Every few months, a crypto exchange gets “shut down.” Headlines run. LinkedIn fills with hot takes. And then, quietly, the money keeps moving. That’s the story I want to walk through today — not as a hypothetical, but as a documented pattern, backed by the two firms that actually trace this money for a living: TRM Labs and Chainalysis.
Throughout my career in technology governance, cyber risk, enterprise transformation, and technology leadership, this case study has become one of the clearest examples of a lesson every risk leader eventually learns: shutting down a bad actor is not the same as dismantling the capability behind it.
The Exchange That Wouldn’t Stay Dead:
eXch was a no-questions-asked crypto swap service. No ID verification. No meaningful compliance program. It marketed that absence as a feature — a “privacy project,” as it called itself — rather than what regulators would call it: a gap.
That gap became national news in February 2025, when North Korea’s Lazarus Group pulled off the largest crypto theft in history: roughly $1.4–1.5 billion in Ethereum (ETH), stolen from the Bybit exchange.1 Bybit and blockchain investigators — Elliptic, TRM, and independent researcher ZachXBT — all pointed to the same off-ramp: eXch allegedly helped launder more than $90 million of it.2
eXch’s owner, publicly known only as “Johann Roberts,” denied it, then partly admitted it, then blamed a slow compliance data feed. For what it’s worth, I looked for a verified real identity behind that name while researching this piece. I couldn’t find one. Treat it as an alias until proven otherwise.
In April 2025, eXch announced it was shutting down — citing, of all things, a DOJ whistleblower and a “transatlantic law enforcement operation.” Here’s the part almost nobody covered: it didn’t actually stop. TRM Labs found that eXch pulled its public website but kept serving business partners through an API, with the same laundering fingerprints continuing right past its own announced shutdown date.3
This Isn’t One Bad Exchange; it’s a Lineage:
If eXch feels like an isolated case, look at what happened to Garantex, the Russian exchange sanctioned back in 2022 for laundering funds tied to darknet markets and ransomware groups like Conti and Hydra. Law enforcement finally seized it in March 2025 — after it had processed an estimated $96 billion since 2019, with at least $1.3 billion of that tied directly to criminal activity.4
What happened next is the whole point of this article. Garantex didn’t disappear. It became Grinex — same liquidity, same users, same money, new name. Then Chainalysis and TRM traced the same pattern into ABCeX and its rebrand AEXBit (identical backend infrastructure, shared hot wallets), the A7/A7A5 payment network ($93.3 billion in on-chain volume and counting), and Heleket — a “new” service that received its opening liquidity directly from Garantex’s own wallets.5
TRM’s own read on this, stated plainly in their 2026 report: this wave of rebrands is likely coordinated — an attempt to keep Russia’s crypto liquidity flowing while insulating the actual operators from further sanctions.1 For what it’s worth, Grinex itself reportedly went dark in April 2026 after a $13.7 million cyberattack. I’d bet money there’s already a successor.4
The Bigger Story Nobody’s Talking About Enough:
Here’s what I think most crypto-crime coverage still misses: individual rogue exchanges, however dramatic, are no longer the main event.
