The Illusion of Control: What the Second Line Gets Wrong—and What Regulators and Failures Reveal

By Jeremy Swenson

Thirty-one. That is how many unaddressed safety-and-soundness supervisory warnings Silicon Valley Bank was sitting on when it collapsed in March 2023—roughly triple the number carried by comparable banks. The warnings existed. Examiners had written them down. Committees had reviewed them. And the bank failed anyway, in 36 hours, taking $209 billion in assets down with it.[1]

This figure isn’t really just about Silicon Valley Bank; it’s a broader story about how governance can falter right when it was meant to prevent failure. Across modern sectors like finance, healthcare, insurance, and tech—especially under heavy regulation—the structure is quite similar: a First Line managing risks, a Third Line (Internal Audit) independently evaluating effectiveness, and a Second Line acting as an oversight layer to challenge and ensure risk remains within boundaries before issues arise.

The uncomfortable pattern across nearly every major governance failure of the last fifteen years is not that the second line was absent. It was there, busy, and documented—and it still didn’t work.

That is the uncomfortable pattern across nearly every major governance failure of the last fifteen years: the second line of defense (2LOD) was rarely absent. It was there, it was busy, and it was thoroughly documented. JPMorgan’s Chief Investment Office had risk managers. Credit Suisse’s Prime Services division had a dedicated risk team. Wells Fargo had a corporate risk function, a legal department, and an audit group that all reviewed the Community Bank. Danske Bank’s Estonian branch had internal audit and a chief risk officer. In each case, the paperwork existed. The risk did not go away.

This raises the question at the center of this piece, and one that boards, regulators, and chief risk officers are increasingly asking out loud: is the modern second line of defense actually reducing risk—or is it primarily producing evidence that governance activities occurred? The two are not the same thing, and the gap between them is where some of the costliest failures in recent corporate history have lived.

What the Second Line Is Supposed to Do

The three-lines model that underpins risk governance at virtually every large regulated institution was formalized by the Institute of Internal Auditors in 2013 and substantially updated in 2020. The first line is operational management—the traders, lenders, engineers, and business unit leaders who own risk because they create it in the course of doing their jobs. The third line is internal audit, an independent function that reports to the board and periodically tests whether the first two lines are actually working. The second line sits in the middle: risk management, compliance, information security, and similar functions that provide, in the Institute’s own language, “complementary expertise, support, monitoring, and challenge” to the business.[2]

In U.S. banking specifically, this structure is not just best practice—it is regulatory expectation with teeth. The Office of the Comptroller of the Currency’s (OCC) 2014 heightened standards for large national banks explicitly require an independent risk management function, organizationally and financially separate from the business lines it oversees. The Federal Reserve’s 2011 guidance on model risk management, SR 11-7, assigns the second line an independent validation role specifically because business lines have an inherent incentive to trust their own models.[3]

Notably, when the Institute of Internal Auditors rewrote its guidance in 2020, it deliberately dropped the word “defense” from the model’s name, worried that the martial framing had encouraged organizations to treat risk management as purely defensive—blocking and reviewing—rather than as a function that helps an organization take the right risks well. That single word change is a useful preview of this piece’s argument: a second line built entirely around defense metrics—how many reviews were completed, how many policies exist, how many attestations were signed—can satisfy every requirement on paper while missing the actual point.[4]

Where the Model Breaks Down

Strip away the acronyms, and the recurring failure modes of the second line reduce to a short, uncomfortable list. Each one, on its own, sounds like a minor process gap. Together, and when combined with real money and real institutions, they have produced some of the largest corporate governance failures on record.

Documentation Instead of Risk Reduction

The clearest symptom is a second line that measures itself by volume: reviews completed, policies published, attestations collected, meetings held. Every one of those activities can be running at full capacity while the underlying risk grows untouched, because none of them require anyone to verify that a control actually works—only that someone said it does.

Self-Attestation Over Independent Verification

Much of traditional second-line practice depends on the first line telling the second line the truth: attestations, self-assessments, and point-in-time control tests that sample a narrow window and assume it represents the whole. When Danske Bank’s Estonian branch was later examined, the bank’s own lawyers conceded that “major deficiencies in controls and governance made it possible to use Danske Bank’s branch in Estonia for criminal activities such as money laundering,” and that internal reporting simply never reached the people positioned to stop it.[5]

Individual Exceptions Over Systemic Patterns

Second lines are often organized to catch one broken control at a time—a missed reconciliation, a late report, an expired certificate—rather than to notice that dozens of small, individually explainable exceptions are actually one large, systemic problem wearing different clothes.

Compliance Treated as a Proxy for Safety

Perhaps the most persistent conflation in second-line practice is the assumption that a control environment which satisfies a regulation is therefore a control environment that manages the underlying risk. The two frequently travel together. They are not the same claim, and treating them as interchangeable is exactly how organizations end up technically compliant and substantively exposed at once.

A Challenge Function That Doesn’t Actually Challenge

Effective second-line challenge requires two things that are hard to combine: enough independence to say no to a profitable business line, and enough technical and commercial fluency to know when “no” is actually warranted. Many second lines have one without the other—independent enough to be disliked, but not fluent enough in the actual business to be heeded, or so embedded in the business that independence quietly erodes.

Struggling to Govern What It Doesn’t Understand

Every one of the weaknesses above compounds sharply the moment the underlying risk is technical: artificial intelligence models, cloud migrations, third-party data pipelines, or novel cyber threats. A second line built to review loan files and sales scripts is not automatically equipped to evaluate a machine learning model’s training data lineage or a cloud vendor’s shared-responsibility boundary—and regulators are now saying so explicitly. NIST’s AI Risk Management Framework (RMF) and the broader push toward AI-specific governance exist precisely because traditional control catalogs were not written with adaptive, probabilistic systems in mind.[6]

Five Failures, One Pattern

These are not abstractions. They are the documented findings of regulators, board-appointed investigators, and congressional committees—and read together, they describe the same failure recurring in different industries, different countries, and different decades.

1. JPMorgan’s “London Whale” (2012)—When Risk Managers Don’t Know What the Business Is Doing

In 2012, JPMorgan Chase’s Chief Investment Office lost more than $6.2 billion on a series of synthetic credit derivative trades that came to be known as the “London Whale.” The U.S. Senate Permanent Subcommittee on Investigations spent nine months and reviewed more than 90,000 documents before concluding that the unit had mismarked its trading book to hide losses, disregarded multiple indicators of increasing risk, manipulated its own risk models, and evaded regulatory oversight.[7]

The Subcommittee’s report found that JPMorgan’s firm-wide risk managers—the second line—“knew little about” the trading strategy and had no role in approving the positions that produced the loss, even as the bank’s own public statements insisted the trades were consistent with firm-wide risk management. This was a second line that existed on the org chart and was functionally absent from the transaction that mattered most.[8]

2. Wells Fargo’s Sales Practices Scandal (2011–2016)—When Egos and Tenure Silence the Second Line

Between 2011 and 2016, Wells Fargo employees opened millions of unauthorized accounts to meet aggressive sales quotas, ultimately leading to the termination of roughly 5,300 employees and $185 million in regulatory penalties. When the bank’s independent directors released their own 110-page investigation in 2017, the findings went well beyond a rogue sales culture.[9]

The report found that Carrie Tolstedt, the long-tenured head of the Community Bank, and other Community Bank leaders “resisted and impeded scrutiny or oversight from corporate risk management and the Board,” and “minimized the scale and nature of problems” when they were forced to report them. Then-CEO John Stumpf, the report found, relied on “the Bank’s decades of success” and was “too slow to investigate or critically challenge” the sales model—a textbook description of tenure-driven bias, where years of past success become evidence against present-day concerns rather than a reason to look harder.[10]

Just as tellingly, the report found that Wells Fargo’s control functions were structurally weakened by internal politics: risk, legal, HR, and audit were “decentralized” and had “parallel units” embedded inside the Community Bank itself, reporting up through business-aligned structures that deferred to the business rather than challenging it. Audit reviewed the relevant controls and largely found them effective—but, the report notes pointedly, “it did not view its role to include analyzing more broadly the root cause of the improper conduct.” That is the governance-activity trap in a single sentence: the review happened, the box was checked, and the actual problem sailed through untouched.[11]

3. Credit Suisse and Archegos (2021)—When the Second Line Is Afraid to Say No

In March 2021, the collapse of Archegos Capital Management, a lightly regulated family office, cost Credit Suisse $5.5 billion—more than any other bank exposed to the same client. The board-commissioned investigation by Paul, Weiss found no fraud and no missing risk architecture. The controls existed. What failed was the willingness to use them.[12]

The investigation found a “persistent failure” to manage and remediate known risks connected to Archegos, and, more specifically, that Credit Suisse’s risk managers had intended to demand additional margin from Archegos to reflect its mounting credit risk—but were prevented from doing so because the business “deemed” it not to be in the bank’s commercial interest to upset the relationship. One outside review summarized the underlying dynamic bluntly: this was “a business more scared of losing a client than addressing the risks that client was bringing to the bank.” The report also found the Prime Services risk team itself was understaffed, had failed to replace departing senior risk staff, and lacked leadership experience—the second line, quite literally, hollowed out from within.[13]

4. Danske Bank Estonia (2007–2018)—When the Second Line Covers Its Own Mistakes

Danske Bank’s Estonian branch moved an estimated $230 billion in suspicious transactions, much of it linked to Russia, between 2007 and 2015—one of the largest money-laundering cases in European history. It might never have come to light if not for Howard Wilkinson, a British trader who filed four internal whistleblower reports to the bank’s audit unit and Copenhagen management between 2013 and 2014.[14]

Wilkinson later testified before the Danish and European Parliaments that the bank had “deliberately ignored” his warnings and that an Estonia branch executive told him the bank was “not the police.” An internal Danske audit team eventually validated the substance of his concerns, yet the bank still failed to take meaningful action until the money-laundering scandal became public in 2018—four years later. As Wilkinson departed the bank, he was reportedly presented with a nondisclosure agreement. This is the sharpest version of the pattern this piece was asked to examine directly: not a second line that failed to notice a problem, but one that noticed, confirmed it internally, and chose containment over correction—protecting the institution’s narrative rather than fixing the underlying failure.[15]

5. Silicon Valley Bank (2023)—When Periodic Reviews Can’t Keep Up With Real-Time Risk

SVB failed in 36 hours following a bank run, but the vulnerabilities behind it built for years. The Federal Reserve’s own review, led by Vice Chair for Supervision Michael Barr, is remarkable for how directly a regulator indicted its own supervisory process: SVB’s board and management “failed to manage their risks,” Federal Reserve supervisors “did not fully appreciate the extent of the vulnerabilities” as the bank grew, and—critically—even when supervisors did identify problems, they “did not take sufficient steps to ensure that Silicon Valley Bank fixed those problems quickly enough.”[16]

The report also found that SVB itself had changed its own risk-management assumptions specifically to reduce how its interest rate risk was measured, rather than managing the underlying exposure—a second-line control quietly redefined until it stopped producing uncomfortable answers. Barr’s report is also a rare admission that periodic, point-in-time supervisory cycles are structurally too slow for a risk that can move at deposit-run speed; a regulator reaching the same conclusion this piece reaches about the second line more broadly.[17]

What Regulators Learned—And Where Their Own Findings Converge

The most useful evidence that this is a systemic problem, not a string of unrelated scandals, comes from the regulators themselves. On April 28, 2023, the Federal Reserve and the Federal Deposit Insurance Corporation (FDIC) each released their own self-critical report on the same weekend of bank failures—an unusually candid coincidence that let the two reports be read side by side.

