Friday, September 11, 2026

How blockchain forensics disrupts crime-as-a-service

Global News
By Scorechain Team

Quick overview

Produced in association with SafeHorizon, the Horizon Europe project on detecting and disrupting crime-as-a-service, in which Scorechain is the blockchain-analytics partner.

Crime-as-a-service has turned cyber-enabled financial crime into a supply chain. Instead of one actor running an end-to-end scheme, specialists now rent out the parts: scam token deployment, laundering, phishing infrastructure, and exploit kits, many of them wired together by smart contracts on Ethereum and other EVM-compatible networks. For law enforcement, that industrialisation is a real problem. It is also the opening. The same programmable infrastructure that lets criminals scale their services records every deployment, call, and transfer on a public ledger, and blockchain forensics is how investigators turn that record into a map of the operation.

What is crime-as-a-service in crypto?

Crime-as-a-service (CaaS) is a model where criminal capabilities are packaged and sold to other offenders, often on a subscription or commission basis. In crypto, this includes laundering-as-a-service, scam token factories, ransomware affiliate programmes, and phishing kits that route stolen funds through smart contracts and cross-chain bridges. The buyer needs no technical skill; the seller runs reusable on-chain infrastructure that serves many campaigns at once.

That reuse is the investigative advantage. A service built to be used repeatedly leaves a repeated, machine-readable footprint. Where a one-off fraud might vanish behind a handful of wallets, a service leaves deployment patterns, shared contracts, and predictable fund flows that connect otherwise separate cases.

Why crime-as-a-service leaves an on-chain trail

Public blockchains are transparent by design. Every contract deployment, function call, token transfer, and bridge interaction is permanently recorded and openly queryable. When criminal services move on-chain to scale, they inherit that transparency, and the Financial Action Task Force (FATF) has been explicit about both sides of this trade-off.

In its targeted report on decentralised finance, published July 21, 2026, FATF found that the very features criminals exploit (permissionless access, automated smart contracts, cross-border reach, and transaction anonymity) are the same ones that expose their activity to analysis. The report documented sophisticated layering through chain-hopping, cross-chain bridges, decentralised exchanges, and mixers, and pointed to cases such as SafeMoon and Forsage, where operators retained hidden control over supposedly automated platform mechanics. It also recorded a stark supervision gap: 93% of the 143 responding jurisdictions had not yet implemented FATF standards for DeFi arrangements. For LEAs, that gap makes on-chain evidence more important, not less, because the regulatory perimeter is not yet doing the work.

How smart contract analysis maps criminal infrastructure

Smart contract analysis lets investigators move from single transactions to whole service ecosystems. Rather than tracing one wallet at a time, an analyst studies how contracts are built, deployed, and reused, then clusters the infrastructure that shows up across multiple campaigns.

The recurring building blocks of crime-as-a-service include:

  • Token factories that mass-produce scam or pump-and-dump tokens from a single reusable template.
  • Automated drain mechanisms in fraudulent DeFi protocols, coded to extract liquidity shortly after victims deposit.
  • Obfuscation and mixer-style contracts that pool and shuffle funds to break the link between source and destination.
  • Proxy and upgradeable patterns that hide ownership and let operators change a contract's behaviour after deployment.
  • Subscription-style access contracts that gate a paid illicit service, from laundering routing to phishing kits.

Because these components are deployed from shared factories and cloned from known templates, matching deployment patterns and contract structure lets investigators tie a new campaign back to an established operator, even when the surface wallets are brand new.

Behavioural signatures, not just addresses

Traditional tracing follows wallet-to-wallet flows. Contract-level analysis adds a higher layer: behaviour. Criminal services tend to repeat the same operational patterns because automation rewards repetition, and those patterns become signatures an analyst can search for.

Common signatures include repeated deployment from the same factory contract, time-based extraction where a drain function fires within minutes of a liquidity event, layered proxy structures that mask the controlling address, and automated interaction with a known set of high-risk protocols. Individual wallets in a service rotate constantly, but the underlying behaviour does not. Tracking the signature rather than the address is what lets LEAs stay with an operator across dozens of disposable wallets.

Tracing laundering-as-a-service across chains

Laundering-as-a-service is one of the most common crime-as-a-service models, and it is built to defeat simple heuristics. A typical flow splits proceeds into many shards, routes each through layered DeFi protocols, swaps assets across chains using bridges, and recombines the funds at destination wallets under new addresses.

Following that flow is a question of indirect exposure, the risk that reaches a wallet through intermediary hops rather than a direct transfer. This is where blockchain analytics does the heavy lifting: reconstructing the path across protocols and chains, attributing intermediary contracts to known services, and surfacing the connection between an inbound deposit and its laundered origin. FATF's 2026 report singled out chain-hopping and cross-chain bridges as the layering methods of choice, and recommended that jurisdictions concentrate supervision on the 20 largest DeFi protocols, which account for roughly 70% of activity. For investigators, that same concentration is a practical starting point: most laundering-as-a-service traffic passes through a manageable set of high-volume venues.

Early detection and proactive enforcement

The biggest shift contract analysis enables is timing. Instead of reconstructing a scheme after victims are hit, LEAs can flag emerging infrastructure as it appears. New crime-as-a-service operations tend to announce themselves on-chain: freshly deployed contracts funded from known high-risk sources, forks of malicious templates, and clusters of contracts sharing near-identical bytecode deployed in quick succession.

Spotting those signals early supports genuinely proactive enforcement. Investigators can monitor suspicious contract factories before they scale, identify a service provider before its customers cause harm, link separate cases through a shared template, and build intelligence on evolving typologies across DeFi and NFT ecosystems. The goal moves from chasing funds after the fact to disrupting the infrastructure that many crimes depend on.

