Threat reportThreat IntelligenceTL-2026-0027

Record $158 Billion Illicit Cryptocurrency Flows in 2025

mediumACTIVE

Record $158 Billion Illicit Cryptocurrency Flows in 2025 (TL-2026-0027), also tracked as Crypto Crime, is a medium-severity tracked intrusion set scored CVSS 5, first published 2026-02-02. It carries a reported North Korea nexus and is not formally attributed, affects N/A Global Financial Systems, maps to 15 MITRE ATT&CK techniques (T1005, T1190, T1204), and is covered by 12 detection rules and 40 indicators of compromise.

CVSS
5/10Medium
CVEs
0None referenced
Techniques
15MITRE ATT&CK
Actors
0Not attributed
Detection rules
12SPL · KQL · Sigma
IOCs
40Indicators of compromise

Key facts for TL-2026-0027

Threat ID
TL-2026-0027
Also known as
Crypto Crime, Cryptocurrency Money Laundering, Ransomware Payments
Severity
MEDIUM
CVSS
5 (N/A - Threat Intelligence Report)
Status
ACTIVE
Category
THREAT_INTEL
First published
Last reviewed
Attribution confidence
NONE
Nation-state nexus
North Korea
Motivation
FINANCIAL
Target sectors
Finance, Cryptocurrency, All Sectors (ransomware targets)
Target regions
Global
Detection rules
12
Indicators of compromise
40

How Record $158 Billion Illicit Cryptocurrency Flows in 2025 works

Chainalysis's 2025 Crypto Crime Report documents a record $51 billion in illicit cryptocurrency transaction volume for 2024, with cumulative illicit flows exceeding $158 billion since comprehensive tracking began. This represents the financial infrastructure layer underpinning virtually all modern cybercrime: ransomware ($1.1B in payments, 2023), investment fraud/pig butchering ($4.57B, FBI IC3 2023), darknet markets ($1.7B), stolen funds from DeFi exploits and bridge hacks ($3.8B, 2022 peak), sanctioned entity transactions ($14.9B), and money laundering through mixers, cross-chain bridges, and unregulated OTC desks. The cryptocurrency ecosystem has become the PREFERRED payment and laundering infrastructure for cybercriminals globally — from state-sponsored North Korean hackers (Lazarus Group: $1.7B in 2022, $600M Ronin Bridge) to ransomware gangs (Conti, LockBit, BlackCat/ALPHV, Cl0p), to HYIP/pig butchering syndicates (TL-2026-0017), to darknet marketplace operators (Hydra: $5.2B lifetime volume before seizure). Key trends: (1) Stablecoins (USDT/USDC) have overtaken Bitcoin as the primary medium for illicit transactions due to faster settlement, lower fees, and broader exchange acceptance; (2) Cross-chain bridges and DEX swaps are replacing traditional mixers (Tornado Cash, Sinbad) as primary laundering tools after OFAC sanctions disrupted centralized mixer operations; (3) North Korea's Lazarus Group is responsible for approximately 60% of all cryptocurrency stolen from DeFi platforms; (4) Ransomware payments remain at billion-dollar levels despite law enforcement successes (Hive, BlackCat takedowns); (5) KYC evasion via identity fraud and nested exchanges undermines the compliance framework designed to prevent crypto crime.

The $158 billion in illicit cryptocurrency flows represents the convergence of traditional organized crime, state-sponsored hacking, cybercrime-as-a-service, and financial fraud into a single financial infrastructure that law enforcement and regulators struggle to control.

**Scale of the Problem:**

Chainalysis tracks illicit cryptocurrency activity across multiple categories: - **Ransomware**: $1.1 billion in direct ransom payments (2023), down from $1.3B peak but still at historically high levels. Includes Conti, LockBit, BlackCat/ALPHV, Cl0p, Royal, Play, Akira. - **Investment Fraud/Pig Butchering**: $4.57 billion (FBI IC3 2023). Connects to TL-2026-0017. Cryptocurrency is the EXCLUSIVE payment method for pig butchering scams due to irreversibility. - **Stolen Funds (DeFi/Bridge Hacks)**: $3.8 billion peak (2022), ~$1.7B (2023). Major incidents: Ronin Bridge ($625M), Wormhole ($320M), Nomad Bridge ($190M), Euler Finance ($197M). - **Sanctioned Entity Transactions**: $14.9 billion annually — includes OFAC-designated exchanges (Garantex), sanctioned nation-state wallets (North Korea, Iran, Russia), and sanctioned mixer services. - **Darknet Markets**: $1.7 billion (2023). Hydra market ($5.2B lifetime) was seized in 2022; successors include Mega, OMG, Blacksprut. - **Scams**: $5.9 billion (2023) across romance, giveaway, impersonation, and investment scams. - **CSAM**: $25.4 million identified on-chain (likely significant undercount).

