Al-Qassam Brigades DOJ Filing: What Crypto Firms Must Know Now
A US Department of Justice asset-forfeiture filing dated 9 September 2026 contains something rarely seen in public legal records: a verbatim letter from the Al-Qassam Brigades, Hamas's military wing, instructing prospective donors on exactly how to move crypto while minimising detection. The document names specific applications, a specific stablecoin, and a specific blockchain network. For accounting firms, auditors, and CFOs who rely on crypto accounting software to monitor digital asset flows, this filing is not background noise. It is a live typology disclosure from a primary government source, and it demands a structured response.
What the DOJ Filing Actually Says
The filing is an asset-seizure warrant. Embedded within it is a letter that the Al-Qassam Brigades sent to potential donors, dated 10 February 2025. The group's instructions are precise.
The donor guidance, in summary
The letter advised donors to avoid sending crypto directly from Binance, citing the risk that wallets could be blocked. Instead, it listed Trust Wallet, Bybit, OKX, Kast, and Redotpay as applications donors could use to transfer funds to an external TRON blockchain address. The letter also told donors to enter fictitious recipient data to obscure the true destination and to use Binance only for purchasing crypto before moving funds to a separate application to complete the transfer.
The designated stablecoin was Tether's USDT, transmitted over the TRC-20 standard on the TRON blockchain. TRON's TRC-20 protocol governs how fungible tokens are created and transferred on that network. USDT on TRON has consistently featured in illicit finance typologies because of its speed, low fees, and the volume of peer-to-peer infrastructure built around it globally. For more context on why this rail keeps appearing in enforcement actions, see our earlier analysis of how USDT on TRON is reshaping terrorist financing typologies.
What the filing does not say
The DOJ filing does not allege that any of the named platforms facilitated the transfers or that their compliance programmes are deficient. The wallet receiving donations was an external address on the TRON blockchain and was not identified in the filing as belonging to any of those companies. The document's significance is analytical: it reveals how a sanctioned group maps exchange-level controls and routes around perceived friction points.
OKX stated that the wallet address referenced in the letter had no association with its platform and had already been identified by its internal controls as linked to illicit activity, meaning any customer attempt to send funds there would have been flagged and blocked. Kast noted it employs more than 50 people across its compliance organisation and uses third-party tools for sanctions screening, customer due diligence, and transaction monitoring. Binance's chief compliance officer publicly stated that the group's instruction to avoid Binance demonstrates that its controls are working. Bybit declined to comment, and Redotpay did not respond before publication.
Regulatory and Enforcement Context
This filing does not emerge from a vacuum. The US Treasury's 2026 terrorist-financing risk assessment noted that Hamas and ISIS have continued soliciting donations and transfers via crypto channels, while also confirming that traditional financial products remain the primary vehicle for terrorist finance overall. The US government refocused its counter-terrorist financing posture on Hamas following the October 2023 attacks on Israel. Reporting from that period indicated that wallets connected to Hamas received approximately $41 million in crypto between 2020 and 2023, and that Treasury was separately investigating $165 million in crypto-linked transactions that may have helped finance the group before October 2023.
OFAC designation risk for platforms and their clients
Any entity that processes a transaction to or from a wallet address designated by the Office of Foreign Assets Control faces strict liability under US sanctions law, regardless of intent. The Al-Qassam Brigades are a designated Foreign Terrorist Organization. A transaction that routes through an intermediary application to reach a sanctioned address does not break the chain of legal exposure simply because an additional hop was inserted. Accounting firms advising clients who operate exchanges, payment applications, or custody solutions need to treat this filing as a typology exhibit, not a news item.
The OFAC Xinbi enforcement action earlier this year demonstrated that regulators are willing to freeze stablecoin balances and sanction entities that process USDT flows linked to illicit actors, even when those entities operate outside the US. Our coverage of sanctions screening obligations after the OFAC Xinbi action sets out the due-diligence steps that firms must embed before onboarding any stablecoin-heavy client.
AML Implications for Accounting Firms and Auditors
The Al-Qassam letter is, in effect, an adversarial test of exchange-level KYC controls. The group's conclusion was that Binance's controls created too much friction for its purposes, while other applications were assessed as more permissive. Whether or not that assessment was accurate at the time, the typology it reveals has direct implications for how accounting professionals should evaluate their clients' AML frameworks.
Transaction monitoring: what to look for
The filing highlights three red flags that should be embedded in any digital asset accounting or bookkeeping workflow:
- Multi-hop USDT transfers on TRC-20: A customer purchases USDT on one platform, withdraws to a self-custodied or third-party wallet, and then sends onward to an external address. The intermediate hop is designed to obscure the origin exchange from the destination. Your transaction monitoring logic must account for this pattern, not just direct sends.
- Fictitious beneficiary data: The letter explicitly instructed donors to enter false recipient information. This is a textbook red flag under the Financial Action Task Force's Recommendation 16 (the travel rule). If your client's platform is not validating beneficiary data against the sending wallet at the point of transfer, that is a gap that an auditor must flag.
