Join our Newsletter — 33% off our NHI Course
Home› FAQ› Cyber Security› Why do criminals and state-backed actors use cryptocurrencies…
Cyber Security

Why do criminals and state-backed actors use cryptocurrencies for illicit activity?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 26, 2026 Domain: Cyber Security

Crypto offers speed, global reach, and relatively low-friction transfer of value across borders. That makes it attractive for ransomware, sanctions evasion, laundering, fraud, and theft, especially when actors try to obscure trails through mixers, bridges, and exchanges. Agencies need to understand these incentives because the same properties that help legitimate users also help threat actors move and hide funds.

Why illicit actors prefer crypto rails

Criminals and state-backed groups are not choosing cryptocurrencies because they are inherently anonymous. They choose them because crypto can move value quickly across jurisdictions, often outside the friction of correspondent banking, chargebacks, and conventional account controls. That combination makes it useful for extortion, sanctions evasion, laundering, fraud, and theft, especially when actors layer mixers, bridges, and exchange hopping.

The practical attraction is not just speed. Crypto also gives malicious actors a payment rail that can be automated, split into many transactions, and routed through services with uneven compliance. That makes it easier to collect ransom, cash out stolen assets, finance operations, and test which counterparties, exchanges, or jurisdictions are least resistant to abuse.

State-linked actors value the same properties for a different reason: they support covert funding, rapid cross-border movement, and operational separation between origin and destination. When attribution, seizure, or sanctions enforcement becomes harder, the payment mechanism itself becomes part of the tradecraft.

How criminals use crypto across the attack lifecycle

Crypto is often the monetisation layer at the end of a compromise, but it can also shape the attack path. Ransomware crews demand payment in crypto because it scales across geographies and can be collected quickly from victims under pressure. Fraudsters use it to move proceeds before banks, exchanges, or victims can reverse or freeze activity. Launderers use chains of wallets, peel chains, swaps, and exchanges to fragment provenance and raise investigation cost.

On the state-backed side, crypto can support covert procurement, sanctions evasion, and the financing of operational infrastructure. The goal is usually not perfect anonymity. It is to increase the number of hops, jurisdictions, and service providers a defender must investigate before funds can be traced, interdicted, or recovered.

That is why services that appear operationally simple, like exchanges, bridges, hosted wallets, or custodial platforms, matter so much to defenders. They are often the control points where identity checks, transaction monitoring, and freeze capability can still interrupt abuse even when the blockchain itself is hard to change.

What defenders should focus on first

The key question is not whether crypto is being used, but what part of the abuse chain it supports. In some cases it is the extortion payment itself. In others it is the funding source, laundering step, or cash-out mechanism. That distinction affects whether the right response is sanctions screening, wallet tracing, exchange engagement, asset freezing, or broader incident containment.

For practitioners, the highest-value signal is usually the intersection of financial movement and known malicious infrastructure. Transfers to or from high-risk wallets, rapid exchange hopping, use of mixing services, and conversions between assets all increase the likelihood that the activity is designed to obscure provenance. Those patterns matter even when the initial compromise is not financial in nature.

A useful operational rule is to treat crypto activity as an enrichment layer, not a standalone verdict. The same transaction pattern can support legitimate treasury activity or criminal monetisation, so defenders need to combine wallet intelligence, account behaviour, and incident context before escalating.

Risk and Threat Considerations

Crypto introduces a durable exposure because it lets adversaries move value without depending on a single bank, geography, or payment processor. That makes the abuse path resilient, especially when actors can chain together wallets, mixers, bridges, and exchanges to delay tracing and recovery.

Failure mechanism: Defenders lose visibility when transactions are split, swapped, or routed through services with weak compliance, and the longer the delay, the harder it becomes to freeze assets or link them to the originating compromise.

Impact: Victims face faster monetisation of the attack, lower recovery odds, and a broader downstream risk surface that can include repeat extortion, sanctions violations, fraud losses, and intelligence blind spots.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK addresses the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
MITRE ATT&CKT1657 — Financial TheftCryptocurrency abuse often monetizes intrusions and fraud through financial theft.
T1020 — Data ExfiltrationCrypto can fund and facilitate monetization after exfiltration or extortion.
Recommendation — Map cash-out activity to financial theft techniques and correlate it with compromise indicators. Trace exfiltration-to-monetization chains and watch for post-breach cash-out behavior.
NIST CSF 2.0GV.RM-01 — Risk Management StrategyCrypto-enabled illicit finance is a cross-cutting risk that needs explicit treatment in strategy.
DE.CM-01 — Personnel Activity and Technology Assets Are MonitoredMonitoring is needed to detect suspicious payment activity and related compromise signals.
Recommendation — Include illicit-finance exposure in risk strategy and define escalation thresholds for suspicious wallet activity. Monitor wallet, exchange, and incident telemetry for suspicious transaction patterns.
NIST SP 800-53 Rev 5AU-6 — Audit Record Review, Analysis, and ReportingInvestigating crypto abuse depends on reviewing logs and transactional evidence.
IR-4 — Incident HandlingCrypto use in ransomware and fraud is part of incident containment and response.
IA-5 — Authenticator ManagementExchanges and wallets depend on credentialed access that attackers often abuse.
Recommendation — Review transaction and account logs for anomalous transfers, hops, and cash-out attempts. Incorporate wallet tracing, exchange engagement, and preservation steps into incident handling. Protect and rotate credentials for wallets, exchanges, and payment platforms.
CIS Controls v8CIS-8 — Audit Log ManagementLogs and transaction records are central to tracing illicit crypto movement.
CIS-17 — Incident Response ManagementCrypto abuse needs defined response actions across tracing, freezing, and recovery.
Recommendation — Centralize and retain logs that support tracing wallet, exchange, and conversion activity. Add crypto tracing and preservation steps to the incident response playbook.

Practitioner Guidance

What to prioritise: Start with the cash-out path, not just the on-chain movement. If a wallet touches an exchange, hosted service, bridge, or mixer, that is often the best place to seek preservation, tracing support, or account action.

What to verify: Confirm whether the crypto flow is tied to a known compromise, a ransom demand, sanctions exposure, or a laundering pattern before you escalate it as malicious. On-chain movement alone is not enough; context is what makes the case operationally useful.

Practitioner takeaway: Crypto is attractive to criminals because it compresses speed, reach, and concealment into one payment layer, so effective defence depends on pairing blockchain intelligence with strong incident context and rapid action at the points where funds can still be interrupted.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 26, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org