Crypto Fraud Watch: A $560,000 Hamas Seizure, Injective's $4.9 Million "Upgrade," and Aquifer's 20% Bounty Offer
The last 48 hours brought one federal enforcement win and two protocol losses handled very differently: a Justice Department seizure aimed at Hamas fundraising, and a derivatives chain and a Solana market maker giving up a combined $7.4 million. Here is what each means legally.
The DOJ Takes $560,000 Bound for Hamas, and the Donor List With It
On September 1, the Justice Department announced the seizure of more than $560,000 in cryptocurrency it says was raised for Hamas and its Al-Qassam Brigades. The funds moved as USDT through rotating deposit addresses, and investigators traced over $1.5 million in movement dating to late 2024, using three seizure warrants issued between March and October 2025. Prosecutors also took over the network's fundraising and recruitment domains.
The money is the smaller half of this story. Seizing the infrastructure also gave the government records identifying thousands of would-be donors, and anyone in the United States on that list has exposure under the federal material support statutes, which carry up to 20 years. The assumption that a stablecoin transfer to an overseas "charity" is anonymous, and that a sincere belief about the recipient is a defense, does not survive 18 U.S.C. § 2339B.
Injective Loses $4.9 Million, Then Calls the Outage an Upgrade
Injective produced block 181027005 at 16:09:59 UTC on August 31, then stopped for about three hours and 42 minutes. The attacker spun up 299 short-lived binary options markets tied to an oracle rigged to fail at settlement. Injective builds market identifiers by concatenating oracle type, ticker, denomination, symbol, and provider without separators, so an INJ-denominated insurance fund could collide with a USDC market, and the no-price refund path paid the manufactured deficit out of that fund's raw balance. Roughly 1,979.8 ETH, about $4.88 million, was bridged out via Circle's CCTP.
On September 1 the foundation said the chain had been "upgraded, not halted," with consensus and staked assets never compromised. On-chain researchers disputed that, and no postmortem exists. That gap is the legal exposure: how a project publicly describes a security incident is where misrepresentation and securities-fraud theories get built.
Aquifer Offers Its Attacker a 20 Percent Cut
Solana automated market maker Aquifer lost roughly $2.5 million in an incident flagged by monitoring service Defimon on August 31, then publicly offered the attacker the right to keep up to 20 percent if at least 80 percent came back by 14:00 UTC on September 3. Reporting so far does not show the smart contracts were exploited, pointing toward compromised wallet access rather than a code flaw.
A bounty offer is a business decision, not a legal settlement. No project can grant immunity from prosecution, and computer-fraud and money-laundering charges stay available regardless of how much returns. If keys rather than contracts failed, liquidity providers will ask what operational-security duties the team owed them.
Bitcoin Slips Under $77,000
Bitcoin traded near $76,988 on September 2, down 1.6 percent in 24 hours, with Ether near $2,417 and total market capitalization off 1.4 percent at $2.7 trillion, a move coverage tied to renewed U.S. airstrikes on Iran. Falling prices surface fraud: schemes that depend on new deposits fail when deposits slow, and "temporary" withdrawal pauses cluster in weeks like this one.
How to Protect Yourself
Treat a donation solicitation routed through rotating deposit addresses as a red flag, and know that sending stablecoins to an unfamiliar overseas cause can create criminal exposure even when your intent is charitable. Before providing liquidity, check whether the team can unilaterally move pooled assets and whether any audit covers settlement and insurance-fund logic, not just the token contract. When a project calls an outage routine, wait for the postmortem before adding funds.
Legal recourse depends on speed and documentation. Preserve transaction hashes, wallet addresses, statements, and screenshots, then report to the FBI's Internet Crime Complaint Center and your state regulator, since federal forfeiture is often how funds actually reach victims. Civil claims may run in parallel, but limitations periods and arbitration clauses buried in terms of service can foreclose options fast.
At Coin Counsel, we work with individuals and businesses navigating the legal fallout of crypto fraud — whether you're a victim seeking recovery, a company facing regulatory scrutiny, or a project working to stay compliant in an increasingly complex legal landscape. The rules are evolving fast, and the cost of getting it wrong has never been higher. Contact us at coin-counsel.com to speak with a crypto-focused attorney today.
Disclaimer
This blog post is for informational purposes only and does not constitute legal advice. Reading this content does not create an attorney-client relationship between you and Coin Counsel or Franco Law PLLC. The legal landscape surrounding cryptocurrency is rapidly evolving and varies by jurisdiction. Do not act or refrain from acting based on information in this post without first consulting a qualified attorney. If you believe you have been the victim of crypto fraud, contact us at coin-counsel.com for a consultation.