix led a seizure of roughly $112 million tied to pig-butchering investment scams, warrants stretching across Arizona, California, and Idaho, coordinated with federal prosecutors. In August 2025, DOJ unsealed warrants seizing over $2.8 million in crypto, $70,000 in cash, and a luxury vehicle from a man charged in connection with Zeppelin ransomware attacks run between 2019 and 2022. In September 2024, a federal agency. seized over $6 million from overseas scammers after the FBI traced victim funds to wallets that still held the money. And a Connecticut case in 2026 saw the FBI and state police trace transactions and recover about $600,000 in Tether after a scam involving fake mail from "Ledger Security & Compliance" convinced a victim to hand over roughly $234,000 in crypto.

Operation Cronos, the February 2024 takedown of the LockBit ransomware group, complicates the victory narrative. The operation, run by law enforcement agencies across multiple countries, seized servers, shut down rogue accounts, froze crypto accounts tied to LockBit, and recovered decryption keys. LockBit had hit a large number of organizations and pulled in substantial ransoms. It was, by most measures, a massive operational win. LockBit was back up within a week. That rarely makes the press release, but it matters most for anyone trying to gauge whether a takedown actually ends a threat or just interrupts it for a few days.

Operation Spincaster, a Chainalysis-led effort spanning six countries in 2024, generated over 7,000 investigative leads connected to roughly $162 million in scam losses, another reminder that the tracing infrastructure itself is no longer the bottleneck. Blockchain analysis is now routine. What happens after the trace is where things get messy.

Why victims often do not receive what enforcement recovers

Diagram: The Recovery Gap: Seized vs. Returned. Visualizes: Contrast the scale of headline seizures against what victims actually received in the same cases.

Here's the mechanism most people don't know about until it bites them: under a federal regulation. Under § 9.8(c), victims are entitled only to the value of the asset at the time it was stolen. If a hacker stole your Bitcoin when it was worth a fraction of its eventual value and it's appreciated several times over by the time forfeiture wraps up, the appreciation doesn't follow you home. It stays with the government.

The Bitfinex case is the textbook illustration. The government recovered more than 94,000 BTC tied to the 2016 Bitfinex hack, and in an April 2025 memorandum opinion, the court in United States v. Lichtenstein awarded zero mandatory restitution under the Mandatory Victims Restitution Act. Why? Because the defendants were convicted of laundering the proceeds, not of the hack itself, which meant Bitfinex and its account holders technically didn't qualify as "victims" under the statute. The court did order voluntary in-kind restitution of roughly 94,643 BTC back to Bitfinex, but only through plea agreements and a separate ancillary process under Rule 32.2, not because the law required it. Recovery happened here almost despite the framework, not because of it.

The Prince Group case shows the same failure mode playing out at a much larger scale. DOJ had rejected numerous victim claims tied to that $15 billion Bitcoin seizure, and claimants faced difficulty getting adequate information about the coin's origin and movement to even build a case. Victims run into a wall of technical tracing requirements, murky administrative procedures, and competition from other claimants, all before a judge even gets to the question of who gets what.

It's not always this bad, though. The BitConnect case is the counterexample to remember. After the government liquidated about $56 million in crypto seized from BitConnect's top domestic promoter. promoter, a federal court in San Diego ordered over $17 million distributed to roughly 800 victims across more than 40 countries. It's one of the cleaner outcomes on record, and it stands out precisely because it's the exception, not the rule. Most victims are looking at a gap of years between the seizure that makes headlines and any actual money hitting their account, if it ever does.

The DOJ's 2025 reassessment and where reform stands

DOJ knows the current system has a problem. In 2025, the department said it would reassess how it values forfeited assets returned to crime victims, particularly in crypto cases, where the gap between seizure-day value and return-day value can be enormous. The Deputy Attorney General directed the Office of Legal Policy and the Office of Legislative Affairs to look at regulatory and legislative changes that might fix the digital asset forfeiture process.

That's the direction. The specifics, the actual policy changes and their timeline, haven't been announced yet.

States aren't waiting around for federal regulators to sort it out. Texas and Connecticut have both passed laws giving officers explicit authority to seize digital assets, but most states still haven't touched the issue, which means the rules an investigator can use depend entirely on which state line the crime happens to cross. That's an awkward setup for a type of crime that, by its nature, doesn't respect state lines at all.

Meanwhile, the most effective recovery tool in operation right now doesn't run through forfeiture at all. The FBI's Financial Fraud Kill Chain initiated about 3,900 interventions in 2025, freezing more than $679 million in fraudulent transfers with a 58% success rate, and it does this before the money ever reaches the forfeiture pipeline. Operation Level Up, a related FBI initiative aimed at crypto investment scams, notified 3,780 victims in 2025, and 78% of them had no idea they were even being scammed. Since 2024, the initiative claims to have reduced potential losses by more than $500 million. Both programs point at the same conclusion: the legal machinery for handling money after it's seized is lagging well behind the technical ability to seize it in the first place.

What the forfeiture record tells practitioners and security vendors about the real threat environment

Blockchain tracing works. The $225.3 million case and the $15 billion Prince Group seizure both prove that large-scale crypto tracing is no longer some cutting-edge capability reserved for a handful of specialists, it's routine work for federal agencies now. That part of the story is settled, and anyone still treating blockchain analysis as a novelty is behind the curve.

But seizure isn't recovery, and treating the two as interchangeable is the single biggest misread available in this space. Bitfinex needed a plea agreement and a separate legal process to get its coins back. Prince Group victims, as of the most recent reporting, still don't have answers, let alone money. For any organization thinking through its own cyber risk, the honest takeaway is that recovery after the fact isn't a plan, it's a hope. Prevention and early interdiction, the kind of real-time intervention the Financial Fraud Kill Chain is built around, represent the actual window where money gets saved. Once funds are gone and a case is filed, the timeline stretches into years and the outcome stops being guaranteed.

That's a useful reality check for security vendors talking to CISOs and security engineers, too. Threat intelligence pitched around "we'll help you recover after a breach" is selling a promise the enforcement data doesn't back up. Pitched around loss prevention instead, that same intelligence is grounded in what actually happens, not what victims wish would happen.

Ransomware economics are shifting in a way that adds another layer of nuance. Chainalysis found ransom payments fell 35% in 2024, yet complaint volume kept climbing anyway, from 3,156 in 2024 to 3,611 in 2025. Operations like Cronos suppress payouts without eliminating the threat, and LockBit's five-day bounce-back is the clearest evidence available that disruption and elimination are two very different outcomes. Even the baseline numbers carry more uncertainty than they look like they do: TRM Labs revised its 2023 illicit crypto volume estimate upward by 69%, to $58.7 billion, after the figure was first published. Anyone citing illicit volume stats should treat them as floors, not ceilings.

The record here doesn't reward tidy narratives. Enforcement has gotten genuinely good at finding the money. Turning that find into a check in a victim's hand is still the unsolved part, and pretending otherwise is the fastest way to lose credibility with anyone who actually knows how the process works.

Sources

  1. Reports
  2. OIG25019(Web-copy, 508)
  3. Cybercrime Losses Increased by 33% in 2024 to $16.6bn
  4. 2025 Losses to Cybercrime Exceeded $20 Billion
  5. A Record-Breaking Year for Cybercrime: Key Findings from the FBI’s 2024 IC3 Report | TRM Labs

More in cybercrime takedowns and seizures