Cross-Chain Crime Hits $21.8 Billion

July 21, 2025

As soon as there was more than one blockchain, crypto crime was not limited to a single chain – in fact, moving from address to address, offramping and then onramping back on chain has been a key strategy for bad actors laundering funds. With increased cross-chain interoperability, illicit actors have increased chain-hopping volume significantly. This post looks at Elliptic’s annual report, discussing what it all means for law, regulation, and compliance.

Summary

Elliptic’s latest report paints a vivid picture of the cross-chain money laundering landscape in 2025. Some of the most important findings include:

  • Cross-Chain Crime Volume: Over $21.8 billion in criminal or high-risk crypto assets have been laundered via cross-chain swapping – i.e. moving funds through decentralized exchanges (DEXs), blockchain bridges, or anonymous coin-swap services. This total far exceeds prior years’ sums and highlights that hopping between assets and chains is now a cornerstone of illicit crypto activity. By comparison, the cross-chain laundering estimate was just $7 billion in mid-2023 and $4 billion in 2022.
  • North Korea’s Outsized Role: One of the most prolific perpetrators is North Korea. Elliptic attributes roughly 12% of that $21.8 billion to DPRK hacking groups, which have developed sophisticated cross-chain laundering methods to wash the proceeds of their crypto hacks. Major incidents like a $1.46 billion exchange hack in Feb 2025 (allegedly tied to North Korea) contributed heavily to these totals and illustrate how state-sponsored hackers exploit cross-chain techniques at scale. Sanctions evasion through crypto remains a paramount concern – the report notes that North Korean and other sanctioned entities account for the vast majority of the ~$4 billion in cross-chain activity linked to sanctions risk.
  • Rising Complexity (Multi-Chain Laundering): Criminal money laundering schemes now routinely span multiple blockchains, making investigations exponentially more complex. About 33% of complex cases Elliptic studied involved transactions across more than three different blockchains; 27% of cases involved over five blockchains, and 20% even touched more than ten distinct chains. This multi-chain tangle is intentional – hopping across many ledgers and token types is meant to throw investigators off the scent. Tracking illicit funds now often means following an elaborate path: for example, stolen Ethereum might be converted into Bitcoin via a DEX, bridged to another chain as an altcoin, then swapped again into privacy coins or stablecoins on yet another platform. Each additional hop or chain in the mix increases the difficulty of tracing and attribution. As a result, cross-chain crypto investigations have become a forensic headache, requiring advanced analytics to stitch together fragmented clues across disparate networks.

Evolving Cross-Chain Laundering Tactics

Elliptic’s report identifies several key tactics and typologies that bad actors use to wash funds across multiple assets and blockchains. Understanding these methods is crucial for compliance professionals and regulators trying to keep up. Here are some of the prominent cross-chain laundering techniques evolving today:

