An Indian crypto investigation has widened into an international terror financing case after Gujarat police said they traced Rs 226.54 crore, or about $23.96 million, through a network tied to dark web drug sales, wallet transfers and hawala channels. On May 19, the Cyber Centre of Excellence under Gujarat CID Crime carried out arrests in Ahmedabad, Mumbai and Haryana, taking nine people into custody.
Police said the case is not a standard fraud probe. Investigators linked the same wallet chain to drug proceeds in the UK, cyber fraud complaints in India and wallets associated with sanctioned groups and entities, including Hamas-related financing lines and Yemen's Houthi rebels.
How investigators say the money chain operated
At a press briefing, Gujarat police described the flow as “dirty crypto,” referring to cryptocurrency used across drug trafficking, fraud, terror financing and laundering. According to investigators, orders were placed over Telegram and dark web platforms, with narcotics delivered in the UK. Payments were then converted into USDT and privacy coin Monero, moved across multiple wallets in a layering process, converted back into USDT, and then routed into India as cash through hawala operators.
Police identified several alleged transaction handlers. Mohammedzaid Siddi accounted for more than $7.52 million in flows through his accounts. Dubai-based Mohammed Zuber Popatiya handled $4.87 million, while Naved Pathan handled $3.83 million. Popatiya remains at large and is the main wanted suspect in the case.
Investigators also said the wallet cluster intersected with 935 cyber fraud complaints filed on India's National Cyber Crime Reporting Portal, with victim funds entering the same network of addresses.
Wallet links extended to Hamas-related and other sanctioned networks
Police said Popatiya's wallet was traced to Al-Kahira, a Gaza-based organisation that Israel's National Bureau for Counter Terror Financing, or NBCTF, has linked to Hamas financing operations. The report states that NBCTF froze those wallets in 2025 through court orders, and one frozen wallet later transferred funds directly into two wallets belonging to Popatiya.
The investigation also drew in US sanctions data. The US Office of Foreign Assets Control, or OFAC, had previously cluster-marked Popatiya's wallet in connection with Yemen's Houthi group, formally known as Ansar Allah. Investigators said they also found links to Iran's IRGC-QF, the sanctioned Russia-based exchange Garantex, and the Moldova-linked Ilan Shor financial crime network.
The UK side of the case remained active as well. Salman Gulamali Ansari was sentenced in a British court to six years in October 2024 on narcotics charges. Investigators allege he continued to run the drug network from prison through 2026. His father, Gulam Sadiq Ibadullah Ansari, was arrested in Ahmedabad during the same operation.
Regulatory scrutiny is moving on the same timeline
Gujarat's CCoE said the case was built using blockchain forensics, AI-driven wallet analysis and human intelligence. The agency used the same toolkit in April 2026 during Operation Mule Hunt, which led to 40 arrests in a Rs 622 crore cyber fraud case.
Police said roughly 30% to 40% of the traced Rs 226 crore may qualify as dirty crypto, while the remaining 60% to 70% involved lawful trading, gold deals and hawala activity. A parliamentary panel in India was scheduled to meet Binance, ZebPay and WazirX on May 20, 2026 to discuss virtual digital asset rules. Meanwhile, questioning of the nine arrested suspects is still under way, and police have not ruled out more arrests in India or abroad.

