What to Know

  • A U.S. Department of Justice asset forfeiture filing from Sept 9 includes a full letter attributed to Al-Qassam Brigades, the military wing of Hamas.
  • The letter advised potential donors that it was preferable not to use Binance to transfer support to the militant group’s wallet.
  • The guidance named rival platforms and applications including Bybit, OKX, Kast, Redotpay and Trust Wallet as options for completing transfers.
  • The letter recommended use of Tether’s USDT stablecoin and the TRC-20 network, which is used to create and manage fungible tokens on the Tron blockchain.
  • The document said Binance could be used to purchase currencies only, with another application then used to complete the transfer process.
  • The inclusion of a company in the letter does not by itself establish weak know your customer or anti-money laundering controls at that company.
  • The U.S. Treasury’s 2026 terrorist-financing risk assessment said groups including Hamas and ISIS continued to use digital assets, while traditional financial products and services remain terrorists’ preferred means of moving money.
  • Binance’s chief compliance officer said the instruction to avoid Binance shows the exchange’s controls are working.
  • OKX said the wallet address referenced in the Feb. 10, 2025, communication had no association with OKX and had already been identified by its internal controls as linked to illicit activity.
  • Kast said all customers are subject to identity verification and screening before accessing its services.

DoJ Filing Puts Crypto Compliance Back in Focus

A U.S. Department of Justice asset forfeiture filing has brought renewed attention to the way sanctioned and militant groups assess crypto platforms when seeking to move funds. The filing from Sept 9 includes a letter attributed to Al-Qassam Brigades, the military wing of Hamas, that advised potential donors to avoid using Binance for transfers tied to the group’s wallet and instead consider rival crypto platforms and applications.

The guidance, as presented in the filing, is notable because it appears to show an illicit financing network making operational judgments about which crypto services may be more likely to block, detect or complicate a transaction. For the digital asset industry, the episode underscores a long-running tension: open blockchain networks and stablecoins can be used for legitimate payments, remittances and trading, but they can also be targeted by sanctioned actors attempting to bypass restrictions.

The letter stated that it was preferable not to use the Binance platform to transfer support and warned donors not to enter any data indicating the group’s official name, saying this could lead to a wallet being blocked and raising safety concerns. It suggested fictitious recipient data and listed Trust Wallet, Redotpay, OKX, Kast and Bybit as applications through which transfers could be made.

USDT and Tron Network Named in the Letter

The communication also recommended Tether’s USDT stablecoin and the TRC-20 network. TRC-20 is a token standard on the Tron blockchain that is used to create and manage fungible tokens. Stablecoins such as USDT are designed to maintain a stable value by being pegged to a reserve asset like the U.S. dollar, making them attractive for users who want to move value without exposure to the sharp price swings associated with many cryptocurrencies.

In the context of illicit finance, stablecoins can be appealing because they combine blockchain settlement with a relatively steady unit of account. At the same time, the transparent nature of public blockchains can give investigators, compliance teams and analytics firms a pathway to trace flows, identify connected wallets and support enforcement actions. That dual character has made stablecoins a central focus for regulators, law enforcement and crypto companies trying to detect and disrupt sanctioned activity.

The letter’s reference to Binance was especially striking because it did not portray the exchange as the preferred channel for completing transfers. Instead, the document said Binance could be used to purchase currencies only, after which another application could be used to complete the transfer process. Market participants viewed that detail as a potential indication that the group perceived greater monitoring, blocking risk or compliance friction at Binance, though the filing does not establish why the instruction was given.

Company Names Do Not Prove Control Failures

The appearance of Bybit, OKX, Kast, Redotpay and Trust Wallet in the letter does not necessarily indicate that any of those firms have inadequate know your customer or anti-money laundering controls. Large crypto platforms, wallets and stablecoins are widely used for lawful purposes, and illicit actors often attempt to exploit well-known infrastructure precisely because it is liquid, accessible and familiar to many users.

That distinction is important for the broader digital asset market. A sanctioned group may name a platform in private instructions, but that alone does not show that a platform knowingly facilitated prohibited activity or lacked screening procedures. Compliance quality depends on factors including identity verification, sanctions screening, wallet risk scoring, transaction monitoring, escalation procedures, law enforcement cooperation and the ability to block or report suspicious activity.

OKX said the wallet address referenced in the Feb. 10, 2025, communication had no association with OKX and had already been identified by its internal controls as linked to illicit activity. The exchange said that any attempts by OKX customers to transfer funds to the address would have been flagged and prevented. That response places emphasis on wallet-level risk detection, a key element of crypto compliance because blockchain addresses can often be screened before funds are released.

Kast said it maintains a dedicated financial crime compliance function and has more than 50 employees across its broader compliance organization. A Kast spokesman said all customers are subject to identity verification and screening before accessing its services. The company also said it combines its own technology with established compliance and risk-management providers including Elliptic, Sumsub and Sardine to support sanctions screening, customer due diligence and transaction monitoring.

Binance Frames the Letter as Evidence of Stronger Controls

Binance responded by pointing to its compliance infrastructure. Noah Perlman, Binance’s chief compliance officer, said that when terrorist groups tell people to avoid Binance, it shows the exchange’s controls are working. He said Binance is not a safe place for illicit actors and that the company invests heavily in sanctions screening, transaction monitoring and investigations while working closely with law enforcement to identify, disrupt and report terrorist financing and other financial crime.

The filing has prompted discussion among technical traders, policy watchers and compliance professionals about whether major centralized exchanges are becoming harder targets for sanctioned actors. While the documents suggest Binance may have improved its know your customer and anti-money laundering protocols, it remains unclear whether the Hamas-linked instruction was directly a response to those improvements or to some other operational consideration.