The Fed’s report on SVB, discussed above, found that supervisors identified real vulnerabilities but did not escalate forcefully enough once they had. The FDIC’s own report on Signature Bank reached a strikingly similar structural conclusion through a completely separate investigation: the bank’s failure was rooted in poor management, but the report also found that FDIC examiners had downgraded Signature’s liquidity rating as early as 2017 while its overall composite rating stayed at a healthy “2-Satisfactory” for six more years—a gap between what examiners were seeing and what the supervisory rating actually communicated.[18]

The U.S. Government Accountability Office (GAO) took a further step by reviewing both agencies together rather than separately. It concluded that this supports the main argument of this piece concerning federal banking regulation: the Federal Reserve and FDIC “identified numerous concerns at the banks as early as 2018, but did not issue enforcement actions.” Additionally, the GAO pointed out that the Federal Reserve’s “procedures for moving from a lower-level concern to an enforcement action often weren’t clear or specific.” This indicates that a regulator, assessing itself, independently recognizes the same core idea discussed here: identifying a risk is not the same as forcing a change. An institution can recognize risks on a large scale for years without reliably enforcing change.[19]

Read together with the NIST AI Risk Management Framework’s push for governance built around measurable, continuous risk assessment rather than static control catalogs, and the IIA’s 2020 shift away from purely defensive framing, a consistent regulatory direction emerges across otherwise unrelated bodies: less faith in point-in-time review, more emphasis on forcing identified risk into actual remediation, and explicit skepticism that documentation volume is a reliable proxy for safety. None of these bodies coordinated with each other. They arrived at overlapping conclusions anyway, because they were all looking at the same underlying failure pattern from different angles.[20],[21]

Figure 1. Most second-line functions do not lack activity—they sit in the high-activity, low-reduction quadrant, producing evidence of governance without changing risk outcomes.

The 2LOD governance trap and its four related boxes.

The Part Nobody Puts in the Org Chart: Tenure, Ego, and Internal Turf Wars

Every case above shares a dynamic that rarely appears in a governance framework diagram but shows up in nearly every post-mortem: the people closest to a mistake are often the ones best positioned to prevent its discovery, and organizational tenure tends to make that worse rather than better.

Long-tenured leaders accumulate something more dangerous than complacency—they accumulate authorship. A risk model, a sales program, a client relationship built over a decade is not just a business asset to the person who built it; it is proof of their own judgment. Wells Fargo’s Board Report describes exactly this pattern in Carrie Tolstedt, who had run the Community Bank for years and treated challenges to the sales model as challenges to her track record, not as useful information. John Stumpf’s decades at the company produced the same effect at the top: reliance on “decades of success” became a reason to discount new evidence rather than investigate it.[22]

Ego compounds this in a specific and predictable way inside the second line itself: once a risk function has signed off on something—approved a model, cleared a client, blessed a control—reversing that judgment later means admitting the earlier review was wrong. The Credit Suisse-Archegos investigation found that risk staff who wanted to tighten margin requirements were overruled by colleagues managing the client relationship, who prioritized the commercial relationship over the escalation. That is not a hypothetical about incentives; it is a documented instance of one part of the organization protecting a prior decision instead of correcting course.[23]

The most direct evidence of internal fighting to cover mistakes is Danske Bank. Wilkinson’s own account describes a bank that did not simply fail to notice a problem—it received internal confirmation that the problem was real, from its own audit function, and chose a non-disclosure agreement and years of silence over disclosure and remediation. That is not a control gap. It is a second line, or the executives who supervise it, actively managing the appearance of the problem rather than the problem itself—the containment instinct that shows up whenever an admission of error threatens a career, a bonus cycle, or a carefully maintained reputation.[24]

A second line that cannot survive telling the truth about its own prior mistakes will eventually stop looking for them.

None of this requires malice to be dangerous. Most of the people in these stories were not villains; they were professionals whose incentives, tenure, and self-image quietly bent the direction of ambiguous judgment calls toward “this is probably fine.” A modern second line has to be designed with the explicit assumption that this bending will happen—through rotation of long-tenured reviewers, external validation of internally cleared decisions, and protected channels for escalation that do not depend on the goodwill of the person whose earlier judgment is being questioned.

Governance Activity Is Not the Same as Risk Reduction

Every case study mentioned earlier successfully passed a compliance test before turning into a scandal. This is the key point repeatedly emphasized here: governance that merely shows evidence of compliance is different from governance that genuinely reduces risk. An organization can generate a lot of documentation proving compliance but still fall short in actually altering risk outcomes.

Evidence-of-compliance governance is legible, defensible in an exam, and relatively cheap to produce: a signed attestation, a completed checklist, a policy that has been “reviewed and approved.” Outcome-based governance is harder and more expensive: independently tested controls, risk metrics tied to actual loss experience, escalation paths that get used even when the news is bad. The first kind of governance protects the organization in an audit. The second kind protects the organization in a crisis. Wells Fargo, Credit Suisse, and Danske Bank all had abundant supplies of the first and a critical shortage of the second.

Figure 2. Modernizing the second line means shifting the underlying operating model, not just increasing the volume of existing activity.

Two columns showing the legacy model of checkbox compliance and the new model of continuous risk governance.

What a Modern Second Line Actually Looks Like

None of this argues for a weaker second line—every case study here shows the cost of that. It argues for a fundamentally different operating model, one that a growing body of regulatory guidance and industry practice is already pointing toward.

Risk-Based, Not Checklist-Based

Oversight intensity should scale with actual risk and complexity, not with how many items happen to be on a standard control list. A stable, well-understood process and a novel AI model deployed into a regulated decision workflow should never receive the same depth of review simply because both appear as line items on the same checklist.

Continuous Monitoring, Not Periodic Snapshots

The Barr report on SVB is itself an argument for this shift: point-in-time exams cannot keep pace with risks—interest rate exposure, deposit concentration, model drift—that can move materially between review cycles. Where technology allows it, continuous, automated monitoring should replace calendar-driven review as the default, with periodic deep-dives reserved for the risks continuous monitoring cannot yet see.

Evidence Over Attestation

Self-reported control effectiveness should be treated as a starting hypothesis, not a conclusion. Independent data validation—sampling actual transactions, actual model outputs, actual system logs—is more expensive than collecting a signature, and it is the only version of assurance that would have caught what self-attestation missed at Danske Bank.

Genuine Business and Technology Fluency

A second line cannot challenge what it does not understand. This means recruiting and developing risk professionals with real technical depth—in derivatives, in cloud architecture, in machine learning—rather than treating the second line as a generalist compliance career track. JPMorgan’s risk managers not knowing what the CIO’s synthetic credit portfolio actually did is the clearest cautionary tale on this point.

Escalation That Survives Internal Politics

Escalation paths need to be structurally protected from the relationship dynamics that killed escalation at Credit Suisse and Danske Bank—which means routing serious concerns to a level of the organization with no commercial stake in the outcome, and protecting the people who raise them, not just on paper but in how the organization actually treats them afterward.

Outcome-Based Metrics

A second line’s effectiveness should be measured by risk events avoided, losses prevented, and issues resolved before they compound—not by the number of reviews completed, policies published, or meetings held. Volume metrics are easy to game and easy to satisfy without changing anything; outcome metrics are harder to fake.

Real Oversight of AI, Cloud, and Third Parties

Emerging-technology governance needs its own competency track within the second line, built around frameworks purpose-designed for these risks—NIST’s AI Risk Management Framework, cloud shared-responsibility models, and structured third-party risk programs—rather than an attempt to stretch legacy control catalogs over technology they were never built to evaluate.[25]

Clear Accountability Between the First and Second Lines

Wells Fargo’s decentralized risk structure, with control functions embedded inside and reporting up through the business they were meant to oversee, shows what happens when the line between “owns the risk” and “challenges the risk” blurs. Modern governance requires those roles to remain organizationally and, where possible, financially distinct—precisely what the OCC’s heightened standards were written to enforce.[26]

Constructive Challenge, Not a Permanent Bottleneck

None of the above is a case for more friction everywhere. A second line that slows every decision equally will be resented, routed around, and eventually ignored—which is its own form of failure. The goal is targeted friction: fast, low-touch review for well-understood, lower-risk activity, and genuinely rigorous, well-resourced challenge concentrated on the decisions that could actually sink the institution.

Conclusion: Measuring the Right Thing

Return to Silicon Valley Bank’s 31 unaddressed supervisory warnings. Every one of them was, in a narrow sense, evidence that governance was happening: someone had identified a risk, written it down, and tracked it. And every one of them failed to change what actually happened to the bank. That is the second line’s central modern challenge, in miniature.

None of this is solvable by better metrics alone. Every case study in this piece also involved someone for whom the honest answer was personally expensive—a bonus, a reputation, a decade of authorship over a program now under question. A second line rebuilt around outcome-based measurement but layered on top of the same career incentives that rewarded Carrie Tolstedt’s silence and cost Howard Wilkinson his job will simply produce more sophisticated versions of the same evasions. The measurement has to change. So does the price of telling the truth.

It is also worth taking seriously what the regulators’ own convergence implies about where this is heading. The Federal Reserve, the FDIC, the GAO, NIST, and the IIA did not coordinate their findings—they arrived at the same conclusion independently, from different mandates, within the same few years. Convergence without coordination is usually a sign that a standard is hardening, not that a moment is passing. Institutions that treat this argument as a post-SVB overreaction, rather than the new baseline expectation, are likely to be rereading their own supervisory letters in a few years and wondering how they missed it.

The stakes of getting this right are also rising, not leveling off. Every failure examined here involved a risk that a sufficiently empowered reviewer could, in principle, still understand—a trading book, a sales incentive, a margin call. The AI models now moving into underwriting, claims, and credit decisions will not extend that same courtesy; their behavior can shift with a single retraining cycle in ways no annual attestation was ever built to catch. A second line that could not reliably catch a mismarked trading book will not reliably catch a model that has quietly drifted—not without first becoming the kind of second line this piece has been describing.

The organizations in this piece did not fail because nobody was watching. They failed because watching, on its own, was mistaken for managing. A modern second line has to be judged by a harder, more honest standard than whether the reviews got done: whether the risks that mattered actually got smaller. Everything else—the frameworks, the dashboards, the attestations—is only useful to the extent it serves that one outcome. Where it doesn’t, it is not governance. It is just paperwork with better branding.

Endnotes


[1]  Board of Governors of the Federal Reserve System, Review of the Federal Reserve’s Supervision and Regulation of Silicon Valley Bank (Washington, DC: Federal Reserve, April 28, 2023), https://www.federalreserve.gov/publications/files/svb-review-20230428.pdf; “Fed’s Barr: ‘Weaknesses in Supervision and Regulation Must Be Fixed,’” American Banker, April 28, 2023, https://www.americanbanker.com/news/feds-barr-weaknesses-in-supervision-and-regulation-must-be-fixed.

