top of page
fnlogo.png

US Seizes More Than $560,000 in Crypto as Authorities Disrupt Hamas Financing Network

  • 2 hours ago
  • 6 min read

US authorities have seized more than $560,000 in cryptocurrency allegedly intended to support Hamas, while simultaneously dismantling websites, servers and online communication infrastructure used to solicit digital-asset donations and recruit supporters.


US Seizes More Than $560,000 in Crypto as Authorities Disrupt Hamas Financing Network

The operation represents another significant intervention against the use of cryptocurrency as a channel for terrorist financing and demonstrates the increasingly sophisticated methods being used by law enforcement to identify and disrupt illicit digital-asset networks.


Court-authorised actions allowed the FBI to take control of cryptocurrency linked to fundraising activities associated with Hamas's military wing, the Al Qassam Brigades. Authorities also seized or disrupted internet domains and servers used as part of the fundraising infrastructure, preventing the platforms from continuing to solicit contributions.


The investigation focused on a fundraising network that had been using online channels to encourage individuals to send cryptocurrency directly to addresses controlled for the benefit of Hamas. The organisation's fundraising activity through digital assets dates back several years, with cryptocurrency promoted as a way for supporters to transfer funds internationally without relying on conventional banking channels.


The latest action indicates that investigators were able to move beyond simply identifying individual cryptocurrency addresses and instead target the infrastructure supporting the fundraising operation.


This included communication platforms, websites and servers that helped connect potential donors with cryptocurrency wallets. By taking control of the infrastructure, authorities were able to disrupt the mechanism through which additional contributions could be solicited.


The operation also generated information about people attempting to contribute to the fundraising network. Investigators obtained data relating to thousands of individuals who interacted with the online infrastructure or attempted to provide financial support.


That information could potentially provide authorities with further investigative leads, particularly where individuals used regulated exchanges, payment providers or identifiable accounts to acquire or transfer the cryptocurrency.


The seizure demonstrates one of the key characteristics of blockchain-based financial crime investigations: although cryptocurrency transactions can be conducted without traditional banking intermediaries, transactions recorded on public blockchains can leave a permanent and analysable trail.


Law enforcement agencies and specialist blockchain investigators can follow transactions between addresses, identify patterns of movement and, in appropriate circumstances, connect pseudonymous wallets with real-world individuals or services.


This creates a significant challenge for terrorist organisations seeking to use cryptocurrency. While digital assets can provide speed, global accessibility and a degree of pseudonymity, they do not necessarily provide the anonymity that criminal or terrorist actors may expect.


The latest case illustrates how investigators can combine blockchain analysis with traditional investigative techniques. Identifying a fundraising address can be only the beginning of the process. Authorities can then examine associated transactions, hosting arrangements, domain registrations, communications and other information to build a broader picture of the financial network.


The investigation also demonstrates the importance of the infrastructure surrounding cryptocurrency rather than cryptocurrency itself. Digital wallets do not operate in isolation. Fundraising campaigns may depend on websites, messaging applications, domain registrars, hosting companies, exchanges, payment services and other technology providers.


Targeting these supporting services can therefore be an effective way of disrupting an illicit financial network.


The US action follows earlier investigations into Hamas-linked cryptocurrency fundraising. In 2025, US authorities seized approximately $200,000 in cryptocurrency connected to a Hamas financing operation, with investigators tracing funds through fundraising addresses that had allegedly been used to launder more than $1.5 million in virtual currency.


Earlier enforcement actions also involved a Gaza-based cryptocurrency exchange that authorities alleged was being used to facilitate financial activity connected with Hamas. These cases have progressively provided investigators with greater insight into the methods used to solicit, receive and move digital assets.


The latest seizure therefore forms part of a wider evolution in the enforcement approach to terrorist financing.


Rather than treating cryptocurrency transactions as isolated financial events, authorities are increasingly examining entire digital ecosystems. Fundraising addresses, online advertisements, social-media posts, encrypted communications, websites and exchange accounts can all form part of the same investigative picture.


For financial institutions and virtual asset service providers, this development carries important compliance implications.


A cryptocurrency exchange or other regulated digital-asset business may encounter transactions involving addresses that have no obvious connection to a sanctioned entity. The risk may only become apparent after analysing transaction history, wallet exposure and indirect connections to other addresses.


This makes blockchain analytics an increasingly important component of AML and counter-terrorist-financing controls.


Traditional customer due diligence remains essential, but it may not be sufficient on its own where customers are conducting cryptocurrency transactions. Institutions may also need to assess wallet exposure, transaction counterparties, geographic risk, sanctions indicators and unusual patterns of cryptocurrency movement.


The case highlights another important issue: the distinction between pseudonymity and anonymity.


A blockchain address generally does not directly reveal the name of its owner. However, once an address interacts with a regulated exchange or another identifiable service, investigators may be able to connect the address to customer information held by that service.


