In the era of deep integration between the digital economy and globalization, virtual currencies represented by Bitcoin, with their decentralized architecture, anonymous transaction characteristics, and crossborder circulation advantages, have become a new carrier for cross-border money laundering crimes. Statistics show that the global virtual currency money laundering scale exceeded the $20 billion threshold in 2024, with cross-border money laundering accounting for 60%. The cross-regional mobility, technological concealment, and regulatory arbitrage characteristics of such crimes pose a subversive challenge to the traditional anti-money laundering governance system. Through in-depth deconstruction of the four core models of virtual currency money laundering—anonymous wallet mixing services, cross-chain bridging and decentralized finance (DeFi) operations, and darknet trading ecosystems—it is evident that they face governance dilemmas in electronic data forensics, such as massive and decentralized data storage and enhanced anonymity technology countermeasures. In response to the new patterns of money laundering crimes in the big data era, public security and judicial authorities need to break down industry barriers, establish cross-departmental judicial collaboration mechanisms, and promote the construction of cloud-based think tank systems. These measures will significantly improve the efficiency and accuracy of electronic data forensics, providing a solid judicial guarantee and technical support for combating cross-border virtual currency money laundering crimes and safeguarding national financial security and order.
Cryptocurrency-related crimes are on the rise and have a wide-ranging impact across various areas. To effectively combat and prevent these illicit activities, cryptocurrency forensics (crypto forensics) is essential. At its core, this field relies on the investigation and analysis of blockchain data. However, the inherent pseudonymity and dynamics of Bitcoin introduce significant complexities to these investigations. The collection and validation of Bitcoin addresses are indispensable processes in blockchain forensic analysis, crucial for identifying suspicious transactions, tracing fund flows, and conducting de-anonymization investigations. Address clustering, which groups addresses likely controlled by the same entity, serves as a foundational technique. The accuracy of clustering outcomes significantly impacts the reliability of crypto forensic findings. While heuristic-based address clustering is commonly adopted, its effectiveness faces limitations primarily due to the absence of ground truth data. This lack introduces fundamental uncertainty into clustering results, hindering the validation of forensic conclusions. This uncertainty is compounded by the increasing adoption of privacy-enhancing technologies, which complicate address relationships and create additional hurdles for investigators. Moreover, other blockchain dynamic factors, such as introducing new network features, further challenge the accuracy of clustering, collectively making reliable forensic analysis increasingly complex. This study undertakes multiple approaches to address these limitations. In the first part, confronting the challenge of unavailable ground truth labels, we develop a simulation model to assess the potential error rates of two widely used clustering heuristics: the multi-input and one-time change address heuristics. The second part provides an in-depth behavioral analysis of peeling chains, a common structure utilized by entities such as exchanges and mixers. This analysis enhances our understanding of the operational characteristics of transaction data associated with privacy-enhancing practices. Building on works and insights from these first two parts, the third part introduces an enhanced simulation platform that more accurately replicates real-world Bitcoin transaction structures. Additionally, we propose and evaluate a novel heuristic algorithm specifically designed to improve the classification of one-time change addresses. This refined simulator provides a robust environment for assessing address clustering methods based on transaction details. The new heuristic aims to reduce misclassifications and achieve better clustering results. Overall, this research presents a simulation framework to quantify the uncertainties in heuristic clustering results. This facilitates a clearer assessment of the reliability and limitations of address clustering algorithms, thus strengthening the basis for the admissibility of clustering findings as forensic evidence. The proposed heuristic more effectively captures relevant transaction patterns, helping to alleviate the uncertainties introduced by privacy techniques in forensic analysis. Additionally, all three parts of this study contribute a comprehensive analysis of Bitcoin blockchain data from different periods, examining aspects such as transaction types, address reuse, and structural details. The identified characteristics and observed trends serve as a basis for refining forensic tools and methodologies.
Alexander Brechlin, Jochen Schäfer, Frederik Armknecht
ABSTRACT Cryptocurrency exchanges have become a multi‐billion dollar industry. Although these platforms are not only relevant for economic reasons but also from a privacy and legal perspective, empirical studies investigating the operations of cryptocurrency exchanges and the behavior of their users are surprisingly rare. A notable exception is a study analyzing the cryptocurrency exchange ShapeShift . While this study described new heuristics to retrieve a significant fraction of trades made on the plaform, its approach relied on identifying cryptocurrency transactions based on previously scraped trade data. This limited the analysis to the timeframe for which data had been acquired and likely led to false negatives in the transaction identification process. In this paper, we replicate and extend previous work by conducting an in‐depth investigation of the cryptocurrency exchange Evonax . Our analysis is based on actual trading data acquired by using a novel methodology allowing to extract detailed information from the public blockchain and the interface of the exchange platform. We are able to identify 30,402 transactions between the launch of Evonax in February 2018 and December 31, 2022, which should be close to a complete set of all transactions. This allows us not only to analyze the business practices of a cryptocurrency exchange but also to identify a number of interesting use cases that are likely to be associated with illegal activity. This paper is an extended version of a research article previously accepted at the CryptoEx Workshop at IEEE ICBC 2024.
