CryptaCount
EN
EnglishENDeutschDEEspañolESFrançaisFRItalianoIT日本語JA한국어KONederlandsNLPolskiPLPortuguêsPT
Log in Start Free

FBI Seizes $560K in Hamas Crypto: What It Means for AML Compliance

CryptaCount Editorial · · 9 min read
AML / KYC / LICENSING FBI Seizes $560K in Hamas Crypto: WhatIt Means for AML Compliance

The U.S. Department of Justice has seized more than $560,000 in cryptocurrency tied to Hamas fundraising operations and dismantled parts of the terrorist group's digital infrastructure across five coordinated legal actions. For accounting firms, CFOs, and compliance teams handling digital assets, this case is a sharp reminder that on-chain evidence never disappears, and that regulators and law enforcement are growing increasingly capable of following funds across chains, services, and years of transaction history. The question for any firm touching crypto today is not whether these tools exist, but whether your own controls are robust enough to catch what investigators will eventually find.

FBI Seizes $560K in Hamas Crypto: What It Means for AML Compliance

The Scope of the Operation

The Justice Department announced the coordinated actions on 1 September 2026, bringing together five related cases that had unfolded over roughly eighteen months. Court-authorized seizure warrants were executed in March, June, and October 2025, targeting cryptocurrency held in Hamas-linked wallets. Two further actions, carried out in July and August 2026, went beyond funds and targeted the online infrastructure Hamas allegedly used to solicit donations and communicate with supporters, including domains and servers tied to the al-Qassam Brigades' main web presence.

By seizing those domains, investigators were able to intercept intended cryptocurrency donations and gather information about individuals attempting to contribute funds, according to the Justice Department. The scope, therefore, extended well beyond a financial forfeiture into active disruption of a fundraising and communications network.

How the Funds Moved

According to FBI affidavits, Hamas used donation addresses shared publicly through websites and encrypted communications channels. Supporters sent funds to those addresses, which were then moved into operational wallets and consolidated before being passed onward. The initial March 2025 seizure, which recovered approximately $200,000 in stablecoins, focused on this early donation-to-consolidation flow.

A recurring gas wallet proved to be a critical forensic link. Investigators identified numerous addresses controlled by the al-Qassam Brigades that all relied on the same gas wallet to fund their transactions, effectively tying together what might otherwise have looked like unrelated activity. That single shared piece of infrastructure allowed blockchain analysts to map a much wider network from a relatively small starting point.

Adaptation and Persistence

After the first seizure, Hamas adjusted its tactics. The group shifted toward single-use donation wallets and began using bridging services to move assets from one blockchain to another, a technique designed to obscure the trail. Despite those changes, certain structural patterns remained consistent: gas funding wallets, donation wallets, and consolidation wallets continued to operate in broadly similar ways. OTC brokers and virtual currency exchanges remained part of the infrastructure, including one account the affidavit linked to a Lebanon-based OTC broker and another showing patterns consistent with money mule activity.

Investigators followed the revised trail regardless. A freeze order was issued on certain assets during the June 2025 phase, and the investigation ultimately led to the wider network of wallets, alleged financial facilitators, and online infrastructure targeted in the 2026 actions.

What Blockchain Analytics Actually Did Here

The investigation illustrates how blockchain analysis functions in a live enforcement context. Investigators were not simply watching a single wallet. They were building a graph of connected addresses, tracing funds through cross-chain activity and exchange accounts, and using shared infrastructure clues, like that gas wallet, to connect activity that appeared unrelated on the surface.

Cumulative Evidence Over Time

One of the most significant aspects of these cases is how each phase built on the last. Evidence gathered during the March 2025 seizure fed directly into the June 2025 action, which in turn informed the October 2025 and subsequent 2026 infrastructure takedowns. Because all transaction history remains permanently on-chain, investigators could revisit earlier activity, identify new connections that became visible only with later context, and extend the investigation as the network evolved.

This cumulative quality of blockchain evidence distinguishes crypto investigations from many traditional financial inquiries. A suspicious transaction flagged today may become the key link in an investigation that does not conclude for another eighteen months. For compliance purposes, that means the look-back window for risk never fully closes.

AML and Sanctions Implications for Firms

For accounting firms, virtual asset service providers (VASPs), and corporate treasury teams that hold or transact in digital assets, this case has several direct compliance implications.

Counterparty Screening Is Not Optional

Hamas and the al-Qassam Brigades are designated terrorist organizations under U.S. law. Any U.S. person or entity that knowingly or unknowingly processes a transaction touching a designated address risks exposure under OFAC sanctions regulations and the Bank Secrecy Act. The challenge is that sanctioned addresses are not always immediately obvious, particularly when funds have passed through intermediary wallets or bridging services designed to break the chain of custody.

Firms relying on manual or infrequent address screening are exposed. The Hamas cases show that designated networks use constantly cycling addresses, bridging across chains, and OTC layers specifically to defeat static blocklist checks. A firm's screening infrastructure needs to assess transaction history and clustering, not just spot-check individual addresses against a published list.

Stablecoin Exposure Deserves Special Attention

The initial March 2025 seizure involved stablecoins, not volatile tokens. That is a meaningful detail. Stablecoins are increasingly the preferred vehicle for moving value across borders quickly and quietly, and their settlement characteristics mean they can move through a network far faster than traditional wire transfers. Compliance teams that treat stablecoin flows as lower-risk because they are "just dollars on-chain" are misreading the threat model.