**The Laundering Pipeline:**

Illicit cryptocurrency follows a consistent laundering pattern: 1. **Placement**: Proceeds deposited to scammer/hacker-controlled wallet 2. **Layering Stage 1**: Rapid transfer through 5-50 intermediate wallets (peel chains) 3. **Layering Stage 2**: Conversion through mixers (Tornado Cash, Sinbad — now sanctioned), cross-chain bridges (RenBridge, THORChain, deBridge), or DEX swaps (Uniswap, 1inch) 4. **Layering Stage 3**: Stablecoin conversion (USDT/USDC) for price stability during layering 5. **Integration**: Conversion to fiat via: - Unregulated OTC desks (predominantly in China, Russia, UAE) - Nested exchanges (services that use Binance/other exchange infrastructure but apply minimal KYC) - Peer-to-peer platforms (LocalBitcoins successor services, Paxful) - Money mule networks with bank accounts in multiple jurisdictions

**North Korea (Lazarus Group / APT38):**

The DPRK's cryptocurrency theft program is arguably the most significant nation-state financial cybercrime operation in history: - $1.7 billion stolen in 2022 alone (Chainalysis) - $600 million Ronin Bridge hack (March 2022) — largest single DeFi theft - Funds directly finance North Korea's weapons of mass destruction programs (UN Panel of Experts) - Laundering via China-based OTC desks, Tornado Cash, Sinbad, and cross-chain bridges - IT worker fraud scheme: DPRK citizens obtain remote tech jobs at Western companies, salary diverted to regime - Estimated cumulative theft: $3+ billion since 2017

**Stablecoin Shift:**

A fundamental change in the illicit crypto landscape: - 2020: Bitcoin dominated illicit transactions (~70%) - 2024: Stablecoins (USDT primarily) account for >60% of illicit transaction volume - Reasons: faster settlement, lower fees, broader acceptance, price stability during laundering - Tether (USDT) has frozen $835+ million in addresses associated with illicit activity (as of mid-2024) - USDC (Circle) has more aggressive compliance — accounts for smaller share of illicit volume - Challenge: Tether operates primarily outside US jurisdiction, complicating enforcement

**Mixer Disruption & Evolution:**

- Tornado Cash sanctioned by OFAC (August 2022) — developers arrested - Sinbad seized by FBI/Europol/Netherlands (November 2023) - ChipMixer seized (March 2023) - Blender.io sanctioned (May 2022) - Result: Criminals shifting to cross-chain bridges and DEX swaps which are harder to sanction - THORChain: $900M+ in illicit flows identified (Chainalysis) - Cross-chain bridges now the PRIMARY laundering tool replacing traditional mixers

**Regulatory Response:**

- Travel Rule implementation expanding globally (FATF requirement for VASPs to share sender/receiver info) - MiCA (Markets in Crypto-Assets) regulation in EU (effective 2024) - US infrastructure bill KYC requirements for brokers - OFAC sanctions on mixers, exchanges, and nation-state wallets - Success: Hive ransomware takedown recovered $130M; Colonial Pipeline recovered $2.3M; Silk Road seizures totaling $3.36B - Challenge: Decentralized protocols (DEXs, bridges) resist regulatory control by design

MITRE ATT&CK techniques used in TL-2026-0027

collection

T1005 Data from Local System

initial-access

T1190 Exploit Public-Facing Application; T1566 Phishing

execution

T1204 User Execution

impact

T1486 Data Encrypted for Impact; T1496 Resource Hijacking; T1565 Data Manipulation; T1657 Financial Theft

credential-access

T1528 Steal Application Access Token; T1552 Unsecured Credentials

exfiltration

T1567 Exfiltration Over Web Service

resource-development

T1583 Acquire Infrastructure; T1585 Establish Accounts

reconnaissance

T1589 Gather Victim Identity Information; T1596 Search Open Technical Databases

Affected products and versions in Record $158 Billion Illicit Cryptocurrency Flows in 2025

