Cryptocurrency: Crime and Terrorism’s Greatest Ally

Published by

on

Recent reports have discovered that the October 7th attacks were funded in part through Garantex, a Russian cryptocurrency exchange favored by criminals worldwide. The involvement of unregulated crypto exchanges in the Israel-Palestione conflict has drawn increased attention to the need to crack down on these shadowy digital transactions.

Since cryptocurrency’s creation in 2009, its popularity has grown exponentially. Cryptocurrency is a form of digital currency that is transferred electronically, free of a governing body. It has low transaction fees, a short processing time, minimal intermediaries, and it resists inflation due to its independence from the market and economic trends, all of which contributes to its acceptance and broad usage among the global public. Others invest in crypto to diversify their portfolios and with two million different types of crypto on the market the investment options are endless. Though any investments involving crypto are highly risky, many are surprisingly willing to experiment with a small portion of their investment portfolio to better understand the field and see if it is worth pursuing. Because cryptocurrency is decentralized and unregulated by any federal bank, however, there is no structure responsible for its maintenance that works to minimize fluctuations in its worth. Thus, the value of cryptocurrency is highly unpredictable: its worth can diminish or inflate in a matter of days. 

The lack of regulation and oversight over cryptocurrency trade is attractive to criminals because it makes anonymous transactions easy to complete and difficult to trace. Countries impose vastly different restrictions on crypto including who can be legally funded and traded. However, because all interactions occur online, U.S legislation is undermined by international trade and a lack of any centralized power, which has made many U.S sanctions ineffective or challenging to properly enforce. With the improvement of data collection and tracking technologies, these sanctions have become more powerful. Many criminals and nefarious organizations choose to fund illicit activities from less regulated countries; if caught, they can collapse and reestablish the organization’s base elsewhere in order to continue illegal trade. For example, Russia has almost no laws surrounding the regulation of crypto and is thus the hub for many of the world’s largest crypto companies including Chatex, Suex, and Garantex. Many criminals, including Bankman Fried with his fraud at FTX and Roman Stirlingov, who laundered $400 million since 2011, were traced by U.S authorities. This is why many choose to base cryptocurrency agencies and fraud out of Russia in order to evade punishment from more strictly regulated countries like the U.S and its allies. 

As tracked by the Department of Justice, Drug Enforcement Administration, Federal Bureau of Investigation, Department of Homeland Security, and U.S Treasury, crypto is used most commonly by weapons dealers, drug dealers, human traffickers, and child pornography distributors. In June 2021, 15 of 27 online commercial sex marketplaces investigated by the United States Government Accountability Office used Bitcoin as a method of peer-to-peer payment. It was also found that many drug deals take place over cryptocurrency ATMs or Helix, a dark web platform made specifically for drug transactions. The Financial Crimes Enforcement Network of the Treasury consequently announced warnings and suggestions to help financial organizations that use crypto detect criminal activity. Other forms of protection offered to organizations include the Bank Secrecy Act and blockchain technology that forces institutions to report crimes and note unusual activity. The blockchain technology not only keeps companies safe, but it also aids law enforcement and the DOJ in their investigations, for they have a greater pool of evidence upon which to track threatening transactions and can even use these data to track behavioral patterns of malicious entities. 

In addition to enabling criminals to evade detection, cryptocurrency also allows actors to hold data captive and require ransom digital payments as demonstrated by both the Colonial Pipeline and Wannacry cases. The Colonial Pipeline case was a ransomware attack that took place in 2021 in which DarkSide, a hacker group, stole 100 gigabytes of the Colonial Pipeline company’s data and infected its IT system. The attack led to complications in both its banking and accounting systems. Colonial Pipeline is one of the nation’s largest gasoline suppliers based in Houston, so the hacking took a significant toll on Americans; the case was sobering for Americans as one of the first instances that painted the threat of cybersecurity as a real, public danger. Gas stations suffered lines that wrapped around the block, people filled and hoarded their own ziploc bags with gasoline due to a fear of supply instability, and many had no access to gas at all.

