The Crypto-Anarchist’s Cookbook: The Block’s analysis of a confidential Elliptic AML report

Quick Take

  • According to a report drafted by blockchain intelligence firm Elliptic, hackers and other cybercriminals rely heavily on cryptocurrency laundering at every stage of their operations, targeting both unlicensed and licensed exchanges

  • The Block has identified three major laundering trends threatening the crypto ecosystem

Advertisement

Timothy Lloyd is a contributing writer for The Block. His work has also been featured in Thomson Reuters Regulatory Intelligence, the Organized Crime and Corruption Reporting Project, InSight Crime and the Wall Street Journal. He is based out of Austin, and he once played the Wu-Tang Clan's RZA to a draw in Chess.


A confidential crypto money-laundering report authored by blockchain-intelligence firm Elliptic exclusively for its network of compliance contacts, and only obtained by The Block, reveals the latest trends in decentralized threat finance.

The report, titled “Money Laundering & Terrorist Financing Typologies in Cryptocurrencies”, was released to a limited audience of compliance, law enforcement and financial intelligence professionals last May. This 84-page document was co-authored by Elliptic’s chief data officer and co-founder, Dr. Tom Robinson, and the firm’s head of community, David Carlisle.

Written to “assist cryptocurrency businesses in identifying specific money laundering and terrorist financing risks they may face,” the compliance guide consists of three sections. The first part details crypto-laundering trends, the second deals with terrorism-financing schemes enabled by digital assets and the third explains specific crypto-rinsing typologies unique to nine different classes of “threat actors.”   

Adversary categories defined by Elliptic include hackers, dark-web vendors, fraudsters, professional money launderers, street-level drug dealers, human/sex-traffickers, tax evaders, state actors and terrorists/political extremists.

Primary Findings 

Not surprisingly, Elliptic found that hackers and other cybercriminals were the “illicit actors most like to operate comfortably in the cryptocurrency domain and who rely most heavily on cryptocurrency laundering at every stage of their operations.” 

These adversaries are generally going to be more adept at using privacy coins like Dash, Monero and Zcash, which conceal the origins of illicit digital assets. The process of converting standard crypto assets to privacy coins as a means of eluding detection is known as “chain hopping,” according to Elliptic. 

Cybercriminals will generally also be more capable when it comes to “chain peeling,” a laundering technique that entails the repeated transfer of small sums of unspent crypto to newly generated addresses. In theory, this precaution can help criminals obscure the connection to the user’s original address, but Elliptic said their software can still detect it.

Also, not unexpected was Elliptic’s finding that cryptocurrency exchanges, because they are major hubs of liquidity in digital-asset markets, “inevitably feature heavily” in crypto laundering. Elliptic cited internal research published in 2018, which showed that between 2013 and 2016, exchanges accounted for 55 percent of all bitcoin-related laundering from “identifiable illicit sources.” 

Obviously, unlicensed and non-compliant exchanges, particularly those that lack viable Know Your Customer (KYC) controls, present the most significant anti-money-laundering (AML) risk. 

Monitoring chatter on the Dread forum, a Reddit-like message board for the dark-web community, Bisq appears to be the preferred crypto exchange for users looking to avoid standard KYC checks. 

Bisq has branded itself as the “decentralized bitcoin exchange,” a type of trading platform that is “non-custodial in nature,” according to Elliptic. Although Elliptic makes no mention of Bisq, if the platform is truly a decentralized exchange, or “DEX,” as it claims, Bisq then offers criminal operators and users one key advantage: the lack of a central administrator with active oversight of user accounts, records, identities, or transactions. 

Overall, these platforms are still relatively illiquid. But, “in many jurisdictions, it is still unclear whether DEXs fall within the scope of AML/CFT regulation. DEXs therefore provide a useful mechanism for the laundering of criminal proceeds – and particularly for undertaking cryptocurrency-to-cryptocurrency swaps – while avoiding exposure to regulators or law enforcement,” writes Elliptic.  

Just like blue-chip Wall Street banks, however, Elliptic found that even legitimate and “well-intentioned” crypto exchanges may be targeted by financial criminals. After combing through the document, The Block has identified three unique and emerging laundering trends that pose the gravest threat to the mainstream crypto ecosystem. These trends include the rise of KYC kits, the deployment of diffuse money-mule networks and the emergence of a new, elite subset of “professional” crypto-launderers.

KYC Kits 

A key driver of the digital identity-fraud crisis that is siphoning increasing billions of dollars from the global banking industry every year, KYC kits are packets of all the personally identifiable information (PII) about a victim that are required to clear AML-customer-onboarding screens and open bank and exchange accounts in their name. 