  • N/A — Global Financial Systems
    Vulnerable versions: All

Remediation for Record $158 Billion Illicit Cryptocurrency Flows in 2025

Immediate actions

  • Block connections to known mining pools
  • Scan for cryptocurrency mining software on endpoints
  • Monitor for high CPU/GPU usage anomalies
  • Review DNS logs for mining-related domains

Workarounds

  • Block common mining ports at firewall
  • Use browser extensions to block web miners
  • Implement application allowlisting

Longer-term hardening

  • Implement crypto transaction monitoring for financial sector
  • Deploy EDR with cryptojacking detection
  • Establish ransomware response procedures including payment policies
  • Train staff on cryptocurrency-related threats

Timeline of Record $158 Billion Illicit Cryptocurrency Flows in 2025

  • Lazarus Group steals $625 million from Ronin Bridge (Axie Infinity) — the largest DeFi hack in history. Exploited compromised validator keys. FBI attributes to North Korea. Demonstrates state-sponsored cryptocurrency theft at scale: single operation exceeds many nations' entire cybercrime losses. Chainalysis traces funds through Tornado Cash. Source: FBI attribution statement, Chainalysis analysis.
  • US Treasury OFAC sanctions Tornado Cash cryptocurrency mixer — the first time a decentralized protocol (smart contract) is sanctioned. Tornado Cash processed $7+ billion including $455M for Lazarus Group. Developers Roman Storm and Alexey Pertsev arrested. Landmark regulatory action disrupting primary mixer used for laundering stolen crypto. Forces criminals to shift to cross-chain bridges. Source: https://home.treasury.gov/news/press-releases/jy0916
  • Chainalysis 2024 Crypto Crime Report documents $24.2 billion in illicit cryptocurrency transaction volume for 2023. Investment fraud ($4.57B) exceeds ransomware ($1.1B) as largest single category. Stablecoins overtake Bitcoin as primary medium for illicit transactions. North Korea steals $1.7B in 2022, Lazarus Group identified as most prolific DeFi attacker. Cumulative illicit flows since tracking began approach $100B. Source: Chainalysis.
  • FBI, Europol, and Dutch National Police seize Sinbad cryptocurrency mixer — the successor to Blender.io (sanctioned May 2022). Sinbad processed hundreds of millions in Lazarus Group stolen funds. Third major mixer taken down in 18 months (Blender, ChipMixer, Sinbad). Mixer disruption campaign forces laundering evolution toward cross-chain bridges and DEX swaps. Source: https://www.europol.europa.eu/
  • Stablecoins (USDT/USDC) now account for over 60% of illicit cryptocurrency transaction volume, overtaking Bitcoin. Tether has frozen $835+ million in addresses linked to illicit activity. Cross-chain bridges (THORChain: $900M+ illicit flows) replace sanctioned mixers as primary laundering tool. The laundering infrastructure has EVOLVED: mixers → bridges → DEX swaps → stablecoins → OTC desks → fiat. Source: Chainalysis, Elliptic.
  • Chainalysis 2025 Crypto Crime Report: cumulative illicit cryptocurrency flows exceed $158 billion since comprehensive tracking began. 2024 volume approximately $51 billion including sanctioned entity transactions. North Korea responsible for ~60% of all stolen DeFi funds. Regulatory response expanding (MiCA, Travel Rule) but decentralized protocols resist control by design. The gap between illicit flows and enforcement capacity continues to widen. Source: Chainalysis 2025 report.
  • As of 2026-05-29, this illicit-crypto-flows trend is intensifying, not dormant: Chainalysis's 2026 report puts 2025 illicit volume at a record $154B (+162% YoY), with sanctions evasion up 694% (Russia's A7A5, $93.3B) and stablecoins at ~84%. North Korea stole a record ~$2.02B in 2025 (incl. the $1.5B Bybit heist) and kept hitting DeFi into 2026.

Sources cited for Record $158 Billion Illicit Cryptocurrency Flows in 2025

Detection coverage for TL-2026-0027

As of 2026-02-02, Threadlinqs Intelligence publishes 12 detection rule(s) for TL-2026-0027 across Splunk SPL, Microsoft KQL and Sigma, covering 40 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

12 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
40 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats