Crypto Briefing published a brief last week that said almost nothing. The headline — Kremlin's hybrid warfare aims to undermine European support for Ukraine — carried no timestamp, no institution, no number, no named official. Just an assertion, a generalized warning, and a masthead. That absence is the actual signal.
I have spent eighteen years watching capital move through systems that advertise their own transparency. In early 2017 I burned 140 hours manually tracking Ethereum gas fees and whale wallets across three ICO launches, and found that 60% of what everyone called decentralized capital was recycling through wash-trading clusters. My employer at the time called it niche noise. The data was never the noise. The narrative was.
So when a crypto-native outlet frames a European security crisis, watch the flow, not the flood. The flood is the headline. The flow is the reason an asset class that Brussels spent five years ignoring is now the connective tissue of a war fought below the threshold of war.
Hybrid warfare is a financing problem before it is a munitions problem. That is the structural truth almost no defense analyst wants to write down, and almost no crypto analyst knows how to price. Drones are cheap. Deepfakes are cheaper. But a sabotage cell, a disinformation farm, a bribed logistics clerk — these require recurring payments to people who cannot be paid through a correspondent bank without leaving a paper trail that survives sanctions screening. That is the gap. That is where the ledger enters the map.
NATO's framework has always defined hybrid operations by what they are not: not an armed attack, therefore not Article 5, therefore not a military response. The doctrinal trick is a deliberately low cost-to-deter balance. A severed Baltic cable, a warehouse fire in a Polish logistics park, a coordinated bot network targeting a Romanian election — each carries a marginal cost in the tens of thousands of dollars and an expected cost to the defender in the millions. This is force protection by accounting. The attacker wins as long as the ledger of pain is asymmetric.
But the money has to move. And here the Crypto Briefing brief, thin as it is, stumbles onto something real: the funding rail for a war fought off the battlefield is increasingly a set of instruments designed to be unbanked. That claim deserves the scrutiny it needs.
The honest number first: crypto is a tiny share of the problem, and it is a growing share of the solution. Chain-analytics firms have consistently placed illicit activity between roughly 0.1% and 0.5% of total on-chain volume for years. That proportion has not scaled with the headlines. Watchers who want to sell crypto as the universal lubricant of sanctions evasion are wrong on the base rate. But they are right on the margin, and the margin is where policy gets decided.
The reason is the rail itself. A ruble-denominated stablecoin does not need a correspondent bank, does not need a SWIFT code, does not need a compliance officer in Vienna. It needs a wallet and a counterparty willing to accept settlement risk. In 2025 the OFAC sanctioned the ruble-backed token A7A5, a product tied to a sanctioned Russian bank and routed through a Kyrgyz-linked exchange, one of a family of offshore structures built explicitly to keep value moving after two decades of correspondent banking relationships were severed. This is not speculation. It is the observable consequence of escalating financial blockade: when you cut the legal channels, capital does not stop. It relocates. Regulation chases shadows, and the shadows settle wherever a node will host them.
I built a real-time dashboard in 2022 tracking tether and USDC reserves against on-chain derivatives exposure, not because I wanted to prove crypto was a sanctions tool, but because I wanted to prove reserves were. What the dashboard actually showed me was subtler: the dominant rail in any evasion scenario is not a privacy coin. It is the stablecoin, and specifically the largest one, because it has liquidity, exchange integration, and — crucially — a freeze function.
The freeze function is the whole story. The same centralization that makes offshore stablecoins useful for moving value across borders is what makes them recoverable. Tether has now frozen billions of dollars in address clusters tied to sanctioned networks, including the Garantex exchange, which US and German authorities took down in coordination and which simply relaunched under a new name with adjusted infrastructure. That pattern — takedown, respawn, relabel — is the actual character of the shadow-finance war. It is not a monolithic escape hatch. It is a whack-a-mole contest with a public scoreboard.
Which brings us to the part the hybrid-warfare literature keeps missing. A public ledger is an intelligence asset before it is a payment rail. Every ruble stablecoin transfers between an exchange and a wallet is a permanent, timestamped, graph-databaseable record. If a GRU-linked recruitment payment lands in a wallet that later funds travel for a sabotage cell, the chain does not forget. Attribution in the physical world is hard; attribution on-chain is a graph problem. The attacker's operational security failure is not leaving a trace — it is leaving a trace that any analyst with a laptop and an API key can reconstruct six months later.
