Alerts

How Crypto Forensics is Dismantling the IRGC

Iran’s Revolutionary Guards embraced cryptocurrency to evade sanctions and sustain their proxy networks. But the transparency of blockchain technology is giving law enforcement an unprecedented tool to trace, freeze, and dismantle illicit financial networks.
Editorial illustration of Iranian sanctions
(AI-generated)

Table of Contents

Summary

Cryptocurrency provides sanctioned and terrorist organizations with new ways to transfer value, but public blockchains also create persistent records that investigators can analyze retrospectively. Crypto forensics can connect wallets, identify infrastructure, expose financial relationships, and support sanctions or asset freezes. Centralized stablecoin issuers and exchanges create particularly important intervention points where authorities may disrupt access to funds. As evasion techniques become more sophisticated, effective enforcement will increasingly combine blockchain analytics, AI, conventional investigative methods, legal powers, and international cooperation.

Key Takeaways

  • Blockchain transparency can work against illicit finance. Public, immutable transaction records allow investigators to trace historical activity, connect related wallets, and uncover financial networks that might be harder to reconstruct through traditional banking systems.
  • Enforcement increasingly targets entire financial ecosystems. Wallet freezes, exchange sanctions, stablecoin blacklisting, and investigations of brokers and infrastructure providers can disrupt the gateways that connect digital assets with real-world money and resources.
  • Crypto forensics is becoming a strategic counterterrorism capability. Its effectiveness depends not only on blockchain analytics, but also on appropriate legal authority, private-sector cooperation, international coordination, and increasingly AI-assisted detection.

The Islamic Revolutionary Guard Corps (IRGC) has long operated as a central architect of international terrorism and illicit finance, sustaining a vast clandestine financial network that supports proxy militias, destabilizes the Middle East, and circumvents global sanctions.

For decades, this shadow economy relied on a labyrinthine network of hawala brokers, bulk cash smuggling, and front companies embedded within the traditional banking sector, exploiting regulatory blind spots and jurisdictional arbitrage to move billions of dollars beyond the reach of Western intelligence.

As the United States and its allies tightened the financial noose, however—expelling Iranian institutions from the SWIFT network and intensifying secondary sanctions—the IRGC and its elite Quds Force were forced to adapt. Increasingly, they pivoted toward the decentralized, borderless realm of digital assets to sustain their operations.

Yet this strategic migration to cryptocurrency, initially perceived by illicit actors as a financial haven shielded from sovereign governments, has inadvertently handed global law enforcement agencies one of the most powerful intelligence-gathering and disruption tools in the history of counterterrorism.

Blockchain’s Forensic Advantage

The inherent nature of blockchain technology—an immutable, transparent, and publicly accessible digital ledger—stands in stark contrast to the opaque, siloed databases of the legacy financial system. This difference is fundamentally transforming the battlefield of illicit finance.

In traditional banking, tracing dirty money can require investigators to navigate mutual legal assistance treaties, subpoenas, and reluctant foreign jurisdictions, often reaching dead ends when funds disappear into offshore havens or non-cooperative states. A blockchain, by contrast, records transactions in perpetuity, cryptographically preserving the network’s financial history for investigators equipped with the appropriate analytical tools.

The moment a terrorist operative moves funds on-chain, an enduring digital trail can be created.

This paradigm shift has given rise to the specialized field of crypto forensics, an increasingly indispensable discipline that enables law enforcement agencies to penetrate the pseudonymous veil of digital wallets, map complex financial networks, and dismantle the economic infrastructure supporting organizations such as the IRGC.

Using sophisticated blockchain analytics platforms provided by companies including Chainalysis, TRM Labs, and Elliptic, financial investigators can conduct cluster analysis, heuristic tracing, and behavioral profiling. These techniques allow them to associate seemingly unrelated cryptocurrency addresses through shared transactional patterns, common funding sources, and overlapping withdrawal behavior.

This capability changes the nature of financial policing by making previously hidden relationships visible. It also gives investigators something particularly valuable: the ability to look backward.

When a new illicit wallet is identified, investigators can reconstruct its historical transaction network, potentially exposing years of previously undetected financial activity and revealing the broader shadow-banking mechanisms facilitating the movement of capital.

