Issue #23 | September 29, 2026 | 7 min read

The Brief

On October 14, 2025, the Justice Department filed a civil forfeiture complaint for 127,271 bitcoin. At the time it was worth roughly $15 billion, the largest forfeiture in DOJ history. The coins traced back to forced-labor compounds in Cambodia, where trafficked workers were beaten into running romance-investment scams against victims across the US and beyond.

Three months later, the man DOJ blamed for the whole operation was in Chinese custody, not American. This issue covers how a $15 billion laundering operation moved money for years without tripping the wires most compliance programs are built to catch, and what a related case against a Cambodian financial conglomerate actually tests for.

Main Feature

DOJ Seized $15 Billion From Chen Zhi. China Got Him Instead.

The largest forfeiture in Justice Department history came out of forced-labor scam compounds, and it still didn't put the man running them in front of a US judge.

On October 14, 2025, prosecutors in the Eastern District of New York unsealed an indictment against Chen Zhi, the Cambodian-Chinese founder and chairman of Prince Holding Group, on charges of wire fraud conspiracy and money laundering conspiracy. Filed alongside it was a civil forfeiture complaint for 127,271 bitcoin, worth about $15 billion at the time, the largest forfeiture action in DOJ history. The bitcoin traces back to years of "pig butchering" schemes: romance and investment fraud that lures a victim into a relationship, then a fake trading platform, then a total loss. One Brooklyn-based cell tied to the network alone victimized more than 250 people in New York. Treasury puts the scheme's total global haul above $16.6 billion.

Prince Group didn't look like a criminal enterprise from the outside. It presented as a diversified Cambodian conglomerate with real estate developments, hotels, and a media arm, the kind of business profile that gets a company treated as a legitimate corporate customer rather than a screening target. Behind that front, DOJ's complaint describes dormitories behind high walls and barbed wire, "phone farms" running thousands of devices and millions of phone numbers, and workers trafficked in and held through documented beatings. The laundering side ran on a technique prosecutors call spraying and funneling: crypto proceeds split across dozens of wallet addresses, then reconsolidated into a handful, breaking the trail a compliance analyst would otherwise be able to follow. Some of the money moved through hosted exchange wallets and ordinary bank accounts. Some never left wallets Chen Zhi controlled personally. A cryptocurrency mining operation reportedly gave the whole thing another layer of legitimate-looking cover, and operations were spread across Cambodia, Mauritius, Taiwan, Singapore, Laos, and Palau to keep any single jurisdiction from seeing the full picture.

❝

127,271 BTC (~$15B) forfeited: The largest DOJ forfeiture in history. Treasury estimates the scheme's global fraud proceeds above $16.6B. Treasury also designated Prince Group a Transnational Criminal Organization and sanctioned 146 linked targets. The compounds ran for years before any of it reached a courtroom.

The bigger failure here isn't one bank's transaction monitoring. It's that an entire parallel financial system grew up to service operations exactly like this one. A companion action makes that concrete: FinCEN used a Section 311 order, the same USA PATRIOT Act tool once reserved for designating rogue foreign banks, to cut Huione Group off from the US financial system entirely, naming the Cambodia-based conglomerate a primary money laundering concern. Investigators tied Huione to more than $4 billion laundered between August 2021 and January 2025, including proceeds from North Korean cyber heists and pig-butchering operations that had nothing to do with Prince Group. Chen Zhi's compounds didn't move $15 billion by slipping past Western compliance programs one transaction at a time. They had a purpose-built alternative financial system to launder through instead.

Red Flags in This Case

  • Wallet clustering showing rapid fragmentation into dozens of destination addresses, followed by reconsolidation into a handful, within a short window, the spray-and-funnel signature

  • A corporate customer profile (diversified conglomerate, real estate, hospitality, media) obscuring a very different underlying cash-generation business

  • Commercial accounts coded as crypto mining operations with revenue inconsistent with their disclosed hash rate or hardware footprint

  • Disproportionate transaction volume routed through a small number of Southeast Asia-based virtual asset service providers relative to their disclosed customer base

  • Account-opening data showing thousands of separate customer identities linked to the same device or IP range, the phone-farm signature

For an institution with no direct Cambodia exposure, the lesson isn't "watch for scam compounds." It's that a Section 311 order is a lagging confirmation of a risk that was already visible, not a surprise. Every VASP or nested correspondent relationship that touched Huione before the designation landed is now a lookback problem, not a monitoring problem. If your program can't currently answer which counterparties have exposure to a newly designated primary money laundering concern, that's the gap this case actually tests.

DOJ got the largest forfeiture in its history. It didn't get Chen Zhi. He's in Chinese custody, formally arrested by Beijing in August 2026, in a country with no extradition treaty with the United States. The money crossed a compliance perimeter. The chairman just crossed a border.

