

The 2026 National Money Laundering Risk Assessment examines the threats and vulnerabilities that allow illicit funds to move through the U.S. financial system. Its assessment period covers January 2024 through December 2025.
The Treasury does not portray digital assets as the only or largest channel for illicit finance. In fact, it states that the overall volume of money laundering involving digital assets remains well below money laundering through fiat currency and other methods.
At the same time, digital asset money laundering can be central to crimes that begin and end in digital channels. Treasury points to digital asset investment scams, ransomware, sanctions evasion, terrorist financing, drug trafficking, and other forms of cyber-enabled crime. In these cases, criminals may use digital assets to receive proceeds, obscure their origin, move value across borders, or convert funds back into fiat currency.
The report’s strongest message is not that every digital asset transaction is suspicious. It is that criminals are becoming more sophisticated in combining several financial channels and technical tools into a single laundering process.
Stablecoins feature prominently in the Treasury’s discussion of digital asset money laundering. The report says illicit actors are increasingly using them to facilitate transactions and store proceeds.
The reasons are practical. Stablecoins can offer liquidity, relative price stability, and rapid settlement. Those same features support legitimate payments and trading activity, but they can also make stablecoins useful to criminals seeking to move value without holding a volatile asset.
Treasury describes stablecoins as one element in a more complex process. A criminal may move funds through a digital asset service provider, switch between assets, transfer value through self-hosted wallets, and then seek a fiat cash-out. Some over-the-counter brokers facilitating conversion from digital assets to fiat may also request stablecoins rather than other digital assets.
That means a stablecoin transfer should not be treated as a verdict. Its relevance depends on the wider facts: source of funds, transaction path, wallet relationships, customer behavior, timing, and destination.
Treasury groups the core digital asset money laundering vulnerabilities into four areas:
Each of these can matter on its own. The greater risk often appears when they overlap.
A service with weak controls may allow criminals to open or use accounts with false identifying information. A cross-border route may pass through a jurisdiction where AML/CFT rules have not been fully implemented. A bridge, swap, or mixing service may then make the transaction trail harder to interpret. The funds may finally move through self-hosted wallets, where there is no intermediary collecting the same customer information available in a regulated account relationship.
This is why digital asset money laundering should be analyzed as a route, not a list of isolated tools.
Mixers, anonymity-enhancing cryptocurrencies, darknet market laundering services, chain-hopping, decentralized finance services, and cross-chain bridges can make tracing more difficult.
Treasury explains that criminals may exchange assets across blockchains, use bridges, or conduct large volumes of rapid transactions through a broad network of addresses. These actions can create a complex transaction trail and complicate efforts to assess whether incoming funds are connected to illicit activity.
None of these technologies automatically indicate wrongdoing. Legitimate users may use bridges, swaps, or self-custody for valid reasons.
The question for an investigator is how the tool was used. A single bridge transaction by a long-standing customer may not mean much. A newly created wallet that receives suspected scam proceeds, swaps assets, moves through a bridge, and sends funds to related off-ramp infrastructure presents a different review question.
Strong digital asset money laundering controls focus on patterns, not shortcuts.
Self-hosted wallets allow users to hold and transfer digital assets without an intermediary financial institution. Treasury notes that peer-to-peer transfers can limit authorities’ ability to access customer and transaction information.
Public blockchains can still provide useful transparency. Transaction flows, timing, token movements, and wallet relationships may all be visible. Yet that transparency does not automatically identify the person controlling a wallet or explain the purpose of a transfer.
For compliance teams, this creates an important gap between visible activity and actionable understanding. An address may have an unusual transaction history, but the organization still needs to determine what the observed facts support.
That is where information provenance becomes important. Teams should be able to separate what they observed onchain, what they inferred from behavior, what a customer explained, and what has been verified through an authorized investigative source.
Treasury’s assessment reinforces the need for a disciplined workflow around digital asset money laundering. Monitoring systems, customer due diligence, sanctions controls, and blockchain analysis can all help surface activity that needs review. No single alert should carry the entire decision.
A useful review should ask:
This approach supports faster decisions without assuming certainty. It can help teams decide whether to monitor activity, conduct enhanced review, preserve relevant records, contact a customer through approved channels, or escalate internally.
Most risk tools are designed to identify or estimate potential exposure. That is valuable work. Yet digital asset money laundering investigations often turn on a different question: has the activity appeared in a relevant investigative matter?
Deconflict helps bring verified investigative context into financial-crime workflows through intelligence contributed by participating law enforcement agencies. When relevant information is available, it can give institutions clearer context around an address, account, or transaction pattern, with provenance and an audit trail.
This does not replace due diligence, internal investigation, or existing monitoring tools. It can help teams understand whether an alert may connect to a broader matter before choosing their next step.
Treasury’s 2026 assessment does not call for broad suspicion of digital assets. It calls for sharper attention to the ways criminal networks combine products, jurisdictions, technical tools, and intermediaries.
The most effective response to digital asset money laundering starts with evidence. Know what happened, how the funds moved, what supports the concern, and whether there is relevant investigative context that changes the picture.
Digital asset money laundering is the use of cryptocurrencies, stablecoins, wallets, or related services to hide, move, or convert proceeds of crime.
No. Stablecoins have legitimate uses in payments, trading, and settlement. Risk depends on the transaction’s source, behavior, counterparties, and surrounding context.
Jurisdictional arbitrage occurs when criminals take advantage of differences in AML/CFT rules or supervision between countries to conceal ownership or move illicit proceeds.
No. Self-hosted wallets are legitimate tools. They can create different due-diligence challenges because an intermediary may not hold the same customer information available in a regulated account relationship.
Deconflict can provide relevant verified investigative context through its participating law enforcement network, helping organizations assess an alert alongside their existing compliance and investigation processes.