The FBI logged 181,565 cryptocurrency-related complaints in 2025, totaling $11.4 billion in reported losses — a 22% year-over-year increase and more than half of the $20.9 billion in total U.S. internet crime losses. At the same time, federal crypto enforcement capacity has contracted sharply: th...
"Crypto criminals are stealing billions from Americans, and Washington lacks a coordinated strategy to stop them." — Rep. Lance Gooden (R-Texas), House Judiciary Committee
The FBI logged 181,565 cryptocurrency-related complaints in 2025, totaling $11.4 billion in reported losses — a 22% year-over-year increase and more than half of the $20.9 billion in total U.S. internet crime losses. At the same time, federal crypto enforcement capacity has contracted sharply: the DOJ disbanded its National Cryptocurrency Enforcement Team (NCET) in April 2025, SEC crypto enforcement actions fell 60% that year, and cryptocurrency is absent from the SEC Division of Examinations' 2026 priorities entirely.
On June 11, 2026, Representatives Lance Gooden (R-Texas) and Josh Gottheimer (D-N.J.) introduced the Federal Cryptocurrency Theft Enforcement and Coordination Act, proposing a DOJ-housed task force to fill the gap. The bill arrives as North Korean state hackers account for 76% of all 2026 crypto hack losses through April, and Chainalysis estimates total illicit crypto volume reached $154 billion in 2025 — a 162% increase. The question is not whether the enforcement vacuum exists, but whether a task force without new funding or subpoena authority can close it.
On April 7, 2025, Deputy Attorney General Todd Blanche issued a memorandum disbanding the NCET, the DOJ's dedicated cryptocurrency enforcement unit established in 2021. The memo characterized the Biden-era approach as "regulation by prosecution" and directed DOJ resources away from cases against exchanges, mixers, and wallet providers, refocusing on investor fraud, organized crime, and terrorism financing.
The NCET had previously led several high-profile investigations, including the Tornado Cash mixer prosecution, the Avraham Eisenberg case (over $100 million exploited from a trading protocol), and investigations into North Korean actors laundering proceeds from crypto hacks.
The SEC followed a parallel trajectory. After initiating 33 cryptocurrency-related enforcement actions in 2024, the agency brought only 13 in 2025 — a 60% decline, according to Cornerstone Research. Monetary penalties against digital-asset market participants dropped to $142 million in 2025, less than 3% of the 2024 figure. The agency dismissed with prejudice its civil action against Coinbase in February 2025 and closed investigations into Binance, Gemini, and other major platforms.
Overall SEC enforcement actions fell to 313 in fiscal year 2025, the lowest in a decade and down 27% from the prior year.
The drawdown in federal enforcement coincides with escalating loss figures across every measurement methodology.
FBI IC3 Data (2025):
Chainalysis 2026 Crypto Crime Report (covering 2025 data):
2026 Year-to-Date Hack Losses (through April, per TRM Labs):
The recovery picture is equally stark. According to Immunefi, only 0.4% of Q1 2025 hack losses were recovered, down from 21.2% in Q1 2024. PeckShield data shows $334.9 million recovered annually in 2025 versus $488.5 million in 2024. Of the $1.46 billion Bybit breach — the largest single crypto heist in history — less than 5% had been recovered as of early 2026.
The Federal Cryptocurrency Theft Enforcement and Coordination Act would create a "Federal Cryptocurrency Theft Task Force" within the DOJ, chaired by the Attorney General or a designated official. Participating agencies would include:
The task force's stated mandate covers:
The bill has drawn support from The Digital Chamber and the Satoshi Action Fund. Dennis Porter, CEO of the Satoshi Action Fund, stated the bill would give "victims, investigators, and local law enforcement the unified federal response they have been missing."
Rep. Gottheimer framed the initiative around victim access: despite billions in losses, "victims have nowhere to turn," and the task force would provide "a single federal point of contact."
With federal enforcement pulling back, state regulators have moved to fill the vacuum. Several data points illustrate the shift:
New York: Attorney General Letitia James secured more than $5 million from cryptocurrency platform Uphold HQ for misleading investors and promoting a fraudulent investment scheme. New York's proposed CRYPTO Act would criminalize unlicensed crypto operations with felony penalties.
California: The state has pursued retroactive enforcement actions, including a settlement with Nexo over unregistered lending products.
