What the rise, fall, and rapid rebirth of eXch tells us about the real shape of crypto crime in 2026

Every few months, a crypto exchange gets “shut down.” Headlines run. LinkedIn fills with hot takes. And then, quietly, the money keeps moving. That’s the story I want to walk through today — not as a hypothetical, but as a documented pattern, backed by the two firms that actually trace this money for a living: TRM Labs and Chainalysis.

Throughout my career in technology governance, cyber risk, enterprise transformation, and technology leadership, this case study has become one of the clearest examples of a lesson every risk leader eventually learns: shutting down a bad actor is not the same as dismantling the capability behind it.

The Exchange That Wouldn’t Stay Dead:

eXch was a no-questions-asked crypto swap service. No ID verification. No meaningful compliance program. It marketed that absence as a feature — a “privacy project,” as it called itself — rather than what regulators would call it: a gap.

That gap became national news in February 2025, when North Korea’s Lazarus Group pulled off the largest crypto theft in history: roughly $1.4–1.5 billion in Ethereum (ETH), stolen from the Bybit exchange.1 Bybit and blockchain investigators — Elliptic, TRM, and independent researcher ZachXBT — all pointed to the same off-ramp: eXch allegedly helped launder more than $90 million of it.2

eXch’s owner, publicly known only as “Johann Roberts,” denied it, then partly admitted it, then blamed a slow compliance data feed. For what it’s worth, I looked for a verified real identity behind that name while researching this piece. I couldn’t find one. Treat it as an alias until proven otherwise.

In April 2025, eXch announced it was shutting down — citing, of all things, a DOJ whistleblower and a “transatlantic law enforcement operation.” Here’s the part almost nobody covered: it didn’t actually stop. TRM Labs found that eXch pulled its public website but kept serving business partners through an API, with the same laundering fingerprints continuing right past its own announced shutdown date.3

This Isn’t One Bad Exchange; it’s a Lineage:

If eXch feels like an isolated case, look at what happened to Garantex, the Russian exchange sanctioned back in 2022 for laundering funds tied to darknet markets and ransomware groups like Conti and Hydra. Law enforcement finally seized it in March 2025 — after it had processed an estimated $96 billion since 2019, with at least $1.3 billion of that tied directly to criminal activity.4

What happened next is the whole point of this article. Garantex didn’t disappear. It became Grinex — same liquidity, same users, same money, new name. Then Chainalysis and TRM traced the same pattern into ABCeX and its rebrand AEXBit (identical backend infrastructure, shared hot wallets), the A7/A7A5 payment network ($93.3 billion in on-chain volume and counting), and Heleket — a “new” service that received its opening liquidity directly from Garantex’s own wallets.5

TRM’s own read on this, stated plainly in their 2026 report: this wave of rebrands is likely coordinated — an attempt to keep Russia’s crypto liquidity flowing while insulating the actual operators from further sanctions.1 For what it’s worth, Grinex itself reportedly went dark in April 2026 after a $13.7 million cyberattack. I’d bet money there’s already a successor.4

The Bigger Story Nobody’s Talking About Enough:

Here’s what I think most crypto-crime coverage still misses: individual rogue exchanges, however dramatic, are no longer the main event.

Both TRM and Chainalysis now point to something structurally different — Chinese-language money laundering networks, or CMLNs. In 2025 alone, these networks moved an estimated $16.1 billion — about $44 million a day — across nearly 1,800 active wallets. That’s not a typo: Chainalysis measured CMLN growth at roughly 7,325 times the growth rate of illicit inflows to centralized exchanges since 2020.6

The anchor of this ecosystem is Huione Group, a Cambodian conglomerate that took in over $98 billion in crypto between August 2021 and January 2025 — more than $4 billion of it confirmed illicit. In October 2025, the U.S. Treasury’s FinCEN designated Huione under Section 311 of the Patriot Act as a primary money laundering concern. Huione is also directly tied to Prince Group, the Cambodia-based criminal network behind a sprawling web of scam compounds across Southeast Asia.7

Why does this matter more than another exchange takedown? Because CMLNs aren’t one company you can seize. They’re a marketplace — fragmentation services, OTC desks, “guarantee” platforms like Huione and Xinbi that connect buyers and sellers of laundering capacity without necessarily touching the illicit funds themselves. Sanction one vendor, and the marketplace barely notices.6

Ransomware Isn’t Slowing Down — It’s Diversifying:

A few numbers that stuck with me from Chainalysis’s ransomware-specific analysis: data-leak-site-claimed ransomware incidents grew 50% year-over-year in 2025, an all-time high, even as enforcement intensified. The Ransomware-as-a-Service market itself has fragmented into as many as 85 active independent extortion groups — harder to track as a whole, even as their individual laundering habits become more identifiable on-chain.8

