1. Introduction
Crypto-enabled fraud has undergone a profound structural transformation over the past decade, evolving from fragmented and opportunistic practices into coordinated, industrialised systems of illicit production and laundering (
Arnone et al. 2025;
Cong et al. 2025). What was once characterised by dispersed online scams and the episodic misuse of digital assets has increasingly taken the form of organised, scalable, and professionally managed criminal enterprises. A central manifestation of this transformation is the emergence of so-called scam compounds across Southeast Asia, physically concentrated facilities in which individuals are coerced or trafficked into conducting large-scale online fraud, including cryptocurrency investment scams, romance scams and related forms of digital deception (
Bartoletti et al. 2021;
Franceschini et al. 2023). These compounds operate not merely as sites of victimisation or labour exploitation, but as organisational hubs embedded within transnational organised crime networks, integrating recruitment, technological infrastructure, financial coordination, and laundering functions into a single operational architecture.
Taken together, these developments suggest that contemporary crypto-enabled fraud cannot be adequately understood through isolated analytical lenses. While international organisations and law enforcement agencies increasingly document the convergence of coerced labour, digital fraud and cryptocurrency-based laundering, regulatory and scholarly responses remain largely fragmented. Scam compounds are predominantly examined through the frameworks of human trafficking and labour exploitation; money mules are often conceptualised as peripheral facilitators or individual offenders; and cryptocurrencies are addressed mainly through compliance obligations imposed on crypto-asset service providers (
Ferreira et al. 2021;
Ferreira and Sandner 2021;
Wronka 2024). Such siloed approaches risk obscuring the systemic interdependencies that enable organised crime networks to adapt, scale, and reconfigure their operations. In particular, they fail to capture how scam compounds, money mule networks and crypto-asset infrastructures operate as mutually reinforcing components of a single laundering process, rather than as discrete or sequential phenomena (
Al-Tawil 2023). This analytical fragmentation limits the capacity of existing anti-money laundering (AML) frameworks to identify structural vulnerabilities and to intervene effectively across the full lifecycle of illicit financial flows. To address this gap, the present paper advances a crypto-laundering chain perspective, conceptualising laundering as a multi-node process encompassing (i) fraud generation within scam compounds; (ii) facilitation and risk distribution through money mules; (iii) movement, layering and obfuscation via crypto-asset infrastructures; and (iv) off-ramping, seizure or asset recovery (
Cong et al. 2025;
Maurushat and Halpin 2022). Shifting analytical attention from individual actors or transactions to the chain as a whole allows for a more precise assessment of where regulatory and enforcement interventions succeed, where they fail, and how organised crime exploits gaps between nodes.
Against this background, the paper adopts a qualitative comparative case-study design to examine how different jurisdictions intervene along the crypto-laundering chain. Two Southeast Asian scam-compound enforcement cases (the Prince Group/Chen Zhi network in Cambodia and the Tai Chang compound in Myanmar) are analysed alongside two European crypto-asset seizure cases: Criminal Assets Bureau v Mannion (Ireland) and The Rock Trading—Cassazione Penale n. 1760/2025 (Italy). The comparison does not seek to equate jurisdictions operating under markedly different institutional, political and regulatory conditions. Rather, it aims to illuminate how divergent enforcement logics target different nodes of the laundering chain, revealing structural asymmetries between network-oriented disruption strategies and asset-centric seizure frameworks (
Akartuna et al. 2022;
Leuprecht et al. 2023;
Trozze et al. 2022;
Wronka 2022).
This paper makes three interrelated contributions to the literature on anti-money laundering and organised financial crime:
First, it advances AML scholarship by integrating scam compounds, money mules and crypto-assets within a single analytical framework, thereby addressing a persistent tendency in the literature to examine these phenomena in isolation (
Al-Tawil 2023).
Second, it offers an empirically grounded comparative analysis of enforcement strategies across Southeast Asia and Europe, illustrating how different legal tools and institutional logics intervene at distinct nodes of the crypto-laundering chain, with uneven implications for systemic disruption (
Leuprecht et al. 2023;
Wronka 2023).
Third, it provides policy-relevant insights for the application of FATF’s risk-based approach and for the European Union’s evolving AML architecture, with particular reference to the Markets in Crypto-Assets Regulation (MiCA) and the establishment of the Anti-Money Laundering Authority (AMLA).
The remainder of the paper is structured as follows.
Section 2 reviews the relevant literature on scam compounds, money mules and crypto-enabled money laundering.
Section 3 explains the methodological approach and case selection.
Section 4 presents the case analyses and
Section 5 discusses the comparative analysis.
Section 6 examines regulatory implications with specific reference to the EU AML regime and MiCAR.
Section 7 discusses broader policy implications, while
Section 8 concludes by outlining limitations and directions for future research.
2. Literature Review
2.1. Scam Compounds and Organised Crime Networks
The emergence of scam compounds in Southeast Asia has been extensively documented by international organisations and a growing body of academic scholarship. These compounds are commonly described as physically concentrated facilities—often operating in regulatory grey zones or under the protection of local elites—where individuals are coerced, trafficked or otherwise compelled to conduct online fraud at scale, including cryptocurrency investment scams and romance fraud (
Franceschini et al. 2023;
Li et al. 2025). Unlike decentralised or opportunistic forms of cybercrime, scam compounds exhibit organisational features traditionally associated with organised crime, including territorial control, hierarchical governance, labour management and the systematic use of coercion to enforce compliance. In this respect, they represent a structural departure from earlier models of online fraud, reflecting a shift towards industrialised and territorially embedded criminal production systems.
Scam compounds can be understood as a distinct organisational form in which digital fraud activities are embedded within coercive, territorially grounded governance structures. This hybrid configuration blurs conventional analytical boundaries between financial crime, cybercrime and human trafficking, pointing to the need for integrative frameworks capable of capturing the interaction between online criminal practices and offline systems of control. Nevertheless, much of the existing literature continues to prioritise the human rights, labour exploitation and victimisation dimensions of scam compounds. As a consequence, their role as financial coordination and laundering hubs (sites where fraud production and illicit value extraction are systematically organised) remains comparatively under-theorised within AML-oriented scholarship (
Cong et al. 2025;
Khalil et al. 2025;
Luong 2025;
Teichmann and Falker 2021).
