What the rise, fall, and rapid rebirth of eXch tells us about the real shape of crypto crime in 2026

Every few months, a crypto exchange gets “shut down.” Headlines run. LinkedIn fills with hot takes. And then, quietly, the money keeps moving. That’s the pattern I want to walk through here—not as a hypothetical, but as a documented case, built on the work of the two firms that actually trace this money for a living: TRM Labs and Chainalysis.

Across my career in technology governance, cyber risk, enterprise transformation, and technology leadership, this particular case study has become one of the clearest illustrations of a lesson every risk leader eventually learns the hard way: shutting down a bad actor is not the same as dismantling the capability behind it. The organization goes away. The infrastructure, the liquidity, and the operators very often do not.

The Exchange That Wouldn’t Stay Dead:

eXch was a no-questions-asked crypto swap service. No identity verification, no meaningful compliance program—and it marketed that absence as a feature, branding itself a “privacy project” rather than what regulators would call it: a gap in the system, wide open and waiting to be used.

That gap became national news in February 2025, when North Korea’s Lazarus Group pulled off the largest crypto theft in history, stealing roughly $1.4 to $1.5 billion in Ethereum from the Bybit exchange.1 Bybit and independent investigators—including Elliptic, TRM Labs, and researcher ZachXBT—all pointed to the same off-ramp: eXch allegedly helped launder more than $90 million of the stolen funds.2

eXch’s owner, publicly known only as “Johann Roberts,” denied it, then partially admitted it, then blamed a slow compliance data feed. For what it’s worth, I went looking for a verified identity behind that name while researching this piece. I couldn’t find one. Treat it as an alias until proven otherwise.

In April 2025, eXch announced it was shutting down—citing, of all things, a DOJ whistleblower and a “transatlantic law enforcement operation.” Here’s the part almost nobody covered: it didn’t actually stop. TRM Labs found that eXch pulled its public-facing website but kept serving business partners through an API, with the same laundering fingerprints continuing right past its own announced shutdown date.3

This Isn’t One Bad Exchange—It’s a Lineage:

If eXch feels like an isolated case, look at what happened to Garantex, the Russian exchange first sanctioned in 2022 for laundering funds tied to darknet markets and ransomware groups like Conti and Hydra. Law enforcement finally seized its infrastructure in March 2025, after the platform had processed an estimated $96 billion in transactions since 2019, a substantial share of it tied to ransomware, darknet-market, and other criminal activity.4

What happened next is the whole point of this article. Garantex didn’t disappear. It became Grinex—same liquidity, same users, same money, new name. Chainalysis and TRM then traced the same pattern into ABCeX and its rebrand AEXBit, which share identical backend infrastructure and hot wallets with their predecessors; into the A7/A7A5 ruble-backed payment network, which has moved more than $93.3 billion in on-chain volume and counting; and into Heleket, a “new” service that received its opening liquidity directly from Garantex’s own wallets.5

TRM’s own assessment, stated plainly in its 2026 crypto crime report, is that this wave of rebrands is likely coordinated—a deliberate attempt to keep Russia’s crypto liquidity flowing while insulating the actual operators from further sanctions.6 For what it’s worth, Grinex itself went dark in April 2026 after a $13.7 million cyberattack it blamed, without evidence, on Western intelligence agencies.7 I’d bet money there’s already a successor standing by.

The Bigger Story Nobody’s Talking About Enough:

Here’s what I think most crypto-crime coverage still misses: individual rogue exchanges, however dramatic the headline, are no longer the main event.

Both TRM and Chainalysis now point to something structurally different—Chinese-language money laundering networks, or CMLNs. In 2025 alone, these networks moved an estimated $16.1 billion, roughly $44 million a day, across nearly 1,800 active wallets. That’s not a typo: Chainalysis measured CMLN growth at roughly 7,325 times the growth rate of illicit inflows to centralized exchanges since 2020.8

The anchor of this ecosystem is Huione Group, a Cambodia-based conglomerate that processed more than $98 billion in total crypto inflows between August 2021 and January 2025, over $4 billion of it confirmed illicit. In October 2025, the U.S. Treasury’s FinCEN designated Huione under Section 311 of the USA PATRIOT Act as a primary money laundering concern. Huione is also directly tied to Prince Group, the Cambodia-based criminal network behind a sprawling web of scam compounds across Southeast Asia.9

Why does this matter more than another exchange takedown? Because CMLNs aren’t one company you can seize. They’re a marketplace—fragmentation services, OTC desks, and “guarantee” platforms like Huione and Xinbi that connect buyers and sellers of laundering capacity, often without the platform operators ever directly touching the illicit funds themselves. Sanction one vendor, and the rest of the marketplace barely notices.10

