DOJ Seizes $560,000 in Hamas-Linked Crypto as FBI Takes Over Fundraising Sites

Crypto Seizures Expose Digital Fundraising Channels Used by Hamas
The U.S. Department of Justice made a significant announcement on September 1, 2026, detailing a coordinated and comprehensive set of actions that successfully recovered more than $560,000 in cryptocurrency donations that were intended for Hamas and its military wing, known as the Al-Qassam Brigades. The court-authorized seizures, which spanned 2025 and 2026, also enabled the FBI to take control of various domains and servers the group had previously used for fundraising and recruitment. Officials described this extensive effort as part of their ongoing work aimed at interrupting and dismantling the digital channels that have been supporting terrorist operations. Human intelligence sources, along with advanced blockchain analysis, played central roles in identifying the rotating wallet addresses promoted through encrypted chats and various websites.
This operation yielded valuable intelligence on thousands of individuals who reached out to the platforms in an effort to contribute funds to the organization. This series of seizures clearly demonstrates how law enforcement agencies effectively combine human intelligence with sophisticated on-chain tracing techniques to disrupt terrorist access to digital assets and online infrastructure. This disruption limits the resources available for recruitment and operational activities while simultaneously generating actionable data that can be utilized for future investigations. The collaborative efforts of various agencies show the importance of innovative strategies in combating the financing of terrorism in the digital age.
Court Warrants Target Rotating Crypto Addresses Promoted Through Encrypted Channels
Investigators identified a fundraising system in which a group chat claiming association with Hamas directed supporters to a website and supplied a changing set of cryptocurrency donation addresses. Three seizure warrants executed on March 25, June 25, and October 10, 2025, authorized the recovery of approximately $560,000 in digital assets destined for the Al-Qassam Brigades. The first of these actions alone recovered about $201,400 from wallets and accounts linked to a network that had moved more than $1.5 million since October 2024. Human sources provided critical leads that enabled tracing of funds across multiple addresses.
Officials noted that the addresses were controlled on behalf of Hamas’s military wing. Blockchain analysis helped follow flows despite efforts to obscure the trail through address rotation. The warrants formed the financial core of a broader disruption that later expanded to internet infrastructure. Court documents released with the September 2026 announcement detailed how these early interventions built the foundation for subsequent actions. The approach relied on repeated identification of new addresses as operators adjusted tactics after earlier freezes. This methodical process limited the network’s ability to consolidate and move donations freely.
FBI Assumes Control of AlQassam.ps Domains and Related Servers
In conjunction with the cryptocurrency recoveries, the FBI’s Albuquerque Field Office worked with human sources to identify and seize domains and servers controlled by the Al-Qassam Brigades, including the main website AlQassam.ps. Warrants dated July 29 and August 18, 2026, authorized these infrastructure actions. Capture of the domains and servers enabled agents to intercept additional cryptocurrency donations that would otherwise have reached the group. The infrastructure had supported both fundraising appeals and recruitment messaging directed at global supporters. Officials stated that the seizures created distrust among potential donors by disrupting reliable communication channels. Related methods also produced information on thousands of people who contacted the platforms to donate via crypto or traditional means.
That intelligence is expected to support future counterterrorism work. The operation involved coordination among the FBI’s Counterterrorism Division, Cyber Division, and New York Field Office. Prosecutors from the U.S. Attorney’s Office for the District of Columbia and the National Security Division handled the case. Assistant Attorney General for National Security John A. Eisenberg emphasized that the actions deprive Hamas of resources used to recruit and finance attacks. The dual focus on funds and platforms illustrated a strategy of targeting both the money and the mechanisms that solicit it.
Human Sources Provide Critical Leads Across Multiple Investigation Phases
Confidential human sources located in the United States and elsewhere supplied early alerts about Telegram posts and encrypted chats soliciting contributions for the Al-Qassam Brigades. One source identified a financing network in February 2025 that directed supporters to contact an associated email address for donation instructions. Responses from that address included new wallet details, often for USDT on the Tron blockchain. Investigators used these leads to initiate blockchain tracing and expand the map of related addresses. Sources continued to collect updated donation instructions as operators rotated wallets after earlier seizures. This human intelligence complemented technical analysis and allowed agents to stay ahead of changes in the network’s operational security.
