The Trail That Names No One: Tracing, Attribution, and the Limits of On-Chain Evidence in the Prince Group Case
- Blockchain Unmasked
- Jun 19
- 9 min read

The largest forfeiture in U.S. history produced a near-complete record of how $15 billion in bitcoin moved — while illustrating why attribution often requires evidence beyond the blockchain. Notes from doing the on-chain work on Southeast Asia's most entangled scam network.
Among the constellation of Southeast Asian scam networks, most compounds are interchangeable points of light that blur into one another. The Prince Group is the moon — not one operation among many, but a conglomerate that grew out of a single compound, bright enough to navigate by and close enough that its light falls across everything around it. That second quality of this mega scam conglomerate is the investigator's problem. When one network is large enough to touch nearly every off-ramp, every guarantee marketplace, and every laundering rail in the region, telling its activity apart from the rest of the sky becomes the hardest part of the job.

On 14 October 2025, the U.S. Department of Justice unsealed an indictment in the Eastern District of New York charging Chen Zhi — founder and chairman of Cambodia's Prince Holding Group — with wire fraud conspiracy and money laundering conspiracy, and filed a civil forfeiture complaint for roughly 127,271 BTC, then worth about $15 billion. It is the largest forfeiture action in DOJ history. The same day, OFAC and the UK's FCDO designated the Prince Group as a transnational criminal organisation alongside 146 associated targets, and FinCEN's final rule severed Huione Group from the U.S. financial system. Chen Zhi, a Chinese-born tycoon whose Cambodian citizenship was later revoked, was arrested in Cambodia on 6 January 2026 and extradited the following day — not to the United States, but to China, where he remains in custody.
This isn't a recap of the prosecution. It's a set of observations from doing the on-chain work, and it turns on a single distinction the case throws into unusually sharp relief: the difference between tracing and attribution. Tracing is following the money — and on this the blockchain is almost flawless. Attribution is proving whose money it is, and which real-world entity sits behind a given address. The Prince Group case is, at bottom, a demonstration of how wide the gap between those two things can be, and why closing it often requires on-chain analysis to be combined with documentary, testimonial, and other off-chain evidence.
Part 1 — What the seizure actually was, and why the dates matter
A key fact for interpreting the on-chain evidence is the age of the coins. The ~127,271 BTC named in the complaint are assessed by multiple blockchain analytics firms to be the same bitcoin drained from the LuBian mining pool in late December 2020. LuBian — a mining operation with infrastructure in China and Iran that at its 2020 peak controlled close to 6% of global hash rate — lost essentially everything in those wallets in a single incident on 28–29 December 2020. The technical cause is well documented and consistent across independent analyses: the pool generated wallet keys with a weak pseudo-random number generator, which left the private keys brute-forceable in roughly an hour of compute. After the drain, the coins sat almost entirely dormant for nearly four years, while the LuBian operators broadcast on-chain OP_RETURN messages in 2021 and again in 2022 pleading for their return.

Three things follow directly from that timeline, and none of them is speculative.
The seized coins are old, and their history predates most named victims. The renewed movement in the seized cluster is dated to June–July 2024 — and, BlockchainUnmasked's analysis assesses that this 2024 movement reflects the coins being shifted into wallets controlled by U.S. authorities, which is consistent with the DOJ’s statement that the assets were ‘already in custody’ by October 2025. The substantive victim conduct in the public record — including frauds dated to 2021 and 2022 — postdates the December 2020 dormancy. This timing distinction does not address the strength of the government’s broader case; it defines what conclusions can be drawn from the public on-chain record alone. If you are working backward from the forfeiture wallets expecting a clean line to a 2023 or 2024 pig-butchering victim, the chain will not give you one — the coins in those wallets stopped moving years before that victim was ever approached.

Mining is the laundering mechanism, not an incidental detail — and that is consistent with the laundering mechanism alleged in the DOJ indictment. The DOJ indictment states that the Prince Group laundered scam proceeds through ostensibly legitimate businesses, including its own crypto-mining operations, which "produced large sums of clean bitcoin dissociated from criminal proceeds." The relevant entities are the group's own mining businesses — LuBian, and the Laos-based Warp Data Technology with a Texas subsidiary (which allegedly leveraged F2 Pool to mine Bitcoins) — not a third-party pool, as is sometimes muddled in secondary commentary. The structural point is what matters: mining manufactures "clean" bitcoin with no prior transactional link to scam deposits. A network that controls its own hash power can manufacture provenance. When you trace Prince-linked flows, you are frequently not tracing scam proceeds at all — you are tracing the output of an industrial laundering layer built to look like ordinary mining revenue.

