# Record $158 Billion Illicit Cryptocurrency Flows in 2025

> Chainalysis's 2025 Crypto Crime Report documents a record $51 billion in illicit cryptocurrency transaction volume for 2024, with cumulative illicit flows exceeding $158 billion since comprehensive tracking began. This represents the financial infrastructure layer underpinning virtually all modern cybercrime: ransomware ($1.1B in payments, 2023), investment fraud/pig butchering ($4.57B, FBI IC3 2023), darknet markets ($1.7B), stolen funds from DeFi exploits and bridge hacks ($3.8B, 2022 peak), sanctioned entity transactions ($14.9B), and money laundering through mixers, cross-chain bridges, and unregulated OTC desks. The cryptocurrency ecosystem has become the PREFERRED payment and laundering infrastructure for cybercriminals globally — from state-sponsored North Korean hackers (Lazarus Group: $1.7B in 2022, $600M Ronin Bridge) to ransomware gangs (Conti, LockBit, BlackCat/ALPHV, Cl0p), to HYIP/pig butchering syndicates (TL-2026-0017), to darknet marketplace operators (Hydra: $5.2B lifetime volume before seizure). Key trends: (1) Stablecoins (USDT/USDC) have overtaken Bitcoin as the primary medium for illicit transactions due to faster settlement, lower fees, and broader exchange acceptance; (2) Cross-chain bridges and DEX swaps are replacing traditional mixers (Tornado Cash, Sinbad) as primary laundering tools after OFAC sanctions disrupted centralized mixer operations; (3) North Korea's Lazarus Group is responsible for approximately 60% of all cryptocurrency stolen from DeFi platforms; (4) Ransomware payments remain at billion-dollar levels despite law enforcement successes (Hive, BlackCat takedowns); (5) KYC evasion via identity fraud and nested exchanges undermines the compliance framework designed to prevent crypto crime.

- **Published:** 2026-02-02T22:25:00Z
- **Last reviewed:** 2026-02-02T22:25:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0027
- **ID:** TL-2026-0027
- **Severity:** MEDIUM (CVSS 5)
- **Category:** THREAT_INTEL
- **Status:** ACTIVE
- **Detections:** 12 · **IOCs:** 40 (full data via the Threadlinqs MCP server — Purple tier)

## Description

The $158 billion in illicit cryptocurrency flows represents the convergence of traditional organized crime, state-sponsored hacking, cybercrime-as-a-service, and financial fraud into a single financial infrastructure that law enforcement and regulators struggle to control.

**Scale of the Problem:**

Chainalysis tracks illicit cryptocurrency activity across multiple categories:
- **Ransomware**: $1.1 billion in direct ransom payments (2023), down from $1.3B peak but still at historically high levels. Includes Conti, LockBit, BlackCat/ALPHV, Cl0p, Royal, Play, Akira.
- **Investment Fraud/Pig Butchering**: $4.57 billion (FBI IC3 2023). Connects to TL-2026-0017. Cryptocurrency is the EXCLUSIVE payment method for pig butchering scams due to irreversibility.
- **Stolen Funds (DeFi/Bridge Hacks)**: $3.8 billion peak (2022), ~$1.7B (2023). Major incidents: Ronin Bridge ($625M), Wormhole ($320M), Nomad Bridge ($190M), Euler Finance ($197M).
- **Sanctioned Entity Transactions**: $14.9 billion annually — includes OFAC-designated exchanges (Garantex), sanctioned nation-state wallets (North Korea, Iran, Russia), and sanctioned mixer services.
- **Darknet Markets**: $1.7 billion (2023). Hydra market ($5.2B lifetime) was seized in 2022; successors include Mega, OMG, Blacksprut.
- **Scams**: $5.9 billion (2023) across romance, giveaway, impersonation, and investment scams.
- **CSAM**: $25.4 million identified on-chain (likely significant undercount).

