VPNs, Anonymization Technology, and Cryptocurrency: The Crime Anonymity Enables, and Why Legal Deterrence Struggles

The technology that protects a journalist's communications and the technology that protects a ransomware crew's identity are the same technology. Here's why that "same tool, different user" structure makes regulation so hard — grounded in real figures and real enforcement cases.

Starting Point: Anonymity as a Dual-Use Technology

VPNs, Tor, proxy chains, and cryptocurrency are often reported as "criminal tools," but that framing leaves out something important. These technologies are useful for crime for exactly the same reasons they are useful for legitimate privacy protection. No central controlling authority, resistance to surveillance, censorship resistance — these properties don't turn good or bad depending on the user. They are technically neutral in the specific sense that they do not distinguish who the user is.

Starting from that duality, this article covers, in order: (1) what anonymization technology actually protects, (2) how the same properties are operationally used as criminal infrastructure, (3) the statistically documented role cryptocurrency plays in the ransomware economy and money laundering, and (4) the structural reasons law enforcement can't keep pace. Wherever possible, the figures and cases cited here come from primary reporting — annual reports from firms like Chainalysis and Elliptic, announcements from the U.S. Department of Justice and Treasury, and published materials from national investigative agencies.

What Anonymization Technology Actually Protects

Before getting to criminal use, it's worth being concrete about the legitimate uses. This is more than a gesture toward balance — it's decisive for the policy argument in the second half.

Journalism and whistleblowing. SecureDrop, the whistleblower submission system built on the Tor network, is operated via .onion addresses by a long list of major news organizations, including the Associated Press, The Washington Post, The New York Times, ProPublica, The Guardian, and Der Spiegel. Some journalism simply cannot happen without a guarantee that a source's IP address won't be exposed to the subject of the story — or to the organization that employs that source. The Tor Project is backed by groups including the Electronic Frontier Foundation, and Reporters Without Borders has recommended Tor to journalists, sources, bloggers, and dissidents.

Circumventing censorship. In environments where specific platforms are blocked at the national level, Tor and VPNs are not a "privacy enhancement" — they are the means of recovering basic internet access at all.

Everyday defense for ordinary users. Encrypting traffic on public Wi-Fi, limiting behavioral tracking by ad networks, avoiding ISP collection of browsing history — these are genuine needs for the vast majority of users, with no connection to crime whatsoever.

Corporate security. Enterprise remote-access VPNs are the standard infrastructure for "getting into the internal network safely from outside" in the first place. Security researchers and incident response teams also routinely use anonymized routes when accessing malware distribution sites or attacker infrastructure under investigation, so as not to expose their own organization's IP addresses. Privacy technology is an operational necessity for defenders too.

The actual usage distribution bears this out: abuse is the minority. Analyses of the Tor network report that only a small share of daily users access onion services associated with malicious purposes, while the large majority are engaged in ordinary browsing. The equation "Tor = dark web = crime" does not accurately describe how the network is used.

How the Same Properties Become Criminal Infrastructure

Now to the main subject. Let's look at how the criminal side actually operates these technologies — as concrete mechanisms, not abstractions.

1. Hiding the location of C2 servers

Ransomware and other malware connect from the infected endpoint to a C2 (command and control) server to receive instructions, exchange encryption keys, and exfiltrate stolen data. From the perspective of defenders and investigators, the real IP address and hosting provider of that C2 server is the shortest path to seizing the attack infrastructure.

So attackers run their C2 as a Tor onion service (hidden service). Onion services are a mechanism by which a server becomes reachable without publishing its IP address at all — neither the client nor the server knows the other's real address. This is a feature designed to let a server be published anonymously, and as long as it works as designed, it makes pinpointing the physical location of a C2 dramatically harder. The same applies to the victim negotiation portals ransomware crews run, and to the "leak sites" where they publish stolen data — most of which sit on onion services.

2. Multi-hop proxies and "residential proxies"

To evade IP-based blocking and geographic detection, attackers chain multiple VPNs and proxies in series. But IP addresses originating from data centers have a weakness: defenders tend to flag them as suspicious. That's where demand for residential proxies comes from — IP addresses that appear to originate from ordinary home internet connections.

