CryptaCount
EN
EnglishENDeutschDEEspañolESFrançaisFRItalianoIT日本語JA한국어KONederlandsNLPolskiPLPortuguêsPT
Log in Start Free

Israel Seizes 84 Crypto Wallets Tied to Hamas Fundraising

CryptaCount Editorial · · 10 min read
AML / KYC / LICENSING Israel Seizes 84 Crypto Wallets Tied toHamas Fundraising

Israel's National Bureau for Counter Terror Financing (NBCTF) has issued a seizure order against 84 cryptoasset addresses believed to be controlled by Hamas or used in terror-related activity. Blockchain analysis by Elliptic shows those addresses collectively received over $7.7 million in cryptoassets. For accounting firms, auditors, and compliance officers whose clients interact with digital assets, this order creates immediate legal obligations that cannot wait for a quarterly review cycle.

Israel Seizes 84 Crypto Wallets Tied to Hamas Fundraising

What the NBCTF Seizure Order Covers

The order is issued under Israeli anti-terrorism legislation and carries specific legal duties for any party that has received funds from the listed addresses, or that has been asked to perform any action involving those funds. That obligation is not optional: Israeli law requires direct contact with the Israel Police upon discovery of any such exposure.

Addresses and asset types involved

The 84 addresses span multiple blockchain networks. The seizure order confirms Hamas is no longer operating exclusively in Bitcoin. The assets identified across the listed wallets include Bitcoin, Tether (USDT), Ether (ETH), and Dogecoin. That breadth is operationally significant: a compliance screening process that checks only Bitcoin addresses will miss exposures on Ethereum and Tron-based USDT rails.

The fundraising campaign timeline

Many of the addresses were used in a fundraising campaign that accepted Bitcoin donations between January 2019 and May 2023. A significant subset of the addresses had previously been identified in public reporting as linked to the Al-Qassam Brigades, the military wing of Hamas. The seizure order now formalises that association under Israeli law and places it on a legally enforceable footing.

A note on the $7.7 million figure

Elliptic's analysis excluded funds sent to addresses known to function as shared deposit addresses for larger services, such as exchange hot wallets that receive deposits from many unrelated users. The $7.7 million figure therefore represents funds that could plausibly be associated with the designated entities, not the gross volume passing through infrastructure that also serves unrelated parties. Firms should be aware that the raw on-chain volume at any given address may look larger than the exposure that is actually attributable to the sanctioned party.

Why This Matters Beyond Israel

The NBCTF order has direct territorial reach within Israel, but the compliance implications extend to any regulated firm globally that may have transaction exposure to these addresses.

Correspondent and cross-border exposure

A European exchange, a US-regulated broker-dealer, or an Asian virtual asset service provider (VASP) whose customer sent or received funds from one of these 84 addresses now faces potential exposure under its own jurisdiction's counter-terrorism financing (CTF) rules. Financial Action Task Force (FATF) Recommendation 6 requires countries to implement targeted financial sanctions related to terrorism financing without delay, and most FATF-member states have domestic legislation that implements this requirement. An Israeli seizure order publicising specific on-chain addresses gives compliance teams elsewhere a concrete data point to act on.

The Travel Rule dimension

Where the Travel Rule applies, a VASP that transferred funds to or from one of these addresses and did not collect or transmit the required originator or beneficiary information faces a compounded compliance problem: a potential CTF exposure layered on top of a Travel Rule deficiency. Both will need to be addressed in any regulatory notification or internal investigation.

Precedent alongside the DOJ Al-Qassam filing

This NBCTF action does not sit in isolation. As covered in our earlier analysis of the Al-Qassam Brigades DOJ filing and what crypto firms must know, US federal prosecutors have already moved against wallets and exchange accounts linked to the same organisation using USDT on Tron. The Israeli order and the US DOJ action together paint a picture of a multi-jurisdictional enforcement posture that is tightening around Hamas-linked crypto infrastructure. Firms that have addressed only one jurisdiction's published lists are not fully covered.

Accounting and Audit Implications

The accounting consequences of a CTF exposure go well beyond a compliance write-up. They touch financial statements, client onboarding records, and the defensibility of prior-period books.

Asset freezing and balance sheet treatment

If a firm's own treasury or a client's balance sheet holds assets that are subject to a seizure or freeze order, those assets cannot be treated as freely available. Under IFRS (IAS 1 and IAS 37) and US GAAP (ASC 450), a restriction on an asset's use affects its balance sheet classification and may require a disclosure or provision. A crypto accounting software workflow that simply marks all wallet balances as current assets without screening for sanctions flags will produce a materially misleading balance sheet. The correct treatment requires quarantining the affected balance, disclosing the restriction, and assessing whether a liability or contingent loss needs to be recognised.

Client onboarding records and KYC retrospective review

When a seizure order publishes specific wallet addresses, the first internal task for any accounting or audit firm serving crypto businesses is a retrospective look at client KYC files. Did any client deposit from or withdraw to one of these addresses? If the answer is yes, the firm's KYC and transaction monitoring records will be scrutinised. Gaps, such as incomplete source-of-funds documentation or an absence of enhanced due diligence on high-risk counterparties, become audit findings of a very different character once a CTF link is established.

Suspicious activity reporting obligations

In most FATF-member jurisdictions, discovery of a transaction linked to a designated terrorist entity triggers a mandatory suspicious activity report (SAR) or suspicious transaction report (STR). The obligation to report typically cannot be deferred pending legal advice, and "tipping off" prohibitions mean the client must not be informed. Accounting firms and auditors that discover such a link while performing year-end work face a tightly constrained timeline and a duty of professional care that sits above any client relationship.

