U.S. federal authorities in Washington, D.C. said they have seized more than $25 million in cryptocurrency tied to cross-border fraud schemes, underscoring how digital assets remain central to modern cybercrime—and how aggressively law enforcement is moving to claw funds back through forfeiture actions.
In an announcement dated July 21, the U.S. Attorney’s Office for the District of Columbia and the U.S. Secret Service’s Washington Field Office said the seizures were made through investigations by their Cyber Fraud Task Force. Prosecutors have since filed five civil forfeiture complaints to permanently confiscate the recovered assets, which they say are linked to an international scam network targeting residents in the U.S. and Canada.
Officials said the largest case involved a ‘romance scam’ affecting more than 200 victims, with losses totaling roughly $12.1 million. A second major case—worth about $10.4 million—stemmed from a network of suspicious wallets flagged by Canadian authorities and shared with the Secret Service. Investigators said they identified more than 270 suspicious transactions connected to fraudulent investment platforms, noting that the two main cases account for roughly 85% of the total assets targeted for forfeiture.
The remaining cases involved schemes characterized by withdrawal restrictions, fake investment accounts, and tracing of stolen proceeds. Investigators also said several key suspected money launderers were based in Southeast Asia, and that they observed internet addresses linked to China, Malaysia, and Cambodia—an operational footprint consistent with broader patterns of industrialized scam operations that rely on layered laundering routes across jurisdictions.
Separately, South Korea’s Mirae Asset Consulting said it has secured management control of Korbit, one of the country’s early cryptocurrency exchanges, as it moves to reposition the business into a broader digital asset infrastructure play. According to local reports, Mirae Asset Consulting increased its stake to 97.15% in a deal valued at about 141.4 billion won (roughly $95 million to $102 million at prevailing exchange rates).
South Korea’s Fair Trade Commission approved the transaction on July 9, 2026, citing Korbit’s estimated 0.5% share of the domestic crypto trading market in 2025 and concluding the acquisition was unlikely to restrict competition. Korbit plans to rebrand as DigitalX and pivot toward becoming a digital asset infrastructure platform, while maintaining its operating entity, client deposits, and core trading services for the time being. The firm said customer assets will continue to be segregated in line with existing protection rules.
Mirae Asset founder and Global Strategy Officer Hyeon-joo Park framed DigitalX as a key pillar of the group’s “Mirae Asset 3.0” initiative, with an ambition to connect ‘real-world asset tokenization,’ security tokens, stablecoins, traditional securities, and digital assets on one platform. The company emphasized that the objective is not to outcompete Korea’s dominant venues by spot volume, but to combine its securities and asset-management capabilities with Korbit’s operational experience in digital assets.
In DeFi, Uniswap said on July 26 UTC it introduced ‘permissioned pools’ built on Uniswap v4, aiming to make regulated on-chain markets more feasible for tokenized securities, funds, and equities by integrating allowlist verification into automated market maker (AMM) trading. Superstate, Securitize, and Daugo were named as launch partners. The protocol stressed that standard ‘permissionless’ pools on Uniswap v4 will continue unchanged.
Russia’s largest bank, Sberbank, is also preparing to expand into regulated digital asset services. The lender is developing cryptocurrency trading infrastructure and digital custody services targeted at regulated financial institutions, with plans to launch by Dec. 1, according to local reporting. Russia’s updated rules governing trading, custody, and payments involving crypto assets are set to take effect on Sept. 1, while requirements for licensed intermediaries will apply beginning in July 2027. Public crypto trading in Russia will be restricted to assets meeting liquidity and market-cap thresholds, while using crypto for domestic payments remains prohibited.
Meanwhile, DeFi trade aggregator Odos said it will shut down all services on July 30, 2026, with its app shifting into read-only mode starting July 27. Users will be able to view balances and transaction history but will not be able to initiate new trades. Odos said it has never directly custodyed user funds; assets held in external wallets such as MetaMask, Rabby, or hardware wallets remain controlled by users’ private keys. However, users who created Odos wallets through Google, Apple, or email login were urged to export their private keys or move assets to self-custody wallets before the cutoff.