The question is where those "ordinary home IP addresses" are sourced from. The takedown of the 911 S5 botnet, announced by the U.S. Department of Justice in May 2024, is the defining case study. According to the published materials, 911 S5 rented out roughly 19 million compromised IP addresses across more than 190 countries as residential proxies. The named infection vectors were "free VPN apps" — ProxyGate, Mask VPN, and Dew VPN — and bundling with pirated software. In other words, the internet connections of users who thought they were protecting themselves with a free VPN were being resold, without their knowledge, as exit nodes for criminals.

In that case, a coordinated investigation across the United States, Singapore, Thailand, and Germany disrupted 23 domains and more than 70 servers, and seized assets valued at approximately $30 million. YunHe Wang, a Chinese national charged as the primary administrator, was arrested in Singapore on May 24, 2024; per the Justice Department's announcement, he received roughly $99 million from selling access to the proxied IP addresses. Authorities stated the infrastructure had been used for cyberattacks, financial fraud, identity theft, and bomb threats.

A practical warning: As 911 S5 demonstrates, "free VPN" apps can do worse than fail to protect your traffic — they can sell your connection itself as a product to third parties. A VPN is a technology that hands the exit point of your traffic entirely to its operator, which means a VPN whose operator and revenue model you cannot identify can be more dangerous than sending traffic unencrypted. That holds for individuals and organizations alike.

3. Dark web marketplaces: a history of takedowns, and of regrowth

Illegal marketplaces built on onion services are the most widely known form of criminal use of anonymization technology. Looking at the major takedowns in sequence reveals some structural features.

  • Silk Road (launched 2011, seized October 2013): The earliest large-scale darknet market, founded by Ross Ulbricht and accessible only via Tor. The FBI shut the site down and arrested Ulbricht in October 2013.
  • AlphaBay (seized July 2017): An operation the U.S. Department of Justice described as the largest dark web takedown in history. The FBI seized AlphaBay's servers in early July 2017 and announced it on July 20. According to authorities, AlphaBay was roughly ten times the size of Silk Road, with more than 40,000 vendors and over 200,000 users. The operation involved authorities in Thailand, Lithuania, Canada, the United Kingdom, and France.
  • Hydra Market (seized April 2022): The largest Russian-language marketplace, whose shutdown Germany's Federal Criminal Police Office (BKA) announced on April 5, 2022, following an investigation run jointly with U.S. authorities since August 2021. The published scale: over $5 billion in cumulative Bitcoin transactions, roughly 17 million customer accounts, and more than 19,000 seller accounts. About $25 million worth of Bitcoin was seized. The U.S. Treasury sanctioned the marketplace following the takedown.

What stands out is that successful takedowns don't make the market disappear. Successor markets proliferated after Silk Road's closure, and a site claiming to be a revived AlphaBay appeared years later. When the cost of rebuilding infrastructure is this low, crushing one node simply means another goes up as long as demand persists. That asymmetry is at the core of the structural problem discussed below.

Cryptocurrency's Role: The Numbers That Are Actually on the Record

For the scale of the ransomware economy, the tallies published by blockchain analytics firms are a relatively reliable starting point. Because on-chain payments are traceable (more on this below), this is a domain where — unusually for crime statistics — figures reasonably close to the real totals are publicly available.

According to Chainalysis's annual reports, total ransomware payments hit a record of roughly $1.25 billion in 2023, then fell to roughly $892 million in 2024 (initially reported at about $813 million and revised upward as additional payments were identified), and roughly $820 million in 2025 — about an 8% year-over-year decline.

The important point is that this decline in total payments does not mean a decline in attacks. Per Chainalysis's February 2026 publication, claimed ransomware victims rose sharply in 2025, while the share of ransom demands actually paid fell to an estimated all-time low of about 28%. At the same time, the median payment rose steeply, from $12,738 in 2024 to $59,556 in 2025. What the data describes, in other words, is a structural shift toward "more victims refusing to pay, and more extracted from the shrinking minority who do."

Chainalysis attributes the refusal side partly to increased law enforcement operations and sanctions. Concretely: Operation Cronos, led by the UK's National Crime Agency (NCA) with the FBI, Europol, and others, and announced on February 20, 2024, seized 34 servers belonging to the LockBit ransomware group across eight countries, closed 14,000 accounts, and froze 200 cryptocurrency accounts. The operation also secured LockBit's decryption keys, and the NCA, the FBI, and the Japanese police, with Europol's support, developed decryption tools from them. Chainalysis measured a 79% drop in payments to LockBit following the operation.

