Assessing the Current State of Terrorist Use of Cryptocurrency

Over 12 years ago, when terrorists and jihadi groups first started using cryptocurrency, I began researching this subject. During that time, this use has greatly expanded and become much more sophisticated. Today, not a single one does not use cryptocurrency. What began as jihadi experimentation with it as a fundraising tool has become an integral element of global jihad’s financial and operational ecosystems across the Middle East, Europe, South Asia, Africa, and North America.

The MEMRI Cyber & Jihad Lab (CJL) has been tracking, documenting, and reporting these developments since July 2014. An upcoming MEMRI study, to be published later this summer, will present the next chapter, offering a comprehensive assessment of jihadi adaptation to developments in cryptocurrency, law enforcement efforts, and emerging financial technologies over the past year.

The new study examines organizations including Hamas, Hizbullah, and Iran-backed Shi’ite militias; the Islamic State (ISIS) and its Khorasan Province (ISKP) and West Africa Province (ISWAP); Iran-backed hacker groups; Salafi-jihadi networks in Syria; terrorist groups operating in Afghanistan and Pakistan; the U.S.-designated terrorist entity and Popular Front for the Liberation of Palestine (PFLP) affiliate Samidoun; and supporters of these groups inside the U.S.

They no longer rely on single cryptocurrency, platform, or fundraising method. Today, they employ a diverse and constantly changing mix of digital assets and payment mechanisms to solicit donations, move funds across borders, evade sanctions, and finance military operations, propaganda, cyber campaigns, recruitment, and logistics.

The cryptocurrencies most frequently used by these actors include Tether (USDT), Monero (XMR), Bitcoin (BTC), and Ethereum (ETH). They also rely heavily on encrypted messaging applications and online platforms that facilitate anonymous fundraising and financial coordination. Although MEMRI has documented use of Middle East-based electronic money transfer services such as Sham Cash, Qi Card, Zain Cash, GiveBrite, and Whish Money, the forthcoming study focuses exclusively on cryptocurrency.

Almost every week, new cases emerge of jihadi use of cryptocurrency, whether through sophisticated fundraising campaigns by major terrorist organization or through attempts by individual supporters to transfer funds abroad. Both rely on encrypted messaging platforms, stablecoins, privacy-focused cryptocurrencies, and rapidly changing wallet addresses. Other schemes involve sham humanitarian campaigns, crowdfunding drives disguised as aid for civilians, and fundraising networks spanning multiple countries.

Terrorist use of cryptocurrency is no longer an emerging phenomenon – it has become an established and continually evolving component of global terrorist financing.

The New MEMRI Report Comes At A Pivotal Moment For The Crypto Industry: From The CLARITY Act To Swift U.S. Treasury Moves Targeting Jihadis Worldwide

The new report is coming at a pivotal moment, as the U.S. and other governments around the world are working to keep pace with terrorists’ evolving use of cryptocurrency and other digital financial technologies. While law enforcement, regulators, and the private sector have made important progress, jihadi organizations continue to adapt – adopting new platforms, cryptocurrencies, and methods faster than most countermeasures can be implemented.

This summer, authorities have taken multiple steps: On July 1, 2026, OFAC added to its sanctions list 134 cryptocurrency wallet addresses linked to Islamic State Khorasan Province (ISKP), including 131 TRON addresses that had received more than $1.4 million since 2023 via fundraising by ISKP’s Al-Azaim Media Foundation. After the designation, Tether froze all 131 sanctioned TRON addresses, though three associated Monero wallets reportedly remained active. These moves show both the effectiveness of coordinated sanctions and terrorist organizations’ ability to quickly migrate to new wallets, cryptocurrencies, and services.

Treasury’s Office of Foreign Assets Control (OFAC) designated the Muslim Brotherhood-linked, Türkiye-based organization El-Kahira for General Trading and two of its shareholders on July 23, 2026. It provided underground banking services with both fiat currency and cryptocurrency to organized crime groups, and was designated for materially assisting and providing financial support to Hamas.

On August 7, the Department of the Treasury sanctioned two major digital asset exchanges used by the Iranian regime to launder billions of dollars, maintain covert access to international financial systems, and support the Islamic Revolutionary Guard Corps (IRGC), among other terrorist groups.

Numerous terrorism investigations over the past year, particularly in the U.S., have involved cryptocurrency financing for foreign terrorist organizations. On June 17, 2026, the U.S. Department of Justice announced terrorism, sanctions evasion, wire fraud, and related charges against a San Diego resident who allegedly raised hundreds of thousands of dollars through fraudulent humanitarian campaigns and funneled the money to Hamas while lining his own pockets.

The forthcoming study is also timely because the CLARITY Act – landmark legislation establishing a comprehensive federal regulatory framework for digital assets – is approaching a vote in the U.S. Senate. The Act would split oversight between the Securities and Exchange Commission (SEC) and the Commodity Futures Trading Commission (CFTC), require many cryptocurrency businesses to register with regulators, and impose anti-money laundering (AML) and related compliance requirements.

The debate is ongoing as to whether these reforms are a step forward or may inadvertently boost terrorist usage of cryptocurrency. Yet terrorist financing methods already extend well beyond the legislation’s primary focus. Jihadi organizations increasingly rely on self-hosted wallets, privacy-focused cryptocurrencies such as Monero, foreign exchanges outside U.S. jurisdiction, decentralized finance (DeFi), peer-to-peer transfers, rapidly changing wallet addresses, and stablecoins such as Tether. These methods underscore the persistent challenge of combating illicit crypto financing.

