Every few months, a crypto exchange gets “shut down.” Headlines run. LinkedIn fills with hot takes. And then, quietly, the money keeps moving. That’s the pattern I want to walk through here—not as a hypothetical, but as a documented case, built on the work of the two firms that actually trace this money for a living: TRM Labs and Chainalysis.
Across my career in technology governance, cyber risk, enterprise transformation, and technology leadership, this particular case study has become one of the clearest illustrations of a lesson every risk leader eventually learns the hard way: shutting down a bad actor is not the same as dismantling the capability behind it. The organization goes away. The infrastructure, the liquidity, and the operators very often do not.
The Exchange That Wouldn’t Stay Dead:
eXch was a no-questions-asked crypto swap service. No identity verification, no meaningful compliance program—and it marketed that absence as a feature, branding itself a “privacy project” rather than what regulators would call it: a gap in the system, wide open and waiting to be used.
That gap became national news in February 2025, when North Korea’s Lazarus Group pulled off the largest crypto theft in history, stealing roughly $1.4 to $1.5 billion in Ethereum from the Bybit exchange.1 Bybit and independent investigators—including Elliptic, TRM Labs, and researcher ZachXBT—all pointed to the same off-ramp: eXch allegedly helped launder more than $90 million of the stolen funds.2
eXch’s owner, publicly known only as “Johann Roberts,” denied it, then partially admitted it, then blamed a slow compliance data feed. For what it’s worth, I went looking for a verified identity behind that name while researching this piece. I couldn’t find one. Treat it as an alias until proven otherwise.
In April 2025, eXch announced it was shutting down—citing, of all things, a DOJ whistleblower and a “transatlantic law enforcement operation.” Here’s the part almost nobody covered: it didn’t actually stop. TRM Labs found that eXch pulled its public-facing website but kept serving business partners through an API, with the same laundering fingerprints continuing right past its own announced shutdown date.3
This Isn’t One Bad Exchange—It’s a Lineage:
If eXch feels like an isolated case, look at what happened to Garantex, the Russian exchange first sanctioned in 2022 for laundering funds tied to darknet markets and ransomware groups like Conti and Hydra. Law enforcement finally seized its infrastructure in March 2025, after the platform had processed an estimated $96 billion in transactions since 2019, a substantial share of it tied to ransomware, darknet-market, and other criminal activity.4
What happened next is the whole point of this article. Garantex didn’t disappear. It became Grinex—same liquidity, same users, same money, new name. Chainalysis and TRM then traced the same pattern into ABCeX and its rebrand AEXBit, which share identical backend infrastructure and hot wallets with their predecessors; into the A7/A7A5 ruble-backed payment network, which has moved more than $93.3 billion in on-chain volume and counting; and into Heleket, a “new” service that received its opening liquidity directly from Garantex’s own wallets.5
TRM’s own assessment, stated plainly in its 2026 crypto crime report, is that this wave of rebrands is likely coordinated—a deliberate attempt to keep Russia’s crypto liquidity flowing while insulating the actual operators from further sanctions.6 For what it’s worth, Grinex itself went dark in April 2026 after a $13.7 million cyberattack it blamed, without evidence, on Western intelligence agencies.7 I’d bet money there’s already a successor standing by.
The Bigger Story Nobody’s Talking About Enough:
Here’s what I think most crypto-crime coverage still misses: individual rogue exchanges, however dramatic the headline, are no longer the main event.
Both TRM and Chainalysis now point to something structurally different—Chinese-language money laundering networks, or CMLNs. In 2025 alone, these networks moved an estimated $16.1 billion, roughly $44 million a day, across nearly 1,800 active wallets. That’s not a typo: Chainalysis measured CMLN growth at roughly 7,325 times the growth rate of illicit inflows to centralized exchanges since 2020.8
The anchor of this ecosystem is Huione Group, a Cambodia-based conglomerate that processed more than $98 billion in total crypto inflows between August 2021 and January 2025, over $4 billion of it confirmed illicit. In October 2025, the U.S. Treasury’s FinCEN designated Huione under Section 311 of the USA PATRIOT Act as a primary money laundering concern. Huione is also directly tied to Prince Group, the Cambodia-based criminal network behind a sprawling web of scam compounds across Southeast Asia.9
Why does this matter more than another exchange takedown? Because CMLNs aren’t one company you can seize. They’re a marketplace—fragmentation services, OTC desks, and “guarantee” platforms like Huione and Xinbi that connect buyers and sellers of laundering capacity, often without the platform operators ever directly touching the illicit funds themselves. Sanction one vendor, and the rest of the marketplace barely notices.10
Ransomware Isn’t Slowing Down—It’s Diversifying:
Data-leak-site-claimed ransomware incidents grew 50 percent year-over-year in 2025, reaching an all-time high even as enforcement activity intensified.11 The Ransomware-as-a-Service market has also fragmented, with some trackers counting as many as 85 active independent extortion groups—a more decentralized field that’s harder to monitor collectively, even as individual groups’ laundering patterns become easier to fingerprint on-chain.12
Separately, broader Chainalysis research on illicit crypto flows (not specific to ransomware) points to a shift in final-stage laundering toward exchanges with little to no know your customer (KYC) verification, with no-KYC exchange usage up 82 percent and usage of “guarantee” aggregators such as Tudou Danbao up 87 percent.13 Whether North Korean state actors rely on these no-KYC exchanges less than independent cybercriminals do—running a more specialized pipeline through Chinese money-laundering networks and bridge protocols instead—is a plausible pattern given DPRK’s well-documented use of dedicated laundering infrastructure. But it isn’t a claim I found directly confirmed in the sources reviewed for this piece, so I’m flagging it as a reasonable hypothesis rather than an established fact.