A common misconception: Bitcoin is not anonymous. Bitcoin is pseudonymous, not anonymous. Every transaction is recorded permanently on a public ledger that anyone can verify. Once an address is linked to a real identity even once, the flow of funds connected to that address becomes visible in retrospect.

This is not a theoretical point. In May 2021, after Colonial Pipeline paid roughly $4.4 million in Bitcoin to the ransomware group DarkSide, the FBI traced the movement of the funds and, in June of that year, announced the seizure of 63.7 bitcoin — worth approximately $2.3 million at the time. Separately, Roman Sterlingov, the operator of the decade-old Bitcoin mixer "Bitcoin Fog," was convicted in March 2024 on evidence that included blockchain analysis, and sentenced on November 8, 2024, to twelve and a half years in prison. Per the Justice Department, the service processed over 1.2 million bitcoin — approximately $400 million at the time of the transactions — across roughly a decade.

Victims don't need to give up on the assumption that "it's crypto, so it can't be traced" — and the attacker's converse assumption, that crypto leaves no trail, doesn't actually hold either.

Which Is Precisely Why Attackers Move to Privacy Coins

The flip side of the point above is a well-documented trend: the more technically sophisticated a ransomware operation is, the more clearly it treats Bitcoin's traceability as a concrete risk and migrates to privacy coins such as Monero. Monero is designed from the ground up to obscure sender, receiver, and amount, so its traceability assumptions differ fundamentally from Bitcoin's public-ledger model.

This preference is clear enough to be observable as a price. According to reporting, the ransomware group REvil — associated with the Russian-speaking cybercrime scene — restricted ransom payments to Monero, and where it accepted Bitcoin as an exception, it charged a 10% surcharge. That surcharge is the tracing risk of accepting Bitcoin, passed straight through to the price. Industry tallies at one point found that at least 22 of more than 50 tracked ransomware groups would accept nothing but Monero.

The point is that this contest is not static. Every time investigators score a win with blockchain analysis, attackers move to an asset class that is harder to trace. Neither "cryptocurrency is traceable" nor "cryptocurrency is untraceable" is correct without specifying which asset, and at what point in time.

Enforcement Against Mixers and Exchanges — and Its Limits

Mixers — services that sever funds from their traceable history — have been the most actively targeted area of enforcement in recent years.

  • ChipMixer (March 2023): Shut down on March 15, 2023, by German and U.S. authorities with support from Europol, Belgium, Poland, and Switzerland. Published estimates put its throughput at roughly 152,000 bitcoin (billions of dollars at then-prevailing rates). Four servers, about 7 TB of data, and roughly $46.5 million in Bitcoin were seized.
  • Blender.io / Sinbad.io: Mixing services designated by the U.S. Treasury's OFAC. Both were identified as laundering channels for North Korea-linked hacking groups and ransomware crews, and prosecutors subsequently indicted operators.
  • Samourai Wallet (April 2024): The U.S. Department of Justice charged the co-founders with operating an unlicensed money services business (MSB) and conspiracy to commit money laundering — a case that drew attention as one where developers of a wallet with mixing functionality were themselves held criminally liable.
  • Binance (November 2023): One of the world's largest exchanges settled with U.S. authorities on November 21, 2023, for more than $4.3 billion. It pleaded guilty to violations of the Bank Secrecy Act (BSA), operating an unlicensed money transmitting business, and sanctions violations under IEEPA. FinCEN's civil penalty was $3.4 billion plus a five-year monitorship; OFAC's penalty was $968 million. Then-CEO Changpeng Zhao also pleaded guilty personally, agreeing to a $50 million fine and to step down.

But the legal boundaries here are not settled. The emblematic case is Tornado Cash. OFAC designated the service on August 8, 2022 — but in November 2024, the U.S. Court of Appeals for the Fifth Circuit held that the immutable smart contracts comprising Tornado Cash could not be classified as "property" under IEEPA, because they lacked the hallmarks of ownership, control, and exclusivity. Following that decision, OFAC removed Tornado Cash from the SDN list on March 21, 2025.

