In June 2025 the DOJ filed a civil forfeiture complaint against more than $225.3M in Tether (USDT) traced to a global pig-butchering money-laundering network, the largest crypto seizure in U.S. Secret Service history and the biggest tied to crypto confidence scams.
Reviewed by the Social Engineering Examples team.
On June 18, 2025, the U.S. Department of Justice filed a civil forfeiture complaint in the U.S. District Court for the District of Columbia against more than $225.3 million in cryptocurrency, all held in Tether's USDT stablecoin. According to the complaint, blockchain analysis and other investigative techniques tied the funds to the theft and laundering of money from victims of cryptocurrency investment fraud, the confidence scams commonly called "pig butchering." Officials described it as the largest cryptocurrency seizure in U.S. Secret Service history and the largest U.S. forfeiture tied to crypto confidence scams to date. The underlying fraud follows the classic pig-butchering pattern: victims are approached over messaging apps, social media, dating apps, or unsolicited "wrong number" texts, groomed into a friendship or romance, then steered into what looks like a lucrative crypto investment on a fraudulent platform that shows fake, growing balances. Small early "withdrawals" are sometimes allowed to build confidence before victims are pushed to deposit ever-larger sums. Once transferred, the funds are gone. Prosecutors said over 400 suspected victims lost money believing they were making legitimate investments. The recovery grew out of work by Tether and the exchange OKX, which flagged suspicious activity and, per court documents, notified the U.S. Secret Service in 2023 after finding roughly 144 OKX accounts, linked to IP addresses in the Philippines, that had moved about $3 billion in crypto over a year in what the government called high-volume money laundering. The scam operators dispersed proceeds across a large web of blockchain addresses and hundreds of thousands of transactions to obscure the source of funds. The USSS San Francisco and FBI San Francisco field offices investigated; DOJ credited Tether's proactive assistance. The action was civil (against the funds), so no individuals were named or charged in this filing. The seized funds are subject to forfeiture proceedings intended to eventually return money to victims. DOJ urged additional victims to file with the FBI's IC3 (referencing complaint code BT06182025). Press release number 25-633.
At an awareness level, the scheme maps to the confidence-fraud kill chain. Recon/contact: fraudsters cast a wide net via messaging apps, social platforms, dating apps, and unsolicited "wrong number" texts to open a conversation. Rapport: over days to months they build a friendship or romance, presenting a consistent, attentive persona to earn trust. Exploitation: once trust exists, the "partner" introduces a supposedly can't-miss crypto opportunity and walks the victim through funding an account on a fraudulent platform that mimics a real exchange and displays fabricated gains. Reinforcement: small early withdrawals are sometimes permitted, and fake profits are shown, to encourage larger deposits and even borrowing. Payout/laundering: victim crypto is immediately moved off the fake platform into attacker-controlled wallets, then split across hundreds of thousands of transactions and many addresses, and cashed through exchange accounts to break the trail. The seizure was made possible because the blockchain is a permanent public ledger: investigators, with exchange and stablecoin-issuer cooperation, clustered addresses and traced the flow back to consolidation wallets. This record is educational and deliberately omits operational detail.
Lure: a warm, patient online relationship (friendship or romance) that pivots to "let me help you make money" on a specific crypto platform showing steady, impressive returns. Tells: an online-only contact who quickly gets personal but avoids verifiable video/in-person meetings; a conversation that steers toward investing; a platform you were told about by that contact rather than one you independently chose; balances that only ever go up; pressure to deposit more or to borrow to invest; and, the clearest sign, new "fees" or "taxes" demanded before you can withdraw. Genuine returns never require paying money to unlock your own money.
DOJ filed to civilly forfeit $225.3M in USDT, described as the largest crypto seizure in Secret Service history and the largest tied to pig-butchering; the funds entered forfeiture proceedings aimed at returning money to victims, and DOJ solicited additional victim reports via IC3. No individuals were charged in this civil action.
Pig butchering is now among the most financially devastating cyber-enabled crimes: FBI IC3 attributed more than $5.8B in reported crypto-investment-fraud losses in 2024, and totals have kept climbing. This case shows both the scale of the laundering (about $3B through ~144 accounts) and that stablecoin/blockchain traceability plus exchange and issuer cooperation can claw funds back, while underscoring that the human vulnerability, manufactured trust, is what the attack exploits.
Treat any online-only contact who introduces an investment as a red flag, no matter how genuine the relationship feels. Never invest through a platform recommended by someone you met online; independently verify exchanges and use only well-known, regulated ones. Be immediately suspicious when you must pay "taxes," "fees," or "verification deposits" to withdraw, that is the scam's signature. Slow down and get an out-of-band second opinion (trusted family, your bank, or the FBI's IC3) before moving funds. Recognize the sunk-cost trap and stop rather than "invest more to recover." Report early: rapid reporting with wallet addresses and transaction hashes materially improves the odds of tracing and seizing funds before they dissipate.
An unidentified impersonator used an AI-cloned voice and a hacked personal-contacts list to pose as White House Chief of Staff…
Scammers impersonating PG&E threaten customers and small businesses with immediate service disconnection, then text or email a barcode/QR code and…
A lone, unidentified hacker jailbroke Anthropic's Claude Code coding agent with a fake "authorized bug bounty/pentest" pretext and paired it…