  • Chain-Hopping (Structured and Multi-Hop Transfers): Chain-hopping refers to swapping assets rapidly across different blockchains (or even within the same chain into different tokens) in succession, in order to confuse the transactional trail. Criminals will convert one cryptocurrency into another repeatedly – jumping through DEXs, using bridge protocols to move between networks, or stringing together many token swaps. The goal is to break the linear flow of funds and frustrate investigators, who must follow each hop manually across blockchains. For example, a thief might swap stolen ETH into BTC, then to an anonymized altcoin on a second chain, and again to a privacy coin on a third chain, all in short order. Elliptic notes that when funds are structured (broken into pieces and chain-hopped in parallel) or multi-hop chain-hopped across numerous networks, it’s a strong red flag for laundering (Elliptic 2025, p. 9). In fact, the Financial Action Task Force (FATF) began highlighting chain-hopping as a money laundering concern in the early 2020s, recognizing that criminals were adopting cross-asset swapping to evade detection (Elliptic 2025, p. 10). Simply put, chain-hopping is the quintessential cross-chain laundering technique – a cat-and-mouse maneuver designed to exploit the siloed nature of blockchain analysis tools and leave compliance teams with an overwhelming puzzle.
  • Avoiding Freezable Assets: Another tactical consideration for illicit actors is to evade assets that can be frozen or seized by authorities. Stablecoins like Tether (USDT) and USD Coin (USDC) are popular in crypto crime, but they carry a unique risk for criminals: centralized issuers can blacklist or freeze tokens associated with illicit activity. To counter this, criminals often swap out of USDT/USDC into other cryptocurrencies as quickly as possible during their laundering process (Elliptic 2025, p. 8). For instance, a hacker who steals USDC will immediately trade it for a less traceable coin (or a decentralized stablecoin without a central issuer) to avoid the chance of the issuer locking those funds. This typology was observed repeatedly – as soon as tainted funds enter a controllable asset, the crooks flip them into something “safer” from intervention. By ditching freezable assets early, launderers lower the risk that an exchange or issuer (under law enforcement pressure) will clamp down on their holdings. It’s a pragmatic adaptation to the fact that some blockchain assets have centralized choke points.
  • Gas Fee Financing: One of the more novel techniques identified is the financing of gas fees through swaps. Every blockchain transaction requires paying fees in that chain’s native token (e.g. ETH for Ethereum, BNB for BSC, TRX for Tron). Criminals who operate across many chains need those native tokens to keep moving funds – which creates a telltale need to acquire gas. Gas fee financing is when illicit actors use DEXs or other services to obtain small amounts of a native cryptocurrency specifically to pay transaction fees and continue their laundering on a given chain (Elliptic 2025, p. 8). For example, if a fraudster primarily holds value in stablecoins, they might swap a bit of USDT for Ether on a DEX simply to stock up enough ETH to pay for subsequent transfers on Ethereum. Elliptic has observed terrorist organizations and other high-risk actors using this tactic: converting some of their funds into the “fuel” needed to traverse blockchains (Elliptic 2025, p. 9). Tracking these gas acquisitions can actually provide investigators clues, as linking addresses that consistently top up gas via DEX swaps may reveal a laundering operation. From the launderer’s perspective, however, gas fee financing is a necessary logistical step – the criminal’s equivalent of refueling the getaway car as they hop from one blockchain highway to the next.
  • Cross-Chain Scam Mechanisms (Rug Pulls & Investment Scams): Beyond pure laundering maneuvers, the report also describes how cross-chain techniques are baked into the scams themselves. In large-scale “pig butchering” investment scams, operatives often direct victims to send crypto to addresses on one chain (like Ethereum or Tron), then immediately route those victim funds through bridges and swaps to obscure where the money ultimately goes. Similarly, memecoin rug pull scams – where scam token creators hype a new coin, then disappear with the liquidity – rely on DEXs and cross-chain swaps to cash out. The scammers typically launch the coin on a popular chain (to lure in buyers), then once they rug pull the project, they’ll chain-hop the proceeds into Bitcoin or Monero, putting them beyond reach. Elliptic’s data shows a rise in these scam-as-a-service operations, with even tools available on the dark web to automate phishing and rug pulls across multiple chains (Elliptic 2025, p. 22). In essence, cross-chain interoperability has enabled “franchise fraud”: scammers can easily convert ill-gotten tokens into spendable crypto and spread their loot across wallets on different chains. This makes it harder for any single blockchain community or law enforcement agency to track the full scope. The typology of scam-based laundering often combines chain-hopping with other tricks (like mixing services or using coin swaps that cater to fraudsters), illustrating how these categories of crime overlap. For compliance officers, the takeaway is that not only are stolen funds being laundered cross-chain after the fact, but increasingly the crime schemes themselves integrate cross-chain moves from the very start.

In summary, crypto criminals have developed an array of cross-chain tactics: rapid chain-hops to lose pursuers, swapping to avoid traceable assets, fueling up on gas tokens, and exploiting DeFi protocols to enable scams and exits. These techniques are constantly evolving, forcing defenders to broaden their view beyond any single blockchain.