Court filings describe a prolonged effort in which sources monitored group chats claiming Hamas ties and reported new addresses as they appeared. The combination of human reporting and on-chain data enabled precise targeting of wallets that received and moved funds. Officials highlighted that reducing the group’s ability to receive donations and sowing distrust in its communication channels formed the primary focus of the latest phase. The sustained use of sources across 2025 and into 2026 demonstrated the value of persistent human collection in digital terrorism-financing cases.
Network Moved Millions Through Stablecoin and Multi-Asset Flows Before Seizures
Court documents indicate the fundraising network operated since around October 2024 and received substantial volumes before the major recoveries. One operational wallet associated with the Al-Qassam Brigades took in approximately 1.57 million USDT between late October 2024 and March 2025. Later estimates placed total donations to the broader network above $3 million by November 2025, with instructions still circulating into early 2026. Assets involved across the cases included Bitcoin, Ethereum, Wrapped Ethereum, Tether, and Tron, spread over numerous addresses and some exchange accounts. Rotation of addresses and movement across bridges and exchanges formed part of the effort to complicate tracing.
Blockchain analytics firms later noted that investigators followed flows into operational wallets and through intermediary services. The first public seizure in March 2025 recovered roughly $201,400 and publicly signaled that the network was under active scrutiny. Subsequent warrants in June and October 2025 expanded the recovered amount to the cumulative $560,000 figure announced in 2026. These volumes, while significant for the specific network, represent only a portion of broader Hamas financing activities documented in earlier related cases. The pattern of using stablecoins for speed and lower fees appeared repeatedly in the affidavits.
Intelligence Yield Identifies Thousands of Potential Donors for Follow-On Work
Beyond the direct recovery of funds and control of infrastructure, the operation produced information regarding thousands of individuals who contacted Hamas-linked platforms in efforts to donate. These contacts involved both cryptocurrency and traditional payment methods. Officials stated that the data will support future FBI counterterrorism efforts. U.S. Attorney Jeanine Ferris Pirro for the District of Columbia described the collection of names and identities as an additional outcome of seizing the servers and domains. The ability to intercept communications and donation attempts after taking control of AlQassam.ps and related systems expanded the intelligence value of the technical seizures. Assistant Director Brett Leatherman of the FBI’s Cyber Division noted that Hamas had relied on cryptocurrency and online platforms to solicit funds from donors worldwide and move money outside formal financial systems.
The disruption therefore struck at both the inflow of resources and the group’s capacity to maintain trusted digital channels. Special Agent in Charge Justin A. Garris of the Albuquerque Field Office underscored the focus on reducing donation capabilities and creating distrust among supporters. This dual impact, financial and operational, distinguishes the set of actions from purely asset-focused recoveries. The intelligence component positions the case as a longer-term contribution to monitoring and disrupting similar networks.
Officials Frame Seizures as Part of Sustained Pressure on Terrorist Financing
Statements accompanying the announcement placed the recoveries in the context of continuous efforts against Hamas financing. Assistant Attorney General John A. Eisenberg said the seizures deprive the group of resources it relies on to recruit and radicalize individuals online and to finance attacks such as those of October 7, 2023. He added that authorities will continue infiltrating online networks, confiscating cryptocurrency, and shutting down websites. U.S. Attorney Pirro delivered a direct message that networks are not secure, crypto is vulnerable, and efforts will persist until the group’s capacity for violence is defeated. FBI Cyber Division leadership emphasized ongoing use of authorities to intercept illicit funds and prevent exploitation of digital networks.
Albuquerque Field Office leadership described the work as demonstrating commitment to shutting off the flow of funds. These comments reflect a strategy that treats cryptocurrency fundraising as one vector among others rather than an isolated phenomenon. Earlier related actions, including a 2025 civil forfeiture targeting roughly $2 million linked to a Gaza-based money-transfer business, illustrate the broader campaign. The September 2026 announcement consolidated five related court-authorized actions into a single public update, underscoring the cumulative nature of the investigation.
Blockchain Analysis Enables Mapping of Wider Networks Over Time
Public analysis of the cases shows how on-chain evidence from earlier seizures helped investigators expand their understanding of the financial network. Blockchain analytics tools supported tracing of funds into donation addresses through operational wallets, across bridges, and into exchanges. The progression from the March 2025 recovery through later warrants shows investigations that build iteratively as new data becomes available. Rotation of addresses and use of multiple assets required sustained monitoring rather than one-time interventions. Analysts observed that such cases provide visibility into how crypto-enabled financing networks adapt.