Ransomware Isn’t Slowing Down—It’s Diversifying:

Data-leak-site-claimed ransomware incidents grew 50 percent year-over-year in 2025, reaching an all-time high even as enforcement activity intensified.11 The Ransomware-as-a-Service market has also fragmented, with some trackers counting as many as 85 active independent extortion groups—a more decentralized field that’s harder to monitor collectively, even as individual groups’ laundering patterns become easier to fingerprint on-chain.12

Separately, broader Chainalysis research on illicit crypto flows (not specific to ransomware) points to a shift in final-stage laundering toward exchanges with little to no know your customer (KYC) verification, with no-KYC exchange usage up 82 percent and usage of “guarantee” aggregators such as Tudou Danbao up 87 percent.13 Whether North Korean state actors rely on these no-KYC exchanges less than independent cybercriminals do—running a more specialized pipeline through Chinese money-laundering networks and bridge protocols instead—is a plausible pattern given DPRK’s well-documented use of dedicated laundering infrastructure. But it isn’t a claim I found directly confirmed in the sources reviewed for this piece, so I’m flagging it as a reasonable hypothesis rather than an established fact.

Enforcement has also started targeting the infrastructure layer itself, not just individual exchanges. In February 2025, the U.S., U.K., and Australia jointly sanctioned Zservers, a Russian bulletproof-hosting provider tied to ransomware operations including LockBit; Chainalysis data shows Zservers funneled at least $5.2 million through high-risk channels, including the sanctioned exchange Garantex.14 OFAC separately sanctioned Aeza Group, another Russian bulletproof host, in July 2025—though, notably, that action does not appear to have included the U.K. and Australia as co-sanctioning parties.15

What This Actually Means:

If you take one thing from this, let it be this: the “shut it down” model of enforcement works—temporarily. eXch kept running through its own back door. Garantex became Grinex became ABCeX became AEXBit. The harder, more consequential fight is against the marketplace model itself—the CMLNs, the guarantee platforms, and the hosting infrastructure underneath all of it—which doesn’t have one throat to choke.

The good news, and it’s a real one, is that blockchain transparency remains investigators’ structural advantage. The same on-chain fingerprinting—shared wallets, co-spending patterns, infrastructure overlap—that unmasked ABCeX as a Garantex clone will eventually do the same to whatever comes after Grinex, and whatever comes after that.

This case study reflects the kind of governance-under-adversarial-pressure challenge I spend a lot of time researching and writing about: how do we design governance, oversight, and risk management frameworks for ecosystems that are deliberately engineered to evade them? Answering that will take a coordinated, multi-layered response—end-to-end mapping of cryptocurrency transaction chains, stronger Know Your Customer and Anti-Money Laundering controls, deeper multinational cooperation among regulators and law enforcement, more rigorous misuse-case modeling to anticipate adversarial behavior, and broader, faster identification and blacklisting of the high-risk exchanges, wallets, and tokens that keep facilitating illicit finance long after their predecessors are supposedly gone.

Endnotes:

1. TRM Labs, “2026 Crypto Crime Report” (TRM Labs, 2026), https://www.trmlabs.com/reports-and-whitepapers/2026-crypto-crime-report.

2. Decrypt, The Block, and CryptoRank.io, contemporaneous news coverage of the Bybit hack and eXch’s role in laundering stolen funds, February–March 2025.

3. TRM Labs, “eXch Remains Active Despite Shutdown: How the Bybit Hack-Linked Exchange Continues to Enable Laundering of CSAM Funds” (TRM Labs Blog, May 2, 2025), https://www.trmlabs.com/resources/blog.

4. Chainalysis, “OFAC Sanctions Tracker: How Sanctions Impact Crypto Crime” (Chainalysis Blog), https://www.chainalysis.com/blog/ofac-sanctions/.

5. TRM Labs, “2026 Crypto Crime Report.”

6. TRM Labs, “2026 Crypto Crime Report.”

7. TRM Labs, “2026 Crypto Crime Report.”

8. Chainalysis, “The Chinese-Language Underground Crypto Money Laundering Ecosystem” (Chainalysis Blog, January 27, 2026), https://www.chainalysis.com/blog/2026-crypto-money-laundering/.

9. Chainalysis, “Crypto Sanctions: 2026 Crypto Crime Report” (Chainalysis Blog, 2026), https://www.chainalysis.com/blog/crypto-sanctions-2026/.