[2] The Institute of Internal Auditors, The IIA’s Three Lines Model: An Update of the Three Lines of Defense (Lake Mary, FL: IIA, July 2020), https://www.theiia.org/globalassets/documents/resources/the-iias-three-lines-model-an-update-of-the-three-lines-of-defense-july-2020/three-lines-model-updated-english.pdf.

[3]  Office of the Comptroller of the Currency, OCC Guidelines Establishing Heightened Standards for Certain Large Insured National Banks, Insured Federal Savings Associations, and Insured Federal Branches, 12 C.F.R. Part 30, Appendix D (2014); Board of Governors of the Federal Reserve System, “Supervisory Guidance on Model Risk Management,” SR Letter 11-7 (Washington, DC: Federal Reserve, April 4, 2011).

[4]  “IIA Unveils New Three Lines Model,” Radical Compliance, July 22, 2020, https://www.radicalcompliance.com/2020/07/22/iia-unveils-new-three-lines-model/.

[5]  “Howard Wilkinson,” Kohn, Kohn & Colapinto Whistleblower Case Archive, accessed August 2026, https://kkc.com/whistleblower-case-archive/howard-wilkinson/.

[6]  National Institute of Standards and Technology, Artificial Intelligence Risk Management Framework (AI RMF 1.0) (Gaithersburg, MD: U.S. Department of Commerce, January 26, 2023), https://doi.org/10.6028/NIST.AI.100-1.

[7]  U.S. Senate Permanent Subcommittee on Investigations, Committee on Homeland Security and Governmental Affairs, JPMorgan Chase Whale Trades: A Case History of Derivatives Risks and Abuses (Washington, DC: U.S. Senate, March 15, 2013), https://www.hsgac.senate.gov/subcommittees/investigations/library/files/report-jpmorgan-chase-whale-trades-a-case-history-of-derivatives-risks-and-abuses-march-15-2013/.

[8]  JP Morgan Chase Whale Trades: A Case History of Derivatives Risks and Abuses, summarized in Demos, https://www.demos.org/research/jp-morgan-chase-whale-trades-case-history-derivatives-risks-and-abuses.

[9]  Independent Directors of the Board of Wells Fargo & Company, Sales Practices Investigation Report (San Francisco: Wells Fargo & Company, April 10, 2017), https://lowellmilkeninstitute.law.ucla.edu/wp-content/uploads/2018/01/WF-Board-Report.pdf.

[10]  Wells Fargo Newsroom, “Wells Fargo Board Releases Findings of Independent Investigation of Retail Banking Sales Practices and Related Matters,” press release, April 10, 2017, https://newsroom.wf.com/news-releases/news-details/2017/Wells-Fargo-Board-Releases-Findings-of-Independent-Investigation-of-Retail-Banking-Sales-Practices-and-Related-Matters/default.aspx.

[11]  “Summary of the Report of the Independent Directors of Wells Fargo & Company into Sales Practices,” Lexology, October 11, 2017, https://www.lexology.com/library/detail.aspx?g=9b82dbcc-146d-4921-847c-526ccbf505a2; Brad S. Karp, Roberto J. Gonzalez, and Vikas Desai, “Lessons Learned from the Wells Fargo Sales Practices Investigation Report,” Harvard Law School Forum on Corporate Governance, April 22, 2017, https://corpgov.law.harvard.edu/2017/04/22/lessons-learned-from-the-wells-fargo-sales-practices-investigation-report/.

[12]  Credit Suisse Group AG, Report of the Special Committee of the Board of Directors of Credit Suisse Group Regarding Archegos Capital Management, prepared by Paul, Weiss, Rifkind, Wharton & Garrison LLP (July 29, 2021), as reported in “Credit Suisse Publishes Independent Review of Archegos Losses,” Paul, Weiss news release, July 29, 2021, https://www.paulweiss.com/practices/litigation/internal-investigations/news/credit-suisse-publishes-independent-review-of-archegos-losses.

[13]  “Unpacking the Report on Credit Suisse’s Archegos Disaster,” Euromoney, July 29, 2021, https://www.euromoney.com/article/28usrfe6tdwq9fkpayosg/capital-markets/unpacking-the-report-on-credit-suisses-archegos-disaster/; “Credit Suisse and the Archegos Collapse – Lessons in Risk Management and Governance for All,” BDO, February 21, 2025, https://www.bdo.co.uk/en-gb/insights/industries/financial-services/credit-suisse-and-the-archegos-collapse-lessons-in-risk-management-and-governance.

[14]  “Whistleblower in Danish Banking Scandal: Bank Ignored Me,” Associated Press via Seattle Times, November 19, 2018, https://www.seattletimes.com/business/whistleblower-in-danish-banking-scandal-bank-ignored-me/; “Danske Bank Money Laundering Scandal – Tip of the Icebergs,” National Law Review, accessed August 2026, https://natlawreview.com/article/danske-bank-money-laundering-scandal-tip-icebergs.

[15]  “Howard Wilkinson,” Kohn, Kohn & Colapinto Whistleblower Case Archive, accessed August 2026, https://kkc.com/whistleblower-case-archive/howard-wilkinson/; “Thanks to Danske Bank Whistleblower, SEC Sets Aside $178 Million for Harmed Investors,” Whistleblower Blog, April 4, 2023, https://whistleblowersblog.org/corporate-whistleblowers/sec-whistleblowers/thanks-to-danske-bank-whistleblower-sec-sets-aside-178-million-for-harmed-investors/.

[16]  Board of Governors of the Federal Reserve System, Review of the Federal Reserve’s Supervision and Regulation of Silicon Valley Bank, i-iii; “Federal Reserve Board Announces the Results from the Review of the Supervision and Regulation of Silicon Valley Bank,” press release, April 28, 2023, https://www.federalreserve.gov/newsevents/pressreleases/bcreg20230428a.htm.

[17]  Board of Governors of the Federal Reserve System, Review of the Federal Reserve’s Supervision and Regulation of Silicon Valley Bank, 3.

[18]  Federal Deposit Insurance Corporation, FDIC’s Supervision of Signature Bank (Washington, DC: FDIC, April 28, 2023), https://www.fdic.gov/news/press-releases/2023/pr23033a.pdf; “FDIC Signature Bank Report Summary,” prepared for the U.S. House Committee on Financial Services, May 2, 2023, https://financialservices.house.gov/uploadedfiles/2023.05.02_-_fdic_signature_bank_report_summary_final.pdf.

[19]  U.S. Government Accountability Office, Bank Supervision: More Timely Escalation of Supervisory Action Needed, GAO-24-106974 (Washington, DC: GAO, 2024), https://www.gao.gov/products/gao-24-106974.

[20]  National Institute of Standards and Technology, Artificial Intelligence Risk Management Framework (AI RMF 1.0) (Gaithersburg, MD: U.S. Department of Commerce, January 26, 2023), https://doi.org/10.6028/NIST.AI.100-1.

[21]  The Institute of Internal Auditors, The IIA’s Three Lines Model: An Update of the Three Lines of Defense (Lake Mary, FL: IIA, July 2020), https://www.theiia.org/globalassets/documents/resources/the-iias-three-lines-model-an-update-of-the-three-lines-of-defense-july-2020/three-lines-model-updated-english.pdf.

[22]  Independent Directors of the Board of Wells Fargo & Company, Sales Practices Investigation Report.

[23]  “Credit Suisse and the Archegos Collapse,” BDO; “Unpacking the Report on Credit Suisse’s Archegos Disaster,” Euromoney.

[24]  “Whistleblower in Danish Banking Scandal: Bank Ignored Me,” Seattle Times; “Howard Wilkinson,” Kohn, Kohn & Colapinto.

[25]  National Institute of Standards and Technology, Artificial Intelligence Risk Management Framework (AI RMF 1.0).

[26]  Office of the Comptroller of the Currency, OCC Guidelines Establishing Heightened Standards, 12 C.F.R. Part 30, Appendix D; Independent Directors of the Board of Wells Fargo & Company, Sales Practices Investigation Report.

What the rise, fall, and rapid rebirth of eXch tells us about the real shape of crypto crime in 2026

Every few months, a crypto exchange gets “shut down.” Headlines run. LinkedIn fills with hot takes. And then, quietly, the money keeps moving. That’s the pattern I want to walk through here—not as a hypothetical, but as a documented case, built on the work of the two firms that actually trace this money for a living: TRM Labs and Chainalysis.

Across my career in technology governance, cyber risk, enterprise transformation, and technology leadership, this particular case study has become one of the clearest illustrations of a lesson every risk leader eventually learns the hard way: shutting down a bad actor is not the same as dismantling the capability behind it. The organization goes away. The infrastructure, the liquidity, and the operators very often do not.

The Exchange That Wouldn’t Stay Dead:

eXch was a no-questions-asked crypto swap service. No identity verification, no meaningful compliance program—and it marketed that absence as a feature, branding itself a “privacy project” rather than what regulators would call it: a gap in the system, wide open and waiting to be used.

That gap became national news in February 2025, when North Korea’s Lazarus Group pulled off the largest crypto theft in history, stealing roughly $1.4 to $1.5 billion in Ethereum from the Bybit exchange.1 Bybit and independent investigators—including Elliptic, TRM Labs, and researcher ZachXBT—all pointed to the same off-ramp: eXch allegedly helped launder more than $90 million of the stolen funds.2

eXch’s owner, publicly known only as “Johann Roberts,” denied it, then partially admitted it, then blamed a slow compliance data feed. For what it’s worth, I went looking for a verified identity behind that name while researching this piece. I couldn’t find one. Treat it as an alias until proven otherwise.

In April 2025, eXch announced it was shutting down—citing, of all things, a DOJ whistleblower and a “transatlantic law enforcement operation.” Here’s the part almost nobody covered: it didn’t actually stop. TRM Labs found that eXch pulled its public-facing website but kept serving business partners through an API, with the same laundering fingerprints continuing right past its own announced shutdown date.3

This Isn’t One Bad Exchange—It’s a Lineage:

If eXch feels like an isolated case, look at what happened to Garantex, the Russian exchange first sanctioned in 2022 for laundering funds tied to darknet markets and ransomware groups like Conti and Hydra. Law enforcement finally seized its infrastructure in March 2025, after the platform had processed an estimated $96 billion in transactions since 2019, a substantial share of it tied to ransomware, darknet-market, and other criminal activity.4

What happened next is the whole point of this article. Garantex didn’t disappear. It became Grinex—same liquidity, same users, same money, new name. Chainalysis and TRM then traced the same pattern into ABCeX and its rebrand AEXBit, which share identical backend infrastructure and hot wallets with their predecessors; into the A7/A7A5 ruble-backed payment network, which has moved more than $93.3 billion in on-chain volume and counting; and into Heleket, a “new” service that received its opening liquidity directly from Garantex’s own wallets.5

TRM’s own assessment, stated plainly in its 2026 crypto crime report, is that this wave of rebrands is likely coordinated—a deliberate attempt to keep Russia’s crypto liquidity flowing while insulating the actual operators from further sanctions.6 For what it’s worth, Grinex itself went dark in April 2026 after a $13.7 million cyberattack it blamed, without evidence, on Western intelligence agencies.7 I’d bet money there’s already a successor standing by.