2.2. Money Mules: From Peripheral Actors to Structural Intermediaries
Money mules have long been recognised as facilitators of money laundering, particularly during the placement and layering stages of illicit financial flows. Early foundational work framed mules as disposable or low-level actors, typically recruited through deception or economic vulnerability, and easily replaced when exposed (
Levi 2022).
More recent research demonstrates a significant evolution in the organisation and governance of mule networks. Studies in AML and financial crime scholarship document increasingly structured recruitment, monitoring and segmentation of mules within organised laundering schemes, indicating that mule networks are no longer incidental but strategically deployed components of criminal systems (
Esoimeme 2020;
Khan et al. 2021). In crypto-enabled fraud, money mules assume a particularly central role. They frequently operate as intermediaries between scam operations and regulated financial systems, providing identity-verified access to bank accounts, crypto exchanges and payment platforms (
Arnone et al. 2025;
Maurushat and Halpin 2022). This intermediary function enables organised crime networks to distribute risk, fragment attribution and adapt rapidly to enforcement pressure, especially in cross-border contexts. Despite this evolution, regulatory frameworks and enforcement practices often continue to conceptualise money mules either as isolated offenders or as vulnerable individuals requiring protection. Such framings obscure the structural role of mules as connective intermediaries within organised laundering chains, thereby limiting the effectiveness of AML interventions and facilitating displacement rather than disruption (
Joyce 2025;
Nazzari 2023). To further specify the functional role of money mules within crypto-enabled laundering systems, it is necessary to consider how mule networks operate in practice. Empirical and enforcement-oriented studies indicate that mule recruitment increasingly relies on digital channels, including social media platforms, encrypted messaging applications and online job advertisements, often framed as legitimate employment or investment opportunities. Recruitment strategies frequently target economically vulnerable individuals, migrants or digitally inexperienced users, thereby externalising legal risk onto low-level participants. Coordination within mule networks is typically decentralised but structured, with organisers allocating wallets, bank accounts or exchange credentials to intermediaries and sequencing transactions to fragment and obscure value flows. Incentive structures vary from fixed commissions per transaction to percentage-based rewards, sometimes combined with coercive elements in scam-compound contexts. Within the crypto-laundering chain, mule networks therefore perform a critical intermediation and risk-distribution function, enabling the transition from victim-originated funds to layered and obfuscated asset flows while insulating core organisers from direct exposure. This operational perspective reinforces the analytical claim that mule networks constitute a distinct and resilient node of the laundering chain, rather than a peripheral or purely auxiliary component.
2.3. Cryptocurrencies and the Transformation of Money Laundering
The literature on cryptocurrencies and money laundering has expanded considerably over the past decade. Scholars and policymakers consistently highlight how crypto-assets facilitate rapid cross-border value transfer, reduce reliance on traditional financial intermediaries, and enable new layering techniques through decentralised exchanges, mixers and cross-chain mechanisms (
Trozze et al. 2022). At the same time, research emphasises that cryptocurrencies do not eliminate traceability. Advances in blockchain analytics and transaction monitoring have enhanced the capacity of enforcement agencies and regulated entities to identify suspicious transaction patterns and wallet clusters (
Wronka 2023). This duality (enhanced traceability alongside increasingly sophisticated obfuscation techniques) has reshaped laundering practices rather than rendering them opaque. To capture these dynamics more systematically, this article conceptualises money laundering in crypto environments as a “crypto-laundering chain”, that is, a multi-stage and functionally differentiated process linking (i) predicate offence generation (e.g., fraud conducted within scam compounds), (ii) value extraction and initial transfer (often mediated through victims’ payments in crypto-assets), (iii) mule-mediated distribution and aggregation (including the use of intermediaries, nominee accounts or wallets), (iv) layering and obfuscation (through mixers, decentralised exchanges, cross-chain bridges and privacy-enhancing techniques), and (v) integration or asset conversion into fiat or other stores of value. This chain-based perspective shifts the analytical focus from isolated transactions to the interconnected infrastructure of actors, technologies and jurisdictions that sustain crypto-enabled illicit finance (
Cong et al. 2025;
Choi et al. 2026;
Meighan 2026). While grounded in established AML concepts such as placement, layering and integration, the notion of a “crypto-laundering chain” advances the literature by reconfiguring these stages into a structurally integrated, actor- and infrastructure-oriented framework that captures the specific organisational and technological dynamics of crypto-enabled illicit finance. Nevertheless, much of the crypto-AML literature remains transaction-centric, focusing on typologies, red flags and compliance obligations. Such approaches often abstract crypto laundering from the organisational contexts in which it occurs. In scam-compound-based fraud, cryptocurrencies function not merely as a payment method but as a critical infrastructural component linking coerced fraud production to global financial extraction (
Collins 2022).
2.4. Regulatory and Enforcement Gaps in Crypto-Enabled Crime
A recurring theme in the literature is the fragmentation of regulatory and enforcement responses to crypto-enabled crime. The Financial Action Task Force (FATF), as the primary international standard-setter for anti-money laundering and counter-terrorist financing (AML/CFT), has progressively extended its risk-based framework to encompass virtual assets and virtual asset service providers (VASPs). In particular, Recommendation 1 (risk-based approach) and Recommendation 15 (new technologies) require jurisdictions to identify, assess, and mitigate risks associated with digital assets, while interpretative guidance has clarified the application of AML/CFT obligations to VASPs, including licencing/registration and customer due diligence. Furthermore, Recommendation 16 (“travel rule”) seeks to enhance traceability in virtual asset transfers by requiring originator and beneficiary information to accompany transactions. Despite these developments, implementation remains uneven across jurisdictions (
Pavlidis 2023), with significant divergences in supervisory capacity and enforcement practices.
Regional initiatives, including the European Union’s AML framework and the Markets in Crypto-Assets Regulation (MiCA), have strengthened institutional oversight of crypto markets and regulated intermediaries. However, existing frameworks remain predominantly institution-focused, prioritising compliance by regulated entities rather than engagement with upstream criminal structures or facilitation networks (
Collins 2022;
Levi 2022). This institutional bias reflects the architecture of the 40 Recommendations issued by the Financial Action Task Force (FATF), which primarily target obliged entities and financial intermediaries, with comparatively limited operational guidance on dismantling decentralised or extra-institutional criminal infrastructures.
As a result, scam compounds and money mule networks frequently operate outside the direct reach of financial regulation, creating enforcement blind spots that organised crime networks can exploit.