Israel’s Wallet Seizures and Blacklisting Campaign

A striking example occurred in September 2025, when Israel’s National Bureau for Counter Terror Financing (NBCTF) ordered the seizure of 187 cryptocurrency wallets linked to the IRGC after blockchain analysis indicated that the addresses had received approximately $1.5 billion worth of Tether (USDT), the dollar-pegged stablecoin.

The operation resulted in the blacklisting of 39 wallets and the freezing of approximately $1.5 million in digital assets by the stablecoin issuer. It underscored the importance of public-private partnerships in modern financial enforcement: when authorities can translate forensic intelligence into actionable identifiers, private-sector actors can help rapidly disrupt terrorist financing channels.

The campaign against the IRGC’s digital financial infrastructure continued. In July 2026, an additional Israeli operation sanctioned 37 digital wallets associated with an international shadow-banking network responsible for moving tens of millions of dollars over several years.

The IRGC had sought to exploit high-liquidity blockchains such as Ethereum and Tron to bypass conventional monitoring frameworks. But once the relevant digital identifiers were blacklisted and cross-referenced against customer databases by compliance teams, the ability to integrate those funds into the mainstream financial system became significantly more difficult.

Exposing the IRGC’s Crypto Infrastructure

Crypto forensics also offers intelligence far beyond individual seizures. At scale, blockchain analysis can provide authorities with insights into the geopolitical strategies and systemic vulnerabilities of hostile state actors.

Investigative reporting by TRM Labs, for example, exposed how the IRGC allegedly embedded itself within crypto-financial infrastructure, using two United Kingdom-registered cryptocurrency exchanges as corporate fronts to process more than a billion dollars in stablecoin transactions.

The investigation also identified direct transfers exceeding $10 million from this infrastructure to Sa’id Ahmad Muhammad al-Jamal, a designated terrorist financier associated with a smuggling network generating revenue for the Houthi rebels in Yemen.

Such findings illustrate an important evolution in the threat landscape: hostile entities are no longer simply abusing existing cryptocurrency infrastructure. They can also seek to build or control elements of that infrastructure themselves in order to evade sanctions.

Sanctioning Iran’s Crypto Gateways

Armed with blockchain evidence, regulatory bodies and law enforcement agencies can respond at a systemic level. On June 2, 2026, the U.S. Department of the Treasury’s Office of Foreign Assets Control (OFAC) imposed sanctions on four major Iranian cryptocurrency exchanges—Nobitex, Bitpin, Ramzinex, and Wallex—for their alleged roles in facilitating sanctions evasion and terrorist financing.

The action followed on-chain analysis indicating that IRGC-associated addresses accounted for more than 50 percent of the total value received by Iran’s $7.78 billion cryptocurrency ecosystem in late 2025.

Nobitex alone reportedly processed more than half of Iranian digital-asset inflows. By bringing such exchanges within the reach of secondary sanctions, authorities can target the on-ramps and off-ramps through which sanctioned actors connect digital assets to the broader global economy.

Blockchain Evidence as an Enforcement Tool

One of crypto forensics’ greatest strategic advantages is the evidentiary nature of blockchain data. Human intelligence can be incomplete, subjective, contested, or difficult to disclose because of national-security classifications. Blockchain records, by contrast, provide a persistent transactional record that can be independently analyzed and used alongside other evidence to support sanctions designations, asset forfeitures, and criminal investigations.

Technological capabilities, however, must be accompanied by appropriate legal authorities.

Building a Legal Framework for Digital Asset Freezes

The United Kingdom’s amendment of the Proceeds of Crime Act 2002 to introduce specialized Crypto Wallet Freezing Orders (CWFOs) illustrates this evolution. The framework gives British authorities mechanisms to freeze certain digital assets when there are grounds to suspect that they constitute criminal property or are intended for unlawful conduct.

Such legal instruments are increasingly important because the speed of digital-asset transfers means that identifying illicit funds is only part of the challenge. Authorities must also be capable of acting before those assets are transferred elsewhere.

