Bitrace said in its crypto crime report for the first half of 2026 that more than $174.9 billion in stablecoins flowed to high-risk addresses across six areas: online gambling, money laundering, gray and black market trading, fraud, sanctions and freezes.
The report added a methodological note. It said HTX-related hot wallet addresses and user addresses were not included in sanctions-related fund statistics because sanctions activity by the UK Foreign, Commonwealth and Development Office, or FCDO, was too aggressive. Activity tied to Huione Group and Xinbi Group was still classified under gray and black market trading and was not counted again.
Potato Guarantee collapsed and Xinbi Guarantee absorbed the flow
Bitrace described Potato Guarantee as an illegal crypto transaction guarantee platform that evolved from the Huione guarantee system. It mainly provided fund custody, transaction guarantees, settlement and dispute arbitration for gray and black market merchants in Southeast Asia. As related entities continued to face sanctions and law enforcement pressure, its payment channels and funding base weakened. News that a key figure had been extradited further shook confidence and triggered concentrated withdrawals of merchant deposits.
Under worsening liquidity, collapsing credibility and a broken funding chain, Potato Guarantee shut down its public-group business in January 2026 and sold some of its groups and related digital assets. After its exit, clients and demand moved quickly to other platforms, with Xinbi Guarantee becoming the main recipient.
According to the report, Xinbi Guarantee took market traffic, expanded its public-group network and built out services tied to laundering, illicit exchange and technical support, gradually moving into a dominant position. It also tried to use its own communications tools to build a more closed trading environment and reduce reliance on third-party platforms. Bitrace said the shift showed the replacement and restructuring capacity of the gray and black market guarantee business: the collapse of one platform did not end the underlying activity, but pushed it onto new platforms and infrastructure.
UK sanctions widened from underground infrastructure to a mainstream exchange operator
Bitrace said the UK stepped up sanctions on high-risk crypto-related entities in the first half of 2026.
On March 26, the UK sanctioned Xinbi Guarantee, an illegal crypto transaction guarantee platform in Southeast Asia. Its transaction volume fell sharply that month, and the policy impact did not fully fade for several months, according to the report. On May 26, the UK added HUOBI GLOBAL S.A. to a new Russia-related sanctions list. Bitrace said the entity currently operates under the HTX name and was accused of providing financial services, funds or economic resources to the sanctioned entity A7 LIMITED LIABILITY COMPANY.
After the sanctions announcement, some crypto trading platforms began taking risk-control steps on funds coming from HTX business addresses, and some user accounts that received related withdrawals were also affected, the report said. Bitrace framed the move from Xinbi Guarantee to HTX as a sign that UK sanctions had expanded from underground gray and black market infrastructure to mainstream crypto trading services.
Two major attacks caused a combined $577 million in losses
Bitrace said major hacking incidents in the first half were still dominated by state-backed groups.
On April 1, Drift Protocol on Solana was attacked and lost about $285 million, more than half of its total value locked. The report said the attacker built a relationship with the project team through long-term social engineering, induced security committee members to pre-sign transactions without understanding the consequences, and gained protocol management rights. The attacker then listed CVT, which the report said lacked real value, as collateral, deposited large amounts of CVT and withdrew real assets including USDC, SOL and ETH. Because the on-chain laundering behavior closely matched historical patterns associated with North Korean hackers, Bitrace said the industry generally attributed the incident to that actor.
On April 18, attackers linked to Lazarus Group stole about $292 million, or 116,500 rsETH, from KelpDAO’s LayerZero cross-chain bridge. Bitrace said the attackers compromised internal RPC nodes while launching denial-of-service attacks on external nodes, feeding false data to a single validation network so that assets were released on Ethereum even though no tokens had actually been burned on the source chain.
KelpDAO later paused the related contracts and blocked a second attempted theft worth about $95 million. The Arbitrum Security Council coordinated with law enforcement and froze more than 30,000 ETH in downstream funds tied to the attackers. After the incident, LayerZero attributed the operation to TraderTraitor, a branch under Lazarus, according to the report.
The two cases caused a combined $577 million in losses, or about 60% of all security-incident losses in the first half of 2026.
On-chain enforcement remained active
Bitrace said one of the main forms of on-chain enforcement remained transfer restrictions imposed by stablecoin issuers on specific addresses tied to investigated cases. In its previous annual report, Bitrace said Tether and Circle had sharply expanded law-enforcement cooperation in 2025, and the same trend continued in the first half of 2026.
Most cooperation requests came from the US and Israel under anti-fraud and counter-terrorist financing grounds, the report said. The scope also widened from ordinary personal addresses to business addresses at centralized entities associated with illicit activity. Bitrace said that suggested both a larger scale and a more aggressive posture from the two issuers.
Gambling-linked addresses received more than 57.4 billion USDT
Bitrace defined online gambling as the organization and provision of betting activity through internet platforms, with proprietary settlement systems or third-party payment tools used for deposits, chip conversion and withdrawals. In crypto settings, participants usually use USDT and other crypto assets as the settlement medium rather than buying or redeeming chips directly with fiat currency.
