Chinese-language money laundering networks (CMLNs) have begun openly marketing their financial services to operators in five sub-Saharan African countries, according to data from blockchain analytics firm Chainalysis, marking a significant geographical expansion of the underground crypto economy.
The advertisements, shared on encrypted messaging app Telegram, explicitly target Angola, Kenya, Mozambique, Madagascar, and Guinea-Bissau. Vendors offer services ranging from bulk stablecoin trading to “money movement” and “over-the-counter” conversions that bypass Know Your Customer (KYC) compliance checks. The marketing materials, reproduced in Chainalysis’s 2026 Crypto Crime Report, advertise “direct from the source” supply, stable volumes, and rock-bottom exchange rates, indicating the establishment of illicit financial corridors in the region.
This expansion comes as the broader CMLN ecosystem processes an estimated $44m a day. In 2025, these networks handled roughly $16.14bn in inflows, an increase of more than 160 per cent year-on-year, and now account for approximately 20 per cent of attributed global on-chain money laundering. Notably, inflows to these networks grew 7,325 times faster than those to mainstream centralised exchanges between 2020 and 2025, according to the report.
Capital controls fuel underground liquidity
The rapid scaling of these networks is closely associated with China’s domestic capital controls. Tom Keatinge, director at the Centre for Finance & Security at RUSI, told Chainalysis that wealthy individuals seeking to move money out of China and evade controls provide the impetus and liquidity pool needed to service transnational organised crime groups.
Chris Urben, managing director at Nardello & Co, noted that cryptocurrency offers a more efficient mechanism for moving funds than traditional informal value transfer systems. “Crypto offers an efficient way to discreetly move funds across borders without having to rely on the complex manual network of informal ledgers in various countries that used to be the norm,” he said.
Operational mechanics and service typologies
The report categorises CMLN vendors into six primary service typologies. Running point brokers serve as the initial entry channel, recruiting individuals to provide their bank accounts and digital wallets for forwarding fraudulent proceeds. Money mules, often described by vendors as “motorcades”, orchestrate the layering phase through multi-account networks, using offline cash conversion, ATM withdrawals, and third-party payment platforms.
Informal over-the-counter (OTC) desks function as another critical pathway, offering peer-to-peer conversions with no regulatory oversight. These services advertise “clean funds”, or “White U”, at premiums above market rates, though on-chain analysis frequently indicates that these supposedly legitimate funds are connected to confirmed money laundering services.
Conversely, “Black U” services occupy a niche market for cryptocurrency derived explicitly from hacks, exploits, and theft. These assets are sold at a 10–20 per cent discount to market rates, reflecting the regulatory and seizure risks assumed by buyers. The report notes that Black U services reach the $1bn cumulative inflow milestone in just 236 days.
All transactions are facilitated through guarantee platforms — centralised marketplaces that function as escrow and marketing infrastructure. While the Huione Group’s operations were disrupted following a Financial Crimes Enforcement Network (FinCEN) designation in October 2025, vendors have migrated to alternative platforms. The ecosystem remains resilient, with service ratings and reviews creating an informal market reputation mechanism.
Physical attacks and the 2026 mid-year update
The 2026 Mid-Year Crypto Crime Report, released in August, highlights a troubling convergence between this digital infrastructure and physical criminal activity. With cryptocurrency adoption accelerating across sub-Saharan Africa and South Africa identified as a mature regional market, violent “wrench attacks” — home invasions and kidnappings targeting individuals known to hold crypto assets — are escalating.
Chainalysis estimates that approximately $30m has been forcibly stolen through physical means in the first half of 2026. Home invasions now account for 37 per cent of documented incidents, up from 14 per cent in 2025, while kidnappings represent 52 per cent. Attackers are increasingly using family members and acquaintances as leverage, a tactic accounting for 25–30 per cent of global cases.
On-chain analysis of the fund flows reveals three distinct threat profiles. At the high end of the sophistication spectrum — labelled Type 3 — attackers are embedded within broader criminal networks and utilise complex laundering infrastructure, including bridges and decentralised exchanges, alongside CMLN services to obfuscate and liquidate stolen assets.
Regulatory and data security warnings
The report contains a cautionary precedent for sub-Saharan African regulators. France has become the leading hotspot for family-targeted extortion, with over 40 per cent of local cases involving relatives, following a data breach at the French tax agency that exposed the identities of domestic crypto holders. As South Africa and other regional nations develop crypto tax frameworks and KYC requirements, the report emphasises that the collection of sensitive holder data must be paired with rigorous data security to prevent those datasets from becoming target lists for criminal enterprises.
Despite the increase in violent attempts, attacker success rates have fallen from 67 per cent in 2024 to 26 per cent in the first half of 2026, according to the mid-year data. The decline is attributed to improved incident response and the traceability of blockchain transactions, which provides law enforcement with a digital trail even when the initial crime is physical.
The combination of industrial-scale CMLN advertising in five African nations and the rise of organised physical theft targeting the region’s maturing crypto markets presents a complex threat landscape. Addressing it will require cross-border enforcement collaboration and stringent data protection measures, rather than reliance on the financial sector’s traditional compliance mechanisms alone.