The Bigger Story Nobody’s Talking About Enough:

Here’s what I think most crypto-crime coverage still misses: individual rogue exchanges, however dramatic the headline, are no longer the main event.

Both TRM and Chainalysis now point to something structurally different—Chinese-language money laundering networks, or CMLNs. In 2025 alone, these networks moved an estimated $16.1 billion, roughly $44 million a day, across nearly 1,800 active wallets. That’s not a typo: Chainalysis measured CMLN growth at roughly 7,325 times the growth rate of illicit inflows to centralized exchanges since 2020.8

The anchor of this ecosystem is Huione Group, a Cambodia-based conglomerate that processed more than $98 billion in total crypto inflows between August 2021 and January 2025, over $4 billion of it confirmed illicit. In October 2025, the U.S. Treasury’s FinCEN designated Huione under Section 311 of the USA PATRIOT Act as a primary money laundering concern. Huione is also directly tied to Prince Group, the Cambodia-based criminal network behind a sprawling web of scam compounds across Southeast Asia.9

Why does this matter more than another exchange takedown? Because CMLNs aren’t one company you can seize. They’re a marketplace—fragmentation services, OTC desks, and “guarantee” platforms like Huione and Xinbi that connect buyers and sellers of laundering capacity, often without the platform operators ever directly touching the illicit funds themselves. Sanction one vendor, and the rest of the marketplace barely notices.10

Ransomware Isn’t Slowing Down—It’s Diversifying:

Data-leak-site-claimed ransomware incidents grew 50 percent year-over-year in 2025, reaching an all-time high even as enforcement activity intensified.11 The Ransomware-as-a-Service market has also fragmented, with some trackers counting as many as 85 active independent extortion groups—a more decentralized field that’s harder to monitor collectively, even as individual groups’ laundering patterns become easier to fingerprint on-chain.12

Separately, broader Chainalysis research on illicit crypto flows (not specific to ransomware) points to a shift in final-stage laundering toward exchanges with little to no know your customer (KYC) verification, with no-KYC exchange usage up 82 percent and usage of “guarantee” aggregators such as Tudou Danbao up 87 percent.13 Whether North Korean state actors rely on these no-KYC exchanges less than independent cybercriminals do—running a more specialized pipeline through Chinese money-laundering networks and bridge protocols instead—is a plausible pattern given DPRK’s well-documented use of dedicated laundering infrastructure. But it isn’t a claim I found directly confirmed in the sources reviewed for this piece, so I’m flagging it as a reasonable hypothesis rather than an established fact.

Enforcement has also started targeting the infrastructure layer itself, not just individual exchanges. In February 2025, the U.S., U.K., and Australia jointly sanctioned Zservers, a Russian bulletproof-hosting provider tied to ransomware operations including LockBit; Chainalysis data shows Zservers funneled at least $5.2 million through high-risk channels, including the sanctioned exchange Garantex.14 OFAC separately sanctioned Aeza Group, another Russian bulletproof host, in July 2025—though, notably, that action does not appear to have included the U.K. and Australia as co-sanctioning parties.15

What This Actually Means:

If you take one thing from this, let it be this: the “shut it down” model of enforcement works—temporarily. eXch kept running through its own back door. Garantex became Grinex became ABCeX became AEXBit. The harder, more consequential fight is against the marketplace model itself—the CMLNs, the guarantee platforms, and the hosting infrastructure underneath all of it—which doesn’t have one throat to choke.

The good news, and it’s a real one, is that blockchain transparency remains investigators’ structural advantage. The same on-chain fingerprinting—shared wallets, co-spending patterns, infrastructure overlap—that unmasked ABCeX as a Garantex clone will eventually do the same to whatever comes after Grinex, and whatever comes after that.

This case study reflects the kind of governance-under-adversarial-pressure challenge I spend a lot of time researching and writing about: how do we design governance, oversight, and risk management frameworks for ecosystems that are deliberately engineered to evade them? Answering that will take a coordinated, multi-layered response—end-to-end mapping of cryptocurrency transaction chains, stronger Know Your Customer and Anti-Money Laundering controls, deeper multinational cooperation among regulators and law enforcement, more rigorous misuse-case modeling to anticipate adversarial behavior, and broader, faster identification and blacklisting of the high-risk exchanges, wallets, and tokens that keep facilitating illicit finance long after their predecessors are supposedly gone.

Endnotes:

1. TRM Labs, “2026 Crypto Crime Report” (TRM Labs, 2026), https://www.trmlabs.com/reports-and-whitepapers/2026-crypto-crime-report.

2. Decrypt, The Block, and CryptoRank.io, contemporaneous news coverage of the Bybit hack and eXch’s role in laundering stolen funds, February–March 2025.

3. TRM Labs, “eXch Remains Active Despite Shutdown: How the Bybit Hack-Linked Exchange Continues to Enable Laundering of CSAM Funds” (TRM Labs Blog, May 2, 2025), https://www.trmlabs.com/resources/blog.

4. Chainalysis, “OFAC Sanctions Tracker: How Sanctions Impact Crypto Crime” (Chainalysis Blog), https://www.chainalysis.com/blog/ofac-sanctions/.

5. TRM Labs, “2026 Crypto Crime Report.”

6. TRM Labs, “2026 Crypto Crime Report.”

7. TRM Labs, “2026 Crypto Crime Report.”

8. Chainalysis, “The Chinese-Language Underground Crypto Money Laundering Ecosystem” (Chainalysis Blog, January 27, 2026), https://www.chainalysis.com/blog/2026-crypto-money-laundering/.

9. Chainalysis, “Crypto Sanctions: 2026 Crypto Crime Report” (Chainalysis Blog, 2026), https://www.chainalysis.com/blog/crypto-sanctions-2026/.

10. Chainalysis, “The Chinese-Language Underground Crypto Money Laundering Ecosystem.”

11. Chainalysis, “Crypto Ransomware: 2026 Crypto Crime Report” (Chainalysis Blog, March 4, 2026), https://www.chainalysis.com/blog/crypto-ransomware-2026/.

12. Chainalysis, “Crypto Ransomware: 2026 Crypto Crime Report.”

13. Chainalysis, “2025 Crypto Theft Reaches $3.4 Billion” (Chainalysis Blog, December 18, 2025), https://www.chainalysis.com/blog/crypto-hacking-stolen-funds-2026/.

14. Chainalysis, “OFAC Sanctions Tracker.”

15. Chainalysis, “OFAC Sanctions Tracker.”

Crypto, Conflict, and Capital Flight: What Iran’s On-Chain Shock Signals for Middle East Economics and U.S. Markets


In late February 2026, shortly after coordinated U.S.–Israeli airstrikes struck targets in Tehran, blockchain analytics firms observed an abrupt spike in cryptocurrency withdrawals from Iran’s largest digital asset exchange. Within minutes of the strikes, Nobitex reportedly experienced a roughly 700 percent surge in withdrawals, with millions of dollars in crypto leaving the platform in a compressed time window.¹ This episode, while modest in absolute global market terms, offers a revealing case study in how digital assets function during geopolitical stress—and what that may signal for Middle East economics and U.S. financial markets over the next year.

A Rapid Withdrawal Shock:

Reporting indicates that nearly $3 million exited Nobitex in a single hour following the strikes, with approximately $10 million leaving Iranian exchanges over several days.² Such flows are small relative to global crypto trading volumes but significant within the Iranian financial context, where capital controls, sanctions, and currency instability already shape economic behavior.

Iran’s domestic currency, the rial, has faced long-standing pressure from inflation, sanctions, and restricted access to global banking networks. In that environment, cryptocurrencies—particularly Bitcoin and dollar-denominated stablecoins—have increasingly served as alternative stores of value and channels for cross-border transfers.³ The surge in withdrawals appears consistent with crisis-driven capital preservation behavior rather than speculative trading alone.

Crypto as a Financial “Pressure Valve”:

The events underscore crypto’s evolving role as a decentralized financial “pressure valve” in sanctioned or conflict-affected economies. When traditional banking rails are constrained or politically vulnerable, digital assets offer relative portability and censorship resistance.¹

Internet blackouts and temporary exchange disruptions complicate interpretation. Outages can cluster transactions when connectivity resumes, making withdrawal spikes appear sharper than underlying demand alone would suggest.³ Nonetheless, the pattern aligns with prior episodes in emerging markets where digital assets gained traction during currency stress.

The lesson is not that crypto replaces sovereign financial systems, but that it increasingly supplements them under strain.

Economic Implications for the Middle East (Next 12 Months):

Looking forward, several dynamics are likely to shape regional economics:

1. Expanded Informal Dollarization via Digital Assets. Sanctioned or financially constrained economies may see broader retail and institutional adoption of dollar-linked stablecoins as parallel monetary tools.

2. Heightened Regulatory and Surveillance Pressure. As crypto flows intersect with sanctions regimes, U.S. and allied regulators are likely to intensify scrutiny of exchanges, custodians, and cross-border blockchain activity.¹

3. Persistent Capital Flight Incentives. Geopolitical volatility increases incentives for households and firms to diversify outside domestic banking systems.

4. Infrastructure Fragility Risks. Internet shutdowns and exchange outages remain structural vulnerabilities in crisis environments.³

Collectively, these forces suggest that digital asset adoption in parts of the Middle East will continue—not as ideological endorsement of crypto, but as pragmatic economic hedging.

What This Means for U.S. Markets:

For U.S. investors and policymakers, the implications extend beyond regional headlines.

Oil and Energy Sensitivity. Any escalation involving Iran carries oil supply risk implications. Even absent sustained disruption, perceived risk premiums can lift energy prices.

Safe-Haven Flows and Dollar Strength. Periods of geopolitical tension historically reinforce demand for U.S. Treasuries and dollar-denominated assets. Concurrently, Bitcoin and gold often experience volatility tied to risk sentiment shifts.⁴

Regulatory Spillover. If crypto is increasingly viewed as a sanctions-adjacent vector, U.S. enforcement posture may tighten, affecting exchanges and institutional investors.

Systemic Interconnectedness. Crypto is no longer a siloed asset class. It is embedded within global liquidity networks. Geopolitical events can trigger rapid on-chain responses that ripple into equities, commodities, and foreign exchange markets.

Forecast—A Converging Risk Landscape:

Over the next year, expect three converging trends:

  1. Greater integration between geopolitical risk modeling and digital asset analytics.
  2. Increased compliance burdens on global crypto infrastructure providers.
  3. Continued volatility transmission across oil, crypto, emerging market currencies, and U.S. equities during regional escalations.

The Iranian withdrawal spike may have involved only millions of dollars—but its significance lies in what it signals: digital capital now moves at the speed of conflict.

For U.S. markets, that means geopolitical shocks increasingly transmit through hybrid financial rails—traditional and decentralized alike. Outside of economic considerations, peace is desirable for the benefit of all.