- External wallet destinations on TRON: Transactions terminating at TRON addresses that are not associated with a regulated custodian warrant enhanced due diligence. The volume of sanctioned-address matches on TRC-20 has grown significantly alongside the network's adoption for stablecoin settlement.
What robust crypto accounting software must capture
Firms using digital asset accounting software to produce books for exchange or payment clients need to confirm that their tooling ingests on-chain data at the transaction level, not just at the settlement or reporting layer. Aggregated wallet balances do not surface the multi-hop patterns described in the DOJ filing. Ledger-level entries must tie each USDT movement to a specific on-chain transaction hash, the counterparty address, and the network (in this case, TRON), so that sanctions screening can be applied in near-real time rather than retrospectively at month-end.
This is not a theoretical requirement. If a client's platform processed a transfer to the wallet address referenced in the February 2025 letter and your crypto bookkeeping software did not capture the transaction hash and counterparty address, you cannot reconstruct the exposure for a regulator or auditor. That gap is both a compliance failure and an accounting control weakness.
Practical Steps for CFOs and Finance Teams
CFOs at crypto-native businesses and at traditional firms with digital asset treasury positions should treat this filing as a prompt for a targeted controls review. The following steps are grounded in what the DOJ document actually discloses.
Immediate actions
First, run the wallet address referenced in the DOJ filing against your transaction history. The address is a matter of public record in the forfeiture filing. If any transaction in your ledger touches that address, directly or through one hop, escalate to your compliance officer and legal counsel immediately.
Second, review your sanctions screening frequency for TRON-based USDT transactions specifically. Many screening workflows apply OFAC checks at onboarding and then at periodic intervals. The Al-Qassam letter was dated February 2025; an address associated with it may have been designated or flagged in blockchain analytics databases before the September 2026 filing made it public. Real-time or near-real-time screening on each transaction, not just each customer, is the appropriate standard for high-risk rails.
Third, audit your travel rule compliance for outbound USDT withdrawals. If your client's platform allows users to withdraw USDT to external TRON addresses without validating the beneficiary name and address, that is a regulatory exposure that this filing makes considerably more visible to enforcement agencies.
Longer-term programme updates
Incorporate the multi-hop obfuscation typology into your annual AML risk assessment. The FATF and FinCEN both require that risk assessments reflect current typologies, and a typology that appears in a federal court filing is by definition current. Update your suspicious activity report narrative templates to include language that covers chain-hopping via TRC-20 USDT, because the pattern described in the Al-Qassam letter will be scrutinised by examiners who have read the same DOJ filing.
Consider whether your client agreements require counterparties to certify that they do not process transactions for sanctioned persons or entities. If those representations exist only at onboarding, this is a good moment to add ongoing certification obligations and to ensure that your engagement terms give you the right to terminate if a sanctions nexus is discovered mid-engagement.
Frequently Asked Questions
Does the DOJ filing mean the named platforms violated sanctions law?
No. The filing does not allege that any named platform processed funds for the Al-Qassam Brigades or that their compliance programmes failed. The wallet receiving donations was an external address not attributed to any platform. The filing's relevance is that it documents how a sanctioned group assessed exchange-level controls, which is valuable typology intelligence for compliance professionals.
Why does USDT on TRON keep appearing in illicit finance cases?
USDT on the TRC-20 network combines dollar-denominated stability, low transaction fees, fast settlement, and a large peer-to-peer ecosystem across jurisdictions with variable AML enforcement. Those characteristics make it attractive for both legitimate and illicit use. The US Treasury's 2026 terrorist-financing risk assessment specifically notes continued illicit use of stablecoins alongside traditional financial channels.
What is the travel rule, and why does it matter here?
FATF Recommendation 16, commonly called the travel rule, requires virtual asset service providers to collect and transmit originator and beneficiary information for crypto transfers above a threshold (typically $1,000 or equivalent). The Al-Qassam letter explicitly told donors to enter fictitious beneficiary data, which is designed to defeat exactly this requirement. A platform that does not validate beneficiary data at the point of withdrawal is therefore more vulnerable to this obfuscation technique.
What should an accounting firm do if a client's transaction history touches the referenced wallet?
Escalate immediately to your compliance officer and legal counsel. Do not attempt to remediate or reclassify the transaction before taking advice. Depending on the facts, your firm may have a suspicious activity reporting obligation. Preserve all on-chain records and internal documentation. Do not tip off the client before confirming with counsel whether doing so would constitute tipping-off under applicable AML law.
How does this filing change the risk profile for TRON-based stablecoin clients?
It elevates the scrutiny warranted for any client whose business model involves high volumes of USDT withdrawals to external TRON addresses, particularly where beneficiary validation is limited. It does not mean all TRC-20 USDT activity is high-risk, but it does mean that your AML risk assessment for such clients should explicitly reference the TRC-20 multi-hop typology and document the controls you have applied to mitigate it.
Source: CoinDesk Policy
