The Chainalysis 2026 Crypto Crime Report has laid bare the industrial scale of illicit value flows coursing through the blockchain economy. In 2025, on-chain money laundering volume surged past $82 billion, up from $10 billion just five years earlier. Chinese-language money laundering networks (C...
The Chainalysis 2026 Crypto Crime Report has laid bare the industrial scale of illicit value flows coursing through the blockchain economy. In 2025, on-chain money laundering volume surged past $82 billion, up from $10 billion just five years earlier. Chinese-language money laundering networks (CMLNs) alone processed $16.1 billion — roughly $44 million per day — establishing themselves as the dominant infrastructure layer for transnational crypto crime. Meanwhile, total crypto theft reached $3.4 billion, with North Korean state-sponsored hackers accounting for $2.02 billion of that figure, a 51% year-over-year increase.
These numbers arrive as the crypto industry approaches the one-year anniversary of the Bybit exploit — a $1.5 billion heist attributed to North Korea's Lazarus Group that remains the largest single theft in digital asset history. One year on, more than $1 billion of those funds have "gone dark," with only $30 million successfully recovered. The Bybit incident did not merely expose a single exchange's vulnerability; it revealed systemic weaknesses in custody infrastructure, multisignature wallet security, and the industry's collective capacity to respond to state-level adversaries.
For institutional participants and policymakers, the data demands a reckoning: crypto's illicit economy is no longer a fringe concern — it is a professionalized, multi-billion-dollar services industry running in parallel to the legitimate one. Understanding its economic structure is essential for anyone deploying capital into this ecosystem.
The headline number from the 2026 Crypto Crime Report is staggering in its implications: illicit cryptocurrency laundering volume exceeded $82 billion in 2025, an eightfold increase from the $10 billion recorded in 2020. This growth rate dramatically outpaces the expansion of the legitimate on-chain economy over the same period.
To contextualize this figure against the blockchain industry's actual revenue base: the webthreepedia foundational economic value analysis estimated total identifiable on-chain revenue across all major networks at approximately $13.7 billion annually. The illicit laundering volume now represents roughly six times the legitimate fee revenue of the entire blockchain sector. While laundering volume and revenue are not directly comparable metrics, the ratio illustrates the sheer magnitude of illicit flows relative to the productive economic output of the networks they exploit.
Total crypto theft reached $3.4 billion in 2025, with an alarming concentration at the top: the three largest hacks accounted for 69% of all service losses. The ratio between the largest hack and the median hack crossed 1,000x for the first time, signaling that the threat landscape is increasingly defined by a small number of catastrophic events rather than a broad distribution of smaller incidents.
The scam ecosystem proved even larger. Chainalysis estimated that $17 billion was stolen through crypto scams and fraud in 2025, with AI-enabled impersonation scams proving 4.5 times more profitable than traditional approaches. Impersonation scams alone grew 1,400% year-over-year.
Perhaps the most significant structural finding in the 2026 report is the emergence of Chinese-language money laundering networks as a professionalized services industry. These networks processed $16.1 billion in 2025 across 1,799+ active on-chain wallets, accounting for approximately 20% of all known illicit laundering activity globally.
The growth trajectory is extraordinary. Since 2020, the flow of illicit crypto into CMLNs has grown 7,325 times faster than flows to centralized exchanges, 1,810 times faster than flows to DeFi protocols, and 2,190 times faster than intra-illicit on-chain transfers. These are not marginal actors — they have become the primary settlement infrastructure for transnational organized crime's crypto operations.
Chainalysis identified six distinct service typologies within the CMLN ecosystem:
The speed differential between these service types reveals the market's evolution. Running point brokers — the fastest-growing category — represent a new generation of laundering infrastructure optimized for throughput and efficiency. Black U services, processing transactions in under two minutes, demonstrate that the technical sophistication of these operations now rivals legitimate fintech payment rails.
As Chris Urben, Managing Director at Nardello & Co, noted: "Crypto offers an efficient way to discreetly move funds across borders without relying on complex manual networks of informal ledgers."
February 21, 2026, marks one year since North Korea's Lazarus Group executed the $1.5 billion Bybit exploit — the largest single theft in cryptocurrency history. The anniversary provides a natural vantage point to assess what the industry learned, and what it failed to fix.
The Attack Vector: The hackers did not exploit a smart contract vulnerability or break cryptographic protections. Instead, they compromised a developer at Safe{Wallet}, the widely-used Ethereum multisig frontend, hijacking AWS session tokens through social engineering. A single modified parameter — changing operation from 0 to 1 — redirected $1.5 billion in assets. The attack demonstrated that the weakest link in institutional custody is not code, but people and the software supply chains they depend on.