Bibliography:

  1. Yahoo Finance. “Millions of Dollars in Crypto Left Iranian Exchanges After Airstrikes.” February 2026.
  2. Economic Times. “Why Did Iran’s Largest Crypto Exchange See a 700% Withdrawal Spike Minutes After US–Israel Airstrikes Hit Tehran?” February 2026.
  3. Bitget News. “Iranian Crypto Exchange Records Surge in Withdrawals Following Tehran Strikes.” February 2026.
  4. Forbes. “Iran War, an Oil Crisis, a Crypto Stress Test.” March 2026.

Why Being Respected Matters More Than Being Nice in Leadership

In leadership, the tension between being respected and being merely nice has been debated for centuries. Niceness is often equated with politeness, affability, and the desire to avoid conflict. Respect, on the other hand, is grounded in trust, competence, and integrity. While niceness may win temporary approval, respect creates lasting influence. Leaders who prioritize being respected over being liked not only drive stronger performance but also safeguard their organizations against complacency and poor decision-making. A change agent leader cannot be overly nice, or he or she will be trampled on.

Fig. 1. Jeremy Swenson, Pink Suit With Yellow Background, 2025, Jeremy Swenson.

Fig. 1. Jeremy Swenson, Ink Suit Yellow Background, 2025.

The Pitfalls of “Niceness”:

Niceness can be an appealing trait, especially in team settings where harmony is valued. However, as a leadership strategy, niceness carries inherent risks. When leaders prioritize being liked, they may avoid difficult conversations, tolerate poor performance, or bend organizational rules to keep others happy. Over time, this erodes accountability. Research in organizational psychology demonstrates that leaders who are overly agreeable may sacrifice effectiveness, as employees perceive them as weak or inconsistent (Judge, Bono, Ilies, & Gerhardt, 2002).

Margaret Thatcher, the former Prime Minister of the United Kingdom, captured this dilemma bluntly: “If you set out to be liked, you will accomplish nothing” (Thatcher, 1993, p. 147). Niceness often becomes a form of self-preservation—leaders seek short-term harmony at the cost of long-term impact. While being liked may feel rewarding in the moment, it does not inspire confidence or loyalty when difficult decisions must be made. An overly nice person would likely give undue favor to people close to them and thus would not encourage growth or innovation.


Why Respect Endures:

Respect is a far more enduring quality. It is not rooted in popularity but in consistency, fairness, and competence. Respected leaders earn trust by setting clear expectations, making principled decisions, and holding themselves and others accountable. Respect does not preclude kindness; rather, it frames kindness in a way that maintains boundaries and integrity.

The late Maya Angelou (1993) famously observed: “People will forget what you said, people will forget what you did, but people will never forget how you made them feel” (p. 21). In a leadership context, being respected makes people feel valued, secure, and motivated because they know their leader will not waiver under pressure or abandon fairness for personal popularity. Respect builds psychological safety, which modern research identifies as one of the strongest predictors of high-performing teams (Edmondson, 2019).

Moreover, people are more likely to trust those who build respect than politeness. Respect crosses all demographics while what is nice in one culture may not be nice in another culture. In other words, respect is less subjective and thus more powerful. Respect means you mean what you say and enforce it over time, across cultures, and no matter what. Niceness signals your pliable and not confident in your approach as to who or what is right.


Lessons from Business Leadership:

Business history is filled with examples that highlight the difference between respected leaders and merely nice ones.

  • Steve Jobs (Apple): Jobs was not widely regarded as “nice.” His demanding nature often clashed with employees. However, he was deeply respected for his vision, creativity, and relentless pursuit of excellence. Walter Isaacson (2011) documented how Jobs inspired loyalty and innovation because employees trusted his uncompromising standards, even if they did not always appreciate his methods.
  • Indra Nooyi (PepsiCo): Nooyi combined respect with empathy. She was known for her warmth and for writing personal letters to employees’ families, yet she also set bold strategic goals and held teams accountable for results. Her leadership illustrates that respect does not exclude kindness but rather enhances it when boundaries and accountability remain intact (Nooyi & Mirza, 2021).
  • Colin Powell (U.S. Army General): Powell (1995) explained that respect is inseparable from accountability: “The day soldiers stop bringing you their problems is the day you have stopped leading them” (p. 54). For Powell, respect came not from being “nice” but from being competent, decisive, and trustworthy in the face of pressure.

These examples highlight that respected leaders may not always win popularity contests, but they leave legacies of trust and performance.


Respect, Boundaries, and Authority:

A crucial distinction between respect and niceness lies in boundaries. Nice leaders often allow others to cross their boundaries in order to avoid discomfort. Respected leaders, by contrast, maintain clear boundaries, which prevents exploitation and reinforces authority. As Maxwell (1998) argued, leadership is fundamentally about influence, and influence requires credibility. A leader without respect may have a title, but not authority.

In practice, this means making unpopular but necessary decisions—layoffs during a downturn, holding a top performer accountable for misconduct, or refusing to compromise ethics for profit. These choices rarely make a leader “liked” in the moment, but they generate long-term respect and loyalty. Employees may not always agree, but they admire the leader’s consistency and courage. This is especially true in contexts that require tough change management, such as mergers, new products, entering new countries, and adopting new technologies. This is where a strong respected visionary leader beats nice person every time.


Conclusion:

In the final analysis, it is far better for leaders to be respected than to be merely nice. Niceness without boundaries leads to exploitation and mediocrity. Respect, however, fosters trust, accountability, and sustainable success. Leaders who cultivate respect create organizations that withstand challenges, adapt to change, and achieve long-term goals.

As Thatcher, Angelou, Jobs, Nooyi, and Powell all remind us in different ways, leadership is not about avoiding conflict or pleasing others—it is about earning trust through integrity, competence, and courage. Respect lasts; niceness fades. In business and leadership, respect is not just preferable—it is essential.

A respected leader will not be taken advantage of. His or her management structure will be less likely to be challenged, making operations run more smoothly. Those around such a leader will be more inspired to follow the tough decisions they make and will feel relief knowing they did not have to shoulder those burdens themselves, yet can remain confident in the respected leader who did. That leader is not doubted. With the right experience and training, you can be that leader.


References:

Angelou, M. (1993). Wouldn’t take nothing for my journey now. Bantam Books.

Edmondson, A. C. (2019). The fearless organization: Creating psychological safety in the workplace for learning, innovation, and growth. Wiley.

Isaacson, W. (2011). Steve Jobs. Simon & Schuster.

Judge, T. A., Bono, J. E., Ilies, R., & Gerhardt, M. W. (2002). Personality and leadership: A qualitative and quantitative review. Journal of Applied Psychology, 87(4), 765–780. https://doi.org/10.1037/0021-9010.87.4.765

Maxwell, J. C. (1998). The 21 irrefutable laws of leadership. Thomas Nelson.

Nooyi, I., & Mirza, R. (2021). My life in full: Work, family, and our future. Portfolio.

Powell, C. (1995). My American journey. Random House.

Thatcher, M. (1993). The Downing Street years. HarperCollins.


About the Author:

Jeremy Swenson is a disruptive-thinking security entrepreneur, futurist/researcher, and senior management tech risk consultant. Over 17 years, he has held progressive roles at many banks, insurance companies, retailers, healthcare organizations, and even government entities. Organizations appreciate his talent for bridging gaps, uncovering hidden risk management solutions, and simultaneously enhancing processes. He is a frequent speaker, podcaster, and a published writer – CISA Magazine and the ISSA Journal, among others. He holds a certificate in Media Technology from Oxford University’s Media Policy Summer Institute, an MBA from Saint Mary’s University of MN, an MSST (Master of Science in Security Technologies) degree from the University of Minnesota, and a BA in political science from the University of Wisconsin Eau Claire. He is an alum of the Cyber Security Summit Think Tank, the Federal Reserve Secure Payment Task Force, the Crystal, Robbinsdale and New Hope Citizens Police Academy, and the Minneapolis FBI Citizens Academy. He also has certifications from Intel and the Department of Homeland Security.

What If You Bought 10,000 Bitcoins on November 30, 2010?

Minneapolis—07/14/25

Fig. 1. Bitcoin Stock Image, 2025.

Investor enthusiasm for Bitcoin continues to grow as corporate treasuries ramp up their acquisitions and the U.S. Congress edges closer to passing pivotal cryptocurrency legislation. Starting on 07/14/25, the U.S. House of Representatives will begin reviewing a suite of crypto-related bills during what has been labeled “Crypto Week.” These proposed measures aim to establish a more transparent regulatory framework for digital assets—an initiative long championed by the crypto industry. The policy push has received backing from former President Donald Trump, who has positioned himself as a crypto-friendly leader and is involved in multiple blockchain-related ventures. Among the most closely watched proposals is the Genius Act, which could introduce federal oversight for stablecoins pegged to the U.S. dollar and potentially open the door for private companies to issue digital dollars.

However, on 11/30/10, Bitcoin was trading at roughly $0.23 per coin.(1) If you had invested $2,300 then, you could’ve acquired 10,000 BTC. At the time, that decision would’ve seemed obscure, laughable even, especially compared to buying gold, stocks, or real estate. The real estate market was down then due to the mortgage bubble-induced Great Recession.

But today, with Bitcoin priced at $121,000 per coin (2), that same purchase would now be worth an astonishing $1.21 billion. Your original $2,300 would have grown by over 52 million percent, delivering a profit of $1,209,997,700—yes, that is billions! That’s not just life-changing wealth—it’s generational. Billionaire status, from a sum that’s less than many people’s rent check.


The High-Risk Investment Nobody Believed In:

Despite the reward, a 2010 Bitcoin investment was far from low-risk. Investors at the time faced:

  • Technology Risk: You had to navigate early exchanges like Mt. Gox and use command-line wallets.
  • Security Risk: Wallet hacks and exchange thefts were rampant. There was no FDIC or insurance for crypto losses.(3)
  • Regulatory Uncertainty: Bitcoin was considered the currency of the dark web. Its legal future was murky at best.(4)
  • Volatility: There were frequent 70–90% drawdowns. Many early holders sold at $1, $10, or $100, fearing it would crash back to zero.

To hold 10,000 BTC from 2010 to 2025 required not just foresight—but ironclad conviction and secure digital hygiene.


Three People Who Made (and Kept) Their Bitcoin Fortunes:

1. Erik Finman

In 2011, a teenage Finman bought about 100 BTC with $1,000. By the time he was 18, he had become a millionaire. He parlayed his gains into building educational tech ventures and became a public face for Gen Z crypto success.(5)

2. Roger Ver

Known as “Bitcoin Jesus,” Ver was among the first to promote Bitcoin full-time. He invested heavily when it was under $1, and his early holdings are believed to number in the hundreds of thousands. Though later he championed Bitcoin Cash, his Bitcoin fortune is still substantial.(6)

3. Charlie Shrem

A co-founder of BitInstant, Shrem acquired thousands of Bitcoins in 2011, using them to build infrastructure for Bitcoin access. Though he served prison time due to regulatory issues, his stake made him a multimillionaire.(7)


Is There Another Bitcoin Out There?

