Crypto Scam Enforcement Operations
Explore how crypto scam enforcement operations freeze assets, disrupt fraud networks, and what this means for victims and markets.

The quick list
Best overall: Operation Atlantic, for cross-border investigators targeting organised fraud networks with identifiable assets to freeze.
Best value: DOJ scam-centre domain seizures, for disrupting large-scale victim acquisition before scammers receive more deposits.
Best for persistent infrastructure: Sality botnet disruption, for reducing malware operators’ access to infected machines and future victims.
Best for high-risk financing cases: Hamas-linked crypto and infrastructure seizures, for combining wallet tracing with website and server control.
Best for laundering networks: AudiA6 disruption, for investigators focused on the services that move criminal proceeds rather than the original scam.
What the enforcement push means for crypto users and markets
The practical question is not whether authorities can seize crypto, they plainly can. It is whether a particular scam, theft or illicit-finance network is still early enough in its cash-out process for a seizure, freeze or infrastructure takedown to matter.
The risk is that enforcement headlines can create a misleading impression of recoverability. Authorities may interrupt future thefts or identify operators, yet victims can still face permanent losses once funds move through bridges, mixers, exchanges or wallets beyond reachable jurisdictions.
The U.S. Justice Department’s latest Hamas-related action illustrates the more mature version of crypto enforcement. Investigators seized more than $560,000 in cryptocurrency donations and took control of domains and servers used for fundraising and recruitment. [1][2]
That figure is meaningful as a confiscation, but modest beside the flow the government says it traced. The DOJ said the associated wallet system had moved more than $1.5 million from October 2024, showing the difference between mapping an illicit network and securing its full balance. [1]
For financial-crime teams, the important detail is the combined approach. The FBI did not only pursue wallet addresses. It also seized infrastructure associated with Alqassam.ps, giving investigators a route to intercept future donations and collect information on people contacting the network. [1]
That model has a clear trade-off. Infrastructure control can prevent additional inflows and generate intelligence, but it relies on jurisdiction, hosting arrangements and the speed at which operators can establish replacement sites, wallets or messaging channels.
Comparison table: the enforcement models
| Option | Reported financial scale | Main enforcement layout | What it can disrupt | Main limitation |
|---|---|---|---|---|
| Operation Atlantic | $45 million in fraud disrupted, $12 million in crypto frozen [[4]](https://www.theblock.co/news/regulation/2026-04-09-us-secret-service-freezes-12-million-crypto-global-fraud-operation-atlantic-396911?utm_source=openai "US Secret Service freezes $12 million in crypto tied to global fraud in Operation Atlantic | The Block") | Multi-country asset tracing and freezing | Existing stolen balances and connected fraud networks |
| DOJ scam-centre action | 503-plus fraudulent .com domains, 8,935 victims notified, estimated $562.7 million in prevented losses [5] | Domain seizure and victim notification | Scam advertising, impersonation sites and lead generation | Scammers can register replacement domains or shift channels |
| Hamas-linked seizure | More than $560,000 seized, more than $1.5 million traced through the system [[1]](https://www.justice.gov/opa/pr/justice-department-continues-disrupt-hamas-terrorist-financing-schemes-through-seizures?utm_source=openai "Office of Public Affairs | Justice Department Continues to Disrupt Hamas Terrorist Financing Schemes Through Seizures of") | Wallet warrants plus domain and server control | Donations, fundraising infrastructure and intelligence collection |
| AudiA6 laundering-service disruption | €336 million allegedly processed [[3]](https://www.fdicoig.gov/news/investigations-press-releases/ransomware-gangs-cut-eur-336-million-audia6-crypto-laundering?utm_source=openai "Ransomware gangs cut off from EUR 336 million ‘AudiA6’ crypto laundering pipeline | FDIC OIG OIG") | International action against laundering infrastructure | Cash-out and laundering capacity for multiple crime groups |
| Sality botnet disruption | About $150,000 in reported crypto theft, with asset value peaking around $1.5 million [Cointelegraph reporting] | Botnet disruption with CrowdStrike and international partners | Malware operators’ control of infected machines | No broad public recovery figure for affected crypto users |
| Coldcard theft tracing | At least 1,789 BTC stolen from 8,865 addresses, valued around $114.7 million at the time [Cointelegraph reporting] | On-chain monitoring of cross-chain swaps | Attribution, exchange alerts and potential future freezes | No public recovery outcome has been reported |
No public budget, operating cost or victim-restitution cost has been disclosed for these actions. The comparable “price” is therefore the value seized, frozen, disrupted or allegedly processed, not the cost of enforcement to taxpayers.