What Compliance Teams Should Do Right Now

The following steps are sequenced by urgency, not alphabetically. Act in this order.

Step 1: Screen the published address list immediately

The NBCTF has published the 84 addresses. Every VASP, exchange, and firm using digital asset accounting software should run those addresses against its transaction history and current open positions before the end of the business day. This is not a week-long project. The legal obligation under Israeli law is immediate, and the reputational and regulatory risk of a delayed response compounds daily.

Step 2: Extend the screen across all asset types

Because the order covers Bitcoin, Ether, Tether, and Dogecoin, the screen must run across all four networks. A Bitcoin-only check is not sufficient. Firms whose crypto bookkeeping software does not natively support multi-chain address screening should use a dedicated blockchain analytics layer and document the methodology used.

Step 3: Quarantine, document, and escalate

Any match, even a second or third-hop match where funds passed through an intermediary address, should be quarantined, timestamped, and escalated to the firm's Money Laundering Reporting Officer (MLRO) or equivalent. The documentation should record the screening method, the date and time of the screen, the person who ran it, and the disposition decision. That audit trail will matter if a regulator asks questions later.

Step 4: Review your sanctions list update cadence

This action is a reminder that sanctions and seizure lists are not static. The NBCTF, OFAC, the EU, and the UK's Office of Financial Sanctions Implementation (OFSI) all publish updates on irregular schedules. A firm that updates its watchlists monthly may have a 30-day window during which a newly designated address goes undetected. Real-time or near-real-time list synchronisation is now table stakes, not a premium feature. For context on how rapidly these designations can follow one another, see our earlier coverage of OFAC sanctions on Iranian exchange BitBank over IRGC Bitcoin transfers, where a similar pattern of rapid on-chain identification preceded formal designation.

Step 5: Update your risk appetite statement

If your firm's written risk appetite statement does not explicitly address exposure to addresses appearing on foreign counter-terrorism financing orders, this event is the prompt to add that language. Regulators in the UK, EU, and US increasingly expect VASPs and their professional service providers to have written policies that cover the full spectrum of sanctions and CTF exposure, not just the domestic list.

Israel Seizes 84 Crypto Wallets Tied to Hamas Fundraising

The Broader AML Signal for Digital Asset Professionals

The use of Dogecoin alongside established channels like USDT and Bitcoin is operationally notable. It suggests that actors subject to sanctions are deliberately diversifying across asset types and networks, likely to reduce the probability that any single screening gap catches all of their activity. Compliance programmes built around a narrow list of "high-risk" assets may need to be widened. The days when a firm could plausibly argue that screening Bitcoin and USDT was adequate are fading.

The multi-asset, multi-chain reality of terror financing in 2026 means that digital asset accounting software and compliance tooling must cover the full breadth of assets a firm touches, not just the most liquid ones. It also reinforces the case for on-chain analytics that can trace funds across hops, not just flag direct counterparties. First-hop screening catches the obvious exposure. Second and third-hop analysis is what a regulator will expect when it reviews your transaction monitoring programme after the fact.

Source: Elliptic

Frequently Asked Questions

Does the Israeli NBCTF seizure order create legal obligations for firms outside Israel?

The order has direct territorial effect within Israel. However, firms in other jurisdictions are not automatically exempt. Most FATF-member states have their own CTF legislation requiring action when a firm discovers a transaction linked to a designated terrorist entity, regardless of which country issued the designation. Firms should check their local CTF rules and take appropriate action, which typically includes filing a suspicious activity report and freezing the relevant assets.

What does "second-hop" exposure mean, and does it matter?

A second-hop exposure means your client did not transact directly with one of the 84 designated addresses, but instead transacted with an intermediary that itself transacted with a designated address. Regulators increasingly expect firms to assess indirect exposure, not just direct counterparty risk. Whether a second-hop exposure triggers a reporting obligation depends on jurisdiction and the specific facts, but it should always be documented and reviewed by the firm's MLRO.

How should a crypto balance sheet be adjusted if a held asset is linked to a seized address?

Under IFRS and US GAAP, an asset subject to a legal restriction or freeze cannot be classified as freely available. It should be reclassified as restricted on the balance sheet, accompanied by a note disclosure explaining the nature of the restriction. Depending on the facts, a contingent liability or provision may also need to be recognised if there is a probable outflow, such as a clawback obligation or regulatory fine.

The order covers Dogecoin. Do standard AML tools screen Dogecoin addresses?

Many enterprise-grade blockchain analytics tools do support Dogecoin screening, but not all do. Firms should verify whether their current tooling covers every asset type named in the order. Where a gap exists, it should be closed immediately, and the interim period during which screening was incomplete should be documented and a manual review conducted for that period.

How quickly must a suspicious activity report be filed after discovering a match?

The timeline varies by jurisdiction. In the UK, a SAR must generally be filed promptly, and firms often seek a defence against money laundering (DAML) before proceeding with the transaction. In the US, a SAR must be filed within 30 calendar days of initial detection, with a possible 60-day extension where no suspect is identified. In the EU, national FIUs set their own timelines. Firms should not wait for legal advice before beginning the documentation process, as the clock often starts at the point of discovery.

ILGLOBALGeneralEnforcementAML/KYC & Licensing

Related articles

AML/KYC & Licensing
Blockchain Dead Drops: How Nation-States Hide Malware On-Chain
AML/KYC & Licensing
OFAC Sanctions BitBank: Iran's Hormuz Toll Settled in Bitcoin
AML/KYC & Licensing
UAE and Sweden Arrest Seven in $7.1M Crypto Laundering Ring Tied to Contract Killings
AML/KYC & Licensing
OFAC Sanctions Iranian Exchange BitBank Over IRGC Bitcoin Transfers