The swift rise of cryptocurrencies has created both groundbreaking opportunities and unique challenges regarding financial crime. The decentralized and pseudo-anonymous characteristics of these digital currencies can facilitate illegal activities; however, the transparency inherent in blockchain technology also provides groundbreaking methods for detection and prevention. This paper investigates the connection between cryptocurrencies and financial crime by outlining common types of crypto-related offenses. Additionally, it explores the growing field of blockchain forensics and assesses the effectiveness of blockchain analytics tools in reducing cryptocurrency theft and bolstering law enforcement efforts. Through a critical analysis of the strengths and weaknesses of blockchain technology, this paper aims to deepen understanding of the changing dynamics of financial crime in the digital era, offering insights for researchers, policymakers, and practitioners interested in leveraging the transparency of blockchain for crime prevention.
Σκοπός της παρούσας διπλωματικής εργασίας ήταν η διερεύνηση του φαινομένου της νομιμοποίησης εσόδων από εγκληματικές δραστηριότητες μέσω της χρήσης κρυπτοστοιχείων. Αρχικά, ορίστηκαν και κατηγοριοποιήθηκαν τα κρυπτοστοιχεία και αναλύθηκε ο τρόπος λειτουργίας τους με τη χρήση της τεχνολογίας του κατανεμημένου καθολικού. Στη συνέχεια, μέσα από την ανασκόπηση της εξέλιξης του φαινομένου της νομιμοποίησης παράνομων εσόδων, φτάνοντας στους σύγχρονους τρόπους εφαρμογής του, αναδείχθηκαν τα πλεονεκτήματα που παρέχει η χρήση κρυπτοστοιχείων στο πλαίσιο εγκληματικών πρακτικών νομιμοποίησης. Ακολούθως, αναλύθηκαν, συστηματικά οι κύριες μέθοδοι που χρησιμοποιούνται για τη νομιμοποίηση παράνομων εσόδων μέσω κρυπτοστοιχείων. Παρουσιάστηκαν πρακτικές που αξιοποιούν τόσο κεντρικά όσο και αποκεντρωμένα συστήματα, από μη αδειοδοτημένα κεντρικά έως αποκεντρωμένα ανταλλακτήρια, πλατφόρμες P2P και OTC μεσίτες, σε συνδυασμό με υπηρεσίες ανάμειξης, παρένθετα πρόσωπα (“money mules”) και τη μέθοδο μεταπήδησης σε άλλο blockchain (“chain hopping”). Ειδική αναφορά έγινε στα πορτοφόλια ιδιωτικότητας (privacy wallets), στα ιδιωτικά νομίσματα (privacy coins), στα σταθερά κρυπτονομίσματα (stablecoins) και στις μη εναλλάξιμες μάρκες (non fungible tokens/NFTs). Στο ίδιο πλαίσιο, επεξηγήθηκε η αξιοποίηση των αυτόματων μηχανημάτων ανάληψης κρυπτοστοιχείων (crypto-ATMs) και προπληρωμένων καρτών, τα οποία παρέχουν τη δυνατότητα ταχείας μετατροπής κρυπτοστοιχείων σε παραστατικά νομίσματα και αντιστρόφως. Παρουσιάστηκαν, επίσης, νεότερες, αναδυόμενες τεχνικές, ενδεικτικές της συνεχούς προσαρμογής των εγκληματικών μεθόδων στις τεχνολογικές εξελίξεις. Εξετάστηκε το υφιστάμενο νομοθετικό πλαίσιο, τόσο σε ευρωπαϊκό όσο και σε εθνικό επίπεδο, και αναλύθηκαν οι πρόσφατες κανονιστικές εξελίξεις, ήτοι ο Κανονισμός MiCA (ΕΕ 2023/1114) και η ευρωπαϊκή δέσμη νομοθετημάτων, γνωστή ως “AML Package”. Στο εθνικό επίπεδο παρουσιάστηκε ο Ν. 5193/2025, ο οποίος θεσπίστηκε με στόχο τη λήψη των αναγκαίων εθνικών μέτρων για την ορθή και ενιαία εφαρμογή των ανωτέρω ευρωπαϊκών πράξεων. Η εργασία κατέδειξε ότι, παρά τον επαναστατικό χαρακτήρα των κρυπτοστοιχείων ως τεχνολογικού εργαλείου και τις πολλαπλές εφαρμογές τους, αυτά δύνανται ταυτόχρονα να χρησιμοποιηθούν ως μέσο νομιμοποίησης παράνομων εσόδων. Η ταχύτητα της τεχνολογικής προόδου, σε συνδυασμό με την καθυστέρηση προσαρμογής του νομοθετικού πλαισίου, αποτελούν κρίσιμες σύγχρονες προκλήσεις για την αποτελεσματική αντιμετώπιση του φαινομένου.