This limitation is particularly evident from a comparative perspective. While some jurisdictions adopt proactive strategies aligned with Recommendations 27 and 30 (powers of competent authorities and law enforcement agencies), emphasising network disruption and infrastructure-focused interventions, others rely predominantly on post-offence mechanisms such as asset seizure and confiscation under Recommendation 4. In the absence of an integrated analytical approach capable of addressing the full laundering chain, interventions targeting one node of the process may be neutralised by adaptability at another, thereby preserving the overall resilience of crypto-enabled criminal ecosystems.
2.5. Research Gap
The foregoing literature review demonstrates that scam compounds, money mules and crypto-assets have largely been examined within distinct scholarly and regulatory silos. Scam compounds are predominantly analysed through the lenses of human trafficking, labour exploitation and cybercrime (
Abdul Rani et al. 2025;
Agarwal et al. 2024); money mules are frequently framed as peripheral facilitators or vulnerable individual offenders (
Esoimeme 2020;
Hassan et al. 2020); and cryptocurrencies are primarily addressed through institutional compliance and market-regulation regimes.
What remains insufficiently explored is how these elements interact operationally as part of a single laundering process and how organised crime networks exploit their interdependence to adapt to regulatory and enforcement pressure. In particular, existing scholarship pays limited attention to how enforcement strategies intervene at different points along the laundering process and to the extent to which interventions targeting one node—such as asset seizure or intermediary compliance—are offset by resilience and adaptability at others (
Dupuis and Gleason 2021;
Scharfman 2024).
As a result, there is a lack of integrated, chain-aware analyses capable of explaining the uneven effectiveness of anti-money laundering responses across jurisdictions, especially in contexts characterised by scam-compound-based fraud and extensive reliance on money mule networks. Addressing this gap requires an analytical framework that links fraud production, facilitation and financial infrastructure within a single explanatory model and examines how different legal and regulatory regimes engage with this model in practice. In light of this research gap, the study adopts a chain-based analytical framework and is guided by the following interconnected research questions:
- -
RQ1: How do scam compounds, money mules and crypto-assets interact within contemporary crypto-laundering chains?
This question examines the functional relationships between fraud production within scam compounds, facilitation and risk distribution through money mule networks, and the movement, layering and concealment of illicit proceeds via crypto-asset infrastructures. By doing so, it moves beyond isolated typologies and seeks to identify how these components mutually reinforce one another within organised crime systems.
- -
RQ2: How do enforcement strategies differ between Southeast Asian scam-compound cases and EU crypto-seizure cases?
This question addresses the comparative dimension of the analysis. It explores how enforcement authorities operating in distinct institutional and regulatory contexts prioritise different intervention points along the laundering chain, contrasting network- and infrastructure-oriented disruption strategies in Southeast Asia with asset-centric seizure and confiscation frameworks prevalent in the European Union.
- -
RQ3: To what extent do current regulatory frameworks disrupt crypto-laundering chains as integrated systems?
This question evaluates the capacity of current AML and crypto-asset regulatory regimes to disrupt laundering processes holistically, rather than at isolated stages. Particular attention is paid to the alignment—and potential misalignment—between FATF’s risk-based approach and the implementation of the European Union’s AML framework, including the Markets in Crypto-Assets Regulation (MiCA).
Collectively, these research questions establish a cohesive analytical framework that connects empirical case analysis with broader debates on regulation, enforcement and policy design in the context of crypto-enabled organised crime.
3. Methodology
3.1. Research Design
This study adopts a qualitative, empirical research design grounded in a comparative legal and regulatory approach (
Almeida et al. 2022;
Köhler et al. 2025). It combines doctrinal legal analysis with case-based qualitative examination of judicial decisions and enforcement actions. This design is particularly well suited to the analysis of complex, covert and transnational forms of organised financial crime, where quantitative data are often incomplete, inconsistent or inaccessible, and where legal and institutional responses play a central role in shaping enforcement outcomes. The objective of the research is not statistical generalisation but analytical generalisation, namely the identification of mechanisms, intervention points and regulatory dynamics that plausibly operate across comparable contexts of crypto-enabled organised crime. By focusing on how different legal systems intervene along the crypto-laundering chain, the study seeks to generate theoretically informed insights into enforcement effectiveness and institutional adaptation.
In practical terms, the research design operationalises the crypto-laundering chain as an analytical device through which each case is systematically decomposed into distinct functional nodes, allowing comparison not only across jurisdictions but also across stages of the laundering process.
3.2. Case-Based Qualitative Analysis
The empirical foundation of the study consists of a structured qualitative analysis of four purposively selected cases—from 2018 to 2025—that reflect different jurisdictions, institutional settings and enforcement logics.
Case inclusion was guided by three cumulative criteria: (i) empirical relevance (documented involvement of crypto-assets in organised or large-scale financial crime); (ii) analytical diversity (representation of different nodes of the crypto-laundering chain, including upstream production, facilitation, infrastructure and downstream recovery); and (iii) legal salience (availability of sufficiently detailed judicial, investigative or enforcement records enabling doctrinal and functional analysis). Cases not meeting these criteria (particularly those lacking transparency or offering only transaction-level data) were excluded, even where high-profile.
In Southeast Asia, the first case examines the
Prince Group/Chen Zhi network in Cambodia, which provides detailed insight into the financial and organisational architecture of scam-compound-based fraud and its transnational laundering operations (
Li et al. 2025;
Ye et al. 2023). The second case focuses on the
Tai Chang scam compound in Myanmar, illustrating both the scale of cryptocurrency investment fraud and the specific enforcement responses directed at local digital infrastructure rather than solely at downstream financial assets (
Akartuna and Manning 2026;
Franceschini et al. 2023). In the European context, the third case analyses
Criminal Assets Bureau v Mannion (Ireland), a landmark decision concerning the application of civil recovery mechanisms to crypto-assets and the evidentiary challenges associated with digital property. The fourth case examines the Italian Supreme Court decision on
The Rock Trading case, Corte di Cassazione—sentenza n. 1760/2025, which offers doctrinal insight into the limits of seizure and confiscation of crypto-assets, particularly in relation to confiscation by equivalence and evidentiary standards.
