On July 21, 2026, the U.S. Attorney’s Office for the District of Columbia filed five lawsuits in federal court. Read the case captions and something is missing: there are no human defendants. The government is suing the money itself — more than $25 million in Tether (USDT) traced to romance scams, spoofed trading platforms and approval-phishing operations run largely out of Southeast Asia.
That is not a technicality. It is now the Justice Department’s primary working tool against transnational crypto fraud, and it tells you something uncomfortable about where enforcement stands in 2026: the people running these schemes are, for practical purposes, beyond arrest. So prosecutors go after the only thing they can actually reach.
Five Complaints, One Pattern
The filings break down into five separate actions, each tracing a different slice of the same industry:
- ~$12.09 million tied to romance-investment schemes that hit more than 200 victims across the U.S. and Canada.
- $10.4 million connected to a broader $78 million laundering network involving approval phishing and multiple fake platforms, with more than 240 identified victim transactions.
- $2.39 million from a domain-spoofing operation impersonating the Zoomex exchange — where investigators traced 99% of the frozen balance to just two victims.
- $1.77 million from a fake platform called MicMarkets, seeded through dating apps, with 17 confirmed victims.
- $284,900 from a two-stage con targeting a British victim, in which the “recovery” offer that followed the original theft was run by the same criminal ecosystem.
The mechanics behind all five are the model the industry calls pig butchering: weeks or months of relationship-building over dating apps or a wrong-number text, a gradual pivot to a “can’t-lose” trading platform, real crypto deposited, fake gains displayed on a fake dashboard — and then, at the moment of withdrawal, the taxes, the fees, and the silence.
Investigators traced IP infrastructure behind the operations to China, Malaysia and Cambodia, consistent with the compound economy that has powered this fraud since 2022.
Why “Suing the Money” Is the Whole Story
Civil forfeiture is an in rem action — a legal proceeding against property rather than a person. Prosecutors don’t have to identify, extradite or convict anyone. They have to convince a federal judge that the specific assets are traceable to crime.
That distinction is the entire strategy. As one legal analysis of the filings put it bluntly: “The government did not indict anyone. It sued the money.”
The upside is real. It produces custody of the assets, a court judgment, and a pool of recoverable funds for victims — outcomes that a criminal case against someone sitting in a guarded compound in Myanmar or Cambodia would never produce. The Scam Center Strike Force, launched in November 2025, has restrained more than $832 million using this approach as of mid-June 2026, and U.S. Attorney Jeanine Ferris Pirro has framed the July filings as a direct product of it.
The downside is equally real: nobody goes to prison, the compounds keep operating, and the recruiters keep trafficking workers into them. Seizing proceeds is damage control, not dismantlement.
The Quiet Role of the Stablecoin Issuer
There is a detail in these complaints that deserves more attention than it usually gets: every dollar at issue is USDT, and none of it was seized with a warrant kicking in a door.
Tether froze the addresses at law enforcement request. In some cases the freeze happened within a day of the referral; in others, the funds sat blacklisted for as long as 20 months before a complaint was ever filed. A centralized issuer with the ability to blacklist addresses is, in practice, the reason this money still exists to be forfeited at all.
That cuts both ways. It is enormously effective against fraud proceeds parked in a freezable asset — and it is a reminder that “your crypto, your keys” is not the whole picture when the token is a centrally administered stablecoin. Scam syndicates know this too, which is why laundering routes increasingly detour through decentralized exchanges and cross-chain swaps to shake off exactly this kind of intervention. One of the five complaints tracks funds doing precisely that.
Tracing Is Not the Same as Proving
The complaints are unusually candid about how much of the frozen money can actually be tied to identified victims: in one case 99%, in another 86%, in another just 11%.
That gap exists because scam proceeds are pooled. Funds from hundreds of victims flow into consolidation wallets, mix with other criminal proceeds, and get split again. Investigators use blockchain clustering and accounting conventions borrowed from finance — LIFO and FIFO — to argue which coins in a commingled wallet are which victim’s. Where direct tracing runs out, the government argues the remainder is laundering property in its own right.
It works, but it is an argument, not a receipt. And it explains why a $25 million forfeiture does not translate into $25 million of neatly labeled refunds.
What Victims Actually Have to Do
This is the part that gets lost in headlines about record seizures. Forfeiture does not automatically return money to anyone. The sequence is:
- Claims. Anyone asserting an interest in the property must file a claim in the forfeiture case — generally at least 35 days after direct notice, or 60 days after publication on forfeiture.gov — with an answer or motion due 21 days later.
- Judgment. The court decides whether the assets are forfeitable.
- Remission. Only then do victims petition the DOJ’s administrative remission process under 28 C.F.R. Part 9, with documented losses, complete transaction records, and communications with the fake platform. If the fund can’t cover proven losses, payouts are pro rata.
Practically, that means the paperwork you keep now determines what you recover later. Deposit records, wallet addresses, screenshots of the platform, the chat logs — all of it. Victims who reported to IC3 or a Secret Service field office at the time are in a far better position than those who didn’t report at all, because that report is often what links a wallet in a spreadsheet to a name.
Protecting Yourself
The enforcement story is encouraging. The prevention story hasn’t changed, because the con hasn’t:
- A stranger who reaches you first and then teaches you to trade is running a script. Wrong-number texts and dating-app matches that pivot to crypto returns are the opening move of pig butchering, every time.
- Verify the platform, not the person. MicMarkets and the spoofed Zoomex domain looked professional and showed real-time balances. Type exchange URLs manually, check for lookalike domains, and treat any platform introduced by a contact — rather than found independently — as hostile.
- Displayed gains are just pixels. The only test that means anything is a successful withdrawal of a meaningful amount. A demand for “taxes” or “unlock fees” before you can withdraw confirms the fraud outright.
- Approval phishing is invisible. Signing a token approval can hand a stranger standing permission to drain your wallet later. Review and revoke approvals; never sign a transaction you can’t read.
- The second call is also a scam. One of these five complaints exists because someone already defrauded was then defrauded again by a “recovery” service. No legitimate recovery effort asks for an upfront fee or crypto payment.
- Report it, even if it feels hopeless. IC3 and Secret Service reports are the raw material investigators use to attribute frozen wallets. The victims who get paid out of funds like this one are, overwhelmingly, the ones who filed.
Twenty-five million dollars is real money, and for a few hundred people it may eventually mean partial restitution. It is also a fraction of the roughly $10 billion a year that Southeast Asian scam operations are estimated to take from Americans alone. The Justice Department is winning cases against wallets. The industry behind the wallets is still hiring.