Best overall: Operation Atlantic
Operation Atlantic is the broadest reported model because it joined asset freezing to international fraud disruption. The U.S. Secret Service reportedly froze $12 million in stolen cryptocurrency tied to a scheme spanning more than 30 countries. [4]
The operation is reported to have disrupted roughly $45 million in fraud. [4] That makes it more directly relevant to conventional crypto scam victims than a terrorism-financing seizure, because the stated target was global fraud rather than a designated militant organisation.
Its advantage is financial immediacy. A freeze can stop the next transfer while investigators sort ownership, counterparties and exchange records. That is more valuable than a later criminal conviction if an operator is actively moving balances through several wallets.
Its weakness is equally important. A freeze is not the same as a completed forfeiture, and neither is necessarily equivalent to reimbursement. The brief does not provide a victim repayment total, so readers should not infer that $12 million was returned.
The operation also depends on sustained cross-border cooperation. A September 2026 agreement involving the U.S. Attorney’s Office for the District of Columbia, the UK Crown Prosecution Service and the UK National Crime Agency reportedly marked the first agreement specifically focused on global crypto scam centres. [5]
Best value: scam-centre domain seizures
The DOJ’s Scam Center Strike Force approach attacks the customer-acquisition side of the fraud business. In April 2026, it seized more than 503 fraudulent .com domains, notified 8,935 victims and estimated that the action prevented $562.7 million in additional losses. [5]
That prevention estimate needs careful treatment. It is an estimate of avoided future harm, not cash seized, not verified restitution and not a realised investment return from the operation. Its underlying assumptions are not detailed in the research provided.
Still, domain seizures can have an attractive enforcement ratio. Removing a cloned exchange, fake support portal or romance-scam payment page may stop thousands of prospective contacts before a wallet transfer occurs, avoiding the more difficult problem of tracing funds afterward.
The trade-off is substitution. Scam operators can change top-level domains, rotate hosting, use social-media direct messages or migrate victims to encrypted chats. Domain action is therefore best seen as a recurring disruption tool, not a permanent market-wide solution.
Reported U.S. scam losses approached $16 billion in 2025, while some estimates reached as high as $200 billion. [5] The gap between those estimates underlines why enforcement success cannot be judged only by seizure announcements.
Best for high-risk financing cases: wallet and infrastructure seizures
The Hamas case demonstrates that crypto enforcement can work alongside traditional counterterrorism methods. The DOJ used sources and blockchain tracing to identify rotating addresses advertised through encrypted chats and fundraising websites, then obtained warrants covering the associated assets. [1]
The current confirmed seizure figure is more than $560,000, with no evidence in the supplied research of a larger total. [1][2] Readers should distinguish that confirmed amount from the broader $1.5 million alleged to have passed through linked wallets. [1]
CoinDesk and Decrypt both reported the same core DOJ action involving Hamas-linked crypto and fundraising infrastructure. The underlying government documents, rather than either outlet’s presentation, are the stronger basis for the seizure and tracing figures. [1]
This is not a template for every consumer scam case. Terrorism financing investigations can involve sanctions authorities, intelligence resources and legal powers that are not available to a victim trying to recover funds sent to a fake trading platform.
Best for laundering networks: AudiA6
The June 2026 action against AudiA6 addressed a different layer of the criminal economy. Authorities described the service as a ransomware laundering pipeline that had processed €336 million, indicating a focus on the channels used to convert or obscure proceeds. [3]
That scale exceeds the value publicly reported as frozen in Operation Atlantic or seized in the Hamas case. But processed volume is not equivalent to assets held at seizure, criminal profit, or money recovered for victims.
The benefit of targeting a laundering service is network-wide leverage. Disabling one cash-out route can raise costs for ransomware groups, scam centres and other criminals that rely on the same service, even where investigators cannot identify every originating theft.