Final-stage laundering increasingly runs through no-KYC exchanges (up 82%) and “guarantee” aggregators like Tudou Danbao (up 87%). Interestingly, North Korean state actors use no-KYC exchanges noticeably less than independent cybercriminals do — a sign that DPRK runs its own specialized, tightly controlled pipeline through CMLNs and bridge protocols, rather than mixing in with the same rogue exchanges everyone else uses.8

And enforcement is starting to catch up to the infrastructure layer, not just the exchanges. OFAC, alongside the UK and Australia, sanctioned Zservers and Aeza Group in 2025 — Russian “bulletproof hosting” providers that knowingly host ransomware infrastructure. Zservers alone funneled at least $5.2 million through high-risk channels including Garantex.4

What This Actually Means:

If you take one thing from this: the “shut it down” model of enforcement works — temporarily. eXch kept running through its own back door. Garantex became Grinex became ABCeX became AEXBit. The harder, more important fight is against the marketplace model — CMLNs, guarantee platforms, and the hosting infrastructure underneath all of it — which doesn’t have one throat to choke.

The good news, and it’s real: blockchain transparency is still the investigators’ structural advantage. The same on-chain fingerprinting — shared wallets, co-spending patterns, infrastructure overlap — that unmasked ABCeX as a Garantex clone will eventually do the same to whatever comes after Grinex, and whatever comes after that.

This case study reflects the type of governance-under-adversarial-pressure challenge I frequently research and write about: how do we design governance, oversight, and risk management frameworks for ecosystems that are intentionally engineered to evade them? Addressing that challenge will require a coordinated, multi-layered approach — including end-to-end mapping of cryptocurrency transaction chains, stronger Know Your Customer (KYC) and Anti-Money Laundering (AML) controls, improved multinational cooperation among regulators and law enforcement, more robust misuse-case modeling to anticipate adversarial behavior, and broader identification and blacklisting of high-risk exchanges, wallets, and tokens that repeatedly facilitate illicit finance.

References:

1. TRM Labs, “2026 Crypto Crime Report” (TRM Labs, 2026), https://www.trmlabs.com/reports-and-whitepapers/2026-crypto-crime-report.

2. Decrypt, The Block, and CryptoRank.io, contemporaneous news coverage of the Bybit hack and eXch’s role in laundering stolen funds, February–March 2025.

3. TRM Labs, “eXch Remains Active Despite Shutdown: How the Bybit Hack-Linked Exchange Continues to Enable Laundering of CSAM Funds” (TRM Labs Blog, May 2, 2025), https://www.trmlabs.com/resources/blog.

4. Chainalysis, “OFAC Sanctions Tracker: How Sanctions Impact Crypto Crime” (Chainalysis Blog), https://www.chainalysis.com/blog/ofac-sanctions/.

5. TRM Labs, “2026 Crypto Crime Report” (TRM Labs, 2026), https://www.trmlabs.com/reports-and-whitepapers/2026-crypto-crime-report.

6. Chainalysis, “The Chinese-Language Underground Crypto Money Laundering Ecosystem” (Chainalysis Blog, January 27, 2026), https://www.chainalysis.com/blog/2026-crypto-money-laundering/.

7. Chainalysis, “Crypto Sanctions: 2026 Crypto Crime Report” (Chainalysis Blog, 2026), https://www.chainalysis.com/blog/crypto-sanctions-2026/.

8. Chainalysis, “Crypto Ransomware: 2026 Crypto Crime Report” (Chainalysis Blog, March 4, 2026), https://www.chainalysis.com/blog/crypto-ransomware-2026/.

What is Crypto-Currency Malware And How Do You Prevent It?

As crypto-currency enters the mainstream cyber-criminals are using crypto-mining malware (Fig. 1) to infect websites and devices ranging from smartphones to servers. All of this is dependent on a strong understanding of bitcoin mining in the blockchain as described below.

Fig. 1. Bitcoin Crypto-Jacking Threat Actor.
bigstock-221140084-940x500

Every ten to fifteen minutes mining computers collect hundreds of waiting bitcoin transactions (a block) and then convert them into mathematical puzzles. The first miner to find the puzzle solution shares it with others on the network. Then other miners check whether the sender of the funds has the right to spend the money and if the solution to the puzzle is correct. If enough of them grant their approval, the block is crypto-graphically added to the ledger and the miners move on to the next set of transactions (hence the term “blockchain”). The miner who found the solution gets 12.5 bitcoins as a reward (presently), but only after another 99 blocks have been added to the ledger. This is the incentive to participate in the system and validate these transactions (L.S., The Economist, 2015).