For firms using digital asset accounting software to record and reconcile stablecoin positions, those same records are part of the audit trail that regulators and investigators will examine. Clean, timestamped, address-level records are not just good accounting practice; they are your first line of defense in any inquiry. See also our earlier analysis of state-linked actors using bridge transactions to obscure fund flows, which maps closely to the techniques observed here.

Suspicious Activity Reporting Obligations

For U.S.-registered money services businesses and VASPs, FinCEN's SAR filing requirements apply when a firm knows, suspects, or has reason to suspect that a transaction involves funds from illegal activity or is designed to evade reporting requirements. The bridging activity and address-cycling described in the Hamas affidavits would, if observed at an exchange or OTC desk, be recognizable red flags under existing BSA guidance. Compliance teams should confirm that their transaction monitoring rules are calibrated to catch cross-chain activity, not just same-chain transfers.

Recordkeeping and the Audit Trail

The multi-year arc of this investigation underlines a principle that is easy to overlook during normal business: crypto accounting records need to be retained at a granular, address-level standard, and they need to be retrievable. When investigators issue a subpoena or a court authorizes a seizure, the firm's ability to demonstrate that it conducted proper due diligence, and maintained the records to prove it, is what separates a cooperative witness from a target. Firms building or upgrading their crypto bookkeeping software infrastructure should verify that their systems log wallet addresses, counterparty identifiers where known, timestamps, and transaction hashes in a format that can be exported for legal review.

Practical Steps for Compliance Teams

Review Your Screening Architecture Now

Static OFAC address lists are a necessary but insufficient control. Firms should be asking whether their transaction monitoring tools perform cluster analysis, whether they flag addresses that have transacted with known sanctioned entities within a configurable number of hops, and whether they have rules specifically addressing cross-chain bridge activity. The Hamas cases demonstrate that a network can adapt its wallet addresses while keeping the same underlying infrastructure, so controls that look only at direct address matches will miss intermediate exposure.

Stress-Test Your SAR Process

Walk through a hypothetical: a client or counterparty sends funds that have, two hops back, touched a Hamas-linked consolidation wallet. Does your current process surface that? Does your compliance team have a clear escalation path and a defined filing deadline? FinCEN guidance is clear that reasonable grounds to suspect are sufficient to trigger a SAR obligation; you do not need certainty. If your process requires certainty before filing, it is set too high.

Document Everything, Including Negative Findings

When a screening check returns a clean result, record it. When a transaction is reviewed and cleared, document the rationale. In an enforcement context, regulators look not just for red flags that were caught but for evidence that the firm had a functioning process. A clean screening log for a transaction that later turns out to be problematic is far better than no log at all. Digital asset accounting software should be configured to attach compliance notes and screening outcomes to individual transaction records, not just to aggregate ledger entries. For a broader view of how blockchain analytics is reshaping AML enforcement practice, see our piece on Bitcoin crime investigation and blockchain analytics.

FBI Seizes $560K in Hamas Crypto: What It Means for AML Compliance

Frequently Asked Questions

Does this case create new legal obligations for crypto firms?

Not directly. The seizures do not introduce new rules. They reinforce existing obligations under the Bank Secrecy Act, OFAC sanctions regulations, and FinCEN's MSB guidance. What changes is the enforcement signal: U.S. authorities have demonstrated both the technical capability and the institutional patience to trace funds across multiple chains, service providers, and years of transaction history.

What is the significance of the stablecoin involvement?

Stablecoins were the vehicle of choice in the initial phase of the Hamas fundraising operation. This matters for compliance teams because stablecoin flows are sometimes treated as routine or low-risk. The DOJ cases show that stablecoins can be moved through sanctioned networks just as readily as other crypto assets, and the compliance obligations for screening and monitoring apply equally.

How does cross-chain bridging affect a firm's AML exposure?

Bridging moves assets from one blockchain to another, which can complicate transaction tracing because the asset appears at a new address on a different chain. However, as this investigation shows, blockchain analytics tools can follow funds across bridges. For compliance purposes, a firm that receives bridged assets without screening the source chain history may be unknowingly processing funds with a tainted provenance. Monitoring rules should explicitly cover bridge-related transaction patterns.

What records should firms be retaining to demonstrate compliance?

At a minimum: wallet addresses for all counterparties, transaction hashes, timestamps, the screening outcome at the time of the transaction, and any manual review notes. For regulated entities, FinCEN's BSA recordkeeping rules set specific retention periods (generally five years). Firms should verify that their digital asset accounting software exports records in formats usable for legal discovery, not just internal reporting.

Could a firm face liability for processing a transaction that was, unknown to it, linked to a Hamas wallet?

Strict liability does not generally apply in U.S. sanctions law when a firm had no knowledge and no reasonable means of knowing about a connection to a designated entity. However, OFAC has penalized firms for inadequate compliance programs even in cases of apparent good faith. The standard is whether the firm had a program reasonably designed to detect and prevent sanctions violations. A weak or absent blockchain screening capability is itself a program deficiency that can attract regulatory scrutiny, regardless of whether a specific transaction was intentionally processed.

Source: Chainalysis

US#stablecoinsGeneralEnforcementAML/KYC & Licensing

Related articles

AML/KYC & Licensing
OFAC Sanctions 134 ISKP Crypto Addresses Tied to $2M in Terrorist Financing
AML/KYC & Licensing
OFAC Sanctions Shelbit: The $6.3 Billion Crypto Settlement Layer Behind Iran's Illicit Economy
AML/KYC & Licensing
The A7 Leaks: What $8 Billion in Stablecoin Flows Mean for Crypto Accounting and AML Compliance
AML/KYC & Licensing
OFAC Sanctions Shelbit and Aban Tether: What Accounting Firms and CFOs Must Do Now