The involvement of stablecoins such as USDT facilitated relatively quick movement while still leaving a permanent ledger that investigators could examine. Coordination between human sources who obtained fresh addresses and technical teams who followed the subsequent flows proved essential. The Albuquerque Field Office’s role in both the financial and infrastructure phases indicates integrated operational planning. Releases of the underlying affidavits allow independent review of the tracing methodology and the evidence supporting attribution to the Al-Qassam Brigades. This transparency supports both public accountability and the development of improved detection practices across the industry.
Infrastructure Seizures Disrupt Recruitment Messaging Alongside Fundraising
Control of the domains and servers extended beyond financial interception to affect recruitment and supporter engagement. The Al-Qassam Brigades’ main website and related platforms had served the dual purpose of soliciting donations and communicating with potential supporters. Taking over these systems interrupted established channels and reduced the reliability of instructions provided to donors. Officials noted that creating distrust in communications formed an explicit operational goal. The Iranian-hosted infrastructure used until spring 2026 further illustrated the international dimensions of the digital operations.
Seizure warrants authorized the FBI to operate the captured infrastructure in a manner that supported interception. This capability generated the donor-contact data later described in public statements. The combination of website control and cryptocurrency recovery addressed both the means of solicitation and the assets themselves. Prior Hamas experimentation with virtual currency fundraising dating to around 2019 provided historical context for the persistence of these methods. The 2026 actions represent a significant escalation in technical disruption relative to earlier messaging-focused efforts.
Cumulative Recoveries Reflect Multi-Year Investigative Continuity
The $560,000 figure announced in September 2026 aggregates results from warrants executed over more than a year rather than a single event. The March 2025 action recovered the initial $201,400 and publicly confirmed the existence of the rotating-address network. Subsequent June and October 2025 warrants were added to the total as investigators continued identifying and freezing additional wallets. Infrastructure actions in July and August 2026 completed the set of five related court orders. This timeline shows an investigation that adapted as the target network adjusted its practices after early losses.
Estimates of overall network inflows exceeding $3 million by late 2025 indicate that the recovered portion, while material, formed part of a larger flow that authorities sought to constrain. Continued distribution of donation instructions into 2026 demonstrated residual activity even after multiple interventions. The public consolidation of these actions in a single announcement allowed officials to present the full scope of progress. Coordination across FBI field offices and National Security Division components supported the sustained effort. The case therefore serves as an example of how digital terrorism-financing investigations often unfold over extended periods with incremental gains.
Asset Composition Includes Stablecoins Favored for Speed and Cost
Filings and subsequent reporting identified Bitcoin, Ethereum, Wrapped Ethereum, Tether, and Tron among the cryptocurrencies involved. Tether’s USDT appeared prominently, consistent with its use for relatively fast, low-fee transfers on networks such as Tron. Eighteen Tether-controlled addresses and three Binance accounts featured in the documentation of assets linked to financing a foreign terrorist organization. The preference for stablecoins reflects practical considerations of value stability and transaction efficiency rather than absolute anonymity. Blockchain records nevertheless enabled investigators to connect individual donation addresses to common operational wallets.
Movement of funds through bridges and exchanges added layers that required specialized analytics to unwind. The presence of exchange accounts among the seized assets highlights the continuing role of centralized platforms as points of potential interdiction when attribution is established. Earlier related forfeiture actions involving multimillion-dollar sums connected to sanctioned entities further contextualize the use of digital assets in the broader financing picture. The specific mix of assets in the $560,000 recovery underscores the need for multi-chain investigative capabilities.
Public Statements Emphasize Vulnerability of Digital Terrorist Channels
Leadership remarks accompanying the announcement repeatedly stressed that cryptocurrency and online platforms remain subject to effective interdiction. Pirro’s video statement asserted that Hamas networks are not secure and that crypto assets are vulnerable. Eisenberg linked the seizures directly to reducing capacity for recruitment and for financing attacks. Leatherman focused on the FBI’s continued authority to intercept funds and prevent exploitation of digital networks. Garris highlighted the creation of distrust among donors as a core outcome.
These coordinated messages serve both to describe the specific achievements and to signal ongoing priority. The inclusion of intelligence on thousands of attempted donors extends the impact beyond the immediate financial recovery. Officials presented the work as continuous rather than conclusive, consistent with the multi-year pattern of related actions. The emphasis on human sources alongside technical tools reinforces that successful disruption often depends on combined methods. Release of the underlying affidavits supports verification of the claims and provides material for further analysis by researchers and compliance professionals.