How Heuristic Clustering Reconstructs Hidden Networks

To understand the revolutionary potential of crypto forensics, it is also necessary to examine the mechanics of heuristic clustering and behavioral analysis.

Criminal actors once assumed that generating thousands of unique, single-use cryptocurrency addresses would fragment their financial activity into countless untraceable pieces. Modern forensic platforms, however, can ingest enormous quantities of blockchain data and apply heuristics designed to identify the underlying control structures connecting apparently separate wallets.

If, for example, a terrorist financier consolidates funds from numerous addresses into a single transaction to pay a supplier, forensic software may identify relationships among those addresses and begin reconstructing the larger financial network.

This allows investigators to shift their focus from individual transactions toward the command-and-control nodes of illicit financial systems.

Raising the Cost of Financial Evasion

These capabilities can also affect the adversary’s operational behavior. The sudden freezing of assets and exposure of carefully constructed corporate fronts may force illicit actors to adopt increasingly convoluted laundering techniques, including cross-chain transfers, privacy-enhancing technologies, decentralized protocols, and other mechanisms intended to obscure financial trails.

But additional complexity comes at a price. More elaborate laundering methods can increase transaction costs, slow operations, introduce additional intermediaries, and expose funds to new technological and counterparty risks.

The Stablecoin Vulnerability

The growing use of stablecoins—particularly Tether (USDT)—represents another important evolution in terrorist-financing typologies.

Unlike highly volatile cryptocurrencies, stablecoins offer relatively predictable purchasing power, making them more practical for real-world logistics, salaries, procurement, and cross-border transfers. USDT’s extensive use on the Tron blockchain, where transaction fees have often been lower than on Ethereum, has made the ecosystem particularly important to financial investigators.

Stablecoins also present a distinctive vulnerability for illicit actors: despite operating on public blockchains, many are issued and administered by centralized private entities.

Companies such as Tether possess technical mechanisms capable of freezing certain tokens at the smart-contract level. When authorities identify an address associated with a sanctioned entity and provide sufficient legal and evidentiary grounds, cooperation with an issuer can potentially render the assets inaccessible.

That capability fundamentally alters the risk calculation for terrorist financiers. A wallet may remain under an operative’s nominal control, yet the stablecoins inside it can potentially become unusable if the address is identified, sanctioned, and frozen.

An Escalating Technological Arms Race

The struggle against the IRGC’s digital financial networks nevertheless remains an evolving technological arms race. Adversaries continue to experiment with decentralized cross-chain bridges, coin mixers, privacy-enhancing protocols, and other techniques intended to disrupt the transactional links investigators rely upon.

Yet the illicit cryptocurrency economy retains a fundamental vulnerability: digital assets ultimately have to acquire real-world utility.

Terrorist organizations need weapons, equipment, salaries, transportation, logistics, and other tangible resources. Digital assets therefore frequently intersect with centralized exchanges, over-the-counter brokers, peer-to-peer marketplaces, merchants, or other points at which blockchain activity can potentially be connected to real-world identities.

The Off-Ramps Where Crypto Meets the Real World

It is at these choke points that crypto forensics becomes particularly powerful.

Investigators can combine blockchain tracing with traditional techniques—including open-source intelligence, undercover operations, confidential informants, financial records, and physical surveillance—to connect alphanumeric wallet addresses with the human beings and organizations operating behind them.

By mapping the wider blockchain ecosystem, authorities can move beyond tracing individual payments and identify infrastructure nodes, exchanges, brokers, and service providers supporting illicit financial networks. Targeting those nodes can produce effects far greater than freezing a single transaction.

The Myth of Untraceable Cryptocurrency

The longstanding narrative that cryptocurrency provides an inherently frictionless and untraceable environment for crime is therefore increasingly difficult to sustain. The transparency of public blockchains can make them a rich source of forensic intelligence, particularly when large organizations repeatedly interact with the same financial infrastructure.

For law enforcement agencies charged with protecting national security and the integrity of the global financial system, advanced blockchain analytics can no longer be treated as a niche capability confined to specialized cyber units. It increasingly requires sustained investment in technological infrastructure, personnel training, and international cooperation.