The recovery wallets are a separate bucket — and they aren't dormant any more. After the 2020 drain, LuBian moved roughly 11,886 BTC into recovery addresses by 31 December 2020. For years these sat untouched, and they are sometimes mistaken for part of the seized cluster. They aren't: they are the salvage, not the loss, and they fall outside the forfeiture. Critically, they didn't stay still — those recovery coins began moving on 15 October 2025, within a day of the DOJ action, followed by further large transfers later that month. BlockchainUnmasked continues to monitor several large, dormant clusters from the seizure window that remain unaccounted for and sit outside the DOJ cluster, where the totals holding reaches above 16,200 BTC. If you've been staring at a few very old, very large Prince-adjacent wallets and wondering why they don't reconcile against the seized cluster, this is usually why.
Part 2 — Why attribution is the hard part
Identifying currently active Prince Group-linked wallets from public on-chain data is a continuing challenge — and not because data is scarce. The problem is the reverse: an overwhelming volume of ambiguous activity where almost everything is suggestive and almost nothing is dispositive. Locating relevant transactions is easy; distinguishing one actor from the many others using the same infrastructure and patterns isn't. Thousands of pig-butchering victims may have been defrauded by a Prince-affiliated operation. Proving which is the hard part.
Over the past several months we've tested the three obvious attribution signals, and it's worth being candid about how each one fails.
Volume doesn't attribute. The bulk of this activity moves over Bitcoin and Tron. Follow the volume and you walk into a mesh of nested services and grey-market desks where balances swing from a few thousand to a few hundred million dollars inside two or three hops. Large flow is evidence that something illicit is happening; it isn't evidence of Prince Group specifically.
Shared infrastructure points everywhere at once. Prince-linked actors made heavy use of the Huione ecosystem and of guarantee marketplaces like Xinbi. So does practically everyone else. FinCEN's May 2025 Section 311 action found that Huione Group laundered at least $4 billion in illicit proceeds between August 2021 and January 2025; analytics firms assess Xinbi at roughly $17.9 billion in gross lifetime volume, with inflows that actually grew after Telegram purged the major guarantee channels in May 2025 — even as competitors such as Haowang and Tudou collapsed. These rails are used by essentially every Cambodian scam network, and by ordinary regional merchants and OTC users besides. "They touched Huione" narrows the suspect pool to roughly the entire region. Shared off-ramp infrastructure cannot, by itself, identify Prince Group.
KYC doesn't attribute either — and neither do IPs or on-chain behaviour. Even when lawful process produces exchange KYC records, additional corroboration may be necessary to identify the individual exercising actual control over the account. In practice these organisations operate like multinationals with thousands of staff and an industrial supply of fraudulent identity documents. You can wait months on a mutual-legal-assistance request to a Southeast Asian authority only to learn that the "account holder" is a farmer who cannot read English and whose ID was rented for $50. The KYC is real; the human behind it is a placeholder. Other commonly used attribution signals may also be insufficient when considered independently. IP geolocation tends to resolve to the same handful of border enclaves that host every other compound, and the on-chain behaviour — the peel chains, the consolidation patterns, the off-ramp choreography — is close to identical across networks, because they all learned the same playbook. The networks share geography and tradecraft without being the same organisation, so the behaviour that should single out a target ends up hiding it.
So the on-chain data records the movement of the money with great fidelity. What the blockchain doesn't independently establish is the identity of the person or entity controlling an address. That gap — between flow and attribution — is the actual subject of this case.
Part 3 — The open questions
With Chen Zhi extradited and the named assets frozen, the live questions are about continuity, not history.
Is there a "Prince Group V2"? The compounds, the trafficked workforce, and the off-ramp relationships don't evaporate when a chairman is removed — and his removal from the organisation raises a continuing question about who, if anyone, now directs its operational activities. If the physical infrastructure is still operating under a new brand or a new principal, the throughput is still flowing somewhere. The sister entities — Jin Bei Group (the hotel-and-casino arm), Warp Data Technology, and the long tail of others — are the obvious places to watch for reconstitution.