Both TRM and Chainalysis now point to something structurally different — Chinese-language money laundering networks, or CMLNs. In 2025 alone, these networks moved an estimated $16.1 billion — about $44 million a day — across nearly 1,800 active wallets. That’s not a typo: Chainalysis measured CMLN growth at roughly 7,325 times the growth rate of illicit inflows to centralized exchanges since 2020.6
The anchor of this ecosystem is Huione Group, a Cambodian conglomerate that took in over $98 billion in crypto between August 2021 and January 2025 — more than $4 billion of it confirmed illicit. In October 2025, the U.S. Treasury’s FinCEN designated Huione under Section 311 of the Patriot Act as a primary money laundering concern. Huione is also directly tied to Prince Group, the Cambodia-based criminal network behind a sprawling web of scam compounds across Southeast Asia.7
Why does this matter more than another exchange takedown? Because CMLNs aren’t one company you can seize. They’re a marketplace — fragmentation services, OTC desks, “guarantee” platforms like Huione and Xinbi that connect buyers and sellers of laundering capacity without necessarily touching the illicit funds themselves. Sanction one vendor, and the marketplace barely notices.6
Ransomware Isn’t Slowing Down — It’s Diversifying:
A few numbers that stuck with me from Chainalysis’s ransomware-specific analysis: data-leak-site-claimed ransomware incidents grew 50% year-over-year in 2025, an all-time high, even as enforcement intensified. The Ransomware-as-a-Service market itself has fragmented into as many as 85 active independent extortion groups — harder to track as a whole, even as their individual laundering habits become more identifiable on-chain.8
Final-stage laundering increasingly runs through no-KYC exchanges (up 82%) and “guarantee” aggregators like Tudou Danbao (up 87%). Interestingly, North Korean state actors use no-KYC exchanges noticeably less than independent cybercriminals do — a sign that DPRK runs its own specialized, tightly controlled pipeline through CMLNs and bridge protocols, rather than mixing in with the same rogue exchanges everyone else uses.8
And enforcement is starting to catch up to the infrastructure layer, not just the exchanges. OFAC, alongside the UK and Australia, sanctioned Zservers and Aeza Group in 2025 — Russian “bulletproof hosting” providers that knowingly host ransomware infrastructure. Zservers alone funneled at least $5.2 million through high-risk channels including Garantex.4
What This Actually Means:
If you take one thing from this: the “shut it down” model of enforcement works — temporarily. eXch kept running through its own back door. Garantex became Grinex became ABCeX became AEXBit. The harder, more important fight is against the marketplace model — CMLNs, guarantee platforms, and the hosting infrastructure underneath all of it — which doesn’t have one throat to choke.
The good news, and it’s real: blockchain transparency is still the investigators’ structural advantage. The same on-chain fingerprinting — shared wallets, co-spending patterns, infrastructure overlap — that unmasked ABCeX as a Garantex clone will eventually do the same to whatever comes after Grinex, and whatever comes after that.
This case study reflects the type of governance-under-adversarial-pressure challenge I frequently research and write about: how do we design governance, oversight, and risk management frameworks for ecosystems that are intentionally engineered to evade them? Addressing that challenge will require a coordinated, multi-layered approach — including end-to-end mapping of cryptocurrency transaction chains, stronger Know Your Customer (KYC) and Anti-Money Laundering (AML) controls, improved multinational cooperation among regulators and law enforcement, more robust misuse-case modeling to anticipate adversarial behavior, and broader identification and blacklisting of high-risk exchanges, wallets, and tokens that repeatedly facilitate illicit finance.
References:
1. TRM Labs, “2026 Crypto Crime Report” (TRM Labs, 2026), https://www.trmlabs.com/reports-and-whitepapers/2026-crypto-crime-report.
2. Decrypt, The Block, and CryptoRank.io, contemporaneous news coverage of the Bybit hack and eXch’s role in laundering stolen funds, February–March 2025.
3. TRM Labs, “eXch Remains Active Despite Shutdown: How the Bybit Hack-Linked Exchange Continues to Enable Laundering of CSAM Funds” (TRM Labs Blog, May 2, 2025), https://www.trmlabs.com/resources/blog.
4. Chainalysis, “OFAC Sanctions Tracker: How Sanctions Impact Crypto Crime” (Chainalysis Blog), https://www.chainalysis.com/blog/ofac-sanctions/.
5. TRM Labs, “2026 Crypto Crime Report” (TRM Labs, 2026), https://www.trmlabs.com/reports-and-whitepapers/2026-crypto-crime-report.
6. Chainalysis, “The Chinese-Language Underground Crypto Money Laundering Ecosystem” (Chainalysis Blog, January 27, 2026), https://www.chainalysis.com/blog/2026-crypto-money-laundering/.
7. Chainalysis, “Crypto Sanctions: 2026 Crypto Crime Report” (Chainalysis Blog, 2026), https://www.chainalysis.com/blog/crypto-sanctions-2026/.
8. Chainalysis, “Crypto Ransomware: 2026 Crypto Crime Report” (Chainalysis Blog, March 4, 2026), https://www.chainalysis.com/blog/crypto-ransomware-2026/.