I have watched this asymmetry reshape entire investigative workflows. The Elliptic and Chainalysis case files on Russian evasion networks are built from exactly this: cluster heuristics, exchange deposit tags, mixer-adjacent flow graphs. That is not surveillance of the guilty alone. It is surveillance of the system, which is precisely why the deterrence value is real but the intelligence value is greater. The attacker who uses a public chain to fund a covert operation is, functionally, publishing their plumbing.
So why use it at all? Because for the operational layer the alternative is worse. The alternative is cash couriers, hawala networks, shell companies in third jurisdictions with banking access the sender does not have. Crypto is not chosen because it is anonymous. It is chosen because it is fast, final, and cheap to instance — three properties that matter more to a logistics cell than privacy does. The privacy is a bonus at best and a liability at worst.
Now the contrarian turn, because the dominant Western framing on this topic is structurally dishonest in a way that matters for capital allocation.
The framing goes: crypto enables hybrid warfare, therefore clamp down on crypto. I have audited enough DeFi infrastructure to say plainly that the clamp-down as designed in MiCA will not touch the rail that actually moves evasion funds, and it will extinguish the small projects that mostly do not. The compliance cost of a CASP license under the current regime is a fixed cost, not a proportional one, which means it functions as a minimum-viable-size filter. The ruble stablecoin routes are not applying for licenses. The attacker-side instruments are deliberately outside the perimeter. What remains inside is the small European issuer that suddenly owes legal, audit, reporting, and travel-rule obligations it cannot fund — the same pattern I watched hollow out three-year RWA roadmaps that never got past pilot because the entities that needed the public chain were never going to use a permissionless one anyway.
Regulation chases shadows. And when it finally arrives on the shadow, it usually finds a compliant office and a compliance trophy, while the flow quietly moves to a jurisdiction that read the rulebook and declined to sign it.
The deeper contrarian point is the one that cuts against the attacker's own calculus. Hybrid warfare funded on-chain is deterred in the data layer, not the law layer. Every base-layer clamp-down — OFAC designations, exchange delistings, stablecoin freezes — lands where the address can be touched. That means an increasing share of evasion migrates to infrastructure the clamp-down cannot reach: the sequencer. I have written for two years that "decentralized sequencing" has been a slide deck, not a product. Almost every major Layer 2 rolls up to a small set of operators, often a single entity behind a foundation, gated by an upgrade key. That centralization is marketed as a performance feature. It is also a censorship surface — and it is exactly the surface where sanctioned flow can be rerouted if you control the operator. The policy framework treats L2s as scaling solutions. They are becoming chokepoints, and everyone is watching the base layer instead.
There is one more underrated vector: the AI agent. I have spent three years researching how autonomous execution systems interact with smart contracts, and the honest assessment is that the most dangerous near-term funding rail is not a coin — it is an agentic wallet transacting at machine speed across venues that human compliance teams cannot screen in real time. A bot moving value across twenty pools in a minute is indistinguishable from normal market-making to a rules-based engine. That is not a future threat. The tooling exists. The regulation does not, and by the time it does, the standard will once again describe a version of the problem that has already mutated.
Where does this leave the actual market position? The geopolitical events here are chronic, not acute. A single cable cut, a single disinformation wave, does not move the dollar system. It moves the risk premium in three places: European defense and security spending, infrastructure-resilience capital, and financial-intelligence technology. The market consequence is a slow, persistent bid — not a black swan, a gray swan that waddles slower than the narrative implies and lives longer.
Liquidity is a liar. It tells you what is moving and stays silent on why. But the flows in this domain are unusually legible to anyone willing to read them: illicit share flat, exempt-rail growth quiet, compliance burden concentrated on the wrong side of the perimeter, and a public ledger quietly doing the counter-intelligence work that no firewall can. The uncomfortable conclusion for the policy class is that the most effective anti-hybrid-warfare instrument deployed so far was not a sanction. It was a permanent, queryable, permissionless record of where the money went.
The question worth carrying into the next quarter is not whether crypto funds hybrid warfare. It is whether the West will keep building walls on a ledger it can already read — or finally admit that the observability of on-chain flow is a strategic asset worth more than the illusion of control. Code is law until it isn't. In this case, the code is the evidence.