Organized Crime Network Investigation: Public Groups Offering Mixing, Cross-Chain Transfers and Transaction-Link Severance

Organized Crime Network Investigation: Public Groups Offering Mixing, Cross-Chain Transfers and Transaction-Link Severance

In cryptocurrency crime, money laundering (Money Laundering) is one of the most significant downstream crime categories. By converting fiat proceeds from fraud victims and illegal online gambling platforms into censorship-resistant cryptocurrency that is difficult to intercept, money launderers have established mature, large-scale, trustless methods of coordination.

Beyond mature fiat-to-crypto conversion methods such as “card/QR code to USDT” and “cash/physical assets to USDT,” crypto-to-crypto laundering (Crypto Laundering) that does not involve fiat currency has also emerged in recent years. Some operators even use illicit cryptocurrency transaction guarantee platforms to provide criminals with entirely crypto-based anti-tracing services under the labels of “mixing, cross-chain transfers and transaction-link severance.”

This article presents Bitrace’s investigation findings on this specialized area of criminal activity and explains its operating model.

Overview of Crypto-Laundering Methods

Core Business Model: Collection and Payout Through a Central Liquidity Pool

Analysis of on-chain transactions, fund flows and smart-contract interactions shows that the service’s purported “cross-chain exchange” function is, in substance, a collection-and-payout model built around a unified liquidity pool and operated as a Money Service Business (MSB), rather than a conventional cross-chain bridge exchange.

Crypto-laundering operators establish distributed liquidity pools spanning multiple channels, including centralized exchanges (CEXs), crypto payment providers and decentralized finance (DeFi) protocols. After receiving customer funds through account addresses at third-party platforms, they pay customers from another channel to customer-designated blockchain addresses. Because both the receiving and payout addresses are often accounts at centralized institutions that are not externally visible or channels offering high anonymity, this obfuscation technique can provide a degree of resistance to tracing. Merchants charge a percentage-based commission in the process.

Current on-chain analysis indicates that the service uses at least two methods of funding payouts: 

1. DeFi liquidity-pool payouts. The platform deposits a portion of its funds into JustLend to obtain jUSDT, which it holds as an internal liquidity-pool asset. When it receives a withdrawal order, it allocates the corresponding amount of jUSDT, converts it into USDT through a redemption execution contract, and pays the funds to the exchange deposit address specified by the customer;

2. VASP-channel payouts. The platform allocates funds to centralized virtual asset service providers (VASPs), such as Binance and B9 Crypto. When an order must be executed, a VASP account controlled by the platform withdraws the funds directly and sends them to the address specified by the customer or to the customer’s internal VASP account;

3. Composite on-chain channel payouts. The platform uses multiple types of on-chain infrastructure, including cross-chain bridges, decentralized exchanges and stablecoin conversion protocols, to convert illicit funds across multiple blockchains and assets before sending them to the customer.

If an on-chain investigator observes DeFi protocols and centralized institutions along the transaction path, this does not indicate multiple independent operations. Rather, they are different payout channels within the same liquidity-pool system.

Differences From the Traditional “Card-to-USDT” Money-Laundering Model

The traditional card-to-USDT model typically relies on large numbers of bank cards to receive funds. Upstream criminal proceeds first flow into multiple bank accounts, after which card dealers or money-mule networks consolidate the funds. Over-the-counter (OTC) merchants then use the proceeds to purchase virtual assets before transferring USDT to a wallet specified by the customer. Throughout the process, a clear conversion relationship exists between the fiat funds and the on-chain USDT. Bank cards are therefore critical nodes in the movement of funds and a primary focus of law enforcement. 

No evidence currently indicates that the crypto-laundering operation relies on the banking-card system. Instead, it operates entirely within the virtual-asset ecosystem. After the platform receives USDT from a user, it does not immediately pay the corresponding customer; the funds first enter a consolidated DeFi liquidity pool. When a customer makes a withdrawal, the platform uses assets already held in the pool to make the payment, severing the direct link between the on-chain source of funds and the ultimate recipient.

Differences From a Mixer

A mixer (Mixer) works by combining funds from multiple users. Cryptocurrency belonging to multiple users enters a common liquidity pool, after which the system uses methods such as randomized splitting, recombination and multiple rounds of transfers to pay funds to different addresses, breaking the direct link between input and output addresses. The mixing process generally does not preserve fixed amount ratios or stable one-to-one mappings of funds. Its anonymity primarily derives from the randomized commingling of funds from a large number of users.

