U.S. authorities have seized 13 internet domains allegedly operated by Chinese intelligence operatives who used cryptocurrency to fund a sprawling, covert recruitment scheme targeting American government personnel.
According to unsealed documents from the Department of Justice, the network masqueraded as a series of elite global consulting firms. The operatives utilized standard web3 freelance platforms, artificial intelligence, and digital asset payments to build a financial pipeline that bypassed traditional banking monitors and directly funded the extraction of sensitive national security information.
The domain seizures mark a significant escalation in how U.S. federal authorities are tracking and dismantling state-sponsored espionage campaigns that rely on decentralized financial rails to operate.
Crypto as an espionage payroll system
The Justice Department revealed that the alleged operation began in late 2023. Operatives created at least 13 fake consulting websites, such as Centrik Global Consulting, CYDF Consulting, Pulse Wave Global, and others, and utilized standard online hiring platforms such as Upwork and Hubstaff Talent to contact potential targets.
The network advertised generic but highly paid roles such as “Senior Analyst” and “International Affairs Consultant,” specifically seeking out current and former federal employees with active security clearances. Once engaged, recruiters pressured the candidates to share confidential reports, non-public research, and insider information in violation of their government duties.
To close the trap, the operatives needed a way to pay the recruits without triggering the alarms of the U.S. traditional banking system.
According to investigators, the operatives turned to cryptocurrency. By using digital assets and online payment accounts registered under fictitious names, the network was able to instantly transfer large bounties to the recruits while heavily obscuring the operators’ true identities and the sovereign origin of the funds.
Assistant Attorney General John A. Eisenberg warned that foreign actors are increasingly using deceptive recruitment tactics to gain access to protected information. “These domain seizures offer a glimpse at how foreign actors can use promises of easy money to lure Americans into revealing sensitive or classified information that they are duty-bound to protect.”
The broader threat to digital platforms
The FBI noted that the network relied on AI-generated profile images, fake identities, encrypted messaging platforms, and overseas payment channels to conceal its activities.
The case highlights a growing structural concern within the digital asset industry: foreign intelligence services are increasingly combining artificial intelligence tools with borderless crypto-payment systems to support recruitment and information-gathering efforts. Because cryptocurrency can be transferred globally without an intermediary bank verifying the sender’s true corporate identity, it has become the preferred vehicle for funding illicit intelligence gathering.
Last month, Taiwanese prosecutors charged a television journalist accused of receiving USDT payments from an alleged Chinese operative. Investigators claimed the payments were linked to politically influenced media content and efforts to obtain military-related information.
The unsealed domain seizures arrive alongside a broader, unified crackdown by federal authorities aimed at cutting off the digital lifeblood of foreign operatives. Following the seizures, the FBI replaced the 13 websites with an official takeover page, warning visitors that the domains had been rendered inoperable to disrupt illegal activity and international money laundering.
Also Read: Coinbase Traders to Face Forced Settlement as Six Perps Near Delisting