Enforcement has also started targeting the infrastructure layer itself, not just individual exchanges. In February 2025, the U.S., U.K., and Australia jointly sanctioned Zservers, a Russian bulletproof-hosting provider tied to ransomware operations including LockBit; Chainalysis data shows Zservers funneled at least $5.2 million through high-risk channels, including the sanctioned exchange Garantex.14 OFAC separately sanctioned Aeza Group, another Russian bulletproof host, in July 2025—though, notably, that action does not appear to have included the U.K. and Australia as co-sanctioning parties.15
What This Actually Means:
If you take one thing from this, let it be this: the “shut it down” model of enforcement works—temporarily. eXch kept running through its own back door. Garantex became Grinex became ABCeX became AEXBit. The harder, more consequential fight is against the marketplace model itself—the CMLNs, the guarantee platforms, and the hosting infrastructure underneath all of it—which doesn’t have one throat to choke.
The good news, and it’s a real one, is that blockchain transparency remains investigators’ structural advantage. The same on-chain fingerprinting—shared wallets, co-spending patterns, infrastructure overlap—that unmasked ABCeX as a Garantex clone will eventually do the same to whatever comes after Grinex, and whatever comes after that.
This case study reflects the kind of governance-under-adversarial-pressure challenge I spend a lot of time researching and writing about: how do we design governance, oversight, and risk management frameworks for ecosystems that are deliberately engineered to evade them? Answering that will take a coordinated, multi-layered response—end-to-end mapping of cryptocurrency transaction chains, stronger Know Your Customer and Anti-Money Laundering controls, deeper multinational cooperation among regulators and law enforcement, more rigorous misuse-case modeling to anticipate adversarial behavior, and broader, faster identification and blacklisting of the high-risk exchanges, wallets, and tokens that keep facilitating illicit finance long after their predecessors are supposedly gone.
Endnotes:
1. TRM Labs, “2026 Crypto Crime Report” (TRM Labs, 2026), https://www.trmlabs.com/reports-and-whitepapers/2026-crypto-crime-report.
2. Decrypt, The Block, and CryptoRank.io, contemporaneous news coverage of the Bybit hack and eXch’s role in laundering stolen funds, February–March 2025.
3. TRM Labs, “eXch Remains Active Despite Shutdown: How the Bybit Hack-Linked Exchange Continues to Enable Laundering of CSAM Funds” (TRM Labs Blog, May 2, 2025), https://www.trmlabs.com/resources/blog.
4. Chainalysis, “OFAC Sanctions Tracker: How Sanctions Impact Crypto Crime” (Chainalysis Blog), https://www.chainalysis.com/blog/ofac-sanctions/.
5. TRM Labs, “2026 Crypto Crime Report.”
6. TRM Labs, “2026 Crypto Crime Report.”
7. TRM Labs, “2026 Crypto Crime Report.”
8. Chainalysis, “The Chinese-Language Underground Crypto Money Laundering Ecosystem” (Chainalysis Blog, January 27, 2026), https://www.chainalysis.com/blog/2026-crypto-money-laundering/.
9. Chainalysis, “Crypto Sanctions: 2026 Crypto Crime Report” (Chainalysis Blog, 2026), https://www.chainalysis.com/blog/crypto-sanctions-2026/.
10. Chainalysis, “The Chinese-Language Underground Crypto Money Laundering Ecosystem.”
11. Chainalysis, “Crypto Ransomware: 2026 Crypto Crime Report” (Chainalysis Blog, March 4, 2026), https://www.chainalysis.com/blog/crypto-ransomware-2026/.
12. Chainalysis, “Crypto Ransomware: 2026 Crypto Crime Report.”
13. Chainalysis, “2025 Crypto Theft Reaches $3.4 Billion” (Chainalysis Blog, December 18, 2025), https://www.chainalysis.com/blog/crypto-hacking-stolen-funds-2026/.
14. Chainalysis, “OFAC Sanctions Tracker.”
15. Chainalysis, “OFAC Sanctions Tracker.”








