The U.S. Department of Justice announced a court-authorized FBI operation that seized more than $560,000 in cryptocurrency allegedly intended for Hamas's al-Qassam Brigades. Authorities also took domains and servers allegedly used to solicit crypto donations and recruit or communicate with supporters, following investigations spanning March 2025 through August 2026.
Investigators traced funds through donation and consolidation wallets, cross-chain bridges, over-the-counter brokers, exchanges, and money-mule-like accounts. Although the network reportedly shifted to single-use donation wallets and bridging services after prior seizures, recurring gas-funding wallets helped link its infrastructure; the FBI also obtained information on thousands of people who allegedly contacted Hamas online, supporting continuing counterterrorism investigations.

See the reporting duties and controls this puts on the clock.
5 events from the most recent confirmed update back to the earliest known activity.
The Department of Justice announced that the FBI had seized more than $560,000 in cryptocurrency allegedly connected to Hamas fundraising campaigns and disrupted associated websites and communications channels. The announcement consolidated five related actions conducted from March 2025 through August 2026.
The FBI conducted a further court-authorized cryptocurrency seizure tied to Hamas fundraising. An October affidavit reported that Hamas had adopted cross-chain bridging services and single-use donation wallets after the earlier seizure, while investigators traced funds and froze certain assets.
Federal investigators used human-source information to identify, trace, and seize additional cryptocurrency allegedly intended for Hamas's al-Qassam Brigades. A June affidavit said blockchain analysis had traced donations through further addresses and accounts used to consolidate and move funds.
In the initial case, the FBI seized approximately $200,000 in stablecoins allegedly donated to Hamas after tracing funds from donation addresses through an operational wallet. Investigators also identified recurring gas-funding infrastructure linked to numerous al-Qassam Brigades-controlled addresses.
U.S. authorities targeted and seized domains and servers allegedly used by the al-Qassam Brigades to solicit cryptocurrency donations and communicate with supporters. Control of the infrastructure enabled the FBI to intercept intended donations and gather information on attempted contributors.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.