Crime-as-a-service has turned cyber-enabled financial crime into a supply chain. Instead of one actor running an end-to-end scheme, specialists now rent out the parts: scam token deployment, laundering, phishing infrastructure, and exploit kits, many of them wired together by smart contracts on Ethereum and other EVM-compatible networks. For law enforcement, that industrialisation is a real problem. It is also the opening. The same programmable infrastructure that lets criminals scale their services records every deployment, call, and transfer on a public ledger, and blockchain forensics is how investigators turn that record into a map of the operation.
Crime-as-a-service (CaaS) is a model where criminal capabilities are packaged and sold to other offenders, often on a subscription or commission basis. In crypto, this includes laundering-as-a-service, scam token factories, ransomware affiliate programmes, and phishing kits that route stolen funds through smart contracts and cross-chain bridges. The buyer needs no technical skill; the seller runs reusable on-chain infrastructure that serves many campaigns at once.
That reuse is the investigative advantage. A service built to be used repeatedly leaves a repeated, machine-readable footprint. Where a one-off fraud might vanish behind a handful of wallets, a service leaves deployment patterns, shared contracts, and predictable fund flows that connect otherwise separate cases.
Public blockchains are transparent by design. Every contract deployment, function call, token transfer, and bridge interaction is permanently recorded and openly queryable. When criminal services move on-chain to scale, they inherit that transparency, and the Financial Action Task Force (FATF) has been explicit about both sides of this trade-off.
In its targeted report on decentralised finance, published July 21, 2026, FATF found that the features criminals exploit — permissionless access, automated smart contracts, cross-border reach, and transaction anonymity — are the same features that expose their activity to analysis. The report documented sophisticated layering through chain-hopping, cross-chain bridges, decentralised exchanges, and mixers, and pointed to cases such as SafeMoon and Forsage, where operators retained hidden control over supposedly automated platform mechanics. It also recorded a stark supervision gap: 93% of the 143 responding jurisdictions had not yet implemented FATF standards for DeFi arrangements. For LEAs, that gap makes on-chain evidence more important, not less, because the regulatory perimeter is not yet doing the work.
Smart contract analysis lets investigators move from single transactions to whole service ecosystems. Rather than tracing one wallet at a time, an analyst studies how contracts are built, deployed, and reused, then clusters the infrastructure that shows up across multiple campaigns.
The recurring building blocks of crime-as-a-service include:
Because these components are deployed from shared factories and cloned from known templates, matching deployment patterns and contract structure lets investigators tie a new campaign back to an established operator, even when the surface wallets are brand new.
Traditional tracing follows wallet-to-wallet flows. Contract-level analysis adds a higher layer: behaviour. Criminal services tend to repeat the same operational patterns because automation rewards repetition, and those patterns become signatures an analyst can search for.
Common signatures include repeated deployment from the same factory contract, time-based extraction where a drain function fires within minutes of a liquidity event, layered proxy structures that mask the controlling address, and automated interaction with a known set of high-risk protocols. Individual wallets in a service rotate constantly, but the underlying behaviour does not. Tracking the signature rather than the address is what lets LEAs stay with an operator across dozens of disposable wallets.
Laundering-as-a-service is one of the most common crime-as-a-service models, and it is built to defeat simple heuristics. A typical flow splits proceeds into many shards, routes each through layered DeFi protocols, swaps assets across chains using bridges, and recombines the funds at destination wallets under new addresses.
Following that flow is a question of indirect exposure — the risk that reaches a wallet through intermediary hops rather than a direct transfer. This is where blockchain analytics does the heavy lifting: reconstructing the path across protocols and chains, attributing intermediary contracts to known services, and surfacing the connection between an inbound deposit and its laundered origin. FATF's 2026 report singled out chain-hopping and cross-chain bridges as the layering methods of choice, and recommended that jurisdictions concentrate supervision on the 20 largest DeFi protocols, which account for roughly 70% of activity. For investigators, that same concentration is a practical starting point: most laundering-as-a-service traffic passes through a manageable set of high-volume venues.
The biggest shift contract analysis enables is timing. Instead of reconstructing a scheme after victims are hit, LEAs can flag emerging infrastructure as it appears. New crime-as-a-service operations tend to announce themselves on-chain: freshly deployed contracts funded from known high-risk sources, forks of malicious templates, and clusters of contracts sharing near-identical bytecode deployed in quick succession.
Spotting those signals early supports genuinely proactive enforcement. Investigators can monitor suspicious contract factories before they scale, identify a service provider before its customers cause harm, link separate cases through a shared template, and build intelligence on evolving typologies across DeFi and NFT ecosystems. The goal moves from chasing funds after the fact to disrupting the infrastructure that many crimes depend on.
Scorechain gives compliance teams and investigators the tooling to turn this approach into casework. Rather than deep bytecode security auditing, Scorechain focuses on the intelligence layer that matters for financial-crime investigations: attribution, tracing, and exposure across the on-chain infrastructure behind a service.
Flux Analysis visualises fund flows and surfaces indirect exposure across protocols and chains, so an analyst can follow shards through bridges and mixers and see where they recombine. Wallet Screening assesses an address against a labelled-entity database and returns a risk score, on a scale of 0 to 100 where a lower score signals higher risk, so a wallet tied to a designated entity or a high-risk service is flagged before funds move further. The Blockchain Analytics API embeds that same risk data into an agency's or institution's own monitoring systems, and Scorechain's Recovery and Investigation support helps trace complex flows in active cases. Coverage spans 25+ blockchains with a labelled-entity database that includes 2,700+ VASP entries, giving investigators the cross-chain reach that laundering-as-a-service depends on.
Crime-as-a-service is a structural evolution in cybercrime, but it is a structured one, and structure leaves evidence. Combined with disciplined investigation, blockchain forensics turns that evidence into a map of criminal infrastructure rather than a pile of isolated events, and gives LEAs a way to disrupt the service, not just the symptom.
If your team is building out crypto investigation or AML capability, book a Scorechain demo to see fund-flow tracing, wallet screening, and cross-chain attribution applied to your own cases.
Crime-as-a-service is a model where criminal capabilities — laundering, scam token deployment, ransomware affiliate programmes, and phishing kits — are packaged and sold to other offenders, often via subscription or commission. In crypto, these services rely on reusable smart contracts, mixers, and cross-chain bridges, which lets one operator serve many campaigns and leaves a repeated on-chain footprint investigators can trace.
Smart contract analysis lets investigators cluster the reusable infrastructure behind a criminal service — token factories, drain mechanisms, and proxy contracts — rather than chasing one wallet at a time. By matching deployment patterns, contract structure, and behavioural signatures, an analyst can connect a new campaign to a known operator even when the surface wallets are fresh.
Yes, in many cases. Laundering-as-a-service splits funds across shards, layers them through DeFi protocols, and swaps assets across chains, but each hop is recorded on-chain. Blockchain analytics reconstructs the path, attributes intermediary contracts to known services, and measures indirect exposure, surfacing the link between a laundered deposit and its origin.
Laundering-as-a-service is a crime-as-a-service model that offers money laundering as a paid, automated service. It typically shards proceeds, routes them through layered protocols and cross-chain bridges, and recombines them at destination wallets. FATF's July 2026 DeFi report identified chain-hopping and cross-chain bridges as the dominant layering techniques.
Crime-as-a-service most often runs on programmable, EVM-compatible networks such as Ethereum and BNB Smart Chain, because smart contracts enable the automation these services depend on. Scorechain provides coverage across 25+ blockchains, which matters because laundering-as-a-service deliberately moves value across chains to break tracing.