The weakness is jurisdictional fragmentation. The AudiA6 case required international coordination, while UK agencies also face sanctions-evasion risks involving networks such as the Kremlin-linked A7 structure and Kyrgyzstan’s financial system. [3][5]
The UK’s Economic Crime and Corporate Transparency Act 2023 gives authorities an evolving legal framework, but enforcement remains divided across agencies and borders. The January 2026 Crypto Cash Fusion Cell reflects both greater coordination and the continuing complexity of the problem. [9]
Malware disruption remains harder to measure
The Sality botnet operation is the clearest example in the supplied reporting of public agencies working with a private cybersecurity company. The DOJ, CrowdStrike, the Shadowserver Foundation and authorities in Bulgaria, Hungary and Romania disrupted the malware network, according to Cointelegraph reporting.
CrowdStrike said the associated EggJagger tool monitored copied wallet addresses and replaced them with addresses controlled by the operator. The reported theft total was at least 12.1 million rubles, or about $150,000, over eight years.
The technique matters more than the historical dollar total. Clipboard hijacking targets ordinary payment behaviour, including copying a Bitcoin or Ethereum address. It can succeed without a fake exchange, a compromised private key or direct contact with the victim.
Newer strains indicate the threat is not confined to one botnet. CryptoBandits has been reported spreading through USB drives and hijacking copied Bitcoin addresses, while Linux-focused ClipXDaemon operates without conventional command-and-control servers. [6][7]
That architecture creates a measurement problem. There is limited public evidence of enforcement actions specifically directed at these newer clipjacking strains. It would be speculative to claim that the Sality action has materially reduced clipboard-hijacking risk across the market.
The unresolved recovery problem
Cointelegraph’s account of a purported 5,000 BTC wallet recovery case is a useful warning against both scam narratives and recovery-service marketing. The recovery specialists ultimately found about $10 in Bitcoin, despite the client’s claim of a multimillion-dollar balance.
The broader lesson is that wallet recovery firms recover access information, not coins that never existed or funds already controlled by another party. A seed phrase, passphrase and password can also produce confusing results, including valid but empty wallets.
Recovery firms cited by Cointelegraph reported that some cases are technically solvable when users retain partial seed phrases, damaged files or predictable passwords. But users should treat unsolicited recovery offers, upfront payment demands and requests for seed phrases as acute security risks.
The Coldcard case shows why tracing should not be confused with recovery. Cointelegraph reported at least 1,789 BTC stolen from 8,865 addresses, while CryptoSlate reported that 20.69 BTC later moved through THORChain toward Ethereum addresses.
Researchers could observe the cross-chain swaps, and Galaxy Research shared identified addresses with relevant authorities and crypto companies, according to Cointelegraph. That may support a future freeze if funds reach a compliant venue, but no recovery result has been publicly reported.
Industry-wide recovery figures are contested. One 2026 dataset cited in the research brief found about $1.5 billion recovered across 25 incidents, roughly 24% of the relevant losses, while a separate long-run estimate put average recovery below 10% since 2020. [8]
The difference likely reflects incident selection, valuation dates and whether frozen assets are counted as recovered. It does not support a confident prediction that Coldcard victims, Sality victims or scam-centre victims will receive a particular percentage back.
Who each option suits
Operation Atlantic suits law-enforcement and compliance teams that can identify active international fraud flows and need to freeze assets before they reach harder-to-reach venues. Its value lies in coordination, not in a promise of universal restitution. [4]
DOJ scam-centre domain seizures suit agencies, registrars and platform operators trying to reduce new victim intake. They are most useful before a victim sends funds, because prevention avoids the costly and uncertain recovery process. [5]
Hamas-style wallet and infrastructure seizures suit high-priority illicit-finance cases where investigators can connect addresses, websites, hosting infrastructure and identified operators. They are less transferable to routine retail disputes over a fraudulent investment platform. [1]
AudiA6-style laundering disruption suits multinational cases where the central problem is not identifying a scam page but breaking the services that help many criminal groups move proceeds. It is strategically broad, but legally and operationally demanding. [3]
Sality-style botnet disruption suits cybersecurity agencies and private security firms seeking to cut operators off from infected endpoints. It can reduce future theft opportunities, although the available evidence does not establish broad victim recovery.
Coldcard tracing suits exchanges, analytics firms and investigators monitoring stolen assets after a major compromise. It can identify routes and raise the chance of intervention, but it should not be presented as evidence that the stolen Bitcoin has been recovered.