AML Compliance is Now a Multichain Exercise

Traditional Anti-Money Laundering (AML) programs in crypto focused on tracing funds on a single blockchain (for example, monitoring Bitcoin addresses or Ethereum wallets for blacklisted activity). That approach may no longer be sufficient to meet regulatory compliance requirements. As criminals disperse transactions across many networks, compliance teams must screen for risk exposure across multiple chains and assets simultaneously. A customer deposit that appears clean on Ethereum might have originated from tainted funds on another chain two hops ago. Without holistic cross-chain analytics, an exchange could easily onboard illicit funds unwittingly, exposing itself to liability. Regulators are starting to expect that exchanges and other Virtual Asset Service Providers (VASPs) invest in tools that can follow complex cross-chain money trails. Elliptic’s report emphasizes that given crypto’s growing integration with traditional finance, these risks affect both crypto-native companies and banks touching crypto assets. For compliance officers, the message is clear: you need a bird’s-eye view of a wallet’s activity across all chains, not just one. Practices like address risk scoring and Travel Rule compliance become trickier when funds teleport via decentralized bridges outside of any VASP oversight. Institutions that fail to adapt their AML monitoring may find themselves blindsided by cross-chain laundering occurring right under their noses.

Sanctions Exposure and Due Diligence

Cross-chain tactics also heighten the risk of sanctions violations. We’ve seen that North Korean hackers and other sanctioned actors heavily leverage DeFi and cross-chain services to evade detection. This means that an exchange or financial institution could unknowingly facilitate a transaction that, somewhere in its lineage, involves sanctioned addresses or entities – a big no-no for sanctions compliance. OFAC and other sanctions authorities have already sanctioned mixer services (like Tornado Cash and Blender) used by North Korea; one can imagine a future where certain cross-chain bridges or coin-swap services known to be conduits for DPRK funds come under similar scrutiny. Financial institutions must therefore up their due diligence on cross-chain flows. If a customer is receiving funds that have passed through an obscure cross-chain bridge or an instant swap service with dark web ties, that should raise questions. The challenge is that these services often don’t collect KYC information and are decentralized or anonymous, making it hard to ascertain counterparty details. Nonetheless, regulators will expect a risk-based approach – for instance, flagging deposits that originate from mixers, risky bridges, or known coin swap facilitators. Failure to do so could mean inadvertent dealings with sanctioned parties. From a legal standpoint, this is new terrain: can an exchange be held liable for sanctions breaches if it didn’t trace a multi-hop path that included a sanctioned address several steps back? It’s a gray area, but prudent compliance officers won’t want to test those waters. The Elliptic report underlines that sanctions evasion via crypto is one of the biggest cross-chain risks now, especially with North Korea’s activity (Elliptic 2025, p. 16). The implication is that compliance teams need to treat cross-chain transactions with the same level of scrutiny as funds coming directly from mixers or high-risk sources, because the end effect is similar.

The Role of Traditional Financial Institutions

As crypto laundering schemes grow more complex, even purely traditional banks and institutions could be impacted. Criminals ultimately often seek to cash out crypto into fiat, which may involve bank transfers, or use crypto to purchase goods and services in the real world. If those crypto funds have been laundered via intricate cross-chain paths, the bank handling the final cash-out might be several steps removed from the initial crime – yet still at risk. Banks that provide services to crypto companies (like offering bank accounts to exchanges or OTC desks) also face indirect exposure; regulators might ask what risk controls the bank has in place for funds that have swirled through DeFi protocols before hitting an exchange account. We’re likely to see more guidance and possibly enforcement around this. For example, regulators could require that banks and exchanges collaborate to share red flag indicators, such as deposit patterns indicative of chain-hopping. There is also discussion of extending travel rule compliance to certain DeFi transactions or at least expecting enhanced customer due diligence if a client’s funds come from self-custody wallets that have interacted with high-risk cross-chain services. In practice, financial institutions will need partnerships with blockchain analytics firms (such as Elliptic, Chainalysis, etc.) to get ahead of these risks. The legal liability for facilitating money laundering or sanctions evasion can be severe – even if the facilitation is unwitting. Therefore, cross-chain literacy is becoming a must not just for crypto exchanges, but for any financial entity touching crypto flows. From an international law perspective, banks might also need to consider multiple jurisdictions’ rules: a cross-chain transaction could trigger AML laws in each country that the respective blockchains or services are associated with. It’s a tangled web that requires a proactive, globally aware compliance strategy.

