Join our Newsletter — 33% off our NHI Course

What are the signs that crypto crime risk is getting worse even if overall illicit traffic looks low?

The clearest signs are rising dollar losses, repeated exploitation of the same control gaps, and a shift toward organized or state-backed actors that can sustain larger thefts. Another warning is when revised estimates keep climbing as incidents are later discovered. Low traffic percentages do not mean low risk if the stolen value is accelerating.

Why Low Illicit Traffic Can Still Hide Rising Crypto Crime Losses

Low-volume traffic can miss the part of crypto crime that matters most: the value extracted per incident. Criminals do not need broad, noisy activity if they can repeatedly target the same weak control, exploit a high-value workflow, or concentrate effort where one compromise produces outsized theft.

That is why practitioners should read traffic metrics alongside loss severity, discovery lag, and repeat failure patterns. A small share of illicit activity can still represent an increasing risk if it is producing larger thefts, more reliable monetisation, or more durable access paths.

What Pattern Shifts Usually Show the Risk Is Worsening

One sign is that losses rise faster than incident counts. That usually means the attacker playbook is becoming more efficient, the targets are more valuable, or both. Another sign is repeat exploitation of the same control gap, because repeated success shows the weakness is systemic rather than opportunistic.

A further warning is the move from scattered opportunistic abuse to more organised or state-backed activity. Those actors can sustain longer campaigns, invest in infrastructure, and absorb failed attempts, which often translates into larger and more consistent losses even when total traffic looks modest.

Revised estimates that keep climbing are also important. When later investigation uncovers missed incidents or reclassifies earlier activity, it often means visibility was incomplete, attribution was lagging, or the original estimate understated the scale of harm.

Why Traffic Percentages Alone Are a Poor Risk Signal

Traffic share is a volume metric, not a loss metric. It can understate risk when attackers focus on a narrow set of profitable paths, when the same compromise pattern is reused across venues, or when stolen value is concentrated in a few high-impact events. In crypto crime, a low percentage of illicit activity can still create a materially worse security picture if each event yields more value.

The practical test is whether the environment is seeing higher-value theft, faster monetisation, or broader repeatability of the same control failure. When those factors move in the wrong direction, the risk is worsening even if the overall illicit traffic line appears flat or low.

Risk and Threat Considerations

Low traffic can create false reassurance when attackers are selecting the most profitable targets rather than the busiest ones. The risk is not simply more malicious activity, but more efficient malicious activity that converts fewer attempts into larger losses and longer-lived abuse.

Failure mechanism: A control gap remains exploitable across multiple incidents, so the same weakness keeps producing high-value thefts while aggregate traffic stays deceptively small.

Impact: Losses accelerate, discovery arrives late, and defenders may misread the threat environment because volume signals look calmer than the underlying harm.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, CIS Controls v8 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
MITRE ATT&CK TA0006 — Credential Access Reused control gaps and repeat exploitation map to attacker access paths.
Recommendation — Map repeated theft paths to credential-access techniques and harden the exposed control gap.
NIST CSF 2.0 DE.CM-01 — Monitoring for anomalies and events Low traffic can hide worsening harm unless detection tracks value and repeat abuse.
Recommendation — Monitor loss severity and repeat abuse signals, not just traffic volume.
CIS Controls v8 CIS-5 — Account Management Repeated exploitation often reflects weak control over accounts or access paths.
Recommendation — Reduce standing access and tighten account controls around high-value crypto workflows.
OWASP Non-Human Identity Top 10 NHI-05 — Overprivileged NHI High-value crypto theft often succeeds through excessive machine or service privilege.
Recommendation — Remove excess privilege from non-human access used in signing, transfer, or custody flows.
NIST SP 800-53 Rev 5 AU-6 — Audit Review, Analysis, and Reporting Rising revised estimates require review of logs and incident records to uncover missed harm.
Recommendation — Correlate audit data with post-incident discovery to update loss estimates quickly.

Practitioner Guidance

What to prioritise: Track dollar losses, repeat exploit paths, and time-to-discovery before relying on traffic-share trends. If losses and re-exploitation are rising, treat the issue as a worsening threat even when overall illicit traffic is stable or down.

What to verify: Separate “how much malicious activity exists” from “how much value it extracts.” The second measure is the better indicator of whether controls are failing in a way that matters operationally.

Practitioner takeaway: In crypto crime, low traffic is only reassuring when the value per incident is also stable or falling; if theft size, repeatability, or revised estimates are increasing, the risk is getting worse.