Criminal liability for individual developers, however, continued to be pursued. On August 6, 2025, a federal jury convicted developer Roman Storm on one count of conspiracy to operate an unlicensed money transmitting business (18 U.S.C. §1960), while deadlocking on the two more serious counts (conspiracy to commit money laundering and conspiracy to violate sanctions). What this sequence shows is that the existing legal framework has no clear answer yet to the question "who is responsible for regulating code that nobody controls?"

Why Legal Deterrence Can't Keep Up — Three Structural Reasons

Rather than stopping at "enforcement is hard," let's break down what is hard, and why.

Reason 1: Jurisdictional arbitrage

Criminal infrastructure and operators sit in jurisdictions that will not prosecute them. This is not an accident; it is a deliberate choice.

One widely reported pattern: many ransomware groups based in the Russian-speaking world embed a hardcoded "do not install" list excluding CIS (Commonwealth of Independent States) countries in their malware. Multiple families, DarkSide among them, have been confirmed to abort infection when the endpoint's system language or keyboard layout is set to Russian, Ukrainian, Belarusian, and similar languages — to the point that "adding a Russian keyboard layout stops some malware from running" has circulated among security researchers as a half-joking but genuinely practical observation. Analyses of the REvil code used in the 2021 Kaseya incident likewise reported that it was written to avoid Russian-language environments.

The pattern of "tolerated as long as they don't attack domestically" has been noted repeatedly in both reporting and research. It's important to be careful here: this does not prove direct state direction or complicity. What can be stated with confidence are three observations: (a) many groups do implement exclusions that carve the CIS region out of their targeting, (b) there is no extradition treaty between the United States and Russia, and (c) as a result, Western law enforcement effectively cannot reach suspects located in those jurisdictions. Those three facts alone are enough to make criminal penalties nearly useless as deterrence, because raising the severity of a punishment produces no deterrent effect against an actor whose non-capture is structurally guaranteed.

Reason 2: The cost of blockchain forensics vs. the pace of obfuscation

Tracing is possible — but it is neither cheap nor fast. And the obfuscation side keeps evolving.

The dominant technique now is chain-hopping: rapidly moving assets back and forth between blockchains using decentralized exchanges (DEXs), cross-chain bridges, and no-KYC coin swap services. According to Elliptic's "State of Cross-Chain Crime" report (published 2025), funds laundered through these cross-chain routes have exceeded $21.8 billion cumulatively — close to a threefold increase over two years. The same report finds that 33% of complex cases span more than three blockchains, 27% more than five, and 20% more than ten. Roughly 12% of that estimate is attributed to North Korea-linked activity.

The decisive factor here is asymmetric cost. For the attacker, splitting funds across ten chains and hopping them through bridges is a few minutes of automated scripting. For the investigator, it means understanding each bridge's behavior, manually reconciling correspondences, and in some cases spending hours of tracing work on every branch — and then, to present it as legally admissible evidence, the tracing methodology itself has to be explainable and contestable in court. The cost of obfuscation is linear, while the cost of tracing scales with the number of branches. As long as that structure holds, the economic advantage stays with the attacker no matter how much analytics improve.

Reason 3: Infrastructure setup speed vs. international legal process speed

This is probably the most fundamental asymmetry of all.

For the attacker, standing up new anonymized infrastructure costs on the order of tens of dollars and a few minutes: rent bulletproof hosting payable anonymously in cryptocurrency, generate keys for a new onion service, buy a residential proxy subscription, done. When a large marketplace like Hydra is shut down, a successor appears as long as demand remains — a direct consequence of how low that barrier to entry is.

For investigators, moving across borders takes months to years. Seizing servers in another country requires requests under mutual legal assistance treaties (MLATs) or the construction of a joint investigation framework with local authorities, and even with a cooperative counterpart, it takes time. The Hydra takedown ran roughly eight months from the August 2021 start to the April 2022 announcement, and Operation Cronos and the AlphaBay seizure were both long-running operations involving authorities in many countries — which gives a sense of the weight of the process.

The result is a permanent condition in which the lifespan of attack infrastructure (days to months) is shorter than the time legal process takes (months to years). By the time law enforcement reaches a given piece of infrastructure, it may already have served its purpose and been abandoned. This mismatch of timescales is an institutional problem that no amount of individual investigator skill or budget can close.

The Hard Problem at the Intersection of Technology, Ethics, and Economics

Put all of this together and you arrive at an uncomfortable fact.