**The Laundering Pipeline:**

Illicit cryptocurrency follows a consistent laundering pattern:
1. **Placement**: Proceeds deposited to scammer/hacker-controlled wallet
2. **Layering Stage 1**: Rapid transfer through 5-50 intermediate wallets (peel chains)
3. **Layering Stage 2**: Conversion through mixers (Tornado Cash, Sinbad — now sanctioned), cross-chain bridges (RenBridge, THORChain, deBridge), or DEX swaps (Uniswap, 1inch)
4. **Layering Stage 3**: Stablecoin conversion (USDT/USDC) for price stability during layering
5. **Integration**: Conversion to fiat via:
   - Unregulated OTC desks (predominantly in China, Russia, UAE)
   - Nested exchanges (services that use Binance/other exchange infrastructure but apply minimal KYC)
   - Peer-to-peer platforms (LocalBitcoins successor services, Paxful)
   - Money mule networks with bank accounts in multiple jurisdictions

**North Korea (Lazarus Group / APT38):**

The DPRK's cryptocurrency theft program is arguably the most significant nation-state financial cybercrime operation in history:
- $1.7 billion stolen in 2022 alone (Chainalysis)
- $600 million Ronin Bridge hack (March 2022) — largest single DeFi theft
- Funds directly finance North Korea's weapons of mass destruction programs (UN Panel of Experts)
- Laundering via China-based OTC desks, Tornado Cash, Sinbad, and cross-chain bridges
- IT worker fraud scheme: DPRK citizens obtain remote tech jobs at Western companies, salary diverted to regime
- Estimated cumulative theft: $3+ billion since 2017

**Stablecoin Shift:**

A fundamental change in the illicit crypto landscape:
- 2020: Bitcoin dominated illicit transactions (~70%)
- 2024: Stablecoins (USDT primarily) account for >60% of illicit transaction volume
- Reasons: faster settlement, lower fees, broader acceptance, price stability during laundering
- Tether (USDT) has frozen $835+ million in addresses associated with illicit activity (as of mid-2024)
- USDC (Circle) has more aggressive compliance — accounts for smaller share of illicit volume
- Challenge: Tether operates primarily outside US jurisdiction, complicating enforcement

**Mixer Disruption & Evolution:**

- Tornado Cash sanctioned by OFAC (August 2022) — developers arrested
- Sinbad seized by FBI/Europol/Netherlands (November 2023)
- ChipMixer seized (March 2023)
- Blender.io sanctioned (May 2022)
- Result: Criminals shifting to cross-chain bridges and DEX swaps which are harder to sanction
- THORChain: $900M+ in illicit flows identified (Chainalysis)
- Cross-chain bridges now the PRIMARY laundering tool replacing traditional mixers

**Regulatory Response:**

- Travel Rule implementation expanding globally (FATF requirement for VASPs to share sender/receiver info)
- MiCA (Markets in Crypto-Assets) regulation in EU (effective 2024)
- US infrastructure bill KYC requirements for brokers
- OFAC sanctions on mixers, exchanges, and nation-state wallets
- Success: Hive ransomware takedown recovered $130M; Colonial Pipeline recovered $2.3M; Silk Road seizures totaling $3.36B
- Challenge: Decentralized protocols (DEXs, bridges) resist regulatory control by design

## MITRE ATT&CK

- T1589 Gather Victim Identity Information
- T1596 Search Open Technical Databases
- T1583 Acquire Infrastructure
- T1585 Establish Accounts
- T1190 Exploit Public-Facing Application
- T1566 Phishing
- T1204 User Execution
- T1528 Steal Application Access Token
- T1552 Unsecured Credentials
- T1005 Data from Local System
- T1567 Exfiltration Over Web Service
- T1657 Financial Theft
- T1486 Data Encrypted for Impact
- T1565 Data Manipulation
- T1496 Resource Hijacking

## Sources

- [Chainalysis — 2025 Crypto Crime Report](https://www.chainalysis.com/blog/crypto-crime-report/)
- [FBI IC3 — 2023 Internet Crime Report](https://www.ic3.gov/AnnualReport/Reports/2023_IC3Report.pdf)
- [US Treasury OFAC — Tornado Cash Sanctions](https://home.treasury.gov/news/press-releases/jy0916)
- [UN Security Council — DPRK Cryptocurrency Theft](https://www.un.org/securitycouncil/sanctions/1718/panel_experts/reports)
- [Europol — Sinbad Mixer Seizure](https://www.europol.europa.eu/media-press/newsroom/news/cryptocurrency-mixing-service-sinbadio-seized-in-international-law-enforcement-operation)
- [FinCEN — Virtual Asset Advisory](https://www.fincen.gov/resources/advisories)
- [FATF — Virtual Asset Guidance](https://www.fatf-gafi.org/en/publications/Fatfrecommendations/guidance-rba-virtual-assets-2021.html)
- [Chainalysis — North Korea Cryptocurrency Theft](https://www.chainalysis.com/blog/north-korea-cryptocurrency-theft/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0027
