Illicit cryptocurrency addresses received $154 billion in 2025, according to Chainalysis — a 162% year-over-year increase. The FBI logged $11.4 billion in crypto fraud losses from U.S. victims alone, across 181,565 complaints. North Korean state actors accounted for 76% of all hack value in 2026 ...
"Crypto criminals are stealing billions from Americans, and Washington lacks a coordinated strategy to stop them." — Rep. Lance Gooden (R-TX), Co-sponsor of the Federal Cryptocurrency Theft Enforcement and Coordination Act
Illicit cryptocurrency addresses received $154 billion in 2025, according to Chainalysis — a 162% year-over-year increase. The FBI logged $11.4 billion in crypto fraud losses from U.S. victims alone, across 181,565 complaints. North Korean state actors accounted for 76% of all hack value in 2026 through April, stealing $577 million across a handful of operations.
Against this backdrop, the U.S. Department of Justice disbanded its dedicated National Cryptocurrency Enforcement Team (NCET) in April 2025, creating a 14-month enforcement vacuum that Congress is now attempting to fill with a new bipartisan bill. The gap between crypto crime scale and enforcement capacity has never been wider. Private-sector entities — Chainalysis, TRM Labs, and the T3 Financial Crime Unit — have stepped into the void, freezing $450 million in illicit assets globally. The question is whether a patchwork of private actors and a proposed-but-not-yet-enacted task force can match the pace of state-sponsored theft operations that move billions within hours.
The numbers are unambiguous. Chainalysis's 2026 Crypto Crime Report documented $154 billion in illicit cryptocurrency volume for 2025, driven primarily by a 694% increase in sanctioned-entity transaction value ($104 billion). Scams and fraud contributed an estimated $17 billion, stolen funds totaled $3.4 billion across nearly 150 hacks, and ransomware payments reached approximately $820 million.
The FBI's IC3 2025 Internet Crime Report recorded $11.366 billion in cryptocurrency-related fraud losses reported by Americans — more than half of the $20.9 billion in total internet crime losses that year. Year-over-year, crypto fraud complaints rose 21% and losses increased 22%. Investment scams alone accounted for $7.2 billion, with Americans aged 60 and older filing 44,555 complaints totaling $4.4 billion in losses.
Monthly 2026 data shows no deceleration. April 2026 set a record as the worst single month in crypto history, with $629.69 million drained — $614.17 million from DeFi protocols alone, according to industry tracking data. Through April 2026, cumulative losses reached $771.8 million across 47 incidents. May 2026 saw a further $84.2 million lost across 41 incidents.
Stablecoins now account for 84% of all illicit transaction volume, per Chainalysis. This mirrors legitimate adoption trends: stablecoins' cross-border transferability and low volatility make them the preferred rail for both legal commerce and criminal operations.
On April 7, 2025, Deputy Attorney General Todd Blanche issued a memorandum disbanding the National Cryptocurrency Enforcement Team effective immediately. The NCET, established in 2021 under the Biden administration, was a joint task force of prosecutors from the DOJ's money laundering and cybercrime units that coordinated some of the department's largest crypto cases.
Blanche stated: "The Department of Justice is not a digital assets regulator." The disbandment aligned with President Trump's January 2025 executive order on digital assets, which redirected prosecutorial focus away from regulatory enforcement toward investor fraud, organized crime, and terrorism.
The policy rationale was coherent — the DOJ should not function as a de facto regulator through selective prosecution. But the practical consequence was a 14-month gap in dedicated federal crypto crime coordination at precisely the moment when state-sponsored actors were scaling operations. No replacement mechanism was announced alongside the disbandment.
According to Chainalysis's analysis of the NCET closure, the team's institutional knowledge, cross-agency relationships, and specialized prosecutorial capacity represented capabilities that could not simply be redistributed to general-purpose DOJ units without loss.
The Democratic People's Republic of Korea has industrialized cryptocurrency theft. TRM Labs data shows DPRK-linked actors stole $2.02 billion in 2025, a 51% year-on-year increase, pushing their all-time cumulative theft to $6.75 billion. Through April 2026, North Korean groups accounted for 76% of all crypto hack value — approximately $577 million — with just two major operations.
