National-Level Players Enter the Game: Deciphering the Escalation and Transformation of Crypto Crime in 2025

marsbitОпубликовано 2026-01-12Обновлено 2026-01-12

Введение

In 2025, state-level involvement in cryptocurrency-related activities has significantly increased, marking a new phase in the maturation of illicit on-chain ecosystems. Illicit addresses received at least $154 billion, a 162% year-over-year surge, largely driven by a 694% increase in transactions involving sanctioned entities. Even excluding these, 2025 was a record year for crypto crime, with growth across most illegal categories. Stablecoins now dominate illicit transactions, accounting for 84% of the total. Nation-state threats were particularly prominent: North Korean hackers stole $2 billion, including a historic $1.5 billion attack on Bybit. Russia launched the ruble-backed A7A5 token, which saw $93.3 billion in transactions within a year, facilitating large-scale sanctions evasion. Iranian proxy networks and China-based money laundering networks also expanded their operations, offering specialized services like fraud, terror financing, and sanctions avoidance. The rise of full-stack illicit infrastructure providers has enabled both criminals and state actors to conduct malicious activities more effectively. Moreover, the connection between crypto crime and real-world violence is growing, with increased use in human trafficking and violent coercion attacks. Despite these challenges, illicit activity still represents less than 1% of all traceable cryptocurrency transaction volume. Collaboration among law enforcement, regulators, and crypto businesses remains crucial t...

Authored by: Chainalysis

Compiled by: Chopper, Foresight News

In 2025, we observed a significant increase in state-level cryptocurrency-related activities, marking a new mature phase in the development of the illegal on-chain ecosystem. Over the past few years, the professionalization within the crypto crime sphere has deepened; illicit organizations have established large-scale on-chain infrastructure to support transnational criminal networks in procuring goods and services and laundering crypto crime proceeds. Against this backdrop, national governments have also begun to engage in this domain, leveraging these mature professional service providers on one hand, and building their own customized infrastructure on the other, to evade sanctions on a large scale. As governments tap into this illicit cryptocurrency supply chain originally built for cybercriminals and organized crime groups, government agencies, compliance, and security teams now face severe challenges in terms of consumer protection and national security.

What are the specific on-chain manifestations of these developments and other industry changes? Next, we will analyze them by combining data and macro trends.

According to our monitoring data, the scale of funds flowing into illicit cryptocurrency addresses in 2025 reached at least $154 billion, a sharp increase of 162% year-on-year. This growth was primarily driven by a surge in fund inflows to sanctioned entities, which soared by 694% year-on-year. However, even excluding the growth from sanctioned entities, 2025 still stands as a record year for crypto crime, as the vast majority of illicit activity categories saw growth.

Nevertheless, the scale of these illicit transactions still pales in comparison to the overall cryptocurrency economy, where legitimate transactions remain the mainstay. We estimate that although the proportion of illicit transactions in the total traceable cryptocurrency transaction volume in 2025 increased slightly compared to 2024, it remained below 1%.

As shown in the figure below, we also observed a continuing shift in the types of assets involved in crypto crime.

Over the past few years, stablecoins have gradually become the dominant asset for illicit transactions, currently accounting for 84% of the total illicit transaction volume. This trend aligns with the overall development characteristics of the cryptocurrency ecosystem: with advantages such as convenience for cross-border transfers, low volatility, and wide application scenarios, the share of stablecoins in the entire cryptocurrency transaction volume continues to expand.

The following sections will delve into the core trends that defined the crypto crime landscape in 2025, trends that will remain important to watch in the future.

National-Level Threats Drive Transaction Volume: North Korean Thefts Hit Record High, Russian A7A5 Token Facilitates Large-Scale Sanction Evasion

In 2025, stolen funds remained a major threat to the cryptocurrency ecosystem, with North Korean-linked hacker groups alone stealing $2 billion. This figure was primarily driven by several highly destructive large-scale hacking incidents, the most notable being the attack on the Bybit exchange in February. The incident involved nearly $1.5 billion, making it the largest digital asset theft in the history of cryptocurrency. Although North Korean hackers have long been a major force threatening the cryptocurrency ecosystem, the past year saw record highs both in the amount stolen and in the sophistication of their intrusion and money laundering methods.

Particularly noteworthy is that the scale of on-chain activities by national governments reached unprecedented levels in 2025. Russia introduced relevant legislation in 2024 to promote the use of cryptocurrency to evade sanctions, and this measure was formally implemented in February 2025. The country launched the ruble-backed token A7A5, which saw its transaction volume exceed $93.3 billion in less than a year since its launch.