Multi-state pattern: According to analysis from Whiteford, Taylor & Preston, states are "intensifying enforcement of cryptocurrency licensing requirements as federal agencies shift focus to fraud and national security," with civil penalties, historical liability claims, and potential criminal exposure emerging as primary tools.
The National Association of Attorneys General has published guidance on criminal forfeiture of cryptocurrencies, signaling a broader state-level institutional commitment to filling the federal gap. However, state-level enforcement remains jurisdiction-bound and lacks the cross-border coordination capabilities that characterized the now-disbanded NCET.
The most concerning trend in the enforcement landscape is the accelerating share of crypto theft attributable to North Korean state actors, primarily the Lazarus Group.
DPRK attribution trajectory (per TRM Labs and Chainalysis):
| Year | Amount Stolen | Share of Total Hack Losses | |------|--------------|---------------------------| | 2022 | ~$1.7 billion | 44% | | 2023 | $660 million | ~37% | | 2024 | $1.34 billion | 61% | | 2025 | $2.02 billion | 76% (service compromises) | | 2026 (through April) | ~$577 million | 76% |
Cumulative DPRK crypto theft since 2017 now exceeds $6 billion, according to TRM Labs.
The two largest attributed attacks in 2026 were the Drift Protocol exploit ($285 million on April 1, involving months of social engineering and three weeks of pre-attack staging) and the KelpDAO breach ($292 million on April 18, exploiting a single-verifier design flaw in a LayerZero bridge). Both were attributed to DPRK-linked actors.
The Bybit breach of February 2025 — $1.46 billion extracted via a compromised Safe{Wallet} signing interface — remains the largest single incident and was also attributed to Lazarus Group by multiple blockchain forensics firms.
The NCET had previously led investigations into North Korean laundering operations. Its disbandment removed the dedicated federal unit with the deepest institutional knowledge of DPRK crypto laundering patterns.
The bill's passage pathway remains uncertain. It requires House Judiciary Committee approval or attachment to broader legislation. Several structural limitations are apparent:
No new funding authorization. The bill mandates coordination but does not allocate additional budget to the FBI, DHS, or Treasury for crypto-specific investigative capacity.
No new subpoena or seizure authority. The task force would operate within existing legal frameworks. Given that recovery rates for stolen crypto have fallen to 0.4% in Q1 2025, the absence of enhanced asset-freezing mechanisms is notable.
Coordination vs. capacity. The bill addresses fragmented reporting channels but does not rebuild the specialized prosecution capacity that the NCET represented. The difference between a coordination body and an enforcement team is substantial.
Political crosscurrents. The Trump administration's stated position — articulated through Blanche's April 2025 memo — prioritizes industry-friendly regulation and explicitly rejects "regulation by prosecution." A new enforcement body, even one focused narrowly on theft rather than regulatory compliance, may face executive branch resistance.
International gaps. While the bill mentions information-sharing with international partners, the majority of crypto theft proceeds flow through cross-border laundering channels (THORChain, mixers, DPRK-controlled wallets) that require multilateral enforcement coordination beyond the scope of a single DOJ task force.
The U.S. crypto enforcement landscape in mid-2026 presents a paradox: crime metrics are at record highs while dedicated federal enforcement capacity is at a multi-year low. The proposed task force addresses the coordination problem — fragmented reporting, inconsistent jurisdiction-level responses, lack of a single federal point of contact for victims — but does not address the capacity problem.
The NCET, whatever its policy controversies, represented specialized institutional knowledge in blockchain forensics, cross-border asset tracing, and DPRK laundering pattern recognition. That knowledge base has been dispersed. A coordinating body cannot substitute for dedicated investigators with years of case experience.
The bill's bipartisan sponsorship (Gooden from Judiciary, Gottheimer from Financial Services) suggests awareness on both sides of the aisle that the current enforcement posture is untenable given the loss figures. Whether the political will exists to fund and empower such a body — rather than merely authorize it — will determine whether the proposal represents a meaningful policy shift or an acknowledgment of a problem without a commensurate solution.
For market participants, the practical implication is clear: the period of reduced federal enforcement has not reduced crypto crime. It has shifted the enforcement burden to state-level actors with narrower jurisdiction, while the most sophisticated threat actors — state-sponsored groups with resources exceeding those of most law enforcement agencies — continue to operate with increasing efficiency.