The operational profile is worth examining. The FBI attributes these campaigns to the cluster it designates "TraderTraitor," a subunit within the Lazarus Group. TraderTraitor does not rely on smart contract exploits or zero-day vulnerabilities. Its primary vector is social engineering: fake recruiter pitches via LinkedIn, malware-laced pre-employment coding tests, and patient relationship-building campaigns that can extend over months before an attack is executed.
The February 2025 Bybit theft — $1.5 billion in Ethereum, the largest single cryptocurrency theft in history — followed this pattern. The April 2026 KelpDAO exploit ($292 million) was attributed to the same group. In both cases, the entry point was human, not code.
As Wiz Blog's deep dive on TraderTraitor documented, the group's tactics involve impersonating company employees via Telegram, deploying fake Calendly and scheduling domains, and targeting individuals with administrative access to custody infrastructure. The Drift Protocol drain of $285 million on April 1, 2026, reportedly followed a six-month social engineering campaign against its Security Council — no smart contract vulnerability was exploited.
The laundering apparatus is equally systematic. Within 48 hours of the Bybit hack, at least $160 million had been moved through intermediary wallets, converted into different cryptocurrencies, and routed through DEXs and cross-chain bridges. By September 2025, Bybit CEO Ben Zhou disclosed that 88.87% of the stolen assets remained traceable but only 3.54% had been frozen and $30 million recovered — while over $1 billion had "gone dark."
On June 11, 2026, Rep. Lance Gooden (R-TX) and Rep. Josh Gottheimer (D-NJ) introduced the Federal Cryptocurrency Theft Enforcement and Coordination Act, a bipartisan bill that would establish a Federal Cryptocurrency Theft Task Force within the Department of Justice.
The proposed task force would include DOJ, the FBI, the Department of Homeland Security, and the Treasury Department (including FinCEN). It would serve as the primary federal coordinating body for combating crypto theft and supporting victims. The bill mandates a standing playbook for evidence collection, blockchain forensics, and victim support that state and local agencies could adopt.
Gottheimer stated: "Last year, Americans lost more than $11 billion to crypto theft and scams, and right now, victims have nowhere to turn. This bill brings DOJ, DHS, and Treasury together to go after these criminals, support victims, and make sure local law enforcement has the federal backup they need."
The bill has not cleared committee as of June 21, 2026. Its passage timeline is uncertain, and its operational provisions would require additional appropriations to implement. Even under favorable conditions, the gap between introduction and operational capacity typically spans 12-18 months.
The structural challenge is evident: the bill proposes to rebuild, through legislation, capabilities that were eliminated by executive action 14 months earlier. Whether Congress can legislate enforcement infrastructure faster than state-sponsored actors can exploit the vacuum remains untested.
In the absence of dedicated federal enforcement, private-sector entities have assumed an outsized role in crypto crime response.
The T3 Financial Crime Unit (T3 FCU), a joint initiative of Tether, TRON, and TRM Labs launched in September 2024, announced in May 2026 that it has frozen over $450 million in illicit assets globally. The initiative intercepted 43.9% more illicit proceeds in 2025 than the previous year. T3 FCU reported the ability to identify suspicious transactions and, at law enforcement request, freeze assets within 24 hours — a response time that most government agencies cannot match.
The Financial Action Task Force has recognized T3 FCU as "an invaluable resource for law enforcement agencies worldwide," alongside TRM's Beacon Network, as leading public-private partnership models.
Chainalysis reported that 85% of U.S. law enforcement agencies now use blockchain analytics tools. Europol reported a 42% increase in blockchain forensics training participants, and Interpol expanded its Crypto Crimes Unit with 40 new analysts.
Yet the private-sector model has inherent limitations. T3 FCU operates on the TRON network and with Tether-denominated assets — it cannot freeze funds on permissionless chains or in non-Tether tokens. Chainalysis and TRM Labs provide analytics, not enforcement authority. The freezing of assets ultimately depends on cooperation from centralized entities (exchanges, stablecoin issuers) or the willingness of law enforcement to act on provided intelligence.
The ratio illustrates the gap. Illicit crypto addresses received $154 billion in 2025. Global enforcement recovered approximately $2.4 billion in the prior year. That is roughly $1 recovered for every $65 lost.
Recovery outcomes vary dramatically by case type, but the aggregate picture is poor.
The Bybit case is instructive as the highest-profile test of 2025-2026 recovery infrastructure. Of $1.5 billion stolen, Bybit reported by September 2025 that $73 million had been frozen and approximately $30 million recovered. Roughly $1 billion had "gone dark" — moved through mixers and peer-to-peer channels beyond current tracing capabilities.