Source: DOJ Press Release, Oct. 14, 2025 | US v. Chen Zhi civil forfeiture complaint, EDNY | Treasury/FinCEN Section 311 Order Against Huione Group, Oct. 2025 | OCCRP, Jan. 2026

Controls & Testing

Risk & Control Matrix

Risk

Control

Rapid wallet fragmentation into dozens of addresses followed by reconsolidation into a handful (spray-and-funnel), breaking transaction lineage before an exchange off-ramp

Blockchain analytics rule flagging address clusters that split into 20+ destination wallets within a defined window and later reconsolidate into fewer than 5

Counterparty VASPs later named under a Section 311 primary money laundering concern order, with no lookback trigger built into the monitoring program

Automated screening of the VASP counterparty list against active and proposed FinCEN Section 311 actions, with a mandatory lookback on any match

Commercial crypto-mining customers whose revenue doesn't match their disclosed hash rate or hardware, used to legitimize fraud proceeds

Independent verification of mining-operation revenue against public network hash-rate data before onboarding, and periodically after

Account-opening data showing shared device fingerprints or IP ranges across large numbers of unrelated identities

Device and IP clustering analytics at onboarding, flagging shared fingerprints above a set customer-count threshold for manual KYC review

Audit Test Steps

An audit program built around this typology could test for it by:

  1. Pulling a sample of virtual-asset transactions above a set dollar threshold and tracing wallet clusters for fragmentation into 20+ addresses followed by reconsolidation into fewer than 5 within 30 days.

  2. Comparing the institution's active VASP counterparty list against FinCEN's current and historical Section 311 actions and confirming a lookback was performed on any match.

  3. Selecting accounts coded as cryptocurrency mining operations and verifying reported revenue against public hash-rate data for the claimed hardware footprint.

  4. Reviewing a sample of new retail account openings for shared device fingerprints or IP ranges across unrelated customer IDs above a set concentration threshold.

  5. Confirming SAR narratives filed on flagged crypto activity in the sample period cite the specific typology indicators above rather than generic "unusual activity" language.

Intelligence Briefing

FinCEN's $12.7B scam center alert. On September 3, 2026, FinCEN published Alert FIN-2026-Alert005, flagging nearly $12.7 billion in suspected digital asset investment scam activity identified across 33,904 BSA filings between September 2023 and December 2025. The alert names the same Southeast Asia-based scam-compound model behind the Prince Group case and asks institutions to watch for stablecoin transfers, shell companies, and money mules tied to it.
Source: FinCEN news release, Sep. 3, 2026 | FinCEN Alert FIN-2026-Alert005, PDF

Treasury sanctions a Brazilian cartel's trade-laundering network. In July 2026, Treasury designated a network tied to Primeiro Comando da Capital that laundered more than $190 million in seven months through a trade-based scheme moving Chinese electronics through an e-commerce platform, plus over $30 million generated in US cities and moved to Brazil via crypto. A reminder that trade-based laundering doesn't need a bank's cooperation. It just needs a counterparty willing to move goods instead of wires.
Source: US Treasury press release, Jul. 1, 2026

Career Intel

ACAMS built its Certified Global Sanctions Specialist credential because generalist AML training doesn't cover sanctions-evasion mechanics at the depth cases like this one require. This issue alone touches two separate sanctions actions, OFAC's designation of 146 Prince Group-linked targets, and FinCEN's Section 311 order against Huione Group, each governed by a different legal authority with different obligations attached. Practitioners moving into sanctions-specific roles are increasingly expected to know which authority applies before they can even start screening for it.

AI in Financial Crimes Compliance

Investigators are starting to see AI agents run the laundering side of crypto fraud, not just the compliance side. Researchers call it agentic smurfing: autonomous software splits illicit funds into thousands of $50–$500 transfers, generates a disposable wallet for each one, times the transfers to blend into peak network congestion, and moves the proceeds across chains through decentralized bridges with no exchange KYC checkpoint anywhere in the path. Every individual transfer sits under both the FATF Travel Rule's $1,000 threshold and FinCEN's $10,000 CTR line, by design.

The countermeasure is the same AI applied in the other direction: behavioral clustering models that treat a spike of correlated sub-threshold transfers across multiple chains as one suspicious event instead of thousands of invisible ones. The catch is timing. Cross-chain attribution can lag by weeks, and in that window the funds often finish consolidating and cashing out before a human ever reviews the alert.

Tip Line

Got any idea for something you'd want to see covered here? Doesn't have to fit neatly into a category. If you think it's interesting, we probably will too.

Send it to [email protected].

If someone forwarded this to you, welcome.

The AML Brief goes out every Tuesday. Subscribe for free and get the Top 10 AML Red Flags cheat sheet as a thank-you:

[BUTTON: Subscribe → theamlbrief.com]

Already subscribed? Forward this to one colleague who works in financial crimes. That's how we grow.

The AML Brief | theamlbrief.com

Disclaimer: The AML Brief is an independent financial crimes intelligence publication. All content is sourced from publicly available regulatory documents, enforcement actions, and published research. Nothing published here constitutes legal, compliance, or regulatory advice. The AML Brief is not affiliated with any financial institution, regulator, law firm, or employer. For advice specific to your situation, consult a qualified attorney or compliance professional.