Odos, which spun out of Semiotic Labs in 2022, said it has routed more than $104 billion in volume across roughly 15 networks. The company noted a sharp contraction in activity, from about $7.85 billion in monthly volume in December 2024 to a few hundred million dollars by mid-2026. It added that the ODOS token will continue to exist independently of the product shutdown, describing the Odos DAO and the operating company as separate entities, and warned users to ignore any scam communications claiming token migrations, claims, or airdrops.
Market activity also flared around Euler (EUL) after Upbit announced a listing in its Korean won market. EUL spiked more than 100% intraday to as high as $2.73 before easing to around $2.30, based on OKX pricing cited in local reports—an example of how top-tier exchange listings can still drive abrupt ‘liquidity inflow’ and volatility in mid-cap tokens.
In security-related developments, on-chain analyst “Vijinn” reported that the attacker behind the AFX Trade exploit swapped 12,467.4 Ether (ETH) for Bitcoin (BTC). AFX Trade’s Arbitrum cross-chain bridge was hacked on July 23, resulting in about $24 million in losses, largely in USD Coin (USDC). The attacker has been reported to have bridged funds from Arbitrum back to Ethereum in stages before conducting the exchange.
The FBI is also investigating a separate malware campaign involving eight downloadable games that authorities say infected roughly 8,000 devices and enabled access to around 80 cryptocurrency wallets, with at least $220,000 in digital assets stolen. Court documents allege the activity ran from May 2024 to February 2026 and that a North Lauderdale, Florida resident, Zaire Dontavius Jamarion Wilkins, 21, financed and promoted the malware operation. Investigators said victims who installed the games had passwords, wallet authentication data, and browser information harvested, with promotion allegedly conducted via Discord, Telegram, X, and LinkedIn, supported by bots used to locate crypto holders across online communities. Wilkins faces a conspiracy charge that carries a maximum sentence of up to 10 years in prison if convicted.
Broader concerns about state-linked theft also resurfaced after a report circulated that Chainalysis CEO Michael Gronager said on CNBC that North Korea has been actively stealing Bitcoin (BTC) to fund nuclear weapons development. Chainalysis, a blockchain analytics company, is widely used by exchanges and law enforcement agencies to trace hacks and money laundering activity.
Finally, liquid staking provider Lido said it is investigating a discrepancy found during a recalculation of stETH yield, while stressing there is no user fund risk and that the issue is not related to validator slashing. According to local reports, Lido developers observed an anomaly in the rebase accounting reported by the protocol’s oracle: the annualized yield was computed at 2.04% versus an expected 2.15%. Lido attributed the mismatch to 32 ETH from a validator deposit awaiting confirmation that was not reflected in oracle statistics, and said the missing amount will be incorporated in the next recalculation after a fix is applied.
🔎 Market Interpretation
- Law-enforcement pressure is rising: The U.S. seizure of $25M+ in crypto linked to cross-border scams shows forfeiture is becoming a primary tool to recover funds, increasing operational risk for laundering networks and suspicious intermediaries.
- Compliance-oriented DeFi is accelerating in parallel with permissionless markets: Uniswap v4’s permissioned pools signal growing demand for on-chain markets that can support tokenized securities/funds via allowlists, while leaving standard pools unchanged—suggesting a “two-track” DeFi structure (regulated + open).
- Institutional infrastructure is the next battleground: Mirae Asset’s near-total control of Korbit (rebranding to DigitalX) and Sberbank’s planned custody/trading stack indicate incumbents are shifting from spot-volume competition to broader digital asset infrastructure (tokenization, custody, rails).
- Regulatory timelines drive product roadmaps: Russia’s rule changes (effective Sept. 1; licensing requirements in 2027) are shaping bank launch schedules and narrowing public access via liquidity/market-cap thresholds.