Scorechain and SafeHorizon, disrupting crime-as-a-service together

Disrupting a service, rather than an individual, needs more than one organisation. It needs the people who regulate, the people who investigate, and the people who build analytical tools working from the same intelligence. That is the model behind SafeHorizon, a Horizon Europe research project built to detect and disrupt crime-as-a-service. SafeHorizon focuses on identifying and monitoring the cybercrime ecosystems and crime-as-a-service networks that operate across the web, deep web, and darknet, and it develops the technologies that help investigators uncover criminal infrastructure and emerging cyber threats before they scale. Formally titled "Innovations in Detecting and Disrupting Crime-as-a-Service Operations" (grant agreement 101168562), the project runs from September 2024 to August 2027 and brings together 12 partners across 11 European countries, coordinated by the Athena Research Center in Greece.

Scorechain supports the initiative as its blockchain-analytics partner, providing blockchain intelligence, transaction analysis, and investigation tools to trace cryptocurrency flows linked to cybercriminal activity. That is the on-chain layer described throughout this article: advanced graph analysis and entity clustering, behavioural risk indicators, and typology mapping that identify criminal infrastructure operating across multiple chains, services, and jurisdictions, built for institutional and law-enforcement environments. Turning fragmented on-chain activity into coordinated intelligence is what lets investigators move from reactive tracing to proactive disruption, the shift this whole approach is built around.

How Scorechain supports investigators

Scorechain gives compliance teams and investigators the tooling to turn this approach into casework. Rather than deep bytecode security auditing, Scorechain focuses on the intelligence layer that matters for financial-crime investigations: attribution, tracing, and exposure across the on-chain infrastructure behind a service.

Scorechain Investigator is the dedicated forensic investigation tool built for this work, and it is designed with law enforcement in mind. It takes an analyst from a single address to a complete, documented case, running on Scorechain's Digital Asset Intelligence graph. Investigator traces funds automatically across swaps, bridges, decentralised exchanges, and mixers on multiple blockchains, clusters addresses under a single controller, and matches them against a database of more than 939,000 labelled on-chain entities. Its visual fund-flow workspace lets an investigator map wallet-to-wallet movement and annotate it, while an auditable risk score, on a scale of 0 to 100 where a lower score signals higher risk, shows the reasoning behind every rating rather than hiding it in a black box. Built-in case management and formatted evidence export mean the same trace that follows stolen or extorted funds toward an off-ramp, where identity can be compelled, also produces a report an agency can submit.

Around Investigator, Flux Analysis visualises fund flows and surfaces indirect exposure across protocols and chains, Wallet Screening flags an address against the same labelled-entity database before funds move further, and the Blockchain Analytics API embeds that risk data into an agency's or institution's own systems. Coverage spans 25+ blockchains with a labelled-entity database that now includes 2,800+ VASP entries, giving investigators the cross-chain reach that laundering-as-a-service depends on. Scorechain works alongside the wider blockchain-analytics field, including providers such as Chainalysis, Elliptic, and TRM Labs, as European-native infrastructure, aligned with MiCA and AMLD6 and trusted by 350+ compliance and digital-asset teams.

Crime-as-a-service is a structural evolution in cybercrime, but it is a structured one, and structure leaves evidence. Combined with disciplined investigation, blockchain forensics turns that evidence into a map of criminal infrastructure rather than a pile of isolated events, and gives LEAs a way to disrupt the service, not just the symptom.

If your team is building out crypto investigation or AML capability, book a Scorechain demo to see fund-flow tracing, wallet screening, and cross-chain attribution applied to your own cases.

Frequently asked questions

What is crime-as-a-service in crypto?

Crime-as-a-service is a model where criminal capabilities (laundering, scam token deployment, ransomware affiliate programmes, and phishing kits) are packaged and sold to other offenders, often via subscription or commission. In crypto, these services rely on reusable smart contracts, mixers, and cross-chain bridges, which lets one operator serve many campaigns and leaves a repeated on-chain footprint investigators can trace.

How does smart contract analysis help investigators?

Smart contract analysis lets investigators cluster the reusable infrastructure behind a criminal service, token factories, drain mechanisms, and proxy contracts, rather than chasing one wallet at a time. By matching deployment patterns, contract structure, and behavioural signatures, an analyst can connect a new campaign to a known operator even when the surface wallets are fresh.

Can law enforcement trace crypto through mixers and bridges?

Yes, in many cases. Laundering-as-a-service splits funds across shards, layers them through DeFi protocols, and swaps assets across chains, but each hop is recorded on-chain. Blockchain analytics reconstructs the path, attributes intermediary contracts to known services, and measures indirect exposure, surfacing the link between a laundered deposit and its origin.

What is laundering-as-a-service?

Laundering-as-a-service is a crime-as-a-service model that offers money laundering as a paid, automated service. It typically shards proceeds, routes them through layered protocols and cross-chain bridges, and recombines them at destination wallets. FATF's July 2026 DeFi report identified chain-hopping and cross-chain bridges as the dominant layering techniques.

Which blockchains can be analysed for crime-as-a-service?

Crime-as-a-service most often runs on programmable, EVM-compatible networks such as Ethereum and BNB Smart Chain, because smart contracts enable the automation these services depend on. Scorechain provides coverage across 25+ blockchains, which matters because laundering-as-a-service deliberately moves value across chains to break tracing.

Share

Summarize with AI

Want to see how Scorechain can help you trace illicit crypto flows and strengthen compliance?

Be the first to get news from Scorechain

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

350+ COMPLIANCE &  DIGITAL ASSET TEAMS TRUST US