Meanwhile, over the past few years, Iran's proxy networks have conducted money laundering, illegal oil trading, and procurement of weapons and bulk commodities on-chain through identifiable wallet addresses already on sanctions lists, with a cumulative transaction volume exceeding $2 billion. Despite multiple military strikes, Iran-backed terrorist groups such as Hezbollah, Hamas, and the Houthis continue to use cryptocurrency on an unprecedented scale.

In 2025, Chinese money laundering networks emerged as a dominant force in the illicit on-chain ecosystem. These organizations operate with sophisticated models, significantly driving the diversification and professionalization of crypto crime, offering specialized criminal services including "money laundering services." Building on early illegal operation models like "Huiyin Guarantee," these networks have established full-service criminal enterprises, covering areas such as fraud, scams, laundering proceeds from North Korean hacker thefts, sanction evasion, and terrorism financing.

Full-Stack Illicit Infrastructure Providers Fuel Malicious Cyber Activities

While national governments are increasing their use of cryptocurrency, traditional cybercrime remains rampant: ransomware operators, child sexual abuse and cybercrime platforms, malware distributors, scammers, and illicit marketplaces still rely on vast support networks to maintain operations. Illicit actors and national governments are increasingly dependent on full-stack on-chain infrastructure providers, including domain registrars, secure and reliable hosting services, and other technical infrastructure that can be used for malicious cyber activities.

These infrastructure providers have evolved into comprehensive infrastructure platforms capable of resisting platform takedowns, abuse complaints, and sanction enforcement. As the scale of these services continues to expand, they are likely to become a key force driving economic crime and state-backed entities to broaden the scope of their malicious cyber activities.

Growing Correlation Between Cryptocurrency and Violent Crime

In the perception of many, crypto crime is still confined to the virtual world. The masterminds are merely anonymous figures hiding behind keyboards, not translating into real-world threats. But in reality, the link between on-chain activities and violent crime is deepening. Human trafficking rings are increasingly using cryptocurrency for transactions; at the same time, disturbingly, there has been a significant rise in cases of violent coercion attacks, where criminals use violence to force victims to transfer crypto assets, and such assaults often occur during peak cryptocurrency price periods.

Looking ahead, collaboration between law enforcement agencies, regulatory bodies, and cryptocurrency companies will be key to addressing these complex, evolving, and interconnected threats. Although the proportion of illicit transactions within legitimate cryptocurrency trading volume remains limited, maintaining the integrity and security of the cryptocurrency ecosystem has never been more important.

Связанные с этим вопросы

QWhat was the total value of illicit cryptocurrency transactions in 2025, and what was the primary driver of this growth?

AThe total value of illicit cryptocurrency transactions in 2025 reached at least $154 billion, a 162% year-over-year increase. This growth was primarily driven by a massive 694% surge in transaction volume from sanctioned entities.

QWhich asset type has become the dominant medium for illicit transactions and what percentage of the total illicit volume does it represent?

AStablecoins have become the dominant asset for illicit transactions, representing 84% of the total illicit transaction volume.

QWhat significant role did nation-states play in the 2025 crypto crime landscape, according to the article?

ANation-states played a significant role, with activities reaching unprecedented levels. This included North Korean hackers stealing a record $2 billion, Russia launching the A7A5 token to facilitate large-scale sanctions evasion (with nearly $93.3 billion in volume), and Iran's proxy networks laundering over $2 billion for activities like illegal oil trading and weapons procurement.

QWhat new concerning trend is emerging regarding the connection between cryptocurrency and real-world violence?

AA concerning trend is the increasing connection between on-chain activity and violent crime. This includes human trafficking syndicates using crypto for transactions and a significant rise in violent coercion attacks, where victims are physically forced to transfer crypto assets, often during periods of peak cryptocurrency prices.

QWhat is the role of 'full-stack illicit infrastructure providers' in the current crypto crime ecosystem?

AFull-stack illicit infrastructure providers offer comprehensive services to both criminals and nation-states. They have evolved into resilient platforms that can withstand takedowns, abuse complaints, and sanctions enforcement. Their services include domain registration, secure hosting, and other technical infrastructure for malicious cyber activity, making them a critical force in enabling economic crime and state-sponsored operations.