10. Chainalysis, “The Chinese-Language Underground Crypto Money Laundering Ecosystem.”

11. Chainalysis, “Crypto Ransomware: 2026 Crypto Crime Report” (Chainalysis Blog, March 4, 2026), https://www.chainalysis.com/blog/crypto-ransomware-2026/.

12. Chainalysis, “Crypto Ransomware: 2026 Crypto Crime Report.”

13. Chainalysis, “2025 Crypto Theft Reaches $3.4 Billion” (Chainalysis Blog, December 18, 2025), https://www.chainalysis.com/blog/crypto-hacking-stolen-funds-2026/.

14. Chainalysis, “OFAC Sanctions Tracker.”

15. Chainalysis, “OFAC Sanctions Tracker.”

The Main Purpose of Cryptocurrency Mixer and/or Splitter Services is Fraud and Money Laundering.

Cryptocurrency mixer and/or splitter services serve no valid “real-world” ethical business use case considering the relevant FinTech and legal options open. Even in the very rare case when you are a refugee fleeing a financially abusive government regime or terrorist organization is seeking to steal your assets while the national currency is failing, like in Venezuela which I wrote about in my 2014 article; that is about political revolution and your personal safety more than anything else. Although cases like this give a valid reason why you might want to mix and/or split your crypto assets – that’s not fully the same use case we’re talking about here with the recent uptick of crypto mixer and/or splitter service use. It’s only fair that we discuss the most likely and common use case, which is trending up, and not the few rare edge cases. This use case would be fraud and money laundering.

The evidence does not support that a regular crypto exchange is the same thing as a mixer and/or splitter service. For definitions sake, I am not defining mixing and/or splitting cryptocurrency as the same thing as selling, buying, or converting it – all of this can be done on one or more of the crypto exchanges which is why they are called exchanges. If they are the same or even considerably similar, then why are people and orgs using the mixer and/or splitter services at all? They use them because they offer a considerably different service. Using a mixer and/or splitter services assumes you have gotten some crypto beforehand, from a separate exchange, a step or more before in the daisy chain. This can be done via legal or illegal means. Moreover, why are they paying repeated and hugely excessive fees for these services? The fees are out of line with anything possibly comparable because there is higher compliance and legal risk for the operators of them in that they could get sanctioned like Blender.IO and others.

You can still have privacy if that is what you are seeking via a semblance of legal moves such as a trust tied to a separate legal entity, family office entity, converting to real estate, and marriage entity – if you have time to do the paperwork. Legally savvy people have anonymity over their assets often to avoid fraudsters, sales reps, and just privacy for privacy’s sake – but again still not the same use case. Even when people/orgs use these legal instruments for privacy, they still have compliance reporting and tax obligations – I.E., some disclosure. Keep in mind some disclosure serves to protect you that you in fact own the assets you say you own. Using these legal instruments with the right technical security including an encrypted VPN and multifactor authentication serves to sustain privacy, and you will then not need a crypto mixer and/or splitter.

Yet if you had cryptocurrency and wanted strong privacy to protect your assets, why would you not at least use some of the aforementioned legal instruments or the like? Mostly because any attorney worth anything would be obligated to report this blatant suspected fraud, and would not want to tarnish their name on the filings, etc. Specifically, the attorney would have to see and know where and what entities the crypto was coming from and going to, under what contexts, and that could trigger them to report or refuse to work with them – I.E. a fraudster would want to avoid getting detected.

Specifically, the use of multiple legal entities in different countries in a daisy chain of crypto coin mixing and/or splitting tends to be the pattern for persistent fraud and money laundering. That was the case in the $4.5-billion-dollar crypto theft out of NY and in Blender mixing fraud, and many other cases.

A recent U.S. Treasury press release concerning mixer service money laundering described it this way:

  • “Blended.io (Blender) is a virtual currency mixer that operates on the Bitcoin blockchain and indiscriminately facilitates illicit transactions by obfuscating their origin, destination, and counterparties. Blender receives a variety of transactions and mixes them together before transmitting them to their ultimate destinations. While the purported purpose is to increase privacy, mixers like Blender are commonly used by illicit actors. Blender has helped transfer more than $500 million worth of Bitcoin since its creation in 2017. Blender was used in the laundering process for DPRK’s Axie Infinity heist, processing over $20.5 million in illicit proceeds”.
Fig 1. U.S. Treasury Dept, Blener.io Crypto Mixer Fraud, 2022.

The question we as a society should be thinking about is tech ethics. What design feature crosses the line to enable fraud too much such that it is not pursued? For example, Silk Road crossed the line, selling illegal drugs, extortion, and other crime. Hacker networks cross the line when they breach companies and steal their credit card data and put it for sale on the dark web. Facebook crossed the line when it enabled bias and undue favor to impact policy outcomes.