KYC kits are thus enabling the proliferation of a type of ID-theft scam called “new account fraud,” where threat actors open bank accounts in the names of their victims. While these fake accounts have traditionally been used by criminals to secure large lines of credit that they will never pay back to banks, they can also help establish untraceable shells through which to mule dirty money and cash out undetected. 

According to data from financial intelligence firm, Javelin Strategy & Research, NAF-related losses grew from $3 billion in 2017 to $3.4 billion last year - a 13.3-percent jump. Thus, the rise of KYC kits is troubling because “Elliptic’s investigations have revealed an increasing number of criminals who are willing to use legitimate, compliant exchanges to launder funds because they are able to employ KYC kits,” according to the report. 

If the threat actor practices particularly good operational security (OpSec), KYC kits can greatly enhance layering and obfuscation at the most crucial link of the laundering chain, and the one which has traditionally been crypto-adversaries’ Achilles heel: the cash-out. 

For example, in recent DNM law-enforcement probes, investigators were able to identify and make substantive charges stick against suspects because the flow of tainted funds inevitably converged in crypto-exchange wallets and bank accounts opened in criminals’ real names. Examples of this include the case of Alphabay Fentanyl vendor Jeremy Achey, AKA EtiKing, and Silk Road dealer Hugh Haney, AKA Pharmville.

However, when suspicious crypto-address clusters of related wallets - which are precisely what Elliptic’s blockchain forensics software is designed to detect - lead to fictitious exchange and bank accounts, investigations become significantly more complex. Layering NAF schemes over crypto-laundering typologies thus represents a hybrid tradecraft that forces bank-compliance officers and law enforcement to allocate more time, manpower and resources to manually uncover the true identity of the account owner.

Further compounding complexities in today’s crypto-AML probes, are when criminal groups cross-pollinate KYC-kit schemes with widely dispersed money-mule networks, whose operatives may themselves open bank accounts using stolen identities.

Money-Mule Networks

Contrary to money-laundering motifs portrayed in asinine Hollywood action-thrillers like “The Accountant”, cleaning dirty cash effectively, be it fiat or crypto, is much more than a one-man job. Thus, the most successful laundromats rely on distributed networks of money mules bouncing funds through seemingly unrelated funnel accounts, until they reach their final destination in the clutches of a crime syndicate’s immediate custody.

Elliptic defines money mules as “individuals (often students, migrants, or other vulnerable individuals) who are co-opted to open accounts and transfer funds on behalf of a criminal network.” Researchers found that mules are generally students with no “awareness that they were engaged in criminal activity.”

Typically recruited on social-media platforms via job advertisements that offer prospective hires a fee for opening accounts at crypto exchanges or transferring Bitcoin via ATMs, cash-starved students all over the world have been easily duped by criminal organizations that pose “under the guise of IT consulting firms or similar businesses,” writes Elliptic.

But Elliptic said that these mule networks can also be a “group of individuals, often of common nationality and similar residential addresses,” who “establish accounts at a cryptocurrency exchange, generally within a short period of time of one another.” Elliptic cautions exchanges to be on alert for large numbers of accounts being opened by groups of foreign nationals “who have no clear link to the country where the exchange operates.”

Mules can operate exchange funnel accounts on their own, under the direction of laundering masterminds, or they can surrender pre-opened accounts to the conspirators. A prime example of the latter typology is the Operation ARGENTI case, where ransomware operators used mules to open accounts at crypto exchanges across Europe and at banks in Spain. Elliptic writes that “some of the mules were from the Baltic countries and were used simply to open accounts, which were handed over to the criminals to use.”   

But just as they target exchanges, criminal organizations can also enlist mules to “funnel illicit funds through cryptocurrency ATM networks,” writes Elliptic. According to a 2017 Europol report, “money mules are increasingly making use of Bitcoin ATMs to launder illegally obtained money. Whereas previously banking transfers or remittance services such as Western Union or MoneyGram where used, criminals now instruct their mules to withdraw money from compromised bank accounts and to use it to buy bitcoins,” via an ATM.

Just like rogue exchanges, Elliptic’s Carlisle told The Block that “the risks of ATM laundering are greatly enhanced when they aren't regulated.” Crypto ATMs are regulated in the U.S. But, under current laws, remain unregulated in Europe. That will change, however, when a new AML regime, called the Fifth Anti-Money-Laundering Directive (5AMLD) goes into effect in the European Union on Jan. 10, 2020. 

Beyond bitcoin ATMs, Elliptic also found that criminals may employ mules to open multiple accounts connected to numerous prepaid cards, adding another layer of complexity. It follows that the growing delegation of criminality to subordinates, the diversification of risk across multiple counterparties and, more broadly, the coordination of illicit-financial networks, all speak to the emergence of a professional class of cryptocurrency launderer.