For crypto companies, the reputational stakes remain high. Exchanges and wallet providers operate in a sector that is still fighting perceptions that digital assets are uniquely suited to illicit finance. The industry often argues that blockchain transparency gives investigators tools unavailable in cash-based systems, while critics point to the speed, global reach and pseudonymous nature of crypto transactions as persistent risks.

Digital Assets Remain One Channel Among Many

U.S. authorities have increasingly focused on digital assets in terrorist-financing investigations, especially after the Oct. 7, 2023, attacks on Israel by Hamas. The U.S. Treasury’s 2026 terrorist-financing risk assessment said groups including Hamas and ISIS have continued using digital assets for donations and transfers. However, it also said traditional financial products and services remain terrorists’ preferred means of moving money.

That point matters because crypto is not the only financial channel available to illicit networks. Terrorist financing can involve banks, money services businesses, cash couriers, informal value transfer systems and trade-based methods. Digital assets have become part of that landscape, particularly where stablecoins and online wallets are available, but they sit alongside older and often still-dominant methods.

Hamas has reportedly solicited cryptocurrency donations, though the scale and effectiveness of those efforts remain unclear. The Wall Street Journal reported on October 10, 2023, that cryptocurrency wallets connected to Hamas received about $41 million between 2020 and 2023. The newspaper subsequently reported that the Treasury is investigating $165 million in cryptocurrency-linked transactions that may have helped finance Hamas prior to the October 2023 attacks.

Those figures have been central to public debate over the role of crypto in terrorism financing, but investigators and policymakers continue to distinguish between funds received, suspected flows, blocked transactions and money that ultimately reaches an intended recipient. Blockchain analytics can identify flows associated with risky wallets, yet determining ultimate control, purpose and successful use of funds can require additional intelligence and law enforcement work.

Why the TRC-20 Reference Matters

The letter’s emphasis on the TRC-20 network is significant because token networks can differ in cost, speed, liquidity and user adoption. Illicit actors often care about the same practical factors that legitimate users do: whether a transfer is cheap, whether the token is widely accepted, whether wallets support it and whether counterparties know how to receive it.

For compliance teams, network choice can also shape monitoring strategy. A stablecoin transfer may move across one blockchain rather than another, requiring surveillance tools that can identify risk across multiple chains and token standards. When an illicit actor names a specific network, it provides a clue about preferred routing and can help investigators focus on transaction patterns, wallet clusters and service exposure.

At the same time, the fact that a stablecoin or network is mentioned in illicit guidance does not mean the technology itself is illicit. USDT and Tron-based tokens are used by a wide range of market participants. The issue for regulators and companies is whether intermediaries can identify prohibited users and suspicious transactions while preserving lawful access for ordinary customers.

Regulatory Pressure Is Likely to Stay Elevated

The DoJ filing adds to the pressure on exchanges, wallet providers and stablecoin issuers to demonstrate that they can manage financial crime risks. Policymakers have repeatedly pushed for stronger standards around sanctions screening, customer due diligence and cross-platform cooperation. The focus is especially intense when digital assets intersect with national security concerns.

For centralized exchanges, the path forward is likely to involve heavier investment in compliance teams, blockchain analytics, law enforcement liaison functions and automated monitoring systems. For wallet providers and payment applications, risk management can be more complex depending on whether they custody user funds, conduct identity checks or operate as software interfaces. The distinctions between custodial platforms and non-custodial tools are often central to regulatory debates.

FXCOINZ views the latest filing as another reminder that crypto market structure is now deeply intertwined with enforcement policy. The industry’s long-term credibility will depend not only on trading volumes, product innovation and user growth, but also on whether platforms can keep sanctioned actors from exploiting the same rails used by legitimate customers.

Frequently Asked Questions (FAQs)

What did the DoJ filing reveal about Hamas-linked crypto instructions?

The filing included a letter attributed to Al-Qassam Brigades that advised potential donors not to use Binance to transfer support and instead named other crypto applications and platforms as options for completing transfers.

Which crypto platforms were named in the letter?

The letter named Bybit, OKX, Kast, Redotpay and Trust Wallet. It also said Binance could be used to purchase currencies only before another application was used to complete the transfer process.

Did the letter recommend a specific stablecoin?

Yes. The guidance recommended using Tether’s USDT stablecoin, which is designed to maintain a stable value by being pegged to a reserve asset like the U.S. dollar.

What is the TRC-20 network?

TRC-20 is a token standard on the Tron blockchain used to create and manage fungible tokens. The letter recommended the TRC-20 network alongside USDT.

Does being named in the letter mean a platform has weak controls?

No. The inclusion of a company in the letter does not by itself prove weak know your customer or anti-money laundering controls. Illicit actors may attempt to use widely known crypto services even when those services operate compliance programs.

How did Binance respond?

Binance’s chief compliance officer, Noah Perlman, said that when terrorist groups tell people to avoid Binance, it shows the company’s controls are working. He said Binance invests in sanctions screening, transaction monitoring, investigations and cooperation with law enforcement.

What did OKX say about the referenced wallet address?

OKX said the wallet address referenced in the Feb. 10, 2025, communication had no association with OKX and had already been identified by its internal controls as linked to illicit activity. The exchange said attempted customer transfers to the address would have been flagged and prevented.

What compliance measures did Kast describe?

Kast said it has a dedicated financial crime compliance function and more than 50 employees across its broader compliance organization. It said customers are subject to identity verification and screening, supported by internal technology and providers including Elliptic, Sumsub and Sardine.

Are digital assets the main method for terrorist financing?

The U.S. Treasury’s 2026 terrorist-financing risk assessment said groups including Hamas and ISIS continued using digital assets for donations and transfers, but it also said traditional financial products and services remain terrorists’ preferred means of moving money.