Case Illustrates Iterative Nature of Crypto Terrorism Financing Investigations
The sequence of warrants and the progressive expansion of the investigation illustrate how blockchain transparency, when paired with human intelligence, supports iterative mapping of networks. Early seizures generated both recovered assets and new leads that informed later actions. Adaptation by the target network through address rotation and infrastructure changes was met with corresponding adjustments by investigators. The eventual takeover of domains and servers marked a shift from pure financial interdiction to control of the solicitation platforms themselves. Intelligence derived from that control added a forward-looking dimension.
Industry observers noted that such public cases offer insight into evolving tactics on both sides. The relatively modest absolute size of the $560,000 recovery relative to estimated total network inflows does not diminish the operational value of disrupting trusted channels and collecting donor data. Coordination across multiple FBI components and the National Security Division enabled the sustained pressure. The case therefore contributes concrete evidence to broader discussions of how digital assets figure in contemporary terrorism-financing risk.
FAQs
What specific cryptocurrencies were involved in the seized funds?
Court filings and subsequent reporting identified Bitcoin, Ethereum, Wrapped Ethereum, Tether (USDT), and Tron among the assets recovered across the three 2025 cryptocurrency warrants. USDT appeared frequently because of its utility for relatively quick and low-cost transfers, particularly on the Tron network. Assets were held across numerous rotating addresses and some exchange accounts. The presence of multiple chains required investigators to conduct multi-network tracing to connect donation addresses to common operational wallets controlled on behalf of the Al-Qassam Brigades.
How did human sources contribute to the investigation?
Confidential human sources provided early identification of encrypted group chats and Telegram posts that directed supporters to fundraising websites and supplied rotating cryptocurrency addresses. Sources obtained updated wallet instructions by contacting associated email addresses and reported changes as operators adjusted after earlier freezes. This human reporting supplied the initial leads that blockchain analysts then expanded through on-chain tracing. The sustained collection of fresh addresses across 2025 and into 2026 enabled investigators to keep pace with the network’s operational security measures.
What role did the seizure of AlQassam.ps play beyond stopping donations?
Taking control of the main website and related domains and servers allowed the FBI to intercept further cryptocurrency transfers that would have reached the group. The action also disrupted established channels for recruitment messaging and supporter engagement. Operation of the captured infrastructure generated information on thousands of individuals who contacted the platforms seeking to donate. Officials described the creation of distrust in the group’s digital communications as an explicit objective of the infrastructure phase.
When were the various warrants executed?
Three cryptocurrency seizure warrants were executed on March 25, June 25, and October 10, 2025, recovering a cumulative $560,000. Two additional warrants dated July 29 and August 18, 2026, authorized the seizure of domains and servers. The Justice Department publicly announced the consolidated results of these five related actions on September 1, 2026. The timeline reflects an investigation that continued and adapted over more than a year.
How large was the overall fundraising network relative to the seized amount?
Court documents estimate that the network received more than $1.5 million since October 2024 by the time of the first major seizure, with one operational wallet alone taking in approximately 1.57 million USDT in a several-month period. Later assessments placed total donations above $3 million by November 2025. The $560,000 recovered therefore represents a meaningful but partial interdiction of a larger flow that authorities sought to constrain through repeated interventions.
🔥 KuCoin Offers A More Stable Option in A Volatile Market
If you worry about the frequent ups and downs in the market, and pursue a more stable option to earn money passively, KuCoin is the right place to come:

Simple Earn: Deposit and withdraw tokens anytime, earning stable returns.
Kucoin Earn: Earn stable profits with professional asset management.
Hold to Earn: Earn rewards by holding assets in Funding, Trading, Margin, Futures, Mining, and Unified Accounts.
Staking: Unlock the earning potential of on-chain assets.
Advanced Investments: Advanced Investments offer a variety of structured products to help your money grow in any market.
Shark Fin: Principal Protection and Guaranteed Gains
Dual Investment: Buy low and sell high with transparent return calculations.
Snowball: High yields, with price protection.
Discount Buy: Buy crypto at discount prices.
KCS Loyalty: Level up to enjoy exclusive perks by staking ≥ 1 KCS.
KuCoin Wealth: Discover future value and begin your smart investing journey.
KCS Benefits: Hold and stake KCS to access benefits across the platform.
KCS Staking 2.0: Participate in KCS on-chain governance to earn yield.
Disclaimer: This content is for informational purposes only and does not constitute investment advice. Cryptocurrency investments carry risk. Please do your own research (DYOR).