Professional Crypto Launderers

According to Elliptic, “a growing body of evidence suggests that professional money laundering networks have made more frequent use of cryptocurrencies, and that criminal actors such as cybercriminals and dark web vendors now look to professional money launderers to move illicit origin cryptocurrencies on their behalf.”

In a 2018 report, the global bank watchdog Financial Action Task Force (FATF) said that professional money launderers (PMLs) are “rarely involved in the proceeds-generating illegal activities. Instead, they provide expertise to disguise the nature, source, location, ownership, control, origin and/or destination of funds to avoid detection.” 

The Elliptic report highlights one crypto-PML case study involving a Russian police investigation into a dark-web drug-trafficking ring, which was first cited by the FATF. The ring operated an illegal drug website hosted on the TOR browser and allowed customers to pay for dope in both fiat and bitcoin. But according to the FATF, “the financial scheme for the drug stores was arranged and managed by a financier and his network.” 

“Numerous e-wallets and debit cards were registered in the names of front men. This usually involved students who issued e-wallets and credit cards, and then sold them to members of the ML network,” writes the FATF. Fiat funds from these e-wallets were then converted into bitcoins via cryptocurrency exchanges and used to pay salaries to members of the drug trafficking organization. The same PML organization worked with numerous dark-web drug trafficking rings, according to the FATF.

But more sophisticated still is the use of shell companies in offshore secrecy havens and corporate “strawmen,” both of which help conceal the true identities of laundromat operators even further. This tradecraft was central to the multi-billion-dollar, BTC-e laundering caper.

A recent report about the BTC-e scandal, published by transparency watchdog Global Witness last weekend, explores how rogue crypto-exchange operators exploited the offshore system. In a press release accompanying the Global Witness report, the author of the expose, Louis Goddard, said “there is no doubt that through a secretive offshore network this is a case that goes far beyond one individual. It is yet another example of how the use of anonymous companies is central to allegations of criminality.”   

 Furthermore, the use of offshore companies and nominee directors in Panama, a known high-risk jurisdiction, has also taken center stage in the developing Crypto Capital scandal. Specifically, the extradition of Ivan Manuel Molina Lee, the president of Panama-based, crypto-payment processor Crypto Capital, to Poland last month reveals how Latin American drug trafficking groups may be exploiting virtual currencies at scale. 

Molina Lee, a Canadian citizen with residency in Panama, stands accused by Polish authorities of laundering at least $390 million for an unnamed Colombian drug cartel. This dollar-amount cited by Polish police refers to assets seized from Bank Spółdzielczy accounts linked to Crypto Capital and its former exchange client, Bitfinex, in April 2018, according to Polish media reports.  

Bitfinex’s general counsel, Stuart Hoegner, responded to The Block’s request for comment on cartel-laundering allegations and said, “any suggestion that Crypto Capital laundered proceeds of crime at Bitfinex's or its customers' behest is false.” Neither the Polish National Prosecutor’s office, nor the Drug Enforcement Administration nor the Federal Bureau of Investigation responded to The Block’s request for comment.

Closing Thoughts 

Also cited by the Elliptic report was the increasing adoption of cryptocurrencies by terrorism financiers (TF), who have typically sought funding via online donations and crowdfunding campaigns. However, the amounts involved in TF schemes identified by Elliptic were relatively insignificant.

Another emerging trend identified by Elliptic was the growing use of crypto in tax-evasion schemes. The report said that cryptocurrencies “can offer attractive vessel for tax evaders seeking to conceal their wealth. Cryptocurrencies offer the prospect of storing and transferring value cross border, outside of the formal banking system and beyond the ready purview of regulators.”

Last week, the Internal Revenue Service’s Criminal Investigation unit announced that it had identified dozens of potential crypto-tax evaders, based on the findings of a joint-intelligence-sharing initiative with tax officials from the U.K., Australia, Canada and the Netherlands.

Ultimately, financial-crime experts like Robert Mazur, a former Customs and DEA agent who infiltrated both the Medellin and Cali cartels as a money launderer, think crypto’s inherent volatility makes it unsuitable for laundering conspiracies of scale.

“Imagine being a launderer who operates on a 10-percent commission and converts a cartel leader’s $5 million to bitcoin in the midst a sharp value decrease,” writes Mazur in a recent KYC360 article.  “Your drug dealing client is expecting something worth 90 percent of the cash he gave you. A 20-percent value decrease puts the launderer in a position to have to give up an additional 10 percent to stay alive. He has a choice, take a $500,000 loss or die.”

Today, criminal organizations’ “principal interests lie in more traditional and predictable value transfer systems,” said Mazur. 


© 2026 The Block. All Rights Reserved. This article is provided for informational purposes only. It is not offered or intended to be used as legal, tax, investment, financial, or other advice.