Похожее

Stuck Polymarket: The Real Test After Riding the Traffic Boom Has Arrived

Polymarket, a leading prediction market platform, is facing significant technical challenges as its growth outpaces its current infrastructure on Polygon. Users are experiencing laggy transactions, unresponsive orders, and delayed confirmations, severely impacting the trading experience. In response, DeFi Engineering VP Josh Stevens outlined a comprehensive engineering overhaul. The plan includes reducing on-chain data delays, fixing order cancellation issues, rebuilding the central limit order book (CLOB), improving website performance, and developing a unified SDK and API. A major revelation was the ongoing "chain migration," indicating a potential move away from Polygon. The core issue is that Polymarket has evolved from a simple prediction market into a high-frequency trading platform, making Polygon's limitations—such as block space, gas fees, and block time—a ceiling for further growth. The migration is not just a simple chain switch but a fundamental rebuild of its trading system to support more complex products like perpetual contracts (Perps). This announcement has sparked competition among chains like Solana, Sui, and Algorand, all vying to host Polymarket. For Polygon, losing this key application, which contributes significantly to its gas fee revenue, would be a major setback. The real test for Polymarket is no longer attracting users but proving it can provide a stable, reliable trading environment that retains them.

Odaily星球日报19 мин. назад

Stuck Polymarket: The Real Test After Riding the Traffic Boom Has Arrived

Odaily星球日报19 мин. назад

Lowering Expectations for BTC's Next Bull Market

The author, Alex Xu, explains his decision to significantly reduce his Bitcoin holdings (from full to ~30% of his portfolio) during the current bull cycle, citing a lowered long-term outlook for BTC's price appreciation in the next cycle. He outlines six key reasons for this reduced expectation: 1. **Diminished Growth Drivers:** The narrative of exponential user adoption has largely played out with institutional ETF adoption. The next major growth phase—adoption by sovereign national reserves or central banks—seems unlikely in the near future. 2. **Personal Opportunity Cost:** More attractive investment opportunities have emerged in other assets, such as undervalued companies. 3. **Industry-Wide Contraction:** The broader crypto industry is struggling, with most Web3 business models (SocialFi, GameFi, DePIN) failing. This overall萧条 (depression) reduces the fundamental demand and consensus for Bitcoin. 4. **Strain on Major Buyer:** MicroStrategy, a major corporate buyer of BTC, faces rising financing expenses for its debt, which could slow its purchasing rate and create significant marginal pressure on the market. 5. **Increased Competition from Gold:** The emergence of "tokenized gold" has closed the functional gap (portability, divisibility) between physical gold and Bitcoin, offering a strong competitor in the non-sovereign store-of-value space. 6. **Security Budget Concerns:** The block reward halving continues to exacerbate the long-standing issue of funding Bitcoin's network security, with new fee source explorations like Ordinals and L2s largely failing. The author's decision to hold a significant (though reduced) position reflects a cautious, not bearish, outlook. He remains open to increasing his exposure if the fundamental reasons for his skepticism change or if new positive catalysts emerge.

marsbit57 мин. назад

Lowering Expectations for BTC's Next Bull Market

marsbit57 мин. назад

Can Iran 'Control' the Strait of Hormuz?

Iran has announced a comprehensive plan to assert control over the strategic Strait of Hormuz, a critical global oil shipping chokepoint. The proposed measures include requiring all vessels to obtain Iranian permission for passage, imposing fees for security, environmental protection, and navigation management—preferably paid in Iranian rials—and absolutely banning Israeli ships. Vessels from countries deemed hostile by Iran’s top security bodies may also be barred. Analysts suggest Iran’s motives are multifaceted: increasing pressure on the U.S. and Israel by leveraging control over oil transit to influence global prices and inflation; creating a new revenue stream, potentially exceeding $7.7 billion annually, to counter Western sanctions and support postwar reconstruction; and using transit permissions as bargaining chips in future negotiations, notably with the U.S. However, the plan faces significant practical and diplomatic challenges. Enforcing comprehensive interception and fee collection in the busy waterway, patrolled by international military forces, would be difficult. The U.S. has already countering with a blockade of Iranian ports and threats to intercept any ship paying fees, potentially strangling Iran’s oil exports and fee revenue. Broad international opposition, led by European and Gulf states, and legal controversies further complicate implementation. The proposal may ultimately serve more as a negotiating tactic than a feasible policy, with its execution remaining highly uncertain.

marsbit2 ч. назад

Can Iran 'Control' the Strait of Hormuz?

marsbit2 ч. назад

Торговля

Спот
Фьючерсы
活动图片