Based on Bitrace monitoring, high-risk gambling addresses on Ethereum and Tron received more than 57.4 billion USDT in the first half of 2026. Of that total, Ethereum accounted for 17 billion USDT and Tron accounted for 40.4 billion USDT.
Virtual asset service providers, including centralized trading platforms and payment platforms, were the main recipients of tainted gambling funds. Major VASPs received more than 2.3 billion USDT in high-risk gambling funds during the period, with the top 10 platforms taking the vast majority. Binance, OKX, Bybit and HTX, which the report said were preferred by Chinese-language laundering networks, together received more than 1.7 billion USDT, or 72.98% of the total.
The report also said guarantee platforms that serve illegal trading are building or controlling large numbers of groups on communications tools such as Telegram and renting some of those groups to gambling operators. Those gambling platforms use the guarantee platforms’ brand recognition and user traffic to promote betting, recruit participants and handle chip conversion inside public groups.
As an example, Bitrace pointed to Xinbi Guarantee, which it described as the largest transaction guarantee platform in Southeast Asia. Its gambling portal Xincai provided guarantee services to third-party gambling platforms and also offered betting directly to users under the Xinbi brand. Bitrace said the trading volume in Xinbi’s self-operated gambling public groups alone exceeded 110 million USDT in the first half of 2026.
Laundering-linked addresses handled more than 20 billion USDT
Bitrace defined crypto laundering as the use of blockchains, crypto assets and related services to transfer, split, aggregate, exchange or obfuscate criminal proceeds in order to hide their illicit source, actual control relationship and final destination, and to return them to a spendable or cashable state.
In the first half of 2026, high-risk laundering addresses processed more than 20 billion USDT in illicit funds, the report said. TRC USDT far exceeded ERC USDT, with 17.7 billion USDT versus 2.3 billion USDT.
The report again discussed the "Card-to-USDT" laundering method, in which launderers rapidly move funds taken from victims’ bank cards and convert them into USDT to evade tracing. Depending on the layering stage, the method includes "First-hand Card-to-USDT" and "Second-hand Card-to-USDT." Each layer profits from exchange-rate spreads and helps obscure the path from fiat to stablecoins and from traceable transfers to repeated breaks in linkage.
For on-chain obfuscation, TornadoCash remained the main mixer. A total of 332,364 ETH flowed into protocol addresses on Ethereum in the first half of 2026, slightly above 256,317 ETH in the same period a year earlier.
Bitrace also said a service described as "Coin Laundering" began gaining traction in gray and black market communities in early 2026. Operators claimed they could cut off the blockchain trail of crypto assets and stop investigators from tracing funds on-chain. While it also directly cleans illicit crypto without involving fiat conversion, Bitrace said the business model is different from a conventional mixer and instead relies on agency collection and payment using multiple VASPs and DeFi protocols. More than $71.16 million in illicit crypto was obfuscated through this channel in the first half, according to the report.
Gray and black market trading addresses took in more than 77.3 billion USDT
Bitrace defined gray and black market trading as transactions involving the exchange of goods, services, funds or technical capabilities around criminal activity or business operating outside regular oversight. These transactions do not directly carry out base crimes such as fraud or gambling, but serve as preparatory crime activity and carry legal or significant compliance risk. The report listed telecom and online fraud materials and services, illicit cross-border human trafficking, cyberattacks, malware and technical development, and illegal virtual goods and unregulated cross-border settlement services.
These transactions are usually matched, guaranteed, settled and managed through crypto guarantee platforms, chat groups and payment tools, mainly using USDT and other stablecoins as the value-transfer medium, Bitrace said. High-risk blockchain addresses in this category received more than 77.3 billion USDT in the first half of 2026.
February came in slightly below other months because China’s Spring Festival fell in mid-February and many gray and black market operators suspended activity and returned home, the report said. Illegal crypto transaction guarantee platforms in Southeast Asia showed a similar pattern. More than 3.4 billion USDT flowed into guarantee-platform addresses in the first half, including public-group merchant deposits and monthly rents, as well as private-group deposits from ordinary traders.
Bitrace added that in 2026 it applied stricter transaction-type distinctions and address-behavior classifications to leading guarantee platforms headed by Huione Guarantee and Xinbi Guarantee, which caused some differences from previously disclosed data.
Fraud-linked addresses received more than 16 billion USDT
In the fraud section, the report focused on fraud inside organized crime networks in Southeast Asia. Bitrace defined it as conduct in which perpetrators use false identities, false information, technical inducement or trust manipulation to make victims transfer crypto assets or other funds based on mistaken beliefs. The report said this remains one of the most watched base criminal activities in the market, with upstream links to various criminal support industries and downstream links to laundering and coin-cleaning services.
High-risk fraud addresses received more than 16 billion USDT in the first half of 2026, with the overall trend moving lower. Bitrace said that suggested the gradually intensifying multinational crackdown since 2025 had already had a significant impact on organized crime networks in Southeast Asia.
