Crypto offers speed, global reach, and relatively low-friction transfer of value across borders. That makes it attractive for ransomware, sanctions evasion, laundering, fraud, and theft, especially when actors try to obscure trails through mixers, bridges, and exchanges. Agencies need to understand these incentives because the same properties that help legitimate users also help threat actors move and hide funds.
Why illicit actors prefer crypto rails
Criminals and state-backed groups are not choosing cryptocurrencies because they are inherently anonymous. They choose them because crypto can move value quickly across jurisdictions, often outside the friction of correspondent banking, chargebacks, and conventional account controls. That combination makes it useful for extortion, sanctions evasion, laundering, fraud, and theft, especially when actors layer mixers, bridges, and exchange hopping.
The practical attraction is not just speed. Crypto also gives malicious actors a payment rail that can be automated, split into many transactions, and routed through services with uneven compliance. That makes it easier to collect ransom, cash out stolen assets, finance operations, and test which counterparties, exchanges, or jurisdictions are least resistant to abuse.
State-linked actors value the same properties for a different reason: they support covert funding, rapid cross-border movement, and operational separation between origin and destination. When attribution, seizure, or sanctions enforcement becomes harder, the payment mechanism itself becomes part of the tradecraft.
How criminals use crypto across the attack lifecycle
Crypto is often the monetisation layer at the end of a compromise, but it can also shape the attack path. Ransomware crews demand payment in crypto because it scales across geographies and can be collected quickly from victims under pressure. Fraudsters use it to move proceeds before banks, exchanges, or victims can reverse or freeze activity. Launderers use chains of wallets, peel chains, swaps, and exchanges to fragment provenance and raise investigation cost.
On the state-backed side, crypto can support covert procurement, sanctions evasion, and the financing of operational infrastructure. The goal is usually not perfect anonymity. It is to increase the number of hops, jurisdictions, and service providers a defender must investigate before funds can be traced, interdicted, or recovered.
That is why services that appear operationally simple, like exchanges, bridges, hosted wallets, or custodial platforms, matter so much to defenders. They are often the control points where identity checks, transaction monitoring, and freeze capability can still interrupt abuse even when the blockchain itself is hard to change.
What defenders should focus on first
The key question is not whether crypto is being used, but what part of the abuse chain it supports. In some cases it is the extortion payment itself. In others it is the funding source, laundering step, or cash-out mechanism. That distinction affects whether the right response is sanctions screening, wallet tracing, exchange engagement, asset freezing, or broader incident containment.
For practitioners, the highest-value signal is usually the intersection of financial movement and known malicious infrastructure. Transfers to or from high-risk wallets, rapid exchange hopping, use of mixing services, and conversions between assets all increase the likelihood that the activity is designed to obscure provenance. Those patterns matter even when the initial compromise is not financial in nature.
A useful operational rule is to treat crypto activity as an enrichment layer, not a standalone verdict. The same transaction pattern can support legitimate treasury activity or criminal monetisation, so defenders need to combine wallet intelligence, account behaviour, and incident context before escalating.
Risk and Threat Considerations
Crypto introduces a durable exposure because it lets adversaries move value without depending on a single bank, geography, or payment processor. That makes the abuse path resilient, especially when actors can chain together wallets, mixers, bridges, and exchanges to delay tracing and recovery.
Failure mechanism: Defenders lose visibility when transactions are split, swapped, or routed through services with weak compliance, and the longer the delay, the harder it becomes to freeze assets or link them to the originating compromise.
Impact: Victims face faster monetisation of the attack, lower recovery odds, and a broader downstream risk surface that can include repeat extortion, sanctions violations, fraud losses, and intelligence blind spots.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK addresses the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| MITRE ATT&CK | T1657 — Financial Theft | Cryptocurrency abuse often monetizes intrusions and fraud through financial theft. |
| T1020 — Data Exfiltration | Crypto can fund and facilitate monetization after exfiltration or extortion. | |
| Recommendation — Map cash-out activity to financial theft techniques and correlate it with compromise indicators. Trace exfiltration-to-monetization chains and watch for post-breach cash-out behavior. | ||
| NIST CSF 2.0 | GV.RM-01 — Risk Management Strategy | Crypto-enabled illicit finance is a cross-cutting risk that needs explicit treatment in strategy. |
| DE.CM-01 — Personnel Activity and Technology Assets Are Monitored | Monitoring is needed to detect suspicious payment activity and related compromise signals. | |
| Recommendation — Include illicit-finance exposure in risk strategy and define escalation thresholds for suspicious wallet activity. Monitor wallet, exchange, and incident telemetry for suspicious transaction patterns. | ||
| NIST SP 800-53 Rev 5 | AU-6 — Audit Record Review, Analysis, and Reporting | Investigating crypto abuse depends on reviewing logs and transactional evidence. |
| IR-4 — Incident Handling | Crypto use in ransomware and fraud is part of incident containment and response. | |
| IA-5 — Authenticator Management | Exchanges and wallets depend on credentialed access that attackers often abuse. | |
| Recommendation — Review transaction and account logs for anomalous transfers, hops, and cash-out attempts. Incorporate wallet tracing, exchange engagement, and preservation steps into incident handling. Protect and rotate credentials for wallets, exchanges, and payment platforms. | ||
| CIS Controls v8 | CIS-8 — Audit Log Management | Logs and transaction records are central to tracing illicit crypto movement. |
| CIS-17 — Incident Response Management | Crypto abuse needs defined response actions across tracing, freezing, and recovery. | |
| Recommendation — Centralize and retain logs that support tracing wallet, exchange, and conversion activity. Add crypto tracing and preservation steps to the incident response playbook. | ||
Practitioner Guidance
What to prioritise: Start with the cash-out path, not just the on-chain movement. If a wallet touches an exchange, hosted service, bridge, or mixer, that is often the best place to seek preservation, tracing support, or account action.
What to verify: Confirm whether the crypto flow is tied to a known compromise, a ransom demand, sanctions exposure, or a laundering pattern before you escalate it as malicious. On-chain movement alone is not enough; context is what makes the case operationally useful.
Practitioner takeaway: Crypto is attractive to criminals because it compresses speed, reach, and concealment into one payment layer, so effective defence depends on pairing blockchain intelligence with strong incident context and rapid action at the points where funds can still be interrupted.
Related resources from NHI Mgmt Group
- How should exchanges detect illicit crypto flows when criminals spread activity across many addresses?
- How should intelligence and security teams use blockchain evidence when assessing state-linked crypto activity in a conflict zone?
- What happens when criminals use casinos, real estate, or shell companies to integrate illicit funds?
- Why do unpatched vulnerabilities in hospitals and contractors create outsized risk for state-backed threat actors?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 26, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org