Key takeaways
- USDT on TRON is, per the UN's own assessment, the preferred laundering rail for Southeast-Asian fraud syndicates — so most real TRON casework is reading a money-flow rather than a single wallet.
- The flows have recognizable shapes: victim → collector → burner-chain layering → cash-out through a nested exchange, an OTC "motorcade," or a guarantee marketplace.
- This kind of origin tracing carries no scam, sanctioned, or illicit category — from the chain alone, an unlabeled counterparty is just an unlabeled personal wallet. It reports the shape of a flow; it does not judge the criminality of who is on the other end.
- One-hop attribution names the nearest burner, not the compound behind it. On a laundering chain, automated tracing narrows the field — the investigator walks the rest.
Most of the wallets a TRON investigator actually opens are not somebody’s personal savings. They are a node in a money-laundering pipeline — a victim’s drained account, a collector wallet, a burner in a layering chain, the deposit address of a service that cashes criminal proceeds into fiat. The United Nations Office on Drugs and Crime put it plainly in its 2024 assessment of the region: Tether “on the TRON (TRX) blockchain represent[s] the preferred choice for Asian crime syndicates engaged in cyber-enabled fraud and money laundering operations.” By TRM Labs’ 2025 measurement, 58% of the illicit crypto volume TRM Labs tracked in 2024 moved through TRON — the largest share of any chain in its analysis, up from ~45% in 2023.
Reading those wallets is less about a single origin and more about recognizing where a wallet sits in a flow. This chapter covers the recurring criminal money-flow shapes on TRON’s stablecoin rails, the counterparty types they run through, and — the part that matters most — the hard line between what on-chain tracing can show and what it cannot. It builds on the obfuscation mechanics in When the Trail Goes Cold and the institutional-attribution ceiling in Reading Exchange Deposit Addresses; here the subject is the criminal shape of the flow and the counterparties on the other end.
The shape of a scam cash-out
The dominant fraud on these rails is the investment scam — “pig butchering,” named, as FinCEN’s 2023 alert puts it, because the schemes “resemble the practice of fattening a hog before slaughter.” The on-chain flow is consistent. A victim is coaxed onto a fake investment platform; the platform is a skin over a wallet the scammer controls, and, in FinCEN’s words, “the funds are funneled to virtual currency addresses and accounts controlled by scammers and their co-conspirators.” From that first collector address the money moves fast: in one seized-domain case FinCEN documented, victim funds “were immediately transferred through numerous private wallets and swapping services in an effort to conceal the source of the funds,” totalling over $10 million.
Two of FinCEN’s red flags are visible from the chain rather than the bank. One is the refund-plus bait: a wallet receives a small deposit at or slightly above an amount it previously sent out, then follows it with much larger outbound transfers — the scammer returning a token “profit” to earn a bigger deposit. The other names TRON directly: proceeds received as a costlier asset are “convert[ed] to a virtual currency with lower transaction fees such as TRX” before being moved off an exchange. The cheap-rail hop into TRON/USDT is a deliberate laundering step.
So the four-stage pipeline an investigator learns to see is: victim → collector → burner-chain layering → cash-out. The first three stages leave the fan-in-then-disperse shape above. The fourth stage — turning stablecoin into spendable money — is where the distinctive counterparties live.
The cash-out counterparties
Three counterparty types dominate the off-ramp, and each has a recognizable role.
Nested exchanges. A nested service, as Chainalysis defines it, “operates using addresses hosted by larger exchanges in order to tap into those exchanges’ liquidity and trading pairs.” That nesting is exactly what makes it launder well: its deposits look like ordinary deposits at the parent exchange. The U.S. Treasury used the term in a sanctions action — Chatex “using Suex’s function as a nested exchange to conduct transactions,” with “over half” of Chatex’s known transactions traced to illicit activity. Suex, sanctioned in September 2021, was the first crypto exchange the U.S. ever designated.