The WannaCry case was a global attack that took place years prior in May of 2017. It used a crypto worm to infect systems using Microsoft Windows and steal user files, asking for a ransom Bitcoin payment for their retrieval. Wannacry began due to the NSA’s development of “ExternalBlue”, a vulnerability exploit. A group called Shadow Brokers stole the software and released it to the public infecting over 150 countries and 200 thousand devices with the old version of Microsoft, including Honda, FedEx, Nissan, and the U.K. National Health Service. Ambulances were diverted and patient care was impacted. In response to the uptick in crises, China attempted to outlaw crypto. However, as mentioned earlier, it is nearly impossible for the U.S to ban or greatly restrict cryptocurrency when its production and exportation is conducted almost entirely in Russia, for all of the top Bitcoin agencies are Russian owned or connected and the U.S has no influence or right to resist the ethics of such agencies. Cryptocurrency’s fast growth and development, while boasting more efficient, convenient trade, fosters an environment favorable to crime and hinders law enforcement’s authority to regulate illicit activity. Both the Wannacry and Colonial Pipeline cases jump-started the Biden-Harris administration’s response and preparedness to cybersecurity events. 

At the U.S Cybersecurity & Infrastructure Security Agency, or CISA, the administration has described the many ways that the cases bolstered their response to cybersecurity threats. First, they established a website to centralize all alerts and advice for business owners as well as individuals to best protect themselves from threats. Second, it created a Joint Ransomware Task Force with FBI officials in order to get the federal government involved in creating a strategy to combat a series of ransomware attacks. The JCDC, or Joint Cyber Defense Collaborative, also helped create the CISA’s Shields Up, a campaign to prevent U.S infrastructure like healthcare, transportation, and energy from Russian attacks. Along with the Transportation Security Administration, it united over 25 pipeline operators and industrial control systems partners, improving pipeline technology and networks. It also improved “CyberSentry,” a detection and monitoring technology, to reduce detection and reaction times for cyber threats and made cybersecurity performance goals which outlines how to make educated investments into cybersecurity defense entities. 

Behind nearly every cyberattack is Garantex, the most popular Bitcoin laundering and cryptocurrency exchange company in Russia. It was established in Estonia in 2019, though the bulk of its transactions take place in Moscow, Federation Tower, and St. Petersburg, Russia. Over $100 million of its assets are associated with illicit funds and darknet actors, and $2.6 million comes from Hydra, a novel and specific form of blockchain technology tailored for business interactions that keeps an electronic record of crypto transactions in a peer-to-peer network. Such malicious funding warranted an investigation on behalf of Estonia’s Financial Intelligence Unit. The investigation concluded that Garantex funded a high number of what are known as “anti-money laundering” and “combating the financing of terrorism” (AML/CFT) risks. These are anonymous transfers that have no account of names associated with the transfer, no verification checks, no listed funding source, and no account number. AML/CFT risks have no receipt proving details of the transfer and offer no method of tracing them to an individual or organization. 

The Estonian investigation also revealed that Garantex reserved digital wallets to fund criminal activity, much of which contributed to secretly financing Russian elites. In response to their findings, the Intelligence Unit revoked Garantex’s license to offer all virtual currency services after working in close communication with the United States Treasury Department. This is not rare: Estonian services often consult the U.S to confirm the most effective course of action, for their efforts to combat Garantex have lasted years. Despite this, however, entities of Garantex continue to stay afloat, for Russia is equipped to avoid U.S sanctions. In fact, Garantex continues to be one of the most active Bitcoin agencies in its industry. After sanctions were placed on the company, its CEO, Mohammad Khalifa, stepped down to create separate cryptocurrency entities not subject to sanctions, including MKAN Coin, an official partner of Garantex and many other Bitcoin organizations. 

Despite the U.S’s contribution to Estonia’s efforts to combat Garantex and Russian misuse of cryptocurrency technology, regulating cryptocurrency by hindering the Russian economy remains a weakness for the Biden administration. The Treasury Department sanctioned over 80% of the Russian banking sector to limit foreign transactions and has tried to sanction Russian crypto enterprises, though enterprises are able to close and reopen their establishments under new names. This is an issue because even when companies are suspected to be malicious they can close and evade discovery by law enforcement before conviction. Additionally, it is extremely easy to replicate digital wallets and tokens, and Garantex allows criminals to launder illicit funds, convert their earnings to crypto, and withdraw from the funds in a different currency. The adaptability of crypto exchanges like Garantex poses a challenge for the federal government and lawmakers to limit all forms of crypto exchange or identify all methods of currency conversion criminals use to transfer money and evade receipts.

One potential solution to the failing sanctions was outlined by a proposed bill, the Digital Asset Sanctions Compliance Act, on behalf of Senator Elizabeth Warren and ten accompanying democratic senators. The bill would allow Biden to sanction foreign cryptocurrency firms in business with Russian companies as well as prevent Russian companies from conducting business with American entities. While this is unlikely to become law in the near future, its proposal increased the pressure placed on Russian cryptocurrency companies. The Biden administration believes that Russia would not be able to completely evade the imposed sanctions due to a lack of liquidity in cryptocurrency that makes it difficult to manage high-volume trades. The bill would allow the Treasury to block digital asset platforms operating in the U.S from working with Russian crypto entities. This would be an effective step, since crypto exchanges including Coinbase and Kraken have stated they would only follow these restrictions if legally required. Finally, the bill would require the Treasury to publicly report foreign trading platforms at high risk for sanction evasion and money laundering and force U.S taxpayers to report offshore crypto transactions over $10,000.