It’s easy to dream that another asset might offer Bitcoin-like returns. But we should note:

  • Bitcoin was a first-mover. It’s the only digital asset to go from $0.01 to over $100,000 while maintaining broad global recognition.
  • Markets are now institutionalized. Regulators, hedge funds, and custodians watch the crypto space closely, making “wild west” gains harder to find.
  • Asymmetric bets still exist. AI startups, early-stage biotech, and deep-tech platforms might offer the next moonshot—but with similar volatility and failure risk.

Lessons from the Bitcoin Billionaires:

  1. Be Early—but Stay Invested Timing is only half the story. Holding through crashes (like in 2014, 2018, and 2022) was just as critical.
  2. Protect Your Holdings Many early holders lost everything due to poor key management. Cold wallets and secure backups are vital.
  3. Have Conviction Amid Doubt The biggest returns often come from believing before the crowd does—when the risk feels scariest.

Final Word: From $2,300 to $1.21 Billion:

Had you purchased 10,000 BTC for $2,300 on November 30, 2010, and held it securely for 15 years, you’d now be worth $1.21 billion. Few people made that choice, and even fewer had the resolve to hold. But this extreme example offers a timeless insight: Fortune doesn’t just favor the bold—it favors the bold who are patient, prepared, and just a little bit lucky. One thing is for sure: paper and coin currency are dead, too burdensome, and are declining in use over credit cards.


Footnotes:

  1. CoinMarketCap. (2023). Bitcoin Historical Data – November 2010. Retrieved from https://coinmarketcap.com
  2. Yahoo Finance. (2025, July 14). Bitcoin (BTC-USD) price. Retrieved from https://finance.yahoo.com
  3. Popper, N. (2015). Digital Gold: Bitcoin and the Inside Story of the Misfits and Millionaires Trying to Reinvent Money. Harper.
  4. Greenberg, A. (2014). This Machine Kills Secrets. Dutton.
  5. CNBC. (2017, Dec 14). Teen Bitcoin Millionaire Erik Finman. https://www.cnbc.com
  6. The Guardian. (2017, July 2). Bitcoin’s Evangelist: Roger Ver. https://www.theguardian.com
  7. Wired. (2014, Jan 27). Bitcoin’s First Felon: The Rise and Fall of Charlie Shrem. https://www.wired.com

About the Author:

Jeremy Swenson is a disruptive-thinking security entrepreneur, futurist/researcher, and senior management tech risk consultant. Over 17 years, he has held progressive roles at many banks, insurance companies, retailers, healthcare organizations, and even government entities. Organizations appreciate his talent for bridging gaps, uncovering hidden risk management solutions, and simultaneously enhancing processes. He is a frequent speaker, podcaster, and a published writer – CISA Magazine and the ISSA Journal, among others. He holds a certificate in Media Technology from Oxford University’s Media Policy Summer Institute, an MBA from Saint Mary’s University of MN, an MSST (Master of Science in Security Technologies) degree from the University of Minnesota, and a BA in political science from the University of Wisconsin Eau Claire. He is an alum of the Cyber Security Summit Think Tank , the Federal Reserve Secure Payment Task Force, the Crystal, Robbinsdale and New Hope Citizens Police Academy, and the Minneapolis FBI Citizens Academy. He also has certifications from Intel and the Department of Homeland Security.

Titans of the Trade: Six Hedge Fund Visionaries

Fig. 1. Hedge Fund Infographic, Generic Rights Free, 2025.


Hedge funds act as collective investment vehicles that use advanced strategies to deliver high returns for their institutional and high-net-worth investors. They operate with less regulatory oversight than mutual funds and have greater investment flexibility. Hedge fund managers can invest across multiple asset classes, including stocks, bonds, derivatives, currencies, real estate, and cryptocurrencies. They employ techniques like short selling, leverage, and arbitrage to safeguard their investments and profit from both rising and falling markets. Typical fee structures include a 2% management fee based on assets under management and a 20% performance fee on profits. Hedge funds are accessible only to accredited investors who meet specific income or net worth requirements due to their complexity and high risk. Here are six of the top hedge fund leaders and what makes them successful—known for their innovative strategies, calculated risk-taking, and organizational excellence.


1. Bill Ackman

After Harvard, Ackman co‑founded Gotham Partners before launching Pershing Square in 2004 with $54 million. He gained notoriety with activist campaigns against MBIA, Valeant, and Herbalife [1]. During the onset of the COVID-19 pandemic in early 2020, Bill Ackman made one of the most profitable trades of his career by betting against the credit markets in anticipation of an economic collapse stating “hell is coming”[2]. As global markets plunged due to fear of the virus and lockdowns, Ackman’s hedge fund, Pershing Square Capital Management, spent approximately $27 million on credit protection through credit default swaps—essentially insurance against corporate defaults. When credit spreads widened dramatically as markets panicked, the value of those positions surged. In less than a month, Pershing Square turned that $27 million into $2.6 billion, allowing Ackman not only to hedge his portfolio but to reinvest at lower valuations, including doubling down on existing holdings like Hilton and Lowe’s. $1.25 billion by trading on inflation forecasts [2][3]. Despite steep losses involving Valeant and J.C. Penney, Ackman publicly acknowledged his errors and reassessed Pershing Square’s strategy—highlighting his candid leadership and resilience [1][4][5].

2. Ken Griffin

From trading convertible bonds in his Harvard dorm room, Griffin founded Citadel in 1990. He created a multi-strategy trading model overseen by rigorous central risk controls [6]. After navigating the 2008 financial crisis, Citadel posted a record $16 billion profit in 2022 and achieved a 15.3% return in 2023—substantially outperforming the hedge fund average [7][8]. Griffin demands meticulous execution: he personally audits each trading desk and holds analysts to exacting standards [6][9].

3. Kyle Bass

Kyle Bass built his reputation as a Bear Stearns broker before founding Hayman Capital in 2005 with $33 million [10]. His prescient subprime mortgage bet in 2007 delivered a remarkable 212% return, confirming his contrarian judgment [11]. Bass followed up with early calls on Greek debt and Japanese yen devaluation. Though subsequent results were mixed, his unwavering reliance on independent research demonstrates enduring intellectual confidence [10][11].

4. Israel “Izzy” Englander

Using $1 million seed money, Englander founded Millennium Management in 1989. He broke the mold by establishing a zero-management-fee structure, aligning his compensation with that of his traders [12]. Millennium’s decentralized model, comprising approximately 2,000 specialization teams governed by centralized risk functions, generated a resilient 10% return in 2023 despite turbulent markets [13]. Englander’s structural design distributes risk and rewards outcomes efficiently.

5. Steve Cohen

Cohen entered the business world at Gruntal & Co. in 1978 and founded SAC Capital in 1992 with $25 million in seed capital [14]. Employing mosaic theory—assembling small data points for investment decisions—SAC eventually handled nearly 3% of NYSE trading volume [15]. Even after a $1.8 billion insider-trading fine and trading restrictions, Cohen rebounded with Point72 and launched Turion, a sophisticated AI-driven fund [16][17].

6. David Tepper

Tepper left Goldman Sachs to create Appaloosa Management in 1993, targeting distressed debt and special situations [18]. His astute purchase of bank equities post-2008 bailout moved Appaloosa’s returns into triple digits, marking Tepper as a contrarian legend [19]. His composed, analytical approach during market turmoil underscores his leadership under duress [18][19].


Common Threads That Elevate Them

  1. Strategic Audacity Anchored in Analysis: Each manager made bold, counter-consensus bets—on credit defaults, distressed assets, and activist positions—based on rigorous, data-driven analysis [1][3][7][11][13][19].
  2. Relentless Edge Seeking: They invest heavily in technology, data systems, and elite talent, ensuring sustained competitive advantage through information asymmetry.
  3. Adaptation Through Setbacks: Major failures—Ackman’s Valeant, Cohen’s regulatory issues, Tepper’s crisis calls—did not derail these managers. Instead, they rebuilt stronger by learning from mistakes.
  4. Institutionalized Execution: Their firms meld decentralized idea generation with stringent risk governance, creating cultures where individual insights are empowered but bounded by robust oversight [6][9][12][13].

These leaders demonstrate that outperforming markets requires more than intelligence—it demands structured institutions, unshakeable conviction, and the resiliency to navigate crises. Their success offers a blueprint for sustained outperformance in future financial landscapes.


References

  1. Ackman, B. (2004). Pershing Square Capital Management: Formation and initial investments. Gotham Partners Archive.
  2. Ackman, B. (2020, March). “Hell is coming” and COVID‑19 credit default swap bets. Vanity Fair.
  3. Ackman, B. (2020). Inflation hedge performance: $1.25 billion gains. Pershing Square Quarterly Report, 1(2).
  4. Ackman, B. (2021). Public admissions regarding Valeant and J.C. Penney losses. Pershing Square disclosures.
  5. Pershing Square. (2022). Strategic recovery and firm recalibration reports.
  6. Citadel Risk Oversight Team. (n.d.). Trading desk structure and internal audits. Citadel Risk & Governance Reports.
  7. Griffin, K. (2022). Citadel’s record profit. The Wall Street Journal.
  8. Griffin, K. (2024). Citadel’s 2023 performance report: 15.3% return vs. 7.4% average. Citadel Annual Review.
  9. Reuters/Benzinga. (2023). Citadel audit and trading desk oversight features.
  10. Bass, K. (2005). Founding of Hayman Capital Management. Hayman Capital Press Release.
  11. Bass, K. (2007). Subprime mortgage collapse: A 212% return for Hayman. Hayman Investor Letter.
  12. Englander, I. (1989). Millennium Management founding and zero-fee structure. Millennium Quarterly.
  13. Millennium Management. (2024). 2023 performance: 10% return in challenging markets. Millennium Annual Report.
  14. Cohen, S. (1992). Founding of SAC Capital. SAC Capital Company Archive.
  15. Cohen, S. (2005). Mosaic theory and market share, up to 3% of NYSE. Trading Insights Journal.
  16. U.S. Securities and Exchange Commission. (2013). Insider-trading settlement and ban of SAC Capital. SEC Litigation Release.
  17. Point72 Asset Management. (2023). Launch of Turion AI quantitative fund. Point72 Press Release.
  18. Tepper, D. (1993). Founding of Appaloosa Management. Appaloosa Press Release.
  19. Tepper, D. (2009). Contrarian bank-bailout bets in 2008: Performance analysis. Appaloosa Manager Report.

Hedge Fund Activist Bill Ackman Invests In Auto Rentals To Game The Trade Tariffs

Fig. 1. Bill Ackman Auto Tariff Infographic, 2025, Jeremy Swenson.

Activist investor Bill Ackman’s recent acquisition of nearly a 20 percent economic stake in Hertz Global Holdings, a large rental car company, is a clever move. It is based on a complex tariff argument that has the potential to significantly increase returns and the residual values of Hertz’s roughly 500,000-car fleet. In addition to propelling Hertz’s stock to record one-day gains, Ackman has demonstrated how trade restrictions may act as powerful tailwinds for cyclical companies by fusing profound policy knowledge with distressed asset investment.