Each case is examined through a common analytical lens focusing on (i) the organisational structure underlying the criminal activity; (ii) the role of scam compounds in fraud generation and coordination; (iii) the functions performed by money mules within laundering processes; (iv) the use of crypto-assets and associated technological infrastructure; and (v) the legal and regulatory instruments deployed by enforcement authorities (
Abdul Rani et al. 2025;
Chowdhury and Shil 2021;
Hunziker and Blankenagel 2024).
Methodologically, the analysis proceeds in two steps: first, a within-case reconstruction combining doctrinal reading of legal sources with functional mapping of the laundering chain; second, a cross-case synthesis in which each intervention is coded according to the specific node(s) targeted and its observed or inferred disruptive capacity. This coding allows systematic comparison of enforcement strategies beyond jurisdictional differences. Following the within-case analysis, a cross-case comparative assessment is conducted to identify recurring patterns, divergences and institutional asymmetries across jurisdictions. This comparative step enables the synthesis of findings and the identification of broader enforcement logics and structural constraints (
Mynott and Kager 2024;
Thomann et al. 2022).
3.3. Justification of Case Selection
Case selection follows a purposive and theoretically informed logic aligned with the research questions and the crypto-laundering chain framework. The selection is intended to be not exhaustive but illustrative of distinct enforcement modalities positioned at different points along the laundering chain, thereby enabling theory-building rather than representativeness.
The two Southeast Asian cases were selected because they exemplify scam compounds as organisational hubs integrating fraud production, coercive labour and crypto-enabled laundering, and because they illustrate enforcement strategies that extend beyond post-offence asset seizure to include network designation and digital infrastructure disruption (
Franceschini et al. 2023;
Li et al. 2025). These cases therefore provide empirical access to upstream and mid-chain dynamics that are typically underrepresented in European doctrinal analysis.
The Prince Group/Chen Zhi case is particularly significant due to its scale, transnational reach and association with large-value crypto-related enforcement actions, making it a paradigmatic example of a scam-compound-based organised crime network. The Tai Chang case was selected because it highlights a distinct enforcement modality focused on the seizure of enabling digital infrastructure used to conduct cryptocurrency investment fraud, thereby allowing analysis of upstream intervention along the laundering chain.
The two European cases were selected to capture asset-centred AML frameworks operating within advanced legal systems.
Criminal Assets Bureau v Mannion represents one of the earliest and most frequently cited judicial applications of civil recovery mechanisms to crypto-assets, illuminating evidentiary and procedural challenges. The Italian Supreme Court decision
Cass. n. 1760/2025 provides critical insight into doctrinal constraints governing seizure and confiscation, particularly with respect to confiscation by equivalence and proof requirements under Italian law. Taken together, the four cases capture different nodes of the crypto-laundering chain and enable a meaningful comparison between enforcement strategies focused on network and infrastructure disruption and those centred on asset deprivation. Indeed, these cases allow for a structured comparison between proactive, network-oriented enforcement (Southeast Asia) and reactive, asset-centred enforcement (Europe), thereby directly operationalising the chain-based framework across different regulatory paradigms (
Goldbarsht 2024;
Wardani et al. 2022).
3.4. Analytical Framework: The Crypto Laundering Chain
The analysis is structured around a crypto-laundering chain framework, which conceptualises money laundering as a multi-node, adaptive process rather than as a linear sequence of transactions (
Wardani et al. 2022;
Xia et al. 2024).
The framework identifies four interrelated stages: (1) fraud generation within scam compounds; (2) facilitation and placement through money mule networks; (3) movement and layering via crypto-asset infrastructures; and (4) off-ramping, substitution and asset recovery through legal mechanisms (
Bjelajac and Bajac 2022;
Leuprecht et al. 2023). Regulatory and enforcement tools are analysed in terms of the specific nodes they target and their capacity to disrupt the laundering chain as a whole.
Crucially, each case study is explicitly mapped onto these nodes, enabling identification of whether interventions are upstream (preventive), mid-chain (disruptive), or downstream (reactive), and whether they generate substitution effects across the chain.
This approach allows for systematic assessment of substitution effects, whereby disruption at one node may be offset by adaptation at another, thereby illuminating both the strengths and limitations of current AML responses. Regulatory and enforcement tools are analysed in terms of the specific nodes they target and their capacity to disrupt the chain as a whole. This framework enables systematic assessment of substitution effects, whereby disruption at one node may be offset by adaptation at another (
Pocher et al. 2023;
Tosza and Voordeckers 2024).
4. Case Analysis: An Empirically Grounded, Chain-Based Approach
This section applies the crypto-laundering chain framework to four empirically grounded cases drawn from Southeast Asia and Europe. For each case, the analysis systematically examines the upstream crime-production setting; the role of money mules and intermediary structures; the crypto-asset and digital infrastructure used to move or conceal value; and the legal and regulatory tools deployed. The objective is to identify where enforcement interventions occur along the laundering chain, and to assess their capacity to disrupt the system as an integrated whole rather than as a series of isolated transactions or assets.
4.1. Prince Group/Chen Zhi (Cambodia): Compound-Based Crime Production and Multi-Node Enforcement
The Prince Group/Chen Zhi case is analytically significant because it connects scam-compound governance (coercive labour and industrialised fraud production) with crypto-enabled laundering techniques and unusually large-scale asset restraint/seizure measures. In October 2025, the U.S. Department of Justice announced an indictment describing Prince Group as an ostensibly legitimate conglomerate that allegedly functioned in practice as a large transnational criminal organisation operating scam compounds across Cambodia and perpetrating fraudulent cryptocurrency investment schemes.
On the crime-production node, the case narrative depicts scam compounds as forced-labour environments: trafficked workers were allegedly compelled to run fraud operations from secured facilities described as surrounded by high walls and barbed wire and operating as violent labour camps. From a laundering-chain perspective, this is not merely a human-rights concern: scam compounds constitute an organisational infrastructure that enables sustained fraud throughput, routinisation and scale, thereby shaping the volume and resilience of downstream laundering (
Makmur 2024;
Shonhadji and Maulidi 2022).
The indictment describes the use of “local networks” assisting the schemes, including actors based outside Cambodia who facilitated the transfer and laundering of funds from hundreds of victims. While these facilitators are not explicitly labelled as money mules, their described function aligns with mule-intermediary logic: distributed actors reduce exposure of core organisers while enabling access to financial and crypto infrastructure across jurisdictions (
Li et al. 2025;
Luong 2025;
Sun et al. 2026).