The technical properties that make anonymization technology and cryptocurrency valuable — no central controlling authority, resistance to surveillance, censorship resistance, permissionless participation — are not merely similar to the properties that enable criminal use. They are mechanically identical. A Tor onion service can hide the location of a whistleblower's server by exactly the same mechanism that hides the location of a ransomware C2. A blockchain lets you send money without a government freezing your account by exactly the same property that lets someone receive a ransom without it being frozen.

There is therefore essentially no design space for "stopping only the abuse." Examining the commonly proposed remedies through that lens:

  • Mandated backdoors or key escrow: There is no technical way to build a hole that only law enforcement can use. A hole that exists is also a target for attackers. And sophisticated criminals simply migrate to unregulated implementations or open-source builds — leaving the law-abiding majority as the only population actually complying with the mandate.
  • Banning anonymization technology outright: The journalism, whistleblowing, censorship-circumvention, and corporate security uses described above are lost wholesale. And enforcement of a ban is least effective precisely against the most technically sophisticated groups.
  • Relying on a single point of control: The Tornado Cash sanctions and the November 2024 appellate ruling showed that existing sanctions frameworks don't map cleanly onto "code with no administrator." Regulation that presumes a controlling entity doesn't engage with a system designed not to have one.

That said, the conclusion isn't that regulation is pointless either. The declining payment rate Chainalysis recorded, the 79% drop in payments to LockBit, the KYC regimes strengthened after Binance's $4.3 billion settlement — these show that it is genuinely possible to reduce the profitability of the criminal economy by applying pressure not to the anonymization technology itself, but to the points of contact with fiat currency (on-ramps and off-ramps) and to the businesses that offer these functions as a service. Criminals eventually have to turn funds into something spendable, and at that exit there are regulatable businesses.

That is this article's conclusion. This problem is not solved by a technical silver bullet or a legal one. What actually works in practice is not banning the technology, but targeting the cash-out exits and points of concentration in the criminal economy — and building enough defensive and recovery capability on the victim side that refusing to pay is a real option. Since the "same tool, different user" structure cannot be dissolved, the only thing we get to choose is where, within that structure, to spend our effort.

And that perspective has a practical implication for defenders. The statistic that payment rates are hitting record lows means, read the other way, that organizations with functioning backup, detection, and recovery capabilities are in fact able to choose not to pay. You may not be able to stop a flow of funds you can't trace, but you can put yourself in a position where you never needed to pay in the first place. Given the limits of law enforcement, that is the most reliable deterrent available.

Summary

  • The properties that make VPNs, Tor, and cryptocurrency useful for crime are technically identical to the ones that make them useful for legitimate privacy protection
  • Tor is widely used in real journalism (SecureDrop), whistleblowing, censorship circumvention, and corporate security; the large majority of its use is not abuse
  • Criminals hide C2 servers and leak sites behind Tor onion services, and evade IP tracing with multi-hop proxies and residential proxies
  • The 911 S5 botnet (taken down May 2024, ~19 million IPs) is a documented case of ordinary users' connections being resold as criminal proxies via "free VPN" apps
  • Chainalysis totals for ransomware payments: ~$1.25B in 2023 → ~$892M in 2024 → ~$820M in 2025. Attacks rose while the payment rate fell to a record-low ~28%
  • Bitcoin is pseudonymous, not anonymous — the 63.7 BTC seizure in the Colonial Pipeline case and the Bitcoin Fog operator's conviction are real instances of tracing and recovery
  • Because of that traceability, sophisticated groups such as REvil preferred Monero and charged a surcharge for Bitcoin payments
  • Legal deterrence lags for three structural reasons: (1) basing operations in jurisdictions without extradition treaties, (2) the cost asymmetry between obfuscation like chain-hopping and tracing, and (3) the gap between infrastructure setup speed and international legal process speed
  • Backdoors and outright bans damage the privacy of the law-abiding majority while failing against technically sophisticated criminals
  • What actually works is regulating the cash-out exits (exchanges, mixers) and building the defensive and recovery posture that lets victims choose not to pay

Start by Checking the State of Your Own Network

Tracing attack infrastructure is law enforcement's job — closing off the entry points is yours. This article walks through the concrete steps for checking your home or office network for vulnerabilities.

Read How to Check Your Home Network for Vulnerabilities