Crypto mixer and/or splitter services (not mere crypto exchanges) are about as close to “money laundering as a service” as it gets – relative to anything else technically available excluding the dark web where there are far worse things available technically. Obviously, the developers, product owners, and project managers behind the crypto mixer and/or splitter services like this are serving the fraud and money laundering use case more than anything else. Some semblance of the organized crime rings is very likely giving them money and direction to this end.

If you are for and use mixer and/or splitter services then you run the risk of having your digital assets mixed with dirty digital assets, you have extortion high fees, you have zero customer service, no regulatory protection, no decedent Terms of Service and/or Privacy Policy if any, and you have no guarantee that it will even work the way you think it will.

In fact, you have so much decentralized “so-called” privacy that it could work against you. For example, imagine you pay the high fees to mix and split your crypto multiple times, and then your crypto is stolen by one of the mixing and/or splitting services. This is likely because they know many of their customers are committing fraud and money laundering, yet even if they are not these platforms are associated with that. Therefore, if the platform operators steal their crypto in this process, the victims have little incentive to speak up. Moreover, the mixing and/or splitting service companies have a nice cover to steal it, privacy. They won’t admit that they stole it but will say something like “everything is private and so we can’t see or know but you are responsible for what private assets you have or don’t have”. They will say something like “stealing it is impossible” which is course is a complete lie.

In sum, what reason do you have to trust a crypto mixing and/or splitting service with your digital assets as outlined above as they are hardly incentivized to protect them or you and operate in the shadows of antiquated non-western fintech regulation. So, what really do you get besides likely fraud? What is the business rationale behind using these services as outlined above considering no solid argument or evidence can support it is privacy alone, and what net benefit do you get besides business-enabling money laundering and fraud?

Now there are valid use cases for crypto and blockchain generally and here are five of them:

  1. Innovative tech removing the central bank for peer-to-peer exchange that is faster and more global, especially helping the underbanked countries.
  2. Smart contracts can be built on blockchain.
  3. Blockchain can be used for crowdfunding.
  4. Blockchain can be used for decentralized storage.
  5. The traditional cash and coin supply chain is burdensomely wasteful, costly, dirty, and counterfeiting is a real issue. Why do you need to carry ten dollars in quarters or a wad of twenty-dollar bills or even have that be a nation’s economic backing in today’s tech world?

Here are six tips to identify crypto-related scams:

  1. With most businesses, it should be easy to find out who the key operators are. If you can’t find out who is running a cryptocurrency or exchange via LinkedIn, Medium, Twitter, a website, or the like be very cautious.
  2. Whether in cash or cryptocurrency, any business opportunity promising free money is likely to be fake. If it sounds too good to be true it likely is. Multi-level marketing is one old example of this scam.
  3. Never mix online dating and investment/financial advice. If you meet someone on a dating site or social media app, and then they want to show you how to invest in crypto or they ask you to send them crypto. No matter what sob story and huge return they are claiming it’s a scam (FTC).
  4. Watch out for scammers who pretend to be celebrities who can multiply any cryptocurrency you send them. If you click on an unexpected link they send or send cryptocurrency to a so-called celebrity’s QR code, that money will go straight to a scammer, and it’ll be gone. Celebrities don’t have time to contact random people on social media, but they are easily impersonated (FTC).
  5. Celebrities are however used to pump crypto prices via social media, so they get a windfall, and everyone else takes a hit. Watch out for crypto like Dogecoin which is heavily tied to celebrity pumps with no real-world business value. If you are lucky enough to get ahead, get out then.
  6. Watch out for scammers who make big claims without details, white papers, filings, or explanations at all. No matter what the investment, find out how it works and ask questions about where your money is going. Honest investment managers or advisors want to share that information and will back it up with details in many documents and filings (FTC).

Jeremy Swenson is a disruptive thinking security entrepreneur, futurist/researcher, and senior management tech risk consultant. Over 17 years he has held progressive roles at many banks, insurance companies, retailers, healthcare orgs, and even governments including being a member of the Federal Reserve Secure Payment Task Force. Organizations relish in his ability to bridge gaps and flesh out hidden risk management solutions while at the same time improving processes. He is a frequent speaker, published writer, podcaster, and even does some pro bono consulting in these areas. As a futurist, his writings on digital currency, the Target data breach, and Google combining Google + video chat with Google Hangouts video chat have been validated by many. He holds an MBA from St. Mary’s University of MN, a MSST (Master of Science in Security Technologies) degree from the University of Minnesota, and a BA in political science from the University of Wisconsin Eau Claire.