Case Library / Pretexting & Impersonation / DOJ files record $225.3M civil forfeiture against USDT laundered from pig-butchering crypto scams (2025)

DOJ files record $225.3M civil forfeiture against USDT laundered from pig-butchering crypto scams (2025)

In June 2025 the DOJ filed a civil forfeiture complaint against more than $225.3M in Tether (USDT) traced to a global pig-butchering money-laundering network, the largest crypto seizure in U.S. Secret Service history and the biggest tied to crypto confidence scams.

Share:

Reviewed by the Social Engineering Examples team.

What Happened

On June 18, 2025, the U.S. Department of Justice filed a civil forfeiture complaint in the U.S. District Court for the District of Columbia against more than $225.3 million in cryptocurrency, all held in Tether's USDT stablecoin. According to the complaint, blockchain analysis and other investigative techniques tied the funds to the theft and laundering of money from victims of cryptocurrency investment fraud, the confidence scams commonly called "pig butchering." Officials described it as the largest cryptocurrency seizure in U.S. Secret Service history and the largest U.S. forfeiture tied to crypto confidence scams to date. The underlying fraud follows the classic pig-butchering pattern: victims are approached over messaging apps, social media, dating apps, or unsolicited "wrong number" texts, groomed into a friendship or romance, then steered into what looks like a lucrative crypto investment on a fraudulent platform that shows fake, growing balances. Small early "withdrawals" are sometimes allowed to build confidence before victims are pushed to deposit ever-larger sums. Once transferred, the funds are gone. Prosecutors said over 400 suspected victims lost money believing they were making legitimate investments. The recovery grew out of work by Tether and the exchange OKX, which flagged suspicious activity and, per court documents, notified the U.S. Secret Service in 2023 after finding roughly 144 OKX accounts, linked to IP addresses in the Philippines, that had moved about $3 billion in crypto over a year in what the government called high-volume money laundering. The scam operators dispersed proceeds across a large web of blockchain addresses and hundreds of thousands of transactions to obscure the source of funds. The USSS San Francisco and FBI San Francisco field offices investigated; DOJ credited Tether's proactive assistance. The action was civil (against the funds), so no individuals were named or charged in this filing. The seized funds are subject to forfeiture proceedings intended to eventually return money to victims. DOJ urged additional victims to file with the FBI's IC3 (referencing complaint code BT06182025). Press release number 25-633.

How the Attack Worked

At an awareness level, the scheme maps to the confidence-fraud kill chain. Recon/contact: fraudsters cast a wide net via messaging apps, social platforms, dating apps, and unsolicited "wrong number" texts to open a conversation. Rapport: over days to months they build a friendship or romance, presenting a consistent, attentive persona to earn trust. Exploitation: once trust exists, the "partner" introduces a supposedly can't-miss crypto opportunity and walks the victim through funding an account on a fraudulent platform that mimics a real exchange and displays fabricated gains. Reinforcement: small early withdrawals are sometimes permitted, and fake profits are shown, to encourage larger deposits and even borrowing. Payout/laundering: victim crypto is immediately moved off the fake platform into attacker-controlled wallets, then split across hundreds of thousands of transactions and many addresses, and cashed through exchange accounts to break the trail. The seizure was made possible because the blockchain is a permanent public ledger: investigators, with exchange and stablecoin-issuer cooperation, clustered addresses and traced the flow back to consolidation wallets. This record is educational and deliberately omits operational detail.

The Lure & the Tell

Lure: a warm, patient online relationship (friendship or romance) that pivots to "let me help you make money" on a specific crypto platform showing steady, impressive returns. Tells: an online-only contact who quickly gets personal but avoids verifiable video/in-person meetings; a conversation that steers toward investing; a platform you were told about by that contact rather than one you independently chose; balances that only ever go up; pressure to deposit more or to borrow to invest; and, the clearest sign, new "fees" or "taxes" demanded before you can withdraw. Genuine returns never require paying money to unlock your own money.

Outcome

DOJ filed to civilly forfeit $225.3M in USDT, described as the largest crypto seizure in Secret Service history and the largest tied to pig-butchering; the funds entered forfeiture proceedings aimed at returning money to victims, and DOJ solicited additional victim reports via IC3. No individuals were charged in this civil action.

Why It Matters

Pig butchering is now among the most financially devastating cyber-enabled crimes: FBI IC3 attributed more than $5.8B in reported crypto-investment-fraud losses in 2024, and totals have kept climbing. This case shows both the scale of the laundering (about $3B through ~144 accounts) and that stablecoin/blockchain traceability plus exchange and issuer cooperation can claw funds back, while underscoring that the human vulnerability, manufactured trust, is what the attack exploits.

Defenses

Treat any online-only contact who introduces an investment as a red flag, no matter how genuine the relationship feels. Never invest through a platform recommended by someone you met online; independently verify exchanges and use only well-known, regulated ones. Be immediately suspicious when you must pay "taxes," "fees," or "verification deposits" to withdraw, that is the scam's signature. Slow down and get an out-of-band second opinion (trusted family, your bank, or the FBI's IC3) before moving funds. Recognize the sunk-cost trap and stop rather than "invest more to recover." Report early: rapid reporting with wallet addresses and transaction hashes materially improves the odds of tracing and seizing funds before they dissipate.

