A hand connecting an Ethernet cable to a server
Crypto

DOJ says Hamas-linked crypto seizures topped $560K as FBI took over Alqassam.ps

The department says the infrastructure seizure let agents intercept donations and collect data on thousands of would-be donors.

By Marcus Hale4 min read

The U.S. Justice Department says it seized more than $560,000 in cryptocurrency intended for Hamas through targeted crypto warrants issued in 2025. The DOJ also says the FBI took control of Alqassam.ps and related infrastructure to intercept donations and identify would-be donors, expanding the playbook beyond on-chain seizures.

DOJ Puts a Number on Hamas-Linked Crypto Seizures as FBI Takes Over Alqassam.ps

The U.S. Justice Department aggregated Hamas-linked crypto seizures at more than $560,000 and paired that figure with a second, more operational claim: the FBI took control of domains and servers tied to Hamas-linked fundraising and recruitment, including the Alqassam.ps website. The stated goal was not only to seize funds, but to intercept additional donations and prevent further fundraising for Hamas’ military wing, the Al-Qassam Brigades.

The DOJ released five affidavits alongside the announcement. Three affidavits dated March 25, June 25, and Oct. 10, 2025 describe crypto warrants that the department says account for the $560,000-plus total. Two affidavits dated July 29 and Aug. 18, 2026 cover the infrastructure seizures, which the DOJ says enabled the FBI to take over the web surface area donors were being routed through.

The department also said the operation produced information on thousands of people who contacted Hamas-linked platforms seeking to donate through crypto or traditional payment methods. That detail matters because it frames the infrastructure action as an intelligence collection event, not just a disruption event.

Inside the Takedown: 2025 Crypto Warrants, 2026 Infrastructure Seizures, and Rotating Addresses

The mechanics in the court documents point to a two-track approach. Track one is financial: court-authorized crypto warrants used to seize or obtain control of cryptocurrency held in specific wallets or accounts, including through service providers. Track two is distribution: domain and server seizures that let law enforcement take control of a website’s domain name and hosting infrastructure to shut it down, monitor it, or redirect traffic.

The DOJ’s timeline implies the crypto side was meaningful but incomplete. The department said the first of the actions recovered about $201,400 from wallets and accounts linked to a system that had moved more than $1.5 million since October 2024. Partial recovery is the point. It reads like disruption of a channel, not a clean shutdown of the broader network described in the filings.

Investigators also described a fundraising tactic designed to resist static labeling: rotating crypto addresses. The DOJ said human sources were used to identify and trace rotating addresses promoted through an encrypted group chat and a fundraising website. That is a direct admission that address churn is expected, and that attribution is being built from human intelligence plus tracing rather than from a single “bad wallet” tag that stays relevant for months.

The DOJ said the addresses were allegedly controlled on behalf of the Al-Qassam Brigades. The packet provides no independent verification of that allegation and no response from any defendant or operator tied to the infrastructure.

Compliance Spillover: What This Means for Screening, Blacklists, and Payment Rails

For exchanges, payment processors, and on-chain compliance teams, the signal is the enforcement sequencing. The DOJ is presenting crypto-terror-finance disruption as a multi-pronged operation: seize funds via 2025 warrants, then neutralize fundraising capacity by taking over web infrastructure in 2026.

The immediate friction is specificity. The excerpt does not identify which blockchains or assets were seized, which wallet addresses were involved, or which service providers received warrants. That missing detail is often what turns a law enforcement action into new screening rules, address labels, and deposit or withdrawal controls.

The second-order risk sits in the infrastructure layer. By saying the FBI takeover yielded information on thousands of would-be donors, including those attempting traditional payment methods, the DOJ is signaling that domain and server seizures can generate intelligence beyond on-chain flows. That can widen the compliance blast radius to platforms that touch the donation funnel, even if they never custody the seized assets.

Watch for follow-on filings that name chains, assets, wallet clusters, or service providers tied to the $560,000-plus figure. Separately, any OFAC or FinCEN action that references the same infrastructure or address clusters would likely accelerate exchange risk controls. More domain or server seizures beyond Alqassam.ps would indicate the campaign is expanding rather than concluding, and compliance updates that explicitly cite rotating donation addresses promoted via encrypted chats would confirm the typology is being operationalized into controls.

My Read: This Case Is About Control Points, Not Just Wallets

The threshold that matters is whether the affidavits eventually pin the $560,000-plus to specific rails: chain, asset, and service-provider touchpoints. Without that, the market impact stays diffuse, and the compliance response remains mostly narrative.

What stands out is the infrastructure seizure. If the FBI can sit on the donation front door and collect “attempt” data at scale, the enforcement edge shifts from chasing rotating addresses to controlling the routing layer that creates them, and that is what turns a seizure headline into durable counterparty risk for crypto payment rails.

Sources