Currently, the Bank of Russia calls cryptocurrency an alternative method to settle transactions and transfer funds, meaning it enforces almost no regulations on crypto trade. The proposed bill would allow the Treasury Secretary to block digital asset platforms operating in the U.S from interacting with any Russian cryptocurrency users. The bill would be significant: many major crypto exchanges, including Coinbase and Kraken, have refused to go so far as to cut all relations amongst the U.S and Russia unless required by law. Legislation hopes that the lack of liquidity in high volume cryptocurrency transactions deems it more difficult for Russia to evade all economic sanctions. Elizabeth Warren has low expectations for the proposed sanctions, however: “Russian President Vladimir Putin ‘and his cronies can move, store and hide their wealth using cryptocurrencies, potentially allowing them to evade the historic economic sanctions the U.S. and its partners across the world have levied in response to Russia’s war against Ukraine.’” She believes economic sanctions would be useless due to Russia’s many international, crypto partnerships and the U.S’s history of failure to enforce cryptocurrency regulation. While based in Russia, the danger associated with cryptocurrency is by no means localized. Garantex is involved with organizations located all over the world, the most notable being Hamas. 

The recent Israel-Palestine conflict brought attention to Garantex’s involvement in funding Hamas military attacks on Oct. 7, as reported by The Wall Street Journal. Similarly, Palestinian Islamic Jihad managed digital wallets funding the Hamas attacks, and reporters found that Garantex donated $93 million to be maintained in these wallets. One method Garantex used to disguise much of its illegal funding was the conversion of Russian rubles. This method allows Garantex to deposit rubles as stablecoin, a currency that can be taken out and used as real money when apart from Garantex and any of its trade partners. This way individuals can deposit crypto in Garantex and later remove it to be used in an entirely different location and form, free of association with the company. On Oct. 10, the Israeli government announced that it froze hundreds of crypto accounts associated with Hamas, though this was not the first time. Israel has fought the establishment and finding of digital Hamas wallets for years, only being able to freeze them when identified rather than prohibit them altogether. In January 2019, the military wing of Hamas known as the Al-Quassam Brigades (AQB) began fundraising crypto donations through social media. For Hamas, 2019 marked their first attempt to turn to crypto due to a need for alternative fundraising sources. The U.S later found their platform, however, and dismantled the AQB website in August 2020. 

Israel has been the victim of multiple cyber attacks on behalf of Hamas in recent months, with activity specifically spiking surrounding the Oct. 7 attack. In April 2023, Hamas told its supporters that it would not be taking donations via cryptocurrency due to vulnerability. At this point, cryptocurrency transactions received by the Palestinian Islamic Jihad experienced a sudden decrease, suspicious due to its region’s crypto wallets worth millions of dollars in crypto being under a freezing order. This most likely means that groups funding the conflict previously used cryptocurrency yet abandoned this form of compensation after concerns arose in order to evade being caught by Israel or its allies. It is likely, however, that Hamas will resume its use of crypto once discovering more secure methods of transactions. Because blockchain analytic solutions enable screening of wallets and transactions, crypto exchanges need to beware of this nuanced tracking method if they want to stay active, especially in the black market. 

In an effort to hinder Russian trade, the U.S Treasury, assisted by the German Federal Police, sanctioned Russia-Based Hydra and Garantex in April of 2022. In a press release, the Treasury stated that this sanction builds upon previous sanctions that attempted to check Russian crypto authority. The action was significant, for it is one of the most extreme sanctions imposed on crypto to date and displays the building severity of the problem. It required that all Russian entities that have property or interest in property in the U.S must be blocked and reported to the OFAC. Any establishments owned by 50 percent or greater by blocked entities, either directly or indirectly, must also be blocked and any transactions by U.S persons with blocked entities are prohibited unless specially permitted by the OFAC. Transactions as indirect as “the making of any contribution or provision of funds, goods, or services by, to, or for the benefit of any blocked person and the receipt of any contribution or provision of funds, goods, or services from any such person” are prohibited. This blocks activity in more ways than one: not only can companies not do business with the U.S, but they are also prohibited from gaining any form of support or resources from American associated entities.