Frequently Asked Questions
What are recent examples of crypto scam enforcement operations?
Recent notable operations include Operation Atlantic in March 2026, which disrupted $45 million in fraud and froze $12 million in stolen cryptocurrency across more than 30 countries. The U.S. DOJ also seized over $560,000 in cryptocurrency donations linked to Hamas, disrupting associated wallets and infrastructure. Additionally, the DOJ’s Scam Center Strike Force seized over 503 fraudulent domains in April 2026, notifying thousands of victims and preventing further losses.
How do authorities seize and freeze cryptocurrency in scams?
Authorities use multi-country asset tracing and freezing techniques to identify and immobilize stolen cryptocurrency linked to fraud networks. For example, Operation Atlantic combined cross-border investigations to freeze $12 million in crypto assets. The DOJ also traced wallet systems associated with illicit activity, such as Hamas-linked donations, and seized both the cryptocurrency and related online infrastructure like domains and servers.
What limitations exist in recovering stolen crypto assets?
Recovery rates for stolen cryptocurrency remain low, with published data showing less than 10% recovery over the long term and roughly 24% in selected 2026 incidents. Even when authorities freeze assets or seize infrastructure, victims may not recover funds once assets move through mixers, cross blockchain bridges, or offshore services. Enforcement actions can disrupt future thefts but do not guarantee restitution for past losses.
How do domain seizures and botnet takedowns disrupt crypto scams?
Seizing fraudulent domains and dismantling botnets can quickly interrupt the infrastructure scammers use to acquire victims and operate malware. For instance, the DOJ’s seizure of over 503 scam-related domains helped prevent additional deposits, while the Sality botnet disruption reduced malware operators’ access to infected machines. However, these actions do not ensure recovery of stolen funds and rely on jurisdictional and technical factors to maintain effectiveness.
What enforcement models are used against crypto laundering networks?
Investigators targeting laundering networks focus on disrupting the services that move criminal proceeds rather than the original scams. The AudiA6 laundering service disruption in 2026, which processed €336 million, exemplifies this approach. Such enforcement involves tracing illicit flows and dismantling the infrastructure that enables laundering, often requiring complex international coordination and multi-agency efforts.
How we researched this
This article was assembled from 6 published articles, 9 cited references.
Nothing here is based on hands-on testing. Where a figure or finding appears, it belongs to the source cited beside it, and the writing says so rather than implying otherwise. Every source is listed below so you can check it.
Sources
DOJ says Hamas crypto seizures reached $560,000 as FBI took over fundraising sites — CoinDesk
Recovery specialists crack $1B crypto wallet... but find just $10 — Cointelegraph
FBI Seizes $560K in Crypto Bound for Hamas, Takes Over Fundraising Sites — Decrypt
Parked Coldcard loot begins moving as attacker routes $1.6M in stolen Bitcoin to Ethereum — CryptoSlate
Coldcard hacker swaps stolen Bitcoin for ETH via THORChain — Cointelegraph
US officials work with CrowdStrike to fight malware behind crypto theft — Cointelegraph
Justice Department seizes more than $560,000 in cryptocurrency donations for Hamas
Ransomware gangs cut off from EUR 336 million ‘AudiA6’ crypto laundering pipeline | FDIC OIG OIG
ClipXDaemon Emerges as C2-Less Linux Clipboard Hijacker, Targeting Crypto Wallets in X11 Sessions
Crypto Hacks Tracker: Losses and What Was Recovered • CoinLaw
Related Articles

Crypto Regulatory Challenges
Explore crypto regulatory challenges, legal risks, and compliance costs shaping stablecoins, blockchain records, and cross-border crypto markets.

AI Impact on Crypto Security: Risks and Defenses Explained
Explore how AI affects crypto security, from autonomous exploits to defense challenges in blockchain and smart contracts.

XRP Resilience: Potential US Reserve Inclusion Sparks Price Surge
Discover how XRP defies the crypto market crash, with potential US strategic reserve inclusion. Ripple's partnerships and strategic moves hint at a bullish future for XRP's price.

XRP Resurgence: Ripple's Legal Win & Future Amid Pro-Crypto Wave
Discover how XRP surged back with regulatory changes, Ripple's legal victory, and the future of crypto post-Washington's pro-crypto shift. #XRP #Ripple #cryptocurrency