Although the operation examined in this case also uses a liquidity-pool model, its mechanics differ markedly from those of a mixer. First, a mixer operates through smart contracts, while crypto-laundering public groups typically execute collections and payouts manually. Second, a mixer uses code to constrain transactions, while crypto-laundering public groups depend heavily on third-party transaction guarantee platforms to provide escrow services. Most importantly, crypto-laundering service providers are specialized participants in certain segments of the conventional on-chain money-laundering industry. They offer substantially greater flexibility and anonymity than ordinary on-chain infrastructure, making them harder to trace, much less subject to law-enforcement cooperation.

Crypto-Laundering Channels and Case Analysis

On July 7, 2026, cryptocurrency worth $1.75 million was stolen from a user of the Gate exchange. The proceeds were laundered through a crypto-laundering public group on Xinbi Guarantee named “Public Group F Team 673—Collateral Provided: 1.88 Million U; Binance/Mixing/Transaction-Link Severance/Cross-Chain/Crypto-to-U Public Group (Supply/Payout 0.1),” prompting significant discussion in the community. Bitrace conducted an in-depth investigation of the service provider. This section presents selected representative cases.

Case Study: Laundering Through JustLend

The service provider introduced JustLend, a lending protocol in the TRON ecosystem, as an intermediate step, completing fund delivery through a USDT–jUSDT–USDT conversion process.

 Across the transaction process, funds moved through multiple stages, including consolidation at operational addresses, deposits into the JustLend protocol, withdrawals by third-party addresses, transfers through operational contracts and final withdrawals to an exchange. This made the flow of funds more complex than conventional USDT transfers and increased the difficulty of on-chain tracing. The following transaction illustrates the public group’s operating model and techniques: 

Deposit: 03c020d244ca1220479589449f61ae7af7e5ab5337a29f416ce0cebd8e53d6cf

Redemption: 60232e19073e28c0b8cb86a1ff00e0abef832832b52d4dfd5cc031de5201b577

The crypto-laundering service provider deployed three contracts on-chain in advance. One contract executes USDT deposits into JustLend, another redeems USDT from JustLend and sends it directly to an address specified by a crypto-laundering customer, and a third controls the first two contracts. The arrangement is intended to isolate direct links among the service provider’s liquidity-pool address, the JustLend contract address and the address specified by the customer.

After confirming a customer transfer, the service provider first sends a specified amount of USDT from the liquidity pool to the collateral contract address. The contract simultaneously deposits the funds into JustLend to obtain the corresponding amount of jUSDT deposit tokens. The service provider then uses another address to trigger the control contract and execute a jUSDT transfer instruction. Finally, it uses the control contract to trigger the redemption contract, which redeems the USDT to the address specified by the customer.

In this case, the service provider charged the customer a commission of 50 USDT, equivalent to 1%. The proceeds remained at the deposit proxy contract address in the form of jUSDT.

Case Study: VASP Laundering Channels

VASPs, primarily centralized exchanges, are also among the most commonly used channels for transferring funds. Bitrace’s review of the merchant’s historical transaction records clearly shows how the operator used VASPs.

The first method involved direct withdrawals from VASP hot-wallet addresses, indicating that the exchange’s compliance function neither detected anomalous account activity on the platform nor identified the risk associated with the destination addresses. The second used several short-lived intermediary addresses to link user receiving addresses with VASP accounts. These intermediary addresses displayed highly regular mirrored-transfer patterns.

Multi-Asset, Multi-Chain Laundering Channels

After the July 7 incident, the service provider abandoned its previous laundering channels and continued operating through infrastructure including cross-chain bridges, decentralized exchanges and third-party stablecoins. The following analysis uses several July 11 transactions involving its Ethereum receiving address as examples:

0x789172f3be2f8d75e5074b6726ac527aa3e87a35

The address received four transactions totaling 1,005,000 USDT that day. It subsequently bypassed Newpay’s fund-consolidation rules, transferred the funds out directly, and completed multiple asset conversions and cross-chain transactions.

Throughout the process, the service provider first used a decentralized exchange (DEX) to convert the customer’s USDT into DAI. It then initiated a series of mirrored transfers, converted the funds back into USDT, routed them through a cross-chain bridge to the TRON Network to evade tracing, and finally converted them into USDD through the USDD-PSM protocol for accumulation. 

Because further-upstream funds were linked to additional funds transferred from Newpay addresses, this transaction may represent only a small part of a larger money-laundering operation.

Conclusion

The scale of crypto laundering is growing rapidly across illicit and gray-market communities. Because these services do not publicly disclose their full set of operational addresses, they can provide greater concealment than conventional mixers and pose a serious threat of illicit fund exposure to regulated entities, including centralized exchanges and centralized crypto payment platforms.

Compliance teams should remain informed about illicit and gray-market communities and prevalent criminal methods to address potential business risks.

Contact us:

Website: www.bitrace.io

Email: bd@bitrace.io

Twitter: @Bitrace_team

LinkedIn:@bitrace tech