The report also repeated a trend it highlighted in an earlier crime report: leading illegal crypto guarantee platforms had begun launching in-house crypto payment platforms to help users receive and send deposits, make small payments and participate in gambling, while those same platforms were also used by criminals to obfuscate stolen and fraud-linked funds.
After Huione Pay under Huione Group formally collapsed, four payment platforms recorded strong growth in activity: Okpay under Dali Guarantee, Newpay under Xinbi Guarantee, Fully Light Wallet under Fulilai Guarantee, and X Wallet, formerly Jinbei Wallet, under Jinbei Guarantee. Together, those four platforms received more than 3.9 billion USDT in the first half of 2026, according to Bitrace.
Sanctions covered 77 disclosed blockchain addresses in the first half
Bitrace said the number of sanctions cases targeting crypto-industry entities declined in the first half of 2026, but the scale was large, and the period included what it described as the first case of sanctions hitting a leading crypto exchange platform.
The sanctions lists for the first half included 77 blockchain addresses disclosed in full string form. By month of first appearance, March and June were the peak periods. All of the related sanctions were imposed by the US Treasury’s Office of Foreign Assets Control, or OFAC, and Israel’s National Bureau for Counter Terror Financing, or NBCTF. OFAC sanctioned 33 addresses and NBCTF sanctioned 44. The stated grounds included counter-terrorist financing, support for the Russian or Iranian war effort or sanctions evasion, and other online illicit activity.
The UK FCDO also remained highly focused on crypto in recent years, the report said. After sanctioning Cambodia’s Prince Group on Oct. 14, 2025, which Bitrace said led to its complete shutdown within several months, the FCDO sanctioned Xinbi Guarantee on March 26, 2026 and HUOBI GLOBAL S.A., the entity behind HTX, on May 26, 2026.
Bitrace said the sanction on Xinbi Guarantee did not produce a major practical effect. Its transaction volume dipped only slightly and by June had nearly returned to the monthly level seen before sanctions. The report added that Newpay, the centralized crypto payment tool under Xinbi Guarantee, also handled an unknown amount of off-chain deposit and withdrawal work not visible externally, and that the tool had expanded rapidly over the last six months. On that basis, Bitrace said Xinbi Guarantee’s real transaction scale may already have exceeded its historical peak.
By Bitrace’s count, Xinbi Guarantee processed transactions or collected public-group deposits worth more than 3.1 billion USDT in the first half of 2026, equal to 91.18% of the entire illegal crypto transaction market in Southeast Asia. The report said the surviving Xinbi Guarantee had effectively taken over Huione Group’s market share.
For HTX, Bitrace cited monitoring from blockchain intelligence and analytics firm Arkham. After the May 26 sanctions, HTX’s asset value under custody fell quickly from $6.7 billion to under $5 billion. A large amount of capital exited through user withdrawals, and the report said that created widespread fund contamination across the crypto trading market, especially at other leading trading or payment platforms favored by Chinese-speaking users.
Tether and Circle recorded 3,192 freeze events
Bitrace said Tether and Circle maintained the aggressive law-enforcement cooperation style seen since 2025, freezing stablecoin transfer permissions for large numbers of addresses across Ethereum and Tron in the first half of 2026.
After excluding repeated freezes on the same address, the report counted 3,192 freeze events in total: 2,451 by Tether and 741 by Circle, affecting 2,576 unique blockchain addresses. Tether cooperated with law enforcement far more often than Circle, while Circle’s activity was mainly concentrated in March.
Excluding addresses that were later unfrozen, the two issuers froze more than $1.5 billion in stablecoins during the first half. USDT on Tron was the main affected asset, accounting for 95% of the frozen amount, followed by USDT on Ethereum.
Bitrace’s distribution analysis of independent blockchain addresses showed that most freeze activity took place on Tron. By freeze type, 1,835 addresses were frozen only by Tether, 125 only by Circle, and 616 by both issuers.
Bitrace also conducted a timing analysis of addresses frozen by both issuers. It set the Tether freeze time at zero, with Circle recorded as negative if it acted earlier and positive if it acted later. The result showed that for almost all addresses frozen by both issuers, Circle acted before Tether, with an average lead of 112 hours per address. Bitrace said that while Tether froze more assets overall, Circle moved faster once it clearly accepted a law-enforcement cooperation request, which may reflect different operating strategies at the two issuers.
Bitrace outlined its own compliance and investigation business
At the end of the report, Bitrace described itself as a regtech company centered on crypto risk data analysis. It said it uses AI and big data to identify and monitor on-chain risks and criminal activity more accurately and efficiently, and provides products and service support for regulation, compliance and investigations.
Bitrace said it has worked with law-enforcement agencies in multiple countries and with Web3 companies, supported thousands of cases, monitored hundreds of billions of dollars in risky funds and helped recover losses totaling tens of billions of dollars.