Consequently, cryptocurrency transactions that initially appear difficult to attribute can become significantly more transparent when combined with information obtained through subpoenas, court orders, exchange records or other investigative mechanisms.


The seizure of the Hamas-linked funds also demonstrates why sanctions and terrorist-financing screening cannot be limited to names appearing on a conventional customer list.


Cyprus Company Formation

A customer may not be named directly as a designated person or organisation but could still transact with a wallet associated with a sanctioned or terrorist entity. Effective controls therefore increasingly require firms to consider both direct and indirect exposure.


The risk is particularly relevant for cryptocurrency exchanges, custodians, payment providers and other businesses facilitating digital-asset transfers.


A provider that allows funds to move between a customer's account and a wallet associated with terrorist financing could potentially face serious regulatory and legal consequences, depending on the circumstances and applicable law.


The investigation also underscores the importance of transaction monitoring after onboarding.


A customer may initially present a legitimate profile, pass conventional KYC checks and establish an apparently normal account. Subsequent transactions, however, could expose connections to high-risk wallets or fundraising campaigns.


Monitoring systems must therefore be capable of identifying activity that becomes suspicious over time rather than relying solely on information collected when the account was opened.


The use of rapidly changing cryptocurrency addresses can add another layer of complexity. Terrorist financing campaigns can publish new wallet addresses when older addresses become known to authorities or when fundraising campaigns are disrupted.


From a compliance perspective, this means that static lists of known wallet addresses may become outdated quickly. Firms may need dynamic monitoring and blockchain intelligence capable of identifying relationships between addresses rather than simply matching individual wallet identifiers.


The operation also provides an example of how cyber and financial enforcement are increasingly converging.


The investigation was not limited to financial transactions. Authorities targeted the digital infrastructure that enabled the fundraising campaign to function. This reflects a broader enforcement strategy in which online infrastructure, financial technology and criminal financing are treated as interconnected elements of the same activity.


The seizure of domains and servers can have an immediate disruptive effect because it removes the platforms through which new donors can be reached.


At the same time, obtaining information from those platforms can potentially provide investigators with evidence about users, administrators, financial flows and other participants in the network.


For businesses operating in the digital-asset sector, the case is a reminder that terrorist-financing risk extends beyond conventional banking channels.


Cryptocurrency businesses are increasingly expected to maintain sophisticated AML and CTF frameworks capable of addressing sanctions exposure, transaction monitoring, suspicious activity reporting and the specific risks associated with blockchain-based transfers.


This is particularly important for businesses operating internationally.


Cryptocurrency transactions can cross borders almost instantaneously, while a single transaction may involve counterparties located in several jurisdictions. A service provider therefore needs to understand not only its immediate customer but also the broader financial environment in which that customer's activity takes place.


The international dimension is also relevant to enforcement. Cryptocurrency transactions can involve exchanges, wallets, hosting providers and users spread across multiple countries. Cooperation between law enforcement authorities, financial intelligence units and private-sector blockchain specialists can consequently become critical to tracing and freezing assets.


The US seizure shows that such cooperation can result in intervention even when fundraising infrastructure is distributed across different technological and geographic environments.


For compliance professionals, the case reinforces several key lessons.


First, cryptocurrency should not automatically be treated as anonymous or untraceable. Second, wallet screening and blockchain analytics can provide important information that conventional KYC processes cannot. Third, terrorist-financing controls need to account for indirect exposure and rapidly changing wallet infrastructure. Finally, digital platforms supporting financial activity can themselves become important components of financial-crime investigations.


The case also demonstrates the importance of maintaining a risk-based approach. Cryptocurrency is not inherently linked to terrorist financing, and the overwhelming majority of digital-asset activity is legitimate. The compliance challenge is to distinguish ordinary transactions from activity displaying characteristics associated with sanctions evasion, terrorist financing or other forms of illicit finance.


The latest enforcement action sends a clear message that cryptocurrency fundraising does not place terrorist organisations beyond the reach of financial investigators.


The ability to trace blockchain transactions, combine that information with off-chain intelligence and seize associated infrastructure gives authorities multiple avenues through which to disrupt digital fundraising campaigns.


As digital assets continue to become integrated into the global financial system, terrorist organisations and other illicit actors are likely to continue experimenting with new methods of transferring and raising funds. At the same time, regulators and law enforcement agencies are developing increasingly sophisticated tools to identify those methods.


The seizure of more than $560,000 in cryptocurrency and the dismantling of the associated online infrastructure therefore represents more than a single asset recovery action. It demonstrates the growing importance of blockchain intelligence, digital forensics and coordinated AML/CTF enforcement in addressing the evolving financial infrastructure used by terrorist organisations.

By fLEXI tEAM

Comments


bottom of page