Motorcade mule fleets. The fiat leg often runs through what the UNODC calls “motorcades” (车队) — organized fleets of mule bank and exchange accounts that offer “sophisticated layering schemes by routing money through multiple bank or cryptocurrency exchange accounts for a percentage,” commonly advertising “commission fees of between 20 to 40 per cent.” One Vietnamese cell disrupted in August 2024 had procured hundreds of local bank accounts and turned over more than 1.1 billion USDT in six months for Cambodia-based fraud groups.
Guarantee marketplaces. The largest cash-out venue of the era was Cambodia-based Huione Group, which FinCEN found in 2025 to be “of primary money laundering concern,” having “received at least USD 4 billion worth of illicit proceeds” between August 2021 and January 2025. Its Telegram marketplace, Haowang Guarantee, acted as escrow for merchants selling laundering services — a merchant would, per Elliptic, “agree to handle $2 million originating from fraud, in return for a fee of 10.5%.” FinCEN called Huione “a ‘one stop shop’ for criminals to launder CVC,” describing the flow verbatim: illicit funds in, then “converted to fiat currency or different CVC, or withdrawn at a later point to move to a different VASP.”
The lifecycle of that last one carries the real lesson. Haowang was forced offline by Telegram bans in May 2025 after taking in more than $31 billion lifetime; its merchants migrated in real time to a successor, Tudou Guarantee (part-owned by Huione), and in June 2026 the Justice Department — working with the FBI under its Operation Riptide campaign — seized the cloud account hosting Huione’s backend infrastructure. Takedowns displace the trade; they do not end it. Learn the shape — an escrow-guaranteed marketplace settling almost entirely in USDT — because the brand will have changed by the time you read this.
What on-chain tracing can show — and the shapes it can’t
Here the honesty has to be exact, because it is easy to expect more of an origin-tracing tool than it delivers against organized crime.
These laundering shapes leave recognizable on-chain signatures. A distribution wallet that has sent to more than 500 recipients across more than 1,000 transactions is a distribution point, not an owner — infrastructure. When a bridge, exchange, or mass-distribution wallet is the nearest funding source for a wallet, an analyst has to look one hop past it to the party behind it: the intermediary is a funds source, not the end-user. Mixer contact, circular self-funding loops, and high-frequency transaction bursts are all shapes that recur in laundering flows. These are covered in their own chapters; the composition — which combination of signals means you are standing next to a criminal flow — is the investigator’s read.
But the limits are structural, and they define the tool’s role:
- There is no illicit taxonomy. No scam, sanctioned, or illicit classification falls out of the funding graph itself. Classifying counterparties can identify infrastructure — exchanges, DEX routers, mixers, smart contracts, faucets, bridges, and services — but from an address’s funding behavior alone, a Huione merchant deposit address, an OTC broker, or a scam collector is just an unlabeled personal wallet, and can even read as a wallet’s origin. Origin tracing of this kind is not sanctions-screening or transaction-monitoring. It tells you the shape of a flow, never the criminality of the counterparty in it.
- Mass-distribution detection reads fan-out, not fan-in. It is tuned for a sprayer — many recipients out. A scam collector is the opposite direction, many victims in, and that logic does not describe it. The tool recognizes the payroll side of a scam operation rather than the victim-collection side.
- The trail resolves one hop. Proximate-funding attribution names the most immediate funding source, which may itself be an intermediate — a laundering chain deeper than one hop is not resolved by it. A pig-butchering pipeline is three or more hops deep by design, so this kind of read names the nearest burner — not the compound behind it.
- A nested exchange is invisible as such. Its deposits sit inside a labelled parent exchange, so a one-hop look-through attributes to the exchange as an institution — and, as the deposit-address chapter establishes, you can say “this is a Binance deposit address” but never whose.
Reading it as an investigator
With no criminality labels to lean on, the read is a shape read, and three properties do most of the discriminating: direction, fan pattern, and dwell time. A collector shows many small deposits in and fast dispersal out. A cash-out counterparty shows consolidated large deposits in and exchange-bound transfers out. A service wallet — a guarantee-market merchant, an OTC desk — shows escrow-like bidirectional churn. None of these is a label the chain hands you; each is a pattern the investigator matches by hand, reading the direction, fan, and dwell-time signals the flow provides.