International Cooperation as a Strategic Requirement

The borderless nature of digital assets also means that no country can confront the challenge alone. Effective disruption of the IRGC’s financial networks requires intelligence sharing among allies, greater harmonization of regulatory standards, and close cooperation with financial institutions and cryptocurrency service providers.

As regulators tighten the perimeter around digital assets and require institutions to screen newly designated addresses against customer and transactional data, the operational space available to terrorist financiers can contract considerably.

Retrospective reviews are especially important. Because blockchain records persist, an address identified today can potentially illuminate transactions conducted years earlier. Historical relationships among wallets, exchanges, brokers, and customers can therefore remain relevant long after the original transfer occurred.

Artificial Intelligence and the Future of Crypto Forensics

The next major transformation in crypto forensics is likely to come from artificial intelligence and machine learning.

Rather than relying exclusively on retrospective investigations, AI-assisted forensic systems may increasingly analyze blockchain activity in near real time, searching for behavioral signatures associated with illicit financing—such as unusual transaction sequencing, repeated interactions with high-risk infrastructure, rapid movement through multiple wallets, or other anomalous patterns.

Such systems could allow authorities and compliance teams to identify suspicious financial networks much earlier in their lifecycle.

But technological sophistication must be matched by human expertise. Investigators, prosecutors, compliance officers, and judges will need continuing education in blockchain architecture and forensic methodology so that complex on-chain evidence can be properly interpreted, challenged, and weighed.

No Financial Safe Haven in the Digital Age

Ultimately, the campaign against the IRGC’s financial networks represents part of a broader struggle over the future of illicit finance.

Cryptocurrency has undoubtedly created new mechanisms through which sanctioned and terrorist organizations can move value. At the same time, however, the transparent architecture of public blockchains has created investigative possibilities that have no direct equivalent in traditional finance.

Crypto forensics can therefore serve as a powerful force multiplier for law enforcement: illuminating financial relationships that were once hidden, identifying the infrastructure supporting illicit networks, enabling targeted asset freezes, and connecting digital transactions to the individuals and organizations behind them.

The lesson for the IRGC and other actors seeking financial sanctuary in digital assets is increasingly clear: blockchain technology may provide pseudonymity, but it does not guarantee invisibility.

In the digital age, transparency—when combined with sophisticated forensic tools, effective legal authorities, private-sector cooperation, and coordinated international enforcement—can become one of the most powerful weapons against the financial machinery of terrorism.

FAQ
Why can cryptocurrency be easier to trace than traditional illicit finance?
Many public blockchains permanently record transactions on transparent ledgers, allowing investigators to reconstruct transaction histories and analyze relationships among wallets even years later.
Can authorities actually freeze cryptocurrency?
In some circumstances, yes. Centralized exchanges can restrict accounts, and issuers of certain stablecoins can freeze tokens associated with identified addresses when appropriate legal and evidentiary requirements are met.
Can criminals defeat crypto forensics by using more sophisticated technology?
Privacy tools, cross-chain transfers, mixers, and decentralized protocols can make tracing more difficult, but illicit funds generally need to interact eventually with exchanges, brokers, merchants, or other real-world infrastructure. Those points can create opportunities to connect blockchain activity with identifiable people and organizations.

Ella Rosenberg

Ella Rosenberg, a senior research fellow at the JCFA, and a Dvorah Forum member, focuses her research on Iran and counter terror financing. A graduate from Maastricht and Erasmus University, Rotterdam, Ella has pioneered the way for EU AML and CTF in Israel and the GCC, while licensing financial institutions in the same areas, designed regtech software for the public and private sector, and has consulted attorney generals worldwide on crypto and financial investigations.
Share this

Invest in JCFA

Subscribe to Daily Alert

The Daily Alert – Israel news digest appears every Sunday, Tuesday, and Thursday.

Related Items

Stay Informed, Always

Subscribe to Jerusalem Issue Briefs
Concise analytical papers focusing on Israeli security, diplomacy, and foreign policy.
The highly-acclaimed Daily Alert Israel news digest includes the most important and timely articles from around the world on Israel, the Middle East and U.S. policy.