The case provides unusually concrete descriptions of laundering techniques, linking scam-compound fraud to identifiable on-chain behaviours (
Wardani et al. 2022;
Wronka 2022,
2023). This connection is empirically valuable because it situates transactional typologies within an organisational context rather than treating them as isolated anomalies.
Enforcement combined multiple tools: designation of Prince Group as a transnational criminal organisation, coordinated sanctions by U.S. and UK authorities, and exceptionally large-scale crypto-asset restraint reportedly exceeding USD 14 billion. From a chain-based perspective, this represents a multi-node enforcement attempt, combining network disruption, infrastructure scrutiny and asset deprivation (
Al-Tawil 2023;
Wardani et al. 2022;
Wronka 2023).
From a chain-based perspective, this case illustrates a multi-node enforcement attempt combining network designation, infrastructure scrutiny and asset deprivation. However, it also demonstrates that large-scale seizures alone do not dismantle scam-compound capacity unless recruitment, coercive governance and mule-mediated facilitation are disrupted in parallel. Despite its scale, the case illustrates a central limitation of seizure-heavy strategies: even extraordinary asset deprivation does not, by itself, dismantle upstream scam-compound capacity unless recruitment pipelines, coercive governance and mule-mediated facilitation are disrupted in parallel (
Franceschini et al. 2023).
4.2. Tai Chang Scam Compound (Myanmar): Infrastructure Seizure as Upstream Intervention
The Tai Chang case illustrates a contrasting Southeast Asian enforcement logic focused on infrastructure disruption rather than downstream asset recovery.
In December 2025, U.S. authorities seized the web domain
tickmilleas.com used to conduct cryptocurrency investment fraud linked to the Tai Chang scam compound (also known as Casino Kosai) in Myanmar. The supporting affidavit characterises the seized domain as a central gateway through which victims were induced to enter a pseudo-investment environment, observe fabricated returns and transfer funds to crypto addresses controlled by overseas actors (
Goldbarsht 2024). The domain mimicked a legitimate financial services platform, demonstrating the role of digital impersonation in fraud generation.
The seizure was explicitly framed as part of a coordinated enforcement initiative and linked to designated criminal entities, situating the action within a broader network-oriented threat assessment rather than as an isolated takedown. From a laundering-chain perspective, this intervention targets an upstream gateway node, interrupting proceed generation before funds enter crypto rails. At the same time, the case highlights a key resilience risk: digital infrastructure is highly substitutable. Domains can be rapidly re-registered unless seizures are paired with sustained monitoring, coordinated action against associated advertising channels, and disruption of mule networks that facilitate fiat-to-crypto conversion and onward transfers (
Abdul Rani et al. 2025;
Ahmad et al. 2018).
At the same time, the case highlights a key resilience risk: digital infrastructure is highly substitutable. Domains can be rapidly re-registered unless seizures are paired with sustained monitoring, coordinated action against associated advertising channels, and disruption of mule networks that facilitate fiat-to-crypto conversion and onward transfers (
Esoimeme 2020;
Zimba et al. 2020). The Tai Chang case demonstrates the preventive value of upstream infrastructure seizure but also underscores that such measures achieve a durable impact only when integrated with interventions targeting facilitation layers and financial conversion points. Compared to asset-centric strategies, infrastructure seizures prioritise prevention over recovery, but their effectiveness depends on sustained action against mule networks and re-registration dynamics.
The case thus illustrates that upstream interventions can disrupt entry points into the laundering chain, but their long-term effectiveness depends on parallel disruption of downstream financial and facilitation nodes.
4.3. Criminal Assets Bureau v Mannion (Ireland): Downstream Asset Recovery
Criminal Assets Bureau v Mannion offers a clear European comparator centred on post-offence asset deprivation through established proceeds-of-crime mechanisms.
In 2018, the Irish High Court considered an application under the Proceeds of Crime Act 1996 concerning 2013.96 ETH (the native crypto-asset of the Ethereum network, functioning both as a medium of exchange and as a unit for executing transactions and smart contracts on a decentralised blockchain, qualified as a virtual asset within the meaning of the Financial Action Task Force standards, namely a digital representation of value that can be digitally traded or transferred and used for payment or investment purposes) discovered on the respondent’s computer.
The judgement documents the forensic identification of crypto-assets and the evidentiary reasoning linking them to predicate offences, including admissions relating to Darknet drug distribution and payment in cryptocurrency (
Joyce 2025;
Siqueira et al. 2020). It also illustrates practical challenges associated with crypto-asset valuation, custody and mixing, and the court’s willingness to shift the evidentiary burden once a prima facie case is established (
Del Sarto et al. 2024;
Silva and Mira da Silva 2022;
da Silva 2022).
Its relevance to AML/CFT frameworks derives from several characteristics: the pseudonymous nature of blockchain transactions, the global and borderless transferability of value, and the possibility of obfuscation through layering techniques (including mixers, decentralised exchanges, and cross-chain transfers). These features can facilitate the placement and layering stages of money laundering while simultaneously posing challenges for asset tracing, attribution, and enforcement. Consequently, the treatment of Ether within proceedings such as Mannion illustrates how traditional proceeds-of-crime regimes are being extended to encompass crypto-assets, while also highlighting the evidentiary and jurisdictional complexities that arise when applying AML/CFT principles to decentralised financial infrastructures. The case also illustrates the limits of a seizure-dominant strategy for scam-compound laundering chains: asset deprivation is inherently reactive and does not disrupt upstream fraud production or facilitation structures, including money mule networks, that enable proceeds generation in the first place (
Nazzari 2024;
Wronka 2022).
From a chain-based perspective, Mannion exemplifies an intervention concentrated at the asset-recovery node, with limited capacity to affect upstream fraud production or mule-mediated facilitation. Once crypto-assets are identified and placed under state control, civil recovery mechanisms can operate effectively to deprive offenders of value. This enforcement logic aligns closely with the framework established by the Financial Action Task Force, particularly Recommendation 4, which requires jurisdictions to adopt measures enabling the confiscation of proceeds of crime, including property derived from or used in money laundering. In addition, Recommendation 38 (mutual legal assistance: freezing and confiscation) and Recommendation 37 (mutual legal assistance more broadly) are directly engaged in cross-border crypto-asset cases, where effective asset recovery depends on international cooperation to trace, freeze, and ultimately confiscate digital assets held across multiple jurisdictions.
