The US Department of Justice unsealed warrants in August 2025 authorising forfeiture of more than $2.8 million in cryptocurrency, approximately $70,000 in cash and other assets connected to ransomware activity.
Put It Next To A Single Payment
This desk filed a single $75 million ransom payment at 25-0728. One transaction, twenty-six times the value of this forfeiture action.
That comparison is not a criticism of the action, which is a real result requiring blockchain tracing, mutual legal assistance and often the cooperation of an exchange. It is a statement about proportion: asset recovery in this domain operates at a scale two orders of magnitude below the flow it is trying to reverse.
Why Tracing Does Not Translate Into Recovery
Public-ledger cryptocurrencies are unusually traceable — every transfer is permanently visible. That is why forfeiture actions are possible at all, and it is a genuine asymmetry in law enforcement’s favour.
Seizure, though, requires reaching a point where the asset touches something a court controls: an exchange with a compliance obligation, a jurisdiction that will act, a custodian that will freeze. Funds that stay in self-custody, move through non-compliant venues or sit in jurisdictions that decline cooperation are visible and untouchable. Watching money you cannot seize is the ordinary condition.
And The Money Is Not The Objective Anyway
Forfeiture serves purposes beyond recovery: it establishes evidentiary links, supports charging decisions, and identifies the services being used. A $2.8 million action may be worth far more as investigative product than as a sum.
The corpus should record it that way rather than as failed restitution. What it cannot support is any suggestion that victims are being made whole — the finding at 25-0521 and 25-0812 holds here too.
Compiled from public reporting of US court filings, listed below. The comparison with 25-0728 is our arithmetic on two separately reported figures. Corrections: corrections@forensicpost.com.
- Crackdowns and takedowns: disrupting ransomware in 2025S-RM
- Ransomware attack 2025 recapCybersecurity News