BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
Policy

FBI crypto forum targets scams, hacks and DPRK threats

The FBI has brought investigators, foreign law-enforcement partners and crypto-security specialists together in San Antonio for its latest Virtual Asset Technical Exchange as U.S. cryptocurre

AnonymousCryptoCompass newsroom
September 24, 2026
7 min read
NEWS
Hero article visual / chart / editorial image
CryptoCompass editorial visual for policy coverage.

The FBI has brought investigators, foreign law-enforcement partners and crypto-security specialists together in San Antonio for its latest Virtual Asset Technical Exchange as U.S. cryptocurrency-related complaints exceed $11 billion in reported annual losses.

Summary
  • The FBI’s Virtual Asset Technical Exchange reportedly brought hundreds of investigators and crypto specialists together.
  • TRM Labs confirmed attendance, while Predicate said CEO Nikhil Raghuveera presented on stablecoin compliance topics.
  • FBI data shows cryptocurrency-linked complaints caused more than $11 billion in reported losses during 2025.
  • Chainalysis estimates sanctioned entities received $104 billion in crypto globally during 2025, rising 694% year-over-year.
  • TRM Labs attributes $643 million in first-half 2026 crypto thefts to North Korea-linked actors alone.

CoinDesk reported that the invitation-only gathering took place in September and represented the ninth year of a forum previously known as the Virtual Currency Symposium, based on accounts from three past attendees. The FBI declined to comment on the event, leaving much of its current public record to participant disclosures and company confirmations.

One independent public reference provides a more precise timetable. Recoveris, a digital-asset investigation and recovery company, listed the FBI Virtual Asset Technical Exchange in San Antonio for Sept. 2–3 on its 2026 conference schedule.

FBI crypto crime forum brings investigators and industry together

The September program reportedly drew several hundred participants, with private-sector vendors and partners capped at roughly 50, according to people familiar with the gathering who spoke to CoinDesk. Attendees ranged from senior FBI officials and frontline investigators to overseas law-enforcement officers, compliance specialists and blockchain-forensics companies.

TRM Labs confirmed its attendance to CoinDesk. Predicate confirmed that co-founder and CEO Nikhil Raghuveera presented at the event on stablecoin compliance and the GENIUS Act. Sources cited by the publication said Chainalysis, the Security Alliance and Treasury Department bureau FinCEN were represented, though Chainalysis and the FBI declined to confirm their participation publicly.

The gathering reportedly included presentations, panels, product demonstrations and discussions on tracing illicit funds. Topics ranged from terrorist financing and cartel activity to scams, human trafficking, child sexual abuse material, violent attacks against crypto holders and activity linked to North Korea.

One attendee described the meeting as a law-enforcement forum instead of an industry conference: “This is not a crypto event. It is a law enforcement event.”

The public record indicates the forum predates the FBI unit now responsible for coordinating much of the bureau’s digital-asset expertise. Token Recovery has previously discussed attending the gathering when it operated under the Virtual Currency Symposium name, while public participant material places the 2024 edition in Austin.

FBI crypto investigations now sit inside a dedicated unit

The FBI formally created its Virtual Assets Unit in 2022 after cryptocurrency had become part of investigations across ransomware, online fraud, child exploitation, terrorist financing and activity linked to hostile states.

The bureau announced that the unit became operational on Feb. 7, 2022. It described the VAU as a central hub combining staff from its criminal and cyber divisions to provide intelligence, technical support and operational assistance across FBI investigations.

Its responsibilities include blockchain analysis, virtual-asset seizure support and training for agents working cases in which funds move through digital currencies. The FBI later described the unit as a specialized team that centralizes cryptocurrency expertise while supporting field offices and partner agencies.

The scale of reported crime involving digital assets has increased since the unit began operating.

The FBI reported that its Internet Crime Complaint Center received 181,565 complaints involving cryptocurrency during 2025, with reported losses exceeding $11 billion. Total IC3 complaints reached 1,008,597, while cyber-enabled crimes produced nearly $21 billion in reported losses.