However, while these recommendations provide a robust normative basis for post-offence deprivation of illicit gains, they remain structurally oriented towards downstream enforcement. As such, they offer limited direct engagement with earlier nodes of the laundering chain, including fraud generation and mule-mediated fund movement. This reinforces the analytical insight that asset recovery, although essential, operates primarily as a reactive mechanism and may be insufficient, in isolation, to disrupt the adaptive and transnational dynamics of crypto-enabled criminal ecosystems.
Therefore, the case reinforces the analytical distinction between enforcement that removes illicit value and enforcement that disrupts the operational continuity of the laundering chain, underscoring the limits of downstream-only strategies.
4.4. The Rock Trading Case, Corte di Cassazione—Sentenza n. 1760/2025 (Italy): Doctrinal Constraints on Preventive Seizure
The The Rock Trading case, Corte di Cassazione—sentenza n. 1760/2025 concerns the legality of preventive seizure of crypto-assets in the context of alleged criminal association aimed at fraud. The Court scrutinised whether the legal requirements governing preventive measures were satisfied, notwithstanding ongoing uncertainty surrounding the legal classification of virtual currencies in Italy.
The Court held that preventive seizure must comply with established standards of seriousness, precision and concordance of evidence, irrespective of the technological novelty of crypto-assets. It emphasised that assets allegedly connected to transactions involving unidentified foreign subjects could not be seized absent demonstrable linkage to the alleged criminal association, warning that failure to meet these thresholds would infringe on property rights under Article 1 of Protocol No. 1 ECHR (
Zatti and Barresi 2023).
The decision illustrates how doctrinal constraints, while rights-protective, may limit the preventive reach of asset deprivation in crypto-laundering chains. From a laundering-chain perspective, the decision illustrates how doctrinal and rights-protective constraints can limit the preventive reach of asset-deprivation tools. While such constraints are legally essential, they may reduce the capacity of downstream interventions to disrupt laundering chains characterised by transnational fragmentation and mule-mediated attribution gaps. From a chain-based perspective, the decision highlights how doctrinal safeguards—while essential for rights protection—may inadvertently constrain early-stage intervention, thereby reinforcing reliance on downstream enforcement and limiting systemic disruption of the laundering chain.
5. Enforcement Strategies Along the Crypto-Laundering Chain
This section integrates the findings of the four case studies within a comparative analytical framework. The comparison does not seek to draw equivalences between Southeast Asian and European legal systems, which operate under markedly different institutional, political and regulatory conditions. Rather, it examines how enforcement authorities in each context intervene at different nodes of the crypto-laundering chain, and with what implications for systemic disruption. By mapping enforcement strategies onto the stages of fraud production, facilitation, crypto-asset movement and asset deprivation, the comparative analysis highlights both functional divergences and shared structural vulnerabilities across jurisdictions.
5.1. Divergent Enforcement Orientations Along the Laundering Chain
The comparative analysis reveals a clear divergence in enforcement orientation that is best understood in functional rather than geographic terms.
In the Southeast Asian cases, enforcement strategies increasingly target upstream and midstream nodes of the laundering chain. The
Prince Group/Chen Zhi case exemplifies a network-oriented approach, in which scam compounds are treated as organisational hubs sustaining large-scale fraud production. Tools such as transnational criminal organisation designation, coordinated sanctions and large-scale asset restraint are deployed not only to recover proceeds but to disrupt organisational capacity and reputational legitimacy (
Calamunci and Drago 2020;
Franceschini et al. 2023;
Friday et al. 2022). Similarly, the
Tai Chang case illustrates an infrastructure-oriented enforcement logic, prioritising the seizure of enabling digital assets, such as impersonation domains, used to onboard victims into crypto-investment fraud schemes. By targeting the deception interface, this approach seeks to interrupt proceed generation before funds enter crypto rails.
By contrast, the European cases are characterised by a predominantly downstream, asset-centric enforcement orientation. Both
Criminal Assets Bureau v Mannion and
The Rock Trading case, Corte di Cassazione—sentenza n. 1760/2025 focus on the legal treatment of crypto-assets as objects of seizure, confiscation or civil recovery once laundering has already progressed through placement and layering stages. Effectiveness therefore depends on the state’s capacity to establish custody, attribution and a legally sufficient nexus between assets and predicate offences (
Friday et al. 2022). From a chain-based perspective, the divergence reflects distinct enforcement rationales: Southeast Asian strategies prioritise disruption of production and facilitation capacity, while European frameworks remain anchored in post-offence deprivation of value, consistent with long-standing proceeds-of-crime paradigms.
5.2. The Money Mule Layer as a Cross-Jurisdictional Vulnerability
Despite divergent enforcement orientations, the comparative analysis identifies a shared structural vulnerability across all four cases: the money mule layer (
Abdul Rani et al. 2025;
Hassan et al. 2020;
Islam et al. 2025;
Taylor et al. 2022). In the Southeast Asian cases, mule networks facilitate cross-border routing, localisation of financial flows and risk externalisation, enabling scam compounds to avoid direct interaction with regulated intermediaries and to adapt rapidly to enforcement pressure (
Li et al. 2025;
Yerkenov et al. 2025). Mule-mediated facilitation allows upstream crime-production structures to remain insulated even when infrastructure or organisational nodes are targeted. In the European cases, the mule layer often remains analytically implicit. Although courts recognise the practical difficulty of disentangling legitimate and illegitimate funds once laundering is advanced (
Goldbarsht 2024;
Goldbarsht and Benson 2024;
Goldsmith et al. 2020), mule ecosystems are rarely treated as primary regulatory targets equivalent in importance to crypto-asset service providers or asset-seizure mechanisms (
Gundur et al. 2021;
van der Linden and Shirazi 2023).
This comparative finding underscores a central implication of the crypto-laundering chain framework: pressure applied at one node intensifies reliance on adjacent nodes, particularly money mules as adaptive buffers. Enforcement strategies that overlook this dynamic risk displacement rather than disruption of laundering activity.
5.3. Partial Versus Holistic Disruption Under Existing Frameworks
The comparative evidence suggests that current enforcement and regulatory frameworks tend to disrupt laundering partially rather than holistically.