Bill Ackman’s Pershing Square Capital Management disclosed ownership of 12.7 million shares of Hertz—costing about $46.5 million—which equates to a 4.1 percent direct equity stake in the company.(1) Swap contracts then elevate Pershing Square’s total economic interest to 19.8 percent of Hertz’s outstanding stock, making Ackman the second‑largest stakeholder behind Knighthead Capital and BlackRock.(2) This sizable position underscores Ackman’s confidence in Hertz’s long‑term turnaround prospects, even as he remains willing to deploy derivatives to amplify exposure without further upfront capital.(3)

The market’s response was swift and dramatic: Hertz shares surged 56.4 percent in regular trading—closing at $5.71—immediately after the SEC filing disclosure, then leapt 33.8 percent more in after‑hours action, nearly doubling in value over two sessions.(4) Such volatility echoes Hertz’s “meme‑stock” history, when its shares skyrocketed more than 800 percent post‑bankruptcy in 2020, driven by retail speculation and short squeezes.(5)

Beyond conventional value metrics, Ackman highlighted that U.S. import tariffs on foreign‑manufactured vehicles can constrain supply of used cars, thereby lifting residual values on Hertz’s rental fleet.(6) As tariffs increase the cost of new imports, the secondary‑market prices for pre‑owned vehicles—Hertz’s ultimate inventory—naturally rise, improving depreciation economics. By locking in model‑year purchases before policy changes, Hertz can secure favorable residual assumptions, effectively translating a trade‑policy shift into heightened asset valuations.(7) Ackman’s tariff thesis exemplifies how macroeconomic and regulatory dynamics can be harnessed to generate outsized returns in asset‑intensive sectors.(8)

Hertz’s dramatic rebound belies underlying challenges. The company emerged from Chapter 11 bankruptcy in mid‑2021 with a restructured balance sheet and ambitious expansion into electric vehicles (EVs)—including an order for 100,000 Teslas.(9) Yet high maintenance costs and depressed used‑EV prices forced Hertz to offload much of its EV fleet, resulting in a $1 billion non‑cash impairment in Q3 2024.(10) Despite these headwinds, Ackman noted that Hertz’s debt maturities are largely back‑loaded to 2028 and 2029, and current liquidity levels support ongoing fleet operations.(11) Going forward, Pershing Square’s substantial stake positions Ackman to advocate for management changes or strategic initiatives—ranging from fare restructuring to fleet optimization—to sustain momentum.(12)

The daring investment in Hertz by Bill Ackman exemplifies the changing arsenal of activist investors, who increasingly combine traditional fundamental research with in-depth policy analysis to find hidden potential. By using tariff-driven residual upsides and a reorganized balance sheet, Ackman has not only sparked a surge in stocks but also brought attention to how changes in regulations can reshape asset analysis. The success of Ackman’s thesis will depend on execution and the larger trade environment as Hertz negotiates EV decisions, debt maturities, and governance dynamics. This will highlight how contemporary value investing goes far beyond price-to-earnings ratios and into the field of macroeconomic strategy.

About the Author:

Jeremy Swenson is a disruptive-thinking security entrepreneur, futurist/researcher, and senior management tech risk consultant. Over 17 years, he has held progressive roles at many banks, insurance companies, retailers, healthcare organizations, and even government entities. Organizations appreciate his talent for bridging gaps, uncovering hidden risk management solutions, and simultaneously enhancing processes. He is a frequent speaker, podcaster, and a published writer – CISA Magazine and the ISSA Journal, among others. He holds a certificate in Media Technology from Oxford University’s Media Policy Summer Institute, an MBA from Saint Mary’s University of MN, an MSST (Master of Science in Security Technologies) degree from the University of Minnesota, and a BA in political science from the University of Wisconsin Eau Claire. He is an alum of the Cyber Security Summit Think Tank , the Federal Reserve Secure Payment Task Force, the Crystal, Robbinsdale and New Hope Citizens Police Academy, and the Minneapolis FBI Citizens Academy. He also has certifications from Intel and the Department of Homeland Security.


Endnotes:

  1. Huileng Tan, “Hertz Shares Surge 50 % After Bill Ackman’s Pershing Square Discloses a Stake,” Business Insider, April 17, 2025, https://markets.businessinsider.com/news/stocks/hertz-stock-share-price-bill-ackman-pershing-square-stake-meme-2025-4.
  2. Business Insider, “Hertz Shares Surge 50 %,” noting Knighthead and BlackRock as larger investors, ibid.
  3. “Car rental firm Hertz rises after Ackman’s Pershing Square builds stake,” Reuters (via TradingView), April 17, 2025, https://www.tradingview.com/news/reuters.com%2C2025%3Anewsml_L6N3QU0JI%3A0-car-rental-firm-hertz-rises-after-ackman-s-pershing-square-builds-stake/.
  4. “Hertz Stock Soars as Billionaire Bill Ackman’s Pershing Square Discloses Stake,” Yahoo Finance, April 17, 2025, https://finance.yahoo.com/news/hertz-surges-ackman-pershing-square-202632370.html.
  5. Huileng Tan, “Hertz Shares Surge 50 %…” Business Insider.
  6. “Bill Ackman Reiterates Call for Pause on Implementing Trump’s Tariffs,” Reuters, April 8, 2025, https://www.reuters.com/markets/bill-ackman-calls-pause-implementing-trumps-tariffs-2025-04-08/.
  7. Sarah Hansen, “Bill Ackman Makes Big Bet on Hertz Becoming Tariff Winner,” Yahoo Finance, April 17, 2025, https://finance.yahoo.com/news/ackman-says-pershing-owns-19-203543846.html.
  8. “Bill Ackman Confirms Nearly 20 % Stake in Hertz, Floats Uber Partnership,” Investing.com, April 17, 2025, https://www.investing.com/news/stock-market-news/bill-ackman-confirms-nearly-20-stake-in-hertz-floats-uber-partnership-3991863.
  9. “Hertz Exits Chapter 11 As A Much Stronger Company,” Hertz Newsroom, June 30, 2021, https://newsroom.hertz.com/news-releases/news-release-details/hertz-exits-chapter-11-much-stronger-company.
  10. Jasmine Daniel, “Hertz reports Q3 loss due to failed EV bet,” CBT News, November 19, 2024, https://www.cbtnews.com/hertz-reports-q3-loss-due-to-failed-ev-bet/.
  11. “Bill Ackman Confirms Nearly 20 % Stake…” Investing.com.
  12. Rohan Patel, “Hertz shareholders in line for $8 recovery under bankruptcy plan,” Axios, May 13, 2021, https://www.axios.com/2021/05/13/hertz-shareholders-bankruptcy-investors-stock.

Digital vs. Physical Heists: Does Crypto Theft Impact Cryptocurrency Value?

Fig. 1. Digital vs. Physical Financial Theft Graphic, Jeremy Swenson, 2025.

Minneapolis—

Cryptocurrencies have revolutionized the financial landscape, offering decentralized and borderless transactions. However, the rise of crypto fraud and theft poses significant challenges to the stability and perception of digital currencies. With large-scale hacks and scams frequently making headlines, the question arises: do these fraudulent activities ultimately raise or lower the value of cryptocurrencies? This article examines the immediate and long-term effects of crypto theft on digital asset valuation, comparing these incidents with traditional cash heists and analyzing market reactions, investor psychology, and regulatory responses.

High-Profile Crypto Thefts and Their Immediate Impact:

One of the most significant incidents in recent history is the Bybit exchange hack in February 2025, where approximately $1.5 billion worth of Ethereum was stolen during a routine transfer from a cold wallet to a warm wallet. The breach led to a temporary decline in Ethereum’s value and prompted over 350,000 withdrawal requests from concerned users. Bybit’s CEO, Ben Zhou, assured clients of the company’s solvency and commitment to reimbursing affected users, highlighting the exchange’s $20 billion in assets to cover the losses.[1] Yet this is hard to believe considering the firm’s newer status. This event underscores the immediate negative impact such breaches can have on cryptocurrency values and investor confidence.

Similarly, the 2016 Bitfinex hack resulted in the theft of 119,756 Bitcoins, causing a sharp decline in Bitcoin’s price by 20%. The exchange managed to recover and reimburse affected users over time, but the incident highlighted vulnerabilities in crypto security and the potential for significant market disruptions.[2] Other major breaches, such as the infamous Mt. Gox collapse in 2014 and the Ronin Network hack of 2022, further illustrate how large-scale thefts can shake the market.[3]

Digital Heists vs. Traditional Bank Robberies:

The magnitude of the Bybit crypto heist becomes more striking when compared to traditional bank robberies. Stealing $1.5 billion in cash presents substantial logistical challenges. For instance, $1 billion in $100 bills weighs approximately 10,000 kilograms (22,046 pounds) and would occupy significant physical space.[4] Transporting such a massive amount would require meticulous planning, heavy machinery, and considerable risk of detection.

In contrast, the largest cash robbery in U.S. history, the Dunbar Armored robbery in 1997, involved the theft of $18.9 million.[5] This amount, while substantial, pales in comparison to the $1.5 billion stolen digitally from Bybit. The largest known cash heist globally was the 2005 Banco Central burglary in Brazil, where thieves stole approximately $70 million by tunneling underground to access the vault.[6] Even this record-setting crime is dwarfed by the scale and ease of execution of digital heists, which require no physical transport or direct confrontation with law enforcement.

Statistical Trends in Crypto Fraud and Theft:

The prevalence of crypto-related fraud and theft has seen a marked increase over the years. In 2022, the FBI reported that Americans lost over $2.57 billion to cryptocurrency investment fraud, a staggering 183% increase from the previous year.[7] This figure represented more than two-thirds of all internet investment scam losses reported that year. By 2023, losses had escalated to over $5.6 billion, indicating a 45% surge from 2022.[8] These statistics reflect a growing trend of illicit activities within the crypto space, which can erode investor trust and negatively impact cryptocurrency values.

Long-Term Effects on Cryptocurrency Value:

While immediate reactions to fraud and theft often result in sharp declines in cryptocurrency values, the long-term effects can vary. In some cases, the market demonstrates resilience, with values rebounding as security measures are enhanced and regulatory frameworks are strengthened. For instance, despite the significant losses from various hacks and scams, the overall market capitalization of cryptocurrencies has continued to grow over the past decade.[9]

However, persistent incidents of fraud and theft can lead to increased volatility and deter potential investors, hindering mainstream adoption. The perception of cryptocurrencies as high-risk assets may be reinforced, leading to more cautious investment approaches and potentially suppressing value growth. Large institutional investors, who could provide market stability, may hesitate to enter the crypto space due to security concerns.[10]

Regulatory Responses and Market Confidence:

Regulatory bodies worldwide are becoming increasingly vigilant in addressing crypto-related fraud and theft. Enhanced regulations aim to protect investors and ensure the integrity of the financial system. While some argue that increased regulation may stifle innovation, others believe it is essential for building trust and stability in the crypto market.[11]

For example, the U.S. government’s recovery of funds from the Bitfinex hack and the subsequent legal actions against the perpetrators demonstrate a commitment to combating crypto-related crimes. Such actions can bolster investor confidence, potentially leading to a positive impact on cryptocurrency values over time.[12] Similarly, stricter Know Your Customer (KYC) and Anti-Money Laundering (AML) requirements for crypto exchanges have been implemented to deter illicit activities and restore trust in the industry.