The most prominent international agency that has emerged as a true educational and uniting force in the fight against crypto abuse is the Financial Action Task Force, or FATF. The FATF was established in 1989 and is currently composed of 39 countries and 200 jurisdictions in addition to influencing many non-member countries and nine FSRBs, or FATF-Style Regional Bodies. In 2014 and 2015, the FATF created a risk analysis generating a list of suggestions to combat cryptocurrency fraud that made great strides in developing preventative response strategies. It “include[ed], among others, the requirements of conducting customer due diligence and ongoing monitoring, recordkeeping, submitting of suspicious transaction reports (STR) to the designated Financial Intelligence Unit (FIU), and screening customers and transactions against designation lists. In order to conduct the needed examinations as part of the consumer due diligence and licensing process, the FATF recommends using…blockchain analytic tools” (95). Over $1,000+ virtual asset (VA) transfers require compliance with FATF recommendation. As a final measure, the task force employed the “Travel Rule” requiring organizations involved in VA transfers as well as VASPs, or virtual asset service providers, to gather and distribute personal information regarding both parties involved in the interactions and allowing private sectors and law enforcement agencies to trace financial transactions over public blockchain. 

All member countries and FSRBs encourage the practice of the 40 FATF recommendations, which address money laundering and confiscation, terrorist financing and financing of proliferation, and the powers and responsibilities of competent authorities. Periodically, member and participating countries must undergo “mutual evaluation” where effectiveness and technical compliance is measured on behalf of fellow member nations in order to maintain their membership. The difference between member and participating countries is that members must also “agree to fund the FATF on a temporary basis with specific goals and projects (a “mandate”)”. The U.S became a member in 1990, and, according to their 2016 evaluation, is compliant to 9 of the 40 recommendations and largely compliant to 22—it is unusual and unheard of for a nation to be entirely complaint to all 40 suggestions due to the nuance of cryptocurrency and fast-changing nature of such threats. Currently, the U.S’s weak spots include money laundering, combating weapons of mass destruction, and financing terrorism, and, as a result, they are required to update the FATF as they improve these areas. In addition to listing such standards, the FATF created a gray and black list categorizing the severity of each non-compliant country’s threat. Only North Korea, Iran, and Myanmar were placed on the blacklist, meaning they were likely to launder money and must continue to be closely monitored. Knowing the categorization of these countries allows the U.S to evaluate where sanctions should most effectively be directed.  

Moving forward, there are many ways that the US can continue to address these issues. To counter recurring threats, the U.S can follow FATF guidelines by continuing to improve regulations and stay up to date with new financial technology products as well as provide extra clarity on such recommendations since the crypto business is novel and growing. Private sectors should assume a leadership role and promote the design of technical solutions that implement principles of AML/CFT that regulate the global finance system and protect any participating nations’ economies from cybercrimes. AML/CFT legislation works to combat the financing of weapons of mass destruction as well as anything that threatens the health of a country’s economy. This can include “hot money” sources, or money that is transferred at a frequent rate to generate high interest, as well as more broad issues regarding banking relationships, revenue collection, and governance. Law enforcement also needs to stay up to date with this industry and discover ways to monitor it more accurately, building upon the blockchain technology previously mentioned that maintains a more detailed account of transaction history and behavior. Finally, international cooperation that the FATF works to achieve is needed in order to end malicious Russian trade and policies having to do with the digital asset economy must be created and passed with more scrutiny.  
The severity of U.S sanctions has increased as the U.S tries to tackle the root of crypto threats and grapple with the vast differences in domestic and global standards of crypto regulation. Crypto is incredibly difficult to monitor since it is deeply intertwined with international organizations rooted in multiple locations that can easily reestablish themselves under a different identity at the threat of being discovered. While the US has continued to research and improve Hydra technologies in order to grow its database surrounding the behavioral patterns of foreign crypto agencies and actors, it seems to be cornered into the solution of sanctions. It can only comply with global, allied agencies like the FATF that encourage solidarity and unity among countries working to protect themselves and their economies from cyberthreats and cannot stop Russia from allowing the unchecked establishment of companies like Garantex. The SEC’s role thus far has primarily been to identify malicious companies and incite high-profile lawsuits against establishments like Coinbase for operating illegal and unregistered security exchanges. The US must work on combined efforts of continuing to enforce sanctions, cutting ties with companies that interact in any way with corrupt Russian crypto agencies, encouraging smaller American businesses to protect their software, and improving compliance with FATF recommendations in order to maintain safety and prevent another major hacking event.

The image used in this article is licensed for use under a CC0 1.0 Universal Deed.

Leave a comment