Investment fraud accounted for almost half of cyber-enabled scam losses. Cryptocurrency investment fraud alone generated more than $7.2 billion in reported losses during 2025, according to the bureau’s annual report. The figures come from complaints filed with IC3 and therefore do not represent a complete measurement of every crypto-related crime committed during the year.

As previously reported, a proposed federal cryptocurrency theft task force would combine DOJ, FBI, DHS and Treasury expertise after lawmakers cited the same rise in reported losses and fragmented investigations across jurisdictions.

North Korean cyber operations were among the subjects covered at the San Antonio gathering, according to CoinDesk’s sources. One presentation reportedly examined the April attack against Solana-based Drift Protocol.

Current blockchain-forensics data puts the Drift loss at approximately $285 million. TRM Labs reported that attackers spent weeks preparing the operation before draining assets on April 1 in roughly 12 minutes. The firm linked the campaign to North Korean actors based on its on-chain investigation, while its initial report said the specific subgroup attribution remained under investigation.

TRM said attackers socially engineered Drift Security Council signers into pre-signing transactions that later granted critical administrative permissions. The attacker then used a fabricated token called CarbonVote Token as manipulated collateral before withdrawing real assets from the protocol.

Drift itself said it was working with law enforcement and third-party forensic firms following the exploit while developing a recovery framework for affected users.

TRM’s subsequent first-half review attributed approximately $643 million, or roughly 66% of cryptocurrency stolen during the first six months of 2026, to North Korea-linked activity. Drift and the $292 million KelpDAO attack accounted for around $577 million combined.

North Korea-linked attacks on Drift and KelpDAO accounted for most early-2026 crypto hack losses when TRM measured the threat earlier in the year.

The Drift investigation has remained active onchain. In July, a wallet tied to the Drift exploit moved roughly $44 million in Ether into Tornado Cash after remaining largely dormant for several months.

Sanctions and state-linked activity deepen the enforcement workload

The forum’s reported focus on nation-state activity comes as blockchain analytics firms record a sharp increase in cryptocurrency moving through sanctioned entities.

Chainalysis estimated that sanctioned entities received roughly $104 billion in cryptocurrency during 2025, up 694% from the previous year. The firm’s preliminary data placed total value received by identified illicit cryptocurrency addresses at at least $154 billion, up 162% year over year.

Chainalysis cautions that its illicit-volume calculation is a lower-bound estimate because new addresses can be identified after transactions have already taken place. Legitimate cryptocurrency transaction volume remains far larger than the illicit activity identified by the company.

Russia, Iran and North Korea drove much of the state-related activity measured by the firm. Chainalysis attributed the increase to cryptocurrency being used not only for laundering but for cross-border trade, sanctions evasion, procurement and state-supported financial infrastructure.

More recent security data show the hack environment continuing to evolve after the San Antonio meeting. TRM Labs reported in September that 2026 had recorded roughly 333 crypto hacking incidents involving approximately $1.73 billion in stolen assets at the time of its analysis.

Security firms increasingly describe compromised credentials, administrative access and social engineering as central risks alongside smart-contract bugs. TRM’s first-half data counted 207 hacks, the largest six-month incident total in its records, while operational and infrastructure compromises generated a disproportionately large share of losses.

As previously reported, compromised keys and social engineering have driven many of 2026’s largest DeFi losses, including attacks where malicious actors targeted people with privileged access before touching protocol infrastructure.

The FBI has not published a public agenda, attendee roster or post-event report for the September Virtual Asset Technical Exchange. Its official material continues to direct victims and companies toward IC3 and local field offices for reporting, while the Virtual Assets Unit provides blockchain analysis, seizure support and technical expertise for investigations across the bureau.

Read more: Circle expands CCTP to EURC and cirBTC on Arc