Cryptocurrency exchange hacks remain a persistent threat, posing significant financial and security risks.The 2025 Bybit hack, resulting in approximately $1.4 billion in losses, is the largest cryptocurrency heist to date, highlighting the vulnerabilities even among leading exchanges.This paper examines the implications of such breaches on market stability, regulatory policies, and investor confidence, particularly within the context of the Trump administration's deregulatory approach to digital assets.The analysis explores the trade-offs between promoting innovation and ensuring robust security frameworks, emphasizing the potential for policy adjustments in light of escalating cyber threats.Additionally, the study reviews historical exchange hacks, demonstrating a pattern of increasing sophistication among malicious actors.The findings suggest that regulatory clarity and enhanced security measures are essential for the long-term stability of the cryptocurrency ecosystem.Future research directions include evaluating global regulatory responses, the role of decentralized exchanges, and the effectiveness of cybersecurity protocols.
Terrence August, Duy Dao, Kihoon Kim, Marius Florin Niculescu
Cryptocurrencies have prompted a shift away from classic security attacks toward ransomware-based extortion. To better understand the impact of cryptocurrencies on the cybersecurity landscape, we conduct a comparative analysis of cybersecurity metrics prior to and after the adoption of cryptocurrency using a series of connected software-use models in the presence of security externalities. In this framework, we endogenize the actions of both heterogeneous consumers and attackers, with entry of the latter being driven by both the size of the unpatched consumer population and, as a subset of it, the size of the ransom-paying consumer population. We first examine users’ adoption and patching behavior under both security scenarios. We explore how changes in attacker entry costs impact outcomes under both conventional and post-crypto ransomware threat landscapes. We show that ransomware scenarios may be more desirable than conventional ones when attacker entry costs are low, provided that the gains from entering with standard attacks under the ransomware scenario are not too high. However, under such scenarios, social welfare can increase under the same conditions that lead to larger ransoms being demanded and a higher expected total ransom being paid, which presents a conundrum to policymakers. We also examine the impact of market parameters associated with security losses from conventional attacks and residual losses when victims pay in ransomware attacks. This paper was accepted by Kay Giesecke, finance. Funding: This work was partially supported by Insung Research Grant of KUBS, the LG Yonam Foundation (of Korea), and an award from the Georgia Institute of Technology Center of International Business Education and Research as part of its funded research program. Supplemental Material: The online appendices are available at https://doi.org/10.1287/mnsc.2023.00969 .
The article examines the problem of digital transformation within organized criminal groups. This transformation results from the introduction of innovative digital technologies into criminal activities and is manifested in the formation of decentralized organizational structures for criminal groups based on network management principles. It is shown that the transition from traditional hierarchical structures to alternative structures based on network interaction among participants is primarily typical of criminal groups specializing in high-tech crimes. In practice, the evolution of organized criminal activity has led to the emergence of groups with complex symbiotic structures, characterized by a combination of network interaction among the group's structural elements while maintaining a hierarchical structure within its governing core. The factors characterizing criminal groups with decentralized mixed structures are described, including a higher level of self-organization, increased group stability, adaptability to external conditions, responsiveness in addressing emerging issues, and enhanced anonymization of participants. The phenomenon of forming a new organizational structure for criminal groups has been revealed. This form is most accurately described by the concept of an ecosystem of criminal communities. It is shown that ecosystems of criminal communities are network associations of autonomous criminal groups interacting with one another based on the principle of "Crime as a Service", similar to the interaction principles found in business ecosystems within the digital economy. The technological basis for these ecosystems consists of digital platforms created and operating on the Darknet, which represent a shadow information environment that unites network services, data, and digital resources, facilitating the joint activities of ecosystem participants. The formation of ecosystems of criminal communities appears to be a qualitatively new and dangerous phenomenon. The criminal advantages gained from this transformation include the ease of attracting resources through the development of a global network market for criminal services and products on the Darknet; the "division of labor" through the narrow specialization of autonomous groups entering into cooperative and collaborative relationships; access to advanced means for committing high-tech crimes through the commercialization of criminal innovations; the rapid incorporation of new participants; the ease of overcoming interregional and interstate borders to commit transnational criminal acts; a combination of globalization and glocalization factors; and a significant reduction in the risk of criminal prosecution due to maximum anonymization of participants. The article concludes that the formation of ecosystems of criminal communities is becoming the dominant trend in the evolution of modern organized crime.