Enforcement Challenges

Law enforcement agencies face a steep learning curve as well. Traditionally, investigators could subpoena a single exchange or block explorer to follow the money. Now, with funds hopping through decentralized protocols, investigations require new tools and cross-border cooperation. Agencies will lean on blockchain analytics solutions that can automate the tracing of funds through cross-chain bridges and DEX swaps – capabilities that Elliptic touts as a new feature in this report (Elliptic 2025, p. 15). But technology is only part of the solution. Prosecutors will also grapple with legal questions: Who is responsible when a decentralized bridge is used to launder money? Can developers or liquidity providers be held accountable, or is it treated like an unowned “tool” that criminals abused? We got a preview of this debate when the U.S. sanctioned Tornado Cash (a mixer) and even arrested one of its developers – moves that raised questions about code neutrality and jurisdiction. With cross-chain bridges and DEXs, the same dilemma arises. From a compliance perspective, even if the protocols are decentralized, regulators may pressure any touchpoints that are within reach. This could include front-end interfaces, DNS domains, or developers/operators if they are identifiable. Internationally, we may see a patchwork of approaches: some jurisdictions might outlaw or regulate anonymizing services, while others take a hands-off approach, inadvertently providing havens. This disparity can fuel cross-chain crime further, as launderers gravitate towards tools hosted in lenient jurisdictions. It underscores the need for international legal coordination – something bodies like the FATF continuously call for. The bottom line is that cross-chain crime is testing the limits of current AML laws and forcing a rethink of how we define facilitators of money laundering in a decentralized era.

Regulatory Outlook and Global Responses

How should regulators and compliance professionals interpret these developments? The picture painted by Elliptic’s report is concerning, but it also offers clarity on where the industry needs to head:

  • Holistic Regulation of the Crypto Ecosystem: Regulators are increasingly realizing that focusing on individual exchanges or single-chain activity is insufficient. Guidance is shifting toward a more holistic view of crypto transactions. For instance, the FATF’s guidelines since 2019 have suggested that even decentralized exchange operators or platforms might qualify as VASPs (and thus have AML obligations) if they exercise control or sufficient influence. We can expect regulators to double down on this principle. DeFi protocols that facilitate cross-chain swaps could come under regulatory scrutiny, especially if they are run by identifiable teams or involve governance structures that authorities can engage with. The likely trajectory is incremental but steady expansion of the regulatory perimeter: first bringing centralized actors (like coin-swap service operators or any exchange supporting multiple chains) into compliance, then gradually finding ways to oversee or constrain truly decentralized mechanisms. In practical terms, we might see requirements for chain-agnostic transaction monitoring as a standard. Jurisdictions like the EU, through its upcoming MiCA and AML regulations, are already contemplating rules that would impact wallet providers and possibly certain DeFi activities. In the U.S., agencies like FinCEN have warned that if a business is actively providing mixing or swapping services, even without custody, it may still be deemed an MSB (Money Services Business) subject to registration and AML rules. The cross-chain crime boom will only accelerate these regulatory efforts. We should also watch for blacklists or sanctions that target specific cross-chain services – similar to Tornado Cash’s designation but perhaps extended to cross-chain bridge contracts if clear patterns of criminal use emerge.
  • Increased International Cooperation: By its very nature, cross-chain crime is borderless. A single laundering chain might involve a DeFi protocol hosted on a website in one country, tokens issued in another, and hackers in a third. No one regulator can tackle this alone. I anticipate greater information-sharing between countries’ financial intelligence units regarding crypto flows. We’re already seeing multinational task forces focusing on ransomware and North Korean hacking – these groups will undoubtedly prioritize cross-chain laundering typologies. On the legal side, extradition and mutual legal assistance treaties will be tested when perpetrators leverage jurisdictional arbitrage (e.g., operating a coin-swap service from a country with no crypto AML enforcement). There’s also an emerging question of international law around sanctioning open-source technology. If one country deems a protocol illegal and another defends it as lawful (or at least not explicitly regulated), this could create diplomatic friction. Nonetheless, the common ground is that nobody wants terrorists or state hackers to exploit crypto. So, we may see a push in bodies like the G7, G20, or United Nations to create norms for cracking down on high-risk cross-chain facilitators. FATF will likely update its crypto guidance to address cross-chain typologies more explicitly, providing a framework for member countries to follow.
  • Tools and Best Practices for Compliance Teams: Regulators will also be advising (and expecting) that compliance teams leverage advanced tools to keep pace. The Elliptic report ends with a guide on establishing effective multichain screening programs, highlighting new features like automated cross-chain tracing. From a practical standpoint, compliance officers should begin treating addresses and transactions in a chain-agnostic way: rather than monitoring blockchain silos separately, use software that can aggregate and correlate activity across many networks. Red-flag indicators provided by reports like Elliptic’s can be integrated into internal controls – for example, if a customer’s funds show signs of structured chain-hopping (many rapid swaps across chains), that should trigger an investigation or SAR (Suspicious Activity Report). Another best practice is to maintain blacklists of high-risk services: if your client’s funds come directly from a known coin swap service or a sanctioned mixer, you’d want to pause or block that transfer pending review. Training is key too. Compliance staff must be educated on these new typologies (e.g. recognizing gas fee top-ups, understanding how a bridge transaction appears on-chain, etc.). The regulatory expectation is moving toward proactive risk management in this area—those who claim ignorance of cross-chain risks may find little sympathy during examinations. On the flip side, forward-thinking compliance programs that effectively tackle cross-chain risks could become a competitive advantage, reassuring regulators and customers alike that an exchange or institution is safe to do business with.
  • Potential Legal Developments: We should also keep an eye on legal precedents. As cases make their way through courts involving cross-chain laundering, we’ll get more clarity on questions like the liability of DeFi devs or the legal status of automated protocols. If courts find, for example, that running a DAO which facilitates anonymous cross-chain swaps can make participants liable for AML violations, that will send shockwaves through the DeFi community. Alternatively, if enforcement actions hit a wall in trying to prosecute decentralized activity, regulators might pivot more to targeting endpoints (like charging individuals when they off-ramp illicit crypto into fiat, since that’s where identity is known). In any case, lawyers in the crypto space will be watching closely. The interplay between code, control, and culpability is being tested in real time. International law might also develop, with new treaties or cooperative frameworks specifically addressing digital asset seizures and investigations across jurisdictions. It’s not far-fetched to imagine a future where cross-chain travel rule standards emerge, or where exchanges are required to share information on suspect addresses globally in near-real-time to prevent criminals from simply bouncing to a different country’s platform.