The Trump administration has done an excellent job going after jihadi groups and their supporters using sanctions, prosecutions, and private sector cooperation to impact terrorist use of cryptocurrency. Yet nearly every major jihadi organization now incorporates cryptocurrency into its financial infrastructure, and their methods continue to evolve as quickly as the technology itself. Closing this gap requires more than after-the-fact arrests, sanctions, or legislation; it requires continuous open-source monitoring of terrorist fundraising, financial networks, wallets, blockchain activity, and operational tradecraft as they evolve in real time.

The Current Cryptocurrency Threat Landscape

Terrorist organizations and their supporters use cryptocurrency across a wide range of activities. This shows that digital assets are now embedded in terrorist financing, sanctions evasion, cyber operations, operational logistics, propaganda, and commercialization of terrorist content.

In one recent case, the Department of Justice, on June 30, 2026, announced the arrest of Catherine Beth Washburn, 37, of Irondequoit, New York, leader of the extremist Direct Action Movement for Palestinian Liberation (DAMPL), on charges of attempting to provide material support to the U.S.-designated terrorist organization Palestine Islamic Jihad (PIJ). According to the criminal complaint, Washburn allegedly made approximately 80 cryptocurrency transfers totaling 30,116 USDC (about $30,000) to a PIJ fighter in Gaza after learning of his affiliation with the group’s Al-Quds Brigades. Prosecutors allege that she raised the money through a purported humanitarian crowdfunding campaign, converted the funds into cryptocurrency through Coinbase, and transferred them to the recipient’s Bybit wallet. In messages, she expressed support for the October 7, 2023 attacks and for PIJ. Investigators further alleged that she maintained social media accounts featuring images of herself in Islamic garb while posing before a Hamas flag and holding two hand grenades.

Hizbullah provides another illustration of how cryptocurrency has become embedded within the financial and cyber operations of a major terrorist organization. Iranian political analyst Mohammad Taghi Aghyan stated on Iran’s Ofogh TV on November 9, 2025 that despite disruptions to Iran’s traditional supply routes to Lebanon via Syria, Hizbullah was continuing to receive funds via a network of shell companies established after the 2006 Lebanon war. He explained that these companies enable Hizbullah to transfer funds internationally, including through cryptocurrency, ensuring that the organization remains financially resilient despite sanctions and logistical obstacles. Hizbullah’s international financial network and domestic weapons production, he emphasized, meant there was “no reason to worry” about the organization’s future.

MEMRI’s documentation of Hizbullah’s use of cryptocurrency within its cyber ecosystem identified, inter alia, a Telegram channel associated with a Hizbullah-linked cyber unit that promoted a ransomware service. It offered access to ransomware and open-source intelligence tools for $1,000, payable exclusively in Monero.

The adoption of cryptocurrency now extends beyond fundraising for traditional terrorist groups, serving as a key instrument for cyber operations and online extremist ecosystems. For example, on December 13, 2025, the Iran-backed Cyber Islamic Resistance (CIR) openly solicited donations in Tether (USDT) on the TRON blockchain to reinforce its cyber “infrastructure” and maintain its “digital resistance.” In a Telegram post, CIR declared that its battle was “not fought with bullets, but with servers, networks, firewalls, and code,” and urged supporters to donate in cryptocurrency to help build its cyber capabilities, providing a public USDT wallet address and suggesting additional secure methods for donating.

ISIS’s use of cryptocurrency marks another significant trend in terrorist financing. Over the past year, ISIS supporters have utilized cryptocurrency, encrypted platforms, and social media fundraising to support detainees and ISIS-affiliated families in Syria’s Al-Hol camp, helping sustain the group’s international support network. Cryptocurrency now supplements traditional terror funding by allowing cross-border, pseudonymous transfers that are more difficult to trace.  The Al-Hol example serves as a blueprint for future terrorist financing operations, offering insights relevant to ISIS branches and other extremist organizations worldwide.

The MEMRI CJL has also documented how cryptocurrency is increasingly being used to monetize terrorist operational content. In one case, a user on an Al-Qaeda-operated server offered an English-language bomb-making manual for $100 in cryptocurrency. Although other Al-Qaeda supporters discouraged users from paying, because similar bomb-making guides are available for free in the Al-Qaeda in the Arabian Peninsula’s Inspire publication, this highlights how cryptocurrency facilitates not just fundraising but also the sale of operational materials.

Conclusion

These examples are just a small part of a much larger and rapidly expanding threat landscape addressed in the upcoming study. Across the global jihadi movement, cryptocurrency is now a vital part of fundraising, sanctions evasion, cyber operations, logistics, propaganda, procurement, and international financial networks. Twenty-five years after 9/11, terrorist organizations continue to exploit technological innovation much faster than governments can regulate, adapting to pressure from sanctions and law enforcement by adopting new cryptocurrencies, platforms, and methods of transferring value.

MEMRI Daily Brief No. 967

Steven Stalinsky, PhD, is Executive Director of the Middle East Media Research Institute (MEMRI). A recognized expert on technology and extremism, Stalinsky frequently briefs government agencies on issues surrounding the Middle East and counterterrorism. In addition to more than 100 original research reports he has authored for MEMRI, Stalinsky has published articles in many newspapers, magazines, and journals, including The Wall Street Journal, The Washington Post, Forbes, USA Today, The Hill, Fox News, and others. Stalinsky’s research has focused on detailing and developing strategies against cyber jihad, describing how terrorist groups such as Al-Qaeda, ISIS, Hamas, Hezbollah, and others use the Internet, social media, and encryption for propaganda, recruiting, hacking, cryptocurrency for fundraising and most recently usage of AI.

Related Articles

- Advertisement -

Latest Articles