Sources
Attack Chain & Defense
The sequence the attacker ran
How it could have been stopped
1
Target sourcing and contact-list building: Pig-butchering operations are documented by outlets covering this case as running from organized overseas scam compounds, typically in Southeast Asia, that acquire bulk phone numbers and social-media or dating-app profiles through data brokers, breach dumps, or scraping, then use low-cost, high-volume outreach like misdirected wrong-number texts to open conversations with strangers likely to reply.
Countering Stage 1: Exposure to bulk contact-list scraping and wrong-number texts is largely outside an individual's control; the practical defense is treating any unsolicited message from an unknown contact as a scam-probability event by default and not engaging past a polite non-response.
2
Persona and infrastructure setup: Operators are typically equipped with fabricated identities, stock or stolen photos, and scripted messaging playbooks, plus a fraudulent crypto trading platform or app styled to resemble a real, reputable exchange, complete with dashboards that only simulate account balances and trading activity.
Countering Stage 2: Persona and fake-platform fabrication happens entirely on the attacker's side before contact and cannot be detected in advance; the nearest real control is Stage 4's independent-verification step, checking any investment app or platform against official regulator registries before funding it.
3
Initial contact and rapport building: Contact opens via a misdirected text, dating app, or social platform message, and over days to months the operator builds a friendship or romance, mirroring the victim's interests and expressing steady attentiveness to establish trust before ever mentioning investing.
Countering Stage 3: Insist on a real-time video call or in-person meeting before any online relationship advances to financial topics, and treat reluctance or excuses to avoid this as a hard stop.
4
Pitch and onboarding: Once trust is established, the trusted contact introduces a supposedly can't-miss crypto opportunity and walks the victim through funding an account on the fraudulent platform, often starting with a small deposit.
Countering Stage 4: Independently verify any investment platform through official regulator registries and reviews rather than trusting a link or app sent by an online contact, and never fund an account you did not discover yourself.
5
Reinforcement and escalation: The platform displays fabricated, steadily climbing gains, and small early withdrawals are sometimes permitted, to encourage larger deposits, borrowing, or draining savings.
Countering Stage 5: Recognize climbing on-screen balances plus permitted small withdrawals as the scam's core trust-building mechanic rather than proof of legitimacy, and refuse pressure to deposit more or borrow to invest.
6
Exit block: When a victim tries to withdraw meaningfully, the platform demands invented taxes, fees, or verification deposits, extracting further payments before cutting off access or contact.
Countering Stage 6: Treat any demand to pay fees, taxes, or verification deposits to access your own funds as conclusive proof of fraud, stop immediately, and get an out-of-band second opinion from your bank, trusted family, or the FBI's IC3.
7
Laundering: Per the unsealed complaint, stolen crypto was rapidly dispersed across a large web of intermediary addresses and hundreds of thousands of transactions, then cycled through a network of roughly 144 OKX accounts linked to Philippine IP addresses to break the audit trail, moving about $3 billion over roughly a year.
Countering Stage 7: Individual victims cannot intervene once funds are moving through the blockchain; the effective control is systemic, exchange and stablecoin-issuer transaction monitoring, like Tether and OKX flagging the 144-account network in this case, that surfaces high-volume, rapidly layered transfers for law enforcement.
8
Consolidation and disruption: Laundered proceeds were consolidated into holding wallets, more than $225.3 million in USDT, until Tether and OKX flagged the account network to the U.S. Secret Service in 2023 and blockchain tracing let the USSS and FBI identify, freeze, and civilly forfeit the funds before the network could fully cash them out.
Countering Stage 8: Rapid victim reporting to the FBI's IC3 with wallet addresses and transaction hashes materially improves the odds that law enforcement can trace and freeze funds before they fully dissipate, which is what allowed this $225.3 million forfeiture to proceed.
Quick Facts
Victim
The unsealed civil forfeiture complaint identifies approximately 430-434 suspected victims (rounded to more than 400 in the DOJ press release), described in the complaint as located primarily in the United States, with additional victims in the United Kingdom, Australia, and Germany. Of these, law enforcement interviewed about 60 confirmed victims who collectively lost roughly $19 million in the transactions specifically traced in the complaint; the complaint recounts millions of dollars in victim losses overall.
Location
United States (case filed in U.S. District Court for the District of Columbia); per the unsealed complaint, victims are located primarily in the United States, with additional victims in the United Kingdom, Australia, and Germany; the laundering accounts are linked to IP addresses in the Philippines.
Date
2025-06
Impact
$225.3M USD in cryptocurrency (USDT, precisely $225,364,961 USDT) targeted for forfeiture; laundering network moved roughly $3B in crypto through approximately 144 OKX exchange accounts over about a year
Status
Confirmed
Case Type
Real-World Incident
Sector
Consumer / General Public, Cryptocurrency & Digital Assets, Financial Services & Insurance
Threat Actor
Organized Crime
Related

Related Cases

Susie Wiles AI Voice Impersonation via Hacked Contact List (2025)

An unidentified impersonator used an AI-cloned voice and a hacked personal-contacts list to pose as White House Chief of Staff…

Incident 2025Read →

PG&E Utility Shutoff Barcode/QR Payment Scam

Scammers impersonating PG&E threaten customers and small businesses with immediate service disconnection, then text or email a barcode/QR code and…

Incident 2025Read →

Single Operator Weaponizes Claude Code and GPT-4.1 to Breach Nine Mexican Government Agencies

A lone, unidentified hacker jailbroke Anthropic's Claude Code coding agent with a fake "authorized bug bounty/pentest" pretext and paired it…

Incident 2025Read →