The honest posture is the same one any responsible trace takes: on-chain origin tracing can narrow a field, flag a mixer, look through a bridge, and signal how much to trust a result — one tool, TRONORIGIN, does exactly this. What it cannot do is the part that would actually convict anyone. A Huione merchant’s deposit address and a stranger’s personal savings wallet produce the identical shape on a ledger that was never built to tell them apart — the same fan pattern, the same dwell time, the same silence about who is on the other end. Closing that gap takes a name matched to a face, a subpoena, a source on the ground in Sihanoukville. None of it lives on the chain.
Sources
- FinCEN — Alert on “Pig Butchering” Investment Scams (FIN-2023-Alert005, Sept 2023) — the scam-flow mechanism (funds funneled to scammer-controlled addresses; immediate dispersal), the refund-plus and convert-to-TRX red flags, and TRX/USDT named among the currencies used.
- UNODC — Transnational Organized Crime and the Convergence of Cyber-Enabled Fraud (Oct 2024) (Wayback Machine capture, May 5, 2026) — USDT-on-TRON as the syndicates’ preferred rail, the “motorcade” (车队) mule-fleet and underground-banking vocabulary, and (footnote 52, citing a Tay Ninh Provincial Police media release) the August 2024 Tây Ninh cell case — hundreds of procured bank accounts moving over 1.1 billion USDT for Cambodia-based fraud groups between Nov 2023 and May 2024. A multilateral source (note it summarizes law-enforcement and vendor analytics). Cited from the archive because the live unodc.org URL now fails to load (confirmed via direct browser fetch); content verified against the archived PDF directly, not just its abstract.
- TRM Labs — The Illicit Crypto Economy 2023 (Mar 2024) — the ~45%/2023 illicit-share figure (“approximately 45% of crypto illicit volume occurred on the TRON (TRX) blockchain, up from 41% in 2022”), traced to its origin rather than the UNODC report above, which cites this same TRM figure secondhand in its own footnote. (Vendor; also a TRON T3 partner — double commercial interest.)
- FinCEN — Finding on Huione Group (NPRM, 90 FR 18934, May 2025; final rule 90 FR 48295, effective Nov 2025) — the $4B+ illicit-proceeds finding, the “one stop shop” cash-out description, and the Haowang Guarantee marketplace.
- U.S. Treasury — Suex designation (Sept 2021) — the first-ever U.S. sanctions action against a crypto exchange.
- U.S. Treasury — Chatex designation (Nov 2021) — “nested exchange” used in an official sanctions action against a Suex successor, with “over half” of Chatex traffic traced to illicit activity.
- Elliptic — Huione Guarantee: the multi-billion-dollar scam marketplace (Jul 2024) — the escrow-guarantee model (a merchant “agree[ing] to handle $2 million originating from fraud, in return for a fee of 10.5%”) and USDT settlement. (Vendor research; Elliptic sells the forensics it reports on.)
- Elliptic — Behind the FBI case against Huione: the $134 billion marketplace and money laundering operation exposed by Elliptic (Jun 2026) — the “more than $31 billion” lifetime transaction total for Haowang/Huione Guarantee by the time it was forced offline, and Tudou Guarantee’s status as a part-owned successor that absorbed displaced merchants. (Vendor research; Elliptic sells the forensics it reports on.)
- TRM Labs — 2025 Crypto Crime Report (teaser) — TRON’s 58% share of the illicit volume TRM tracked in 2024 (the largest of any chain in its analysis) and T3-facilitated freezes. (Vendor; also a TRON T3 partner — double commercial interest.)
- U.S. Department of Justice — Justice Department Seizes Backend Infrastructure Used by the Huione Group for Money Laundering Services (June 2026) — the June 2026 seizure of the cloud account hosting Huione’s backend infrastructure, an FBI-investigated action (Operation Riptide) executed by the DOJ Criminal Division.