In Southeast Asia, the combination of sanctions, infrastructure seizure and network designation reflect movement toward multi-node intervention, particularly where enforcement actions integrate cybercrime, fraud and organised crime intelligence (
Shafa and Sultana 2024). However, even these approaches face substitution risks, as digital infrastructure and recruitment pipelines remain highly adaptable. In the European Union, the AML regime and MiCA significantly strengthen oversight of crypto-asset service providers and market conduct (
Kozieł 2025;
Mkrtchyan and Treiblmaier 2025;
van der Linden and Shirazi 2023). Yet their primary focus remains institutional rather than systemic. Asset recovery and supervisory compliance harden specific nodes of the laundering chain while leaving upstream fraud production and human facilitation layers comparatively exposed. Across both contexts, organised crime groups exploit these asymmetries by reallocating functions across the chain—rotating infrastructure, recruiting new mules, or shifting jurisdictions—thereby preserving overall system resilience.
5.4. Comparative Implications for Chain-Based Regulation
Taken together, the comparative findings point to a fundamental regulatory implication: effective disruption of crypto-enabled scam ecosystems requires chain-aware enforcement and regulation.
The Southeast Asian cases demonstrate the value of targeting organisational and infrastructural nodes early in the laundering process, while the European cases illustrate the continuing importance and inherent limits of downstream asset deprivation tools. A holistic approach treats these strategies not as substitutes but as complementary interventions operating across interconnected nodes (
Ahmed and Alabi 2024;
Chukwunweike et al. 2024).
From a policy perspective, AML frameworks should therefore be assessed not only on their capacity to detect suspicious transactions or seize illicit assets but also on their ability to simultaneously constrain fraud production, facilitation and value stabilisation. The crypto-laundering chain framework provides a structured basis for evaluating whether regulatory interventions reduce overall system capacity or merely displace activity across nodes (
Gaviyau and Sibindi 2023;
Slavhorodska 2025).
6. Regulatory Assessment Through a Chain-Based Lens
This section assesses how existing regulatory frameworks (specifically the European Union’s AML regime, the Markets in Crypto-Assets Regulation, and the FATF risk-based approach) engage with the crypto-laundering chain identified through the empirical and comparative analysis. The focus is analytical rather than prescriptive: the aim is to evaluate where current frameworks intervene along the laundering chain, and where structural asymmetries persist, rather than to propose regulatory reforms. Adopting a chain-based perspective also enables a critical assessment of how these frameworks may generate unintended effects, including regulatory displacement, selective hardening of specific nodes, and the adaptive reconfiguration of laundering strategies.
The European Union’s AML framework has historically relied on asset deprivation mechanisms (criminal confiscation, preventive seizure and civil recovery) as its primary response to financial crime (
Erken and Türkşen 2024;
Goldbarsht 2024;
Pavlidis 2023). This orientation is clearly reflected in the European cases analysed in this study. Both
Criminal Assets Bureau v Mannion and
The Rock Trading case, Corte di Cassazione—sentenza n. 1760/2025 demonstrate the centrality of post-offence asset deprivation, including its extension to crypto-assets.
From a chain-based perspective, these mechanisms predominantly target the downstream node of the laundering process. Where crypto-assets can be identified, attributed and legally qualified as proceeds of crime, asset deprivation can operate as an effective recovery and deterrence tool (
Nyreröd et al. 2023). However, the case analysis also highlights the inherent limits of this approach: asset deprivation is necessarily reactive and dependent on evidentiary thresholds that are difficult to meet in transnational, mule-mediated laundering chains (
Nazzari 2023;
Wronka 2022).
More critically, this downstream orientation may generate displacement effects, whereby increased enforcement pressure at the recovery stage incentivises criminal actors to adopt more sophisticated upstream obfuscation strategies, including the use of layered mule networks, privacy-enhancing technologies and rapid cross-jurisdictional transfers, thereby reducing the probability of successful confiscation ex post.
MiCA represents a major regulatory intervention aimed at harmonising governance, transparency and conduct-of-business requirements for crypto-asset issuers and crypto-asset service providers (CASPs) across the European Union (
Ferreira and Sandner 2021;
van der Linden and Shirazi 2023). From an AML perspective, MiCA strengthens oversight at the point where crypto-assets interface with regulated markets.
Within the crypto-laundering chain, MiCA primarily reinforces the midstream infrastructure node, particularly where laundering relies on custodial wallets, exchanges and fiat on- and off-ramps (
Kozieł 2025;
Mkrtchyan and Treiblmaier 2025;
Movchan et al. 2023). By increasing compliance costs and supervisory scrutiny, MiCA constrains laundering pathways that depend on regulated intermediaries. However, this node-specific strengthening also produces identifiable regulatory blind spots. By concentrating regulatory pressure on CASPs, MiCA may unintentionally incentivise migration towards unregulated or less-regulated environments, including decentralised exchanges (DeFi), peer-to-peer transfers and unhosted wallets, thereby displacing rather than eliminating laundering activity. Nevertheless, the empirical findings of this study suggest that MiCA’s impact is structurally node-specific. Scam-compound-based laundering chains often combine regulated and unregulated infrastructure, including unhosted wallets, mule-controlled accounts and jurisdictional substitution. As a result, MiCA does not directly engage with upstream crime-production structures or the human facilitation layer that enables access to crypto infrastructure.
This structural limitation reflects a broader regulatory asymmetry: while MiCA enhances transparency and compliance within formal crypto markets, it leaves largely unaddressed the informal and coercive organisational environments in which large-scale fraud and initial value extraction occur.
The establishment of the EU Anti-Money Laundering Authority (AMLA), which came into effect on 26 June 2024, represents a significant step towards enhancing supervisory convergence and mitigating fragmentation among Member States (
Tosza and Voordeckers 2024). This effort aligns with the broader framework of the EU’s anti-money laundering (AML) regulations, specifically Directive (EU) 2015/849, which sets forth comprehensive measures to prevent the misuse of the financial system for money laundering or terrorist financing. Moreover, Regulation (EU) 2019/758, which establishes AMLA, complements these efforts by strengthening coordination across Member States in the supervision of high-risk obliged entities, ensuring the uniform application of AML standards throughout the European Union.
From a chain-based perspective, however, institutional coordination alone does not resolve the misalignment between regulatory focus and laundering dynamics. Unless scam-compound typologies and money mule risks are explicitly incorporated into supervisory priorities, AMLA’s impact is likely to remain concentrated on regulated financial and crypto intermediaries, leaving upstream organisational structures comparatively unaddressed (
de Haro-Olmo et al. 2020;
Kreminskyi et al. 2021;
De Marzo et al. 2022).