Reporting speed is the single largest determinant of recovery success. Industry data suggests that reporting within 24-72 hours dramatically improves outcomes, as delays allow funds to traverse mixers, cross-chain bridges, and privacy-preserving protocols. After 72 hours, recovery rates drop precipitously.
The FBI's 2026 enforcement protocol has shifted toward proactive identification — identifying potential victims through blockchain forensics rather than waiting for reports. The FBI also seized web domains belonging to three fraudulent "crypto recovery" services (MyChargeBack, Payback LTD, Claim Justice) that were further victimizing those already defrauded, highlighting a secondary predation layer in the recovery ecosystem.
For the broader market, the recovery ratio remains structurally unfavorable. Some large-scale hacks recover as little as 0.4% of stolen funds. While certain enforcement agencies cite average recovery rates of up to 70% for specific scam types with rapid response, independent validation of these figures is limited.
International coordination shows both progress and persistent friction. In May 2026, law enforcement agencies from 31 countries participated in Europol's Project A.S.S.E.T. (Asset Search & Seize Enforcement Taskforce), involving over 40 agencies from Asset Recovery Offices, Financial Intelligence Units, and anti-money laundering teams.
Burkhard Mühl, head of Europol's European Financial and Economic Crime Centre (EFECC), stated that the misuse of crypto for criminal purposes is "becoming increasingly sophisticated." Participants at the 9th Global Conference on Criminal Finances and Cryptoassets identified three priority areas: developing common standards, deepening cooperation, and investing in capacity.
The structural challenge remains speed. As conference participants noted, criminal proceeds move across borders in seconds, while inter-agency cooperation still takes days or weeks. The mismatch between the velocity of crypto transactions and the latency of international law enforcement coordination represents an exploitable gap that state-sponsored actors have optimized against.
Europol's 10th Global Conference on Criminal Finances and Cryptoassets, scheduled for later in 2026, will focus on reducing this response latency. Whether institutional reforms can compress multi-day coordination into the sub-24-hour window required for effective asset freezing is an open question.
$154 billion in illicit crypto volume in 2025 (Chainalysis), with $11.4 billion in FBI-reported U.S. losses across 181,565 complaints. Crime scale is accelerating.
14-month enforcement vacuum: The DOJ disbanded NCET in April 2025 with no replacement. The proposed Congressional task force has not cleared committee and would require 12-18 months to become operational even if enacted.
North Korea dominates: DPRK-linked actors account for 76% of all crypto hack value in 2026 YTD ($577M), using social engineering rather than code exploits. Cumulative DPRK theft: $6.75 billion.
Recovery ratio is 1:65: For every $1 recovered by global enforcement, $65 flows to illicit addresses. The Bybit case — the highest-profile test — recovered approximately 2% of stolen funds.
Private sector has stepped in but cannot substitute: T3 FCU froze $450 million, but operates only on specific networks and token types. Blockchain analytics firms provide intelligence, not enforcement authority.
Speed gap is structural: Criminal proceeds move in seconds; international enforcement coordination takes days. This latency is the core exploitable weakness.
The crypto crime enforcement landscape in mid-2026 presents a paradox. Illicit volume has reached $154 billion annually. State-sponsored actors have industrialized theft operations. Recovery infrastructure remains structurally inadequate at a 1:65 recovery-to-loss ratio. And the primary dedicated U.S. federal enforcement mechanism was dismantled 14 months ago.
The Gooden-Gottheimer bill represents an acknowledgment that the enforcement gap is untenable, but legislation moves at legislative speed — months to years — while the Lazarus Group moves at blockchain speed. Private-sector initiatives like T3 FCU and blockchain analytics platforms have demonstrated partial capability but lack the enforcement authority, cross-chain reach, and international mandate required to match the scale of the problem.
The economic implications are material. A market that loses $3.4 billion annually to theft, where the largest single incident ($1.5 billion, Bybit) saw approximately 2% recovery, imposes a de facto security tax on all participants. Whether that tax is priced into the market or simply absorbed as an externality shapes the risk calculus for institutional adoption.
The data suggests that neither deregulation nor private-sector self-policing has closed the enforcement gap. What the market requires — and does not yet have — is enforcement infrastructure that operates at the speed and scale of the financial rails it is meant to protect.