Asset seizure is temporary government control over property suspected to be linked to crime, usually to prevent movement while a case proceeds. Asset forfeiture is the later legal step in which ownership transfers to the government after a court decides the assets are connected to criminal activity. In practice, seizure secures the asset, while forfeiture finalizes disposition.
Why This Matters for Security Teams
Crypto investigations often move quickly because digital assets can be transferred, mixed, bridged, or converted in minutes. That makes the distinction between seizure and forfeiture operationally important, not just legal. Seizure is about control during an investigation; forfeiture is about title after due process. Teams that confuse the two can mishandle custody, disclosure, or evidence preservation, especially when keys, wallets, exchanges, and custodians are involved. The control problem is familiar to NHI security teams too: NHI Mgmt Group notes that only 5.7% of organisations have full visibility into their service accounts, which is why Ultimate Guide to NHIs — What are Non-Human Identities is often used as a baseline for understanding asset control, rotation, and revocation. For investigators, the legal status of the asset determines what can be done next, who must be notified, and what standards of proof still apply. The same discipline that underpins NIST Cybersecurity Framework 2.0 also applies here: identify, protect, detect, respond, and recover in a way that preserves chain of custody. In practice, many teams discover the difference only after a wallet has already moved or a custodian has already acted.
How It Works in Practice
In a crypto case, seizure usually happens first. Authorities obtain legal authority to take temporary possession or restrict movement of tokens, keys, hardware wallets, exchange accounts, or related records. The purpose is to stop dissipation, preserve evidence, and maintain leverage while the investigation and litigation continue. Forensic handling matters here because the asset may still need to be traced, valued, or linked to specific transactions.
Forfeiture comes later, after a court or other lawful process decides the asset is tied to criminal activity and the government may retain ownership. At that point, the asset is no longer merely held pending a case; it is transferred as a final legal disposition. In practice, this means the process changes from securing access to proving nexus, documenting notice, and meeting procedural requirements.
- Seizure answers: can the asset be controlled now?
- Forfeiture answers: can the asset be permanently taken after adjudication?
- Seizure depends on probable cause or equivalent legal grounds, while forfeiture requires a stronger final legal finding.
- Custody procedures should preserve wallet data, transaction history, and key material without contaminating evidence.
This is especially important in crypto because control may depend on private keys, custodial accounts, multisig approvals, or smart contract permissions rather than a single physical object. The same identity and access issues show up in NHI environments, where long-lived secrets and poor offboarding create lingering exposure. The operational lesson aligns with the broader warning in Ultimate Guide to NHIs — What are Non-Human Identities: if control is not explicit, revocation is delayed and loss spreads. These controls tend to break down when assets are held across multiple jurisdictions because ownership, custody, and enforcement authority do not line up cleanly.
Common Variations and Edge Cases
Tighter legal control often increases operational friction, requiring investigators to balance speed against evidentiary integrity. Not every case follows the same sequence, and there is no universal standard for this yet across all jurisdictions or asset types.
Some cases involve administrative seizure before a criminal conviction, while others use civil forfeiture procedures that do not require the same criminal finding. Exchange-held assets may be easier to freeze than self-custodied wallets, but freezing is not the same as forfeiture. Stablecoins, privacy coins, cross-chain bridges, and DeFi positions can complicate valuation and custody even after seizure. If assets are mixed or partially converted, tracing may continue long after control is established.
Practitioners should also distinguish between temporary restraint, preservation orders, seizure, and forfeiture. Those terms are not interchangeable, and the wrong label can create procedural errors or overstate what the government can legally do. In practice, teams often see this confusion surface when a custodian or platform responds to a preservation request as if it were a final transfer of ownership.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST AI RMF and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AA-1 | Identity and access decisions affect seizure, custody, and transfer control. |
| OWASP Non-Human Identity Top 10 | NHI-05 | Wallets, keys, and custodial APIs behave like NHIs in evidence handling. |
| NIST AI RMF | Investigation decisions need governance, accountability, and traceable controls. | |
| NIST Zero Trust (SP 800-207) | AC-2 | Restraining asset movement requires continuous authorization and least privilege. |
Map crypto asset custody workflows to identity-proofing and access governance before restraint or transfer.
Related resources from NHI Mgmt Group
- What is the difference between privilege reduction and secret rotation?
- What is the difference between a rules-based secret scanner and a hybrid scanner?
- What is the difference between code scanning and runtime identity monitoring?
- What is the difference between zero trust for users and zero trust for NHIs?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 1, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org