- Liquidity shocks remain powerful in mid-caps: Euler (EUL) spiking 100%+ on an Upbit KRW listing highlights how top exchange listings still trigger rapid inflows and volatility, especially for mid-cap assets.
- Security risks remain multi-vector: From bridge exploits (AFX Trade, ~$24M) to malware-distributed wallet theft (~$220K) and state-linked narratives (North Korea), the ecosystem continues to face both technical and social attack surfaces.
- DeFi business models are under pressure: Odos shutting down after volumes collapsed from $7.85B/month (Dec 2024) to “hundreds of millions” by mid-2026 reflects competitive compression and lower aggregators’ margins/activity during downcycles.
- Protocol accounting issues can be non-fatal yet market-sensitive: Lido’s stETH yield discrepancy (2.04% vs. 2.15%) is framed as an oracle/accounting visibility issue—not slashing or fund loss—illustrating how transparency events can still affect confidence.
💡 Strategic Points
- Exchanges, custodians, and OTC desks: Strengthen transaction monitoring for romance/investment-scam patterns, cross-jurisdiction wallet clusters, and rapid chain-hopping behavior; forfeiture actions increasingly target identifiable endpoints.
- Tokenization/TradFi entrants: Track Korea’s DigitalX pivot as a template: integrate securities compliance, stablecoin rails, and tokenized RWAs rather than chasing spot volume; anticipate consolidation among smaller exchanges.
- DeFi builders: Consider modular compliance layers (allowlists/attestations) to access regulated liquidity while preserving permissionless composability elsewhere; Uniswap v4 permissioned pools provide a reference architecture.
- Risk managers: Treat bridges and cross-chain infrastructure as high-severity risk; AFX Trade shows attackers can bridge in stages and swap across assets to obfuscate flows.
- Users impacted by product shutdowns: For Odos users with social-login wallets, immediately export private keys or migrate assets—read-only modes can create time-pressure and increase phishing risk.
- Traders: Exchange listings can create short-lived price dislocations; manage slippage and consider staged entries/exits, especially in KRW markets where retail-driven bursts can be intense.
- Security hygiene: Avoid installing unsigned/unknown “games” or apps; use hardware wallets where possible, segregate hot wallets, and maintain separate browser profiles to reduce credential harvesting impact.
- Protocol participants: Monitor staking/oracle updates (e.g., Lido) for accounting anomalies; even non-loss events can affect yield expectations and secondary-market pricing of liquid staking tokens.
📘 Glossary
- Civil forfeiture: A legal process allowing the government to seize assets suspected to be connected to crime, often without needing a criminal conviction tied to the property.
- Romance scam: Fraud where attackers build a relationship to induce victims to send funds, often routed through crypto for speed and cross-border laundering.
- Allowlist verification: A mechanism that restricts participation to approved addresses (e.g., KYC/eligibility-verified users).
- AMM (Automated Market Maker): A DEX model where liquidity pools and pricing formulas replace traditional order books.
- Permissioned pool: A liquidity pool that limits who can trade/provide liquidity, often to meet regulatory or issuer requirements.
- Tokenized real-world assets (RWA): On-chain representations of off-chain assets (e.g., bonds, funds, equities, real estate) enabling programmable ownership and transfer.
- Digital custody: Secure storage and administration of digital assets (keys, settlement, reporting), typically required for regulated institutions.
- Bridge exploit: An attack on cross-chain transfer systems, often enabling attackers to mint/withdraw assets illegitimately.
- Chain-hopping: Moving funds across blockchains to reduce traceability and complicate enforcement actions.
- Read-only mode: A product state where users can view history/balances but can’t execute new transactions.
- Liquid staking / stETH: A system where staked ETH yields are represented by a liquid token (stETH) that can be used elsewhere while staking continues.
- Oracle: A component that supplies external or aggregated data to smart contracts (e.g., validator balances/yields), enabling on-chain accounting.
Comment 0