The Recovery Effort: Bybit launched the LazarusBounty program, offering 10% of recovered funds as bounties. The results, as of September 2025, underscore the difficulty of recovering state-sponsored theft:
The laundering speed was unprecedented. Within 48 hours, $160 million had been moved through intermediary wallets, decentralized exchanges, and cross-chain bridges. By February 26, 2025, over $400 million had been laundered. CEO Ben Zhou reported that by March 20 — less than one month after the hack — 86.29% of stolen ETH had been converted to Bitcoin.
Industry Response: Bybit implemented 50 security upgrades and completed nine third-party audits. The exchange secured 446,870 ETH to maintain 1:1 asset backing, and its total assets rebounded to a record $29.3 billion by October 2025. Regulators in the US, Singapore, and the EU began reviewing tighter requirements for wallet audits, software supply-chain controls, and incident-response transparency.
Yet the fundamental vulnerability — the dependency on trusted third-party interfaces for multisig operations — has not been structurally resolved across the industry. Most institutional custody setups continue to rely on the same class of web-based signing interfaces that were exploited in the Bybit attack.
North Korea's cyber theft apparatus has matured from opportunistic hacking into what 38 North, the specialist DPRK analysis group, describes as a "rogue crypto-superpower." The numbers tell the story:
| Year | DPRK Crypto Theft | |------|------------------| | 2022 | ~$1.7 billion | | 2023 | ~$1.0 billion | | 2024 | ~$1.3 billion | | 2025 | $2.02 billion | | All-time total | $6.75 billion |
In 2025, DPRK-affiliated actors accounted for 76% of all service compromises while conducting 74% fewer known attacks than in previous years. This efficiency gain — more money stolen through fewer, more precisely targeted operations — represents a qualitative shift in capability.
The operational methodology has evolved significantly. Beyond traditional protocol exploits, Lazarus Group now embeds IT workers inside legitimate crypto companies, uses sophisticated impersonation tactics targeting executives, and deploys fake hiring processes to establish initial access to target organizations. The typical laundering timeline for DPRK-stolen funds is 45 days, with over 60% of volume processed in transactions below $500,000 to avoid detection thresholds.
DPRK actors showed strong preferences for specific laundering infrastructure: usage of Chinese-language services increased by 355% to 1,000% relative to other criminal actors, bridge services by 97%, mixing services by 100%, and the Huione platform by 356%. The convergence between North Korean state hackers and Chinese-language laundering networks represents a structural alignment of the two most significant threat vectors in the crypto crime ecosystem.
The U.S. Department of Justice has stated plainly that these funds "enable DPRK's malign activities worldwide, undermining sanctions and fueling proliferation" — a direct reference to weapons of mass destruction programs.
While mega-hacks dominate headlines, the Chainalysis data reveals an underreported crisis at the individual level. Personal wallet compromises surged to 158,000 incidents in 2025 — nearly triple the 54,000 recorded in 2022. Unique victims rose from 40,000 to 80,000 over the same period.
Notably, the total USD value stolen from individuals actually declined from $1.5 billion in 2024 to $713 million in 2025, suggesting attackers are targeting more victims for smaller amounts — a shift toward scalable, automated attack methodologies likely powered by AI tools. Ethereum and Tron showed the highest victimization rates per 100,000 wallets, while newer chains like Base and Solana maintained lower rates despite significant user bases.
The convergence of AI-powered social engineering, phishing-as-a-service toolkits, and automated wallet-draining infrastructure has created an industrialized attack surface that no single protocol can address in isolation. Individual wallet security is now a systemic risk, not merely a user responsibility.
The data from the 2026 Chainalysis Crypto Crime Report and the one-year retrospective on the Bybit hack converge on a single conclusion: the crypto crime economy has professionalized faster than the industry's defenses have matured. An $82 billion laundering ecosystem, a $2 billion state-sponsored theft apparatus, and a 158,000-incident individual victim crisis are not anomalies — they are structural features of a financial system still operating with immature security infrastructure relative to the value it carries.
For institutional capital allocators, the implications are direct. The economic value framework that governs legitimate blockchain activity — where 85-90% of ecosystem flows remain subsidy-driven — now faces a parallel challenge: a significant and growing share of on-chain economic activity serves illicit purposes. The industry's ability to address this structural reality will determine whether blockchain infrastructure achieves mainstream institutional adoption or remains a niche technology burdened by reputational and regulatory risk.
The path forward requires treating crypto security not as a feature to be marketed, but as critical infrastructure to be engineered — with the same rigor applied to banking systems that process comparable values. Until the industry closes the gap between the sophistication of its attackers and the maturity of its defenses, the $82 billion shadow economy will continue to grow.