Conclusion:

Crypto fraud and theft present significant challenges to the stability and perception of cryptocurrencies. While the immediate consequences often include sharp value declines and shaken investor confidence, the long-term impact hinges on the industry’s ability to strengthen security, implement effective regulations, and promote transparency. For crypto thieves and threat actors, the profitability of theft can incentivize further attacks, potentially driving up cryptocurrency values. The real question is: how much theft and insecurity can the system withstand before it collapses, or will its architects continue propping it up just long enough to cash out? As the crypto ecosystem evolves, addressing these vulnerabilities is essential for sustaining growth and maintaining public trust.

About the Author:

Jeremy Swenson is a disruptive-thinking security entrepreneur, futurist/researcher, and senior management tech risk consultant. Over 17 years, he has held progressive roles at many banks, insurance companies, retailers, healthcare organizations, and even government entities. Organizations appreciate his talent for bridging gaps, uncovering hidden risk management solutions, and simultaneously enhancing processes. He is a frequent speaker, podcaster, and a published writer – CISA Magazine and the ISSA Journal, among others. He holds a certificate in Media Technology from Oxford University’s Media Policy Summer Institute, an MBA from Saint Mary’s University of MN, an MSST (Master of Science in Security Technologies) degree from the University of Minnesota, and a BA in political science from the University of Wisconsin Eau Claire. He is an alum of the Cyber Security Summit Think Tank , the Federal Reserve Secure Payment Task Force, the Crystal, Robbinsdale and New Hope Citizens Police Academy, and the Minneapolis FBI Citizens Academy. He also has certifications from Intel and the Department of Homeland Security.

References:

  1. “Hackers steal $1.5bn from crypto exchange in ‘biggest digital heist ever,'” The Guardian, February 23, 2025.
  2. “Bitcoin Exchange Bitfinex Hacked, Loses $72 Million,” Reuters, August 3, 2016.
  3. “The Mt. Gox Bankruptcy and Its Lasting Impact on Crypto,” CoinDesk, March 2022.
  4. “Money Weight Calculator,” Good Calculators.
  5. “Dunbar Armored robbery,” Wikipedia.
  6. “The Biggest Bank Robbery in History,” Guinness World Records.
  7. “Fact Sheet: Crypto Harms by the Numbers,” Americans for Financial Reform, May 2024.
  8. “Americans lost $5.6 billion last year in cryptocurrency fraud scams,” AP News, September 2024.
  9. “Cryptocurrency Market Capitalization Hits New High Despite Scams,” Bloomberg, January 2025.
  10. “How Institutional Investors Approach Cryptocurrency,” Financial Times, November 2024.
  11. “How Global Regulators Are Cracking Down on Cryptocurrency Fraud,” Financial Times, December 2024.
  12. “US Recovers $3.6B Stolen in Bitfinex Hack, Arrests Two,” CNBC, February 8, 2022.

Mastercard’s Strategic Cyber, AI, and Blockchain Acquisitions: RiskRecon, CipherTrace, and Recorded Future

Fig. 1. Master Buys Recorded Future Infographic.[1]

Minneapolis—

Mastercard has long been a leader in the payments industry, known for its global network and cutting-edge financial solutions. However, in recent years, Mastercard has expanded its focus beyond traditional payments to include a broader suite of digital security, risk management, and compliance services. This shift is evident in its key acquisitions of RiskRecon, CipherTrace, and Recorded Future, each of which bolsters the company’s position in the fintech and cybersecurity ecosystems. By integrating AI, advanced analytics, blockchain, and enhanced compliance capabilities, Mastercard has emerged as a more competitive and savvy player in today’s rapidly evolving cyber and fintech landscapes.

1. RiskRecon (Acquired in December 2019):[2]

RiskRecon is a cybersecurity firm that specializes in third-party risk assessment. The company uses AI-driven analytics to help businesses understand and manage their cybersecurity exposure by continuously monitoring the cyber risk of vendors and partners.

Acquisition Details:

  • Date: December 2019
  • Cost: Undisclosed, but estimates place it around $150-200 million.
  • Company Size: A relatively small firm but highly influential in cybersecurity monitoring.

Strategic Value:

RiskRecon’s technology allows Mastercard to offer enhanced cyber risk management services to its business customers. The acquisition integrates AI-driven analytics to assess security risk levels, providing organizations with continuous monitoring of third-party systems, enabling early detection of vulnerabilities, and helping to avoid costly breaches.

For Mastercard, integrating RiskRecon offers:

  • Enhanced cybersecurity: Real-time risk assessments ensure the security of financial transactions.
  • Improved compliance: RiskRecon’s platform ensures businesses adhere to international regulations and frameworks for data security.
  • Fraud avoidance: By continuously scanning systems for vulnerabilities, Mastercard helps its customers avoid fraud or breaches stemming from third-party risks.

2. CipherTrace (Acquired in September 2021):[3]

CipherTrace is a blockchain analytics firm that helps organizations monitor and secure cryptocurrency transactions. Given the growing adoption of digital assets, CipherTrace provides tools for detecting fraud, tracing illicit transactions, and ensuring compliance with anti-money laundering (AML) regulations.

Acquisition Details:

  • Date: September 2021
  • Cost: Estimated at $250 million.
  • Company Size: Medium-sized firm with a specific focus on cryptocurrency compliance and fraud detection.

Strategic Value:

The acquisition of CipherTrace positions Mastercard as a key player in the emerging blockchain space. By integrating CipherTrace’s tools, Mastercard is equipped to:

  • Secure cryptocurrency transactions: Provide greater transparency in blockchain activities, reducing the risks of fraud, money laundering, and other illicit activities.
  • Enhance anti-money laundering (AML) compliance: CipherTrace’s tools help organizations comply with strict AML regulations, a significant concern with cryptocurrency.
  • Support blockchain adoption: As cryptocurrency becomes more mainstream, Mastercard ensures its networks are prepared to support digital asset transactions securely.

This acquisition directly ties into Mastercard’s strategy of offering fraud avoidance and enhanced compliance in the evolving digital economy. As blockchain technology continues to mature, Mastercard is well-positioned to support safe and compliant transactions in the cryptocurrency space.

3. Recorded Future (Acquired in September 2024):[4]

Recorded Future is an intelligence company specializing in real-time threat intelligence. By using machine learning and AI, Recorded Future aggregates and analyzes data to provide businesses with insights into potential cyber threats before they can cause damage. They currently have more than 1,900 clients, which span 75 countries, according to Mastercard. Those customers include 45 national governments as well as more than half of the companies in the Fortune 100, the payments firm said.

Acquisition Details:

  • Date: September 2024
  • Cost: Approximately $2.65 billion. Yet Mastercard was one of the key investors via an equity stake acquired through Insight Partners in 2021.
  • Company Size: Large, globally recognized threat intelligence company.

Strategic Value:

Recorded Future’s AI-driven threat intelligence adds another layer of security to Mastercard’s offerings:

  • Proactive cybersecurity: Recorded Future’s data and analytics can identify emerging threats before they impact Mastercard’s networks or those of its partners.
  • Advanced analytics and AI: Mastercard gains access to an enormous database of threat indicators, allowing the company to leverage AI to detect patterns and anticipate future threats.
  • Fraud prevention: Real-time threat intelligence makes it easier to stop fraud before it happens, protecting customers from financial loss.

By incorporating Recorded Future’s threat intelligence capabilities, Mastercard is enhancing its ability to prevent cyberattacks and protect the integrity of its global payments infrastructure.

Comparing Mastercard to Visa and American Express:

Mastercard’s acquisitions of RiskRecon, CipherTrace, and Recorded Future have significantly differentiated it from competitors like Visa and American Express.

  • Visa has also invested heavily in cybersecurity and compliance but lacks the comprehensive focus on third-party risk management (RiskRecon) and blockchain analytics (CipherTrace) that Mastercard now possesses. While Visa has ventured into cryptocurrency through partnerships and blockchain experimentation, it hasn’t yet integrated a firm like CipherTrace, which is critical for cryptocurrency compliance and fraud detection.
  • American Express, while focused on fraud prevention and customer experience, hasn’t made as aggressive a push into the cybersecurity and blockchain spaces as Mastercard. Amex remains a leader in traditional fraud detection and financial services but lacks the AI-driven intelligence and blockchain transparency that Mastercard has through Recorded Future and CipherTrace.

Mastercard’s comprehensive approach, combining cybersecurity (RiskRecon and Recorded Future), blockchain analytics (CipherTrace), and AI-enhanced threat intelligence, puts it ahead of both Visa and American Express in terms of securing digital transactions and ensuring regulatory compliance.

ConclusionA Well-Rounded Competitive Advantage:

In today’s fintech landscape, the convergence of cybersecurity, compliance, AI, and blockchain is crucial for payment processors to remain competitive. Mastercard’s strategic acquisitions of RiskRecon, CipherTrace, and Recorded Future provide a holistic solution to the growing challenges of cyber threats, cryptocurrency fraud, and AML compliance. These moves not only strengthen Mastercard’s existing payment network but also position the company as a leader in digital security.

By diversifying its portfolio and incorporating advanced technologies, Mastercard has gained an edge over competitors like Visa and American Express, especially in the areas of fraud avoidance, enhanced compliance, and cryptocurrency security. This forward-thinking approach ensures that Mastercard remains at the forefront of the financial industry, well-prepared for the future of digital payments and the ongoing battle against cybercrime.

About the Author:

Jeremy A. Swenson is a disruptive-thinking security entrepreneur, futurist/researcher, and seasoned senior management tech risk and digital strategy consultant. He is a frequent speaker, published writer, podcaster, and even does some pro bono consulting in these areas. He holds a certificate in Media Technology from Oxford University’s Media Policy Summer Institute, an MSST (Master of Science in Security Technologies) degree from the University of Minnesota’s Technological Leadership Institute, an MBA from Saint Mary’s University of Minnesota, and a BA in political science from the University of Wisconsin Eau Claire. He is an alum of the Federal Reserve Secure Payment Task Force, the Crystal, Robbinsdale, and New Hope Community Police Academy (MN), and the Minneapolis FBI Citizens Academy. You can follow him on LinkedIn and Twitter.


References:

[1] N, Balaji. “Mastercard Buys Recorded Future for $2.65 Billion.” 09/12/24. https://cybersecuritynews.com/mastercard-buys-recorded-future/

[2] Miller, Ron. “Mastercard acquires security assessment startup, RiskRecon.” Techcrunch. 12/23/19. https://techcrunch.com/2019/12/23/mastercard-acquires-security-assessment-startup-riskrecon/

[3] Mastercard. “Mastercard acquires CipherTrace to enhance crypto capabilities.” 09/01/24. https://www.mastercard.com/news/press/2021/september/mastercard-acquires-ciphertrace-to-enhance-crypto-capabilities/

[4] Alspach, Kyle. “5 Things To Know About Mastercard Acquiring Recorded Future”. CRN. 09/13/24. https://www.crn.com/news/security/2024/5-things-to-know-about-mastercard-acquiring-recorded-future