Moreover, enhanced coordination at the supervisory level does not necessarily translate into operational disruption across the laundering chain, particularly where enforcement capacities remain uneven across jurisdictions or where criminal networks exploit regulatory arbitrage.
FATF’s risk-based approach provides a conceptual framework capable of recognising laundering risks arising from evolving typologies, organisational forms and crime ecosystems (
De Koker 2024;
Pavlidis 2023).
Scam compounds and mule networks, as evidenced in the Southeast Asian cases, fall squarely within this systemic risk logic (
Nicholls et al. 2024;
Windari et al. 2024). However, the analysis suggests a persistent gap between FATF’s typological recognition and its translation into binding regulatory and supervisory practice, particularly within institution-focused regimes such as MiCA. In practice, while FATF guidance acknowledges emerging risks, its reliance on national implementation and its focus on regulated entities limit its capacity to address decentralised, extra-institutional and coercive criminal structures. This creates a structural lag between risk identification and effective intervention.
This gap contributes to a regulatory asymmetry in which downstream and midstream nodes are hardened, while upstream fraud production and facilitation remain structurally exposed.
Taken together, these dynamics suggest that current AML frameworks, while individually robust, may collectively produce a form of “selective hardening” of the laundering chain, reinforcing resilience rather than achieving systemic disruption.
7. Policy Implications for Regulating Crypto-Enabled Scam Ecosystems
Building on the regulatory assessment above, this section translates the chain-based findings into policy-relevant implications for stakeholders involved in the design, supervision and enforcement of AML frameworks. The focus is on how existing tools may be operationalised and coordinated, rather than on proposing new regulatory mandates.
A central implication of the analysis is the need for AML strategies to move beyond node-specific interventions, such as CASP compliance or post-offence asset seizure, towards approaches that recognise laundering as an integrated, adaptive process. The comparative cases demonstrate that pressure applied to one node of the laundering chain often results in displacement to adjacent nodes, rather than overall disruption. This displacement dynamic should be understood not as an anomaly but as a structural feature of adaptive laundering systems, particularly in crypto-enabled environments characterised by low entry barriers and high technological substitutability. For policymakers and supervisors, this implies that AML effectiveness should be assessed in terms of reduced system capacity and resilience, not merely transaction detection or asset recovery volumes.
Treating mules primarily as isolated offenders or vulnerable victims obscures their systemic role and limits the effectiveness of intervention strategies (
Nazzari 2024).
From a policy perspective, reframing money mules as a systemic AML risk category supports targeted prevention and disruption strategies, including cross-platform intelligence sharing, identification of recruitment patterns and coordination between financial supervisors, cybercrime units and labour-exploitation authorities. This reframing does implies not harsher criminalisation but rather more accurate risk allocation.
The Southeast Asian cases highlight the preventive value of upstream interventions such as domain seizures and infrastructure disruption, while the European cases underscore the continued importance of downstream asset deprivation once laundering has occurred (
Song et al. 2023;
Trozze et al. 2022). A key policy implication is that these approaches should be complementary rather than alternative. For enforcement agencies, this implies sustained cross-border coordination to ensure that disabling fraud pipelines is paired with actions against facilitation and conversion layers, including mule networks and crypto off-ramps.
The findings suggest that the effectiveness of MiCA and the EU AML framework depends on their operational alignment with FATF’s systemic risk logic. For regulators and supervisors, this entails incorporating scam-compound and mule-related indicators into risk-based supervision, enforcement prioritisation and CASP expectations, rather than treating crypto-AML risk as predominantly transactional (
Duncan 2024;
Robert 2009). Absent such alignment, there is a risk that regulatory efforts will continue to reinforce already-visible segments of the laundering chain while leaving its most adaptive and opaque components relatively untouched.
Finally, the analysis underscores that crypto-enabled scam ecosystems generate not only financial harm, but also severe social harms linked to coercive labour, trafficking and exploitation (
Kattamuri and Klein 2025;
Sarkar and Shukla 2023). Chain-based AML strategies therefore support closer coordination between financial regulators, trafficking enforcement bodies and labour inspectors.
Such coordination enhances both financial crime prevention and the protection of exploited individuals, aligning AML objectives with broader social justice and human rights considerations (
Pocher et al. 2023;
Zetzsche et al. 2020).
8. Conclusions, Limitations and Further Research
8.1. Conclusions
This paper has examined crypto-enabled fraud through a chain-based analytical framework that integrates scam compounds, money mule networks and crypto-asset infrastructures as interdependent components of contemporary laundering systems. Drawing on a comparative analysis of four empirically grounded cases from Southeast Asia and Europe, the study has shown that organised crime networks rely not on isolated techniques or actors but on adaptive configurations that distribute functions across multiple nodes of the laundering chain.
The findings demonstrate that enforcement and regulatory responses currently intervene at different points along this chain, with uneven implications for systemic disruption. Southeast Asian cases illustrate the preventive value of upstream interventions targeting organisational capacity and digital infrastructure, while European cases underscore the continuing importance—and inherent limits—of downstream asset deprivation within established proceeds-of-crime frameworks. Across jurisdictions, money mules consistently emerge as a critical connective layer that absorbs enforcement pressure and enables substitution, relocation and resilience.
By mapping these dynamics, the paper contributes to AML scholarship in three ways. First, it advances an integrated conceptualisation of crypto-laundering that moves beyond transaction-centric and institution-focused approaches. Second, it provides a comparative, empirically grounded account of how different enforcement logics shape outcomes along the laundering chain. Third, it offers a structured basis for assessing regulatory asymmetries within existing frameworks, including the EU AML regime, MiCA and the implementation of FATF’s risk-based approach.
8.2. Limitations and Further Research
The analysis also highlights important limitations. The qualitative design and reliance on a limited number of judicial and enforcement cases constrain statistical generalisation. However, given the covert, transnational and rapidly evolving nature of scam-compound-based laundering systems, a chain-based qualitative approach is well suited to capturing organisational and institutional dynamics that remain largely invisible in quantitative datasets.
Future research could extend this framework through mixed-methods designs, larger comparative samples or jurisdiction-specific empirical studies, including systematic analysis of money mule recruitment and governance mechanisms. As crypto-enabled fraud continues to evolve, understanding laundering as an integrated and adaptive process, rather than as a series of isolated compliance failures, remains essential for both scholarship and policy.