Conclusion: The Road Ahead for Crypto Compliance

The scale of cross-chain illicit finance – $21.8 billion and climbing – shows that crypto’s bad actors have been as innovative as the industry’s legitimate builders. They are leveraging every tool at their disposal: decentralized exchanges, anonymous swapping services, and multi-chain bridges that connect the crypto economy in novel ways. For those of us in the legal and compliance realm, the task now is to turn that connectivity against the criminals. Just as they can hop chains to launder funds, we must connect the dots across those same chains to trace and block illicit activity.

The future of crypto compliance will undoubtedly be more complex, but also more comprehensive. I expect that by the next iteration of this report, we’ll see increasing adoption of holistic compliance solutions that monitor risk across dozens of blockchains at once. Regulators, for their part, are not sitting idle – they are learning quickly and will impose expectations that mirror the evolving threat. We’re likely headed toward a regime where “ignorance is no excuse” for not catching cross-chain dirty money. Crypto businesses and financial institutions will need to demonstrate that they are screening beyond the obvious and anticipating new typologies as they emerge.

On an optimistic note, the industry is rising to the challenge. Collaborative initiatives are forming to share intel on hacks and laundering patterns. Blockchain analytics technologies are improving, often powered by the same transparency that criminals believed they could exploit. There’s a sense that with the right combination of smart regulation, international cooperation, and cutting-edge compliance practices, the tide can be turned. Cross-chain crime may be growing, but so is our ability to detect it.

In the end, the cat-and-mouse dynamic between launderers and law enforcement will continue into this multi-chain era. But reports like Elliptic’s give us a valuable map of the battlefield. For the legally literate and tech-savvy audience, the takeaway is clear: crypto compliance is no longer just about monitoring a blockchain – it’s about overseeing an entire interconnected web of value. The coming years will test our agility in this regard. Those who adapt will help ensure that the benefits of crypto innovation can thrive, while those seeking to abuse the technology are met with robust and unified resistance. That, more than anything, is the direction crypto compliance is headed – toward a future where holistic oversight keeps pace with holistic crime.

Written by David Lopez Kurtz