Clever as it may be, this system has weaknesses. One is rapid consolidation. Most mining power today is provided by pools—big groups of miners who combine their computing power to increase the chance of winning the coin reward. As mining pools have gotten bigger, it no longer seems inconceivable that one of them might amass enough capacity to mount a 51% attack—whereby an organization is somehow able to control most of the network mining power (hashrate). Bitcoin is secured by having all miners (computers processing the networks transactions). Indeed, in June 2014 one pool, GHash.IO, had the bitcoin community running scared by briefly touching that level before some users voluntarily switched to other pools.

As the bitcoin price continues to fall, consolidation could become more of a problem. Some miners are giving up because the rewards of mining no longer cover the costs. Some worry that mining will become concentrated in a few countries where electricity is cheap, like China, thus allowing a hostile government to seize control of bitcoin. Others predict that mining will end up as a monopoly—the exact opposite of the decentralized system that the elusive Bitcoin founder Mr. Nakamoto set out to create.

Fig. 2.  General Crypto-Jacking Attack Flow. (Sugata Ghosh, ET Bureau, 05/11/2018).

Cryptojacking
With a strong understanding of blockchain technology, crypto-mining malware attacks and infects websites and devices ranging from smartphones to servers in one of these three common but not exhaustive ways.

1) Sneaking dedicated crypto-mining software into your network via unpatched and out of date server vulnerabilities. Servers are especially at risk here: the crooks love them because they’re usually more powerful than desktops and laptops, and they’re usually running 24/7. Old mid-sized data centers are at high risk because they often have minimal defenses.

2) Sneaking JavaScript crypto-mining software into hacked web pages via cross side scripting (forms and comment fields) and WordPress plug-in vulnerabilities—hard to keep track of because there are so many. Then your browser mines for currency as you surf the web. The crooks get much less out of each victim – as soon as you leave the poisoned website, the mining stops – but a single hacked site could end up crypto-jacking millions of visitors each day, whatever operating system they’re using.

3) Mobile application exploits—twenty-four Android apps recently (Sept 2018) made it into the Google Play store with code that turns users’ phones into crypto-currency mining workers. Some of them targeted users in the U.S. by using the guise of educational tools—they have been download around 120,000 times (Bleeping Computer, Ionut Ilascu, 09/28/18).

Crypto-jacking malware on enterprises running thousands of computers can disturb the daily operations of the business and even damage the hardware. In February 2018, Crypto-currency mining malware CoinHive was found on more than 5,000 government websites (Fig 3.) in the U.K., U.S., and Australia (Patrick Greenfield, The Guardian, 02/11/18).

Fig. 3. CoinHive JavaScript Crypto-jacking Malware (GitHub).
CoinHive Cryptojacking
At present, CoinHive is easy to deploy and generated hundreds of thousands of dollars in its first month, so its arguably easy money for the attacker. In support of this conclusion RWTH Aachen University in Germany added: “embedded crypto-currency miner CoinHive is generating $250 thousand worth of Monero every month – most of it going to just 10 individuals. Moreover, they found that Monero accounts for 75 percent (Fig 3.) of all browser-based crypto-currency mining (David Canellis, TNW, 08/14/2018).

Once infected, the crypto-mining malware uses hosts CPU / GPU power to mine coins thus allowing cyber-criminals to grow their personal wallets. According to McAfee Labs crypto-mining malware attacks increased by 1,189% in Q1 2018. Attackers are getting smarter, instead of a one-time payment from ransomware, they prefer the long game and a steady revenue stream from infected devices (McAfee Labs Threats Report, June 2018). Crypto-mining is in its infancy and thus there’s a lot of room for growth and evolution over the next few years.

Oftentimes crypto-jacking goes undetected as attackers find new ways to infect the devices.

Yet here are the top three indicators that a machine is infected with crypto-malware:

1.    The device is acting unusually slow.

2.    Smartphone or personal computer constantly overheats.

3.    The battery on laptop or phone dies unreasonably fast.

In today’s threat landscape here are the top five things you can do to prevent crypto-jacking:

1.    Run the most up-to-date anti-malware and antivirus programs. Ideally a strong one like Avast.

2.    If your device significantly slows down when you’re on a certain site close it and check it again. It may be an infected website especially if you get a bunch on pop-ups.

3.    Install web browser anti-crypto-mining extensions.

4.    Use AI driven network monitoring software (SecBl, Darktrace, etc). Mostly for servers not so much individual PCs.

5.    Disable JavaScript to prevent in-browser crypto-jacking. On side effect is that you will not be able to view all sites in an optimal way.

By Jeremy Swenson & Andrew Erkomaishvili