Which victims actually fall under the umbrella? Because the seized coins are old, restitution is genuinely complicated. For claims involving later victim activity, establishing a connection to assets that became dormant in 2020 may require evidence beyond a direct on-chain tracing path. The appropriate analytical framing for investigators supporting that work: the seized BTC and the contemporary victim flows may sit on entirely different timelines, and bridging them takes corroboration — documentary, testimonial, infrastructural — rather than a single tracing line. A direct on-chain path from a forfeiture wallet to a particular victim deposit may not always be available and should not be assumed without corroborating evidence.
Where are the live addresses? The FBI’s public actions establish a substantial historical record and enforcement foundation. Identifying any currently active successor wallets is a separate, forward-looking analytical task. That remains an important priority for continued public-private investigative work.
Part 4 — Where the pivots actually are
If the three easy signals don't attribute, the useful work moves elsewhere. Three pivots have held up for us, and all three share one discipline: apply a corroboration-first approach to attribution — and don't let a random pig-butchering address eat three weeks of your time pretending to be Prince Group.
1. Aggregate the small cases before chasing the big wallet. Any successor operation still carries the compound infrastructure, so throughput should remain substantial. The practical method is bottom-up: compile individual pig-butchering cases, cluster them, and see whether the aggregate resolves into something structurally coherent. If it does, you have a target. And if it turns out not to be Prince Group, it is still illicit money and still worth disrupting. The standard is "demonstrably illicit," not "definitely Prince."
2. Tag the off-ramps. Every scam network needs a cash-out. You cannot buy groceries or pay an electricity bill in USDT, and legitimate OTC or cash desks cannot absorb this kind of volume — and if one tries, that itself is a flag worth tagging. Disciplined labelling of the laundering layer is what actually disrupts these organisations. It is the logic behind the UK's May 2026 designation of HTX alongside the A7 Russian-evasion network — the first time a UK sanctions listing has directly named a major crypto exchange — and behind exchange-level accountability cases such as KuCoin's 2025 AML guilty plea. Sanctions and seizures of this kind are downstream of on-chain evidence; the labels are what make the enforcement possible.
3. Treat Telegram and the social layer as primary collection. Over the past several months our most productive non-chain signal has come from monitoring scam-reporting channels, regional pig-butchering communities, and illicit-service marketplaces, then correlating that web2 data back to address clusters. This is where BlockchainUnmasked has concentrated its own effort. We have been running a structured open-source collection programme against the Chinese-language layer of this ecosystem and feeding it to our in-house China analyst, who ingests, translates, and analyses the material in the original language rather than relying on after-the-fact machine translation. The objective is explicitly forward-looking: to surface a possible Prince Group V2 — or the next operation running at comparable scale — to identify emerging threats and support future investigative and enforcement action. The watchlist includes the Myanmar border compounds operating under the protection of the Karen Border Guard Force and the DKBA, with KK Park in Myawaddy the most prominent, where the October–November 2025 raids materially disrupted activity, while continued monitoring remains important to determine whether residual infrastructure or successor operations persist. Neither layer carries a case alone; the strong ones come from fusing chat and chain.
That these venues matter is not a theoretical claim. When the DOJ's Scam Center Strike Force — stood up in November 2025 — announced its first major milestones in April 2026, the package included charges over the Myanmar-based Shunda compound, more than $700 million in cryptocurrency restrained, 503 fraudulent investment sites taken down, and a first-of-its-kind seizure of a recruitment Telegram channel with more than 6,000 followers. The chat layer is both intelligence and infrastructure.
Conclusion
The Prince Group case shows the limits of a single data source. The blockchain gave investigators an unusually detailed record of how $15 billion in bitcoin moved, while attribution depended on a broader body of on-chain and off-chain evidence. The next phase of the work complements the enforcement actions already taken by aggregating small cases into provable structure, labelling the off-ramps the next operation will inevitably need, and reading the chat layer where the humans still talk. The chairman’s extradition is a significant enforcement milestone. Continued monitoring can help identify and disrupt any surviving or successor infrastructure. That is where the live trail runs.


