One of the laziest attacks on bitcoin is that criminals use it to launder money, as if that settles the argument. The Coldcard attacker is now demonstrating the weakness in that claim in real time. Galaxy traced 97.09 bitcoin, roughly 45% of the third theft wave, moving through THORChain and CoinJoin. About 20.5 bitcoin crossed into Ethereum, then another 76.6 bitcoin entered CoinJoin rounds. The attacker has emptied the 11 largest vaults, yet roughly 82% of the wider 1,806 bitcoin haul remains parked at addresses already associated with the theft.
Bitcoin is pseudonymous, not anonymous. CoinJoin makes attribution harder, and THORChain and other shitcoins let attackers move value into other assets and obfuscate their history. But the original theft is still sitting on a permanent public ledger. The Bitfinex thieves spent years splitting stolen funds across thousands of transactions, exchanges, darknet markets, and other assets. U.S. investigators still traced the trail and seized 94,636 bitcoin.
Treasury’s own risk assessment says virtual asset laundering remains far below fiat currency. UNODC estimates that $800 billion to $2 trillion is laundered globally each year, overwhelmingly outside bitcoin. The current crypto numbers make the bitcoin point even more clearly. Stablecoins accounted for 84% of illicit crypto volume in 2025, and Chainalysis says darknet operators have been moving away from BTC because bitcoin’s inherent transparency keeps burning them. Of course criminals use bitcoin. Criminals also use dollars, banks, phones, and the internet. A useful tool does not become bad because a bad person uses it. The relevant question is whether the tool makes the crime easier to hide. Bitcoin creates a public record that never goes away, which is a pretty shitty feature for a money launderer and for central planners trying to print money.