The DOJ’s Latest Crypto Seizure Shows That Address Tracing Is Only One Layer of an Enforcement Operation

Written by Helena Markou

The U.S. Department of Justice announced on September 1 that court-authorized actions allowed the FBI to seize $560,000 in cryptocurrency and take control of domains and servers it says were used by Hamas to raise funds and recruit supporters. The official release describes an operation that did more than identify blockchain addresses. It paired asset seizure with the disruption of the web and communications infrastructure that connected donors to those addresses.

According to the Justice Department, a group chat claiming association with Hamas directed supporters to a fundraising website and supplied a rotating set of cryptocurrency donation addresses. Investigators then used information from multiple human sources to identify, trace and seize donations that the government alleges were intended for the Al Qassam Brigades. The department notes that three unsealed seizure warrants were issued on March 25, June 25 and October 10 of 2025. These are the government’s allegations and procedural account; the announcement is not a general proof that every address associated with a public cause is controlled by the actor named in a case.

The use of rotating addresses is a reminder that a blockchain address is not an identity. Rotating identifiers can complicate basic screening because a compliance team that blocks one known address may not automatically catch the next. But rotation does not eliminate evidence trails. Transactions, service-provider records, server logs, human reporting and operational mistakes can be combined to build an attribution case. The key word is combined. Public ledger data can reveal flows, yet a legal seizure requires the relevant court process and sufficient evidence under applicable law.

The infrastructure component may be the most durable lesson. The DOJ says the FBI’s control of domains and servers enabled it to intercept donations intended for the targeted organization. A fundraising operation typically has dependencies beyond a wallet: a website, hosting, messaging distribution, social channels, payment instructions, custodial touch points or conversion services. Taking down those links can reduce fundraising capacity even when an operator can create a new address. It can also yield evidence about who attempted to donate and how a network was being managed.

That does not mean infrastructure seizures are simple or costless. Authorities must establish jurisdiction and legal authority, and service providers must respond to valid orders in a timely way. Donors and innocent users may interact with a compromised service without understanding the full context. There are also privacy and due-process questions around data obtained from servers and communications platforms. A strong enforcement model needs transparent legal safeguards as well as sophisticated tracing tools.

For virtual-asset service providers, the case favors a layered risk model. Address screening remains useful, but it is insufficient alone. Behavioral indicators, rapid address rotation, repeated links to a common fundraising interface, connections to sanctioned entities and suspicious off-chain operational patterns can all matter. The implementation must be calibrated: automated flags can reduce risk, but they can also produce false positives and restrict lawful activity if not reviewed by trained investigators.

The September 1 announcement should not be read as a claim that crypto uniquely enables illicit finance, nor as proof that tracing automatically neutralizes it. Its narrower lesson is more practical. Digital-asset investigations increasingly bridge on-chain flows and off-chain systems. The measurable outcome here was $560,000 seized, but the strategic objective was disruption: make the fundraising path harder to find, harder to trust and harder to operate. That combination, rather than a wallet-address blacklist in isolation, is what gives an enforcement action lasting effect.

DeFi
Helena Markou

Helena Markou

Markets and policy reporter covering institutional crypto strategy, exchange-traded products, and the slow-motion merger of TradFi and digital assets. Before joining CryptoSibyl News, Helena spent four years covering European fintech regulation and cross-border capital flows for a Geneva-based financial wire. Outside the terminal, she collects first-edition maps of trade routes that no longer exist and maintains that the best coffee in Europe is in Thessaloniki, not Rome.