BLOCKCHAIN AI.NEWS

Policy · In court Tuesday

The Two Firms That Count Crypto Crime Are Suing Each Other

ICE decided, over fifteen days in June, that exactly one company on earth could trace blockchains for its task forces. The company that lost is now in the Court of Federal Claims asking a judge to say that decision was unlawful. The argument is about procurement. What it exposes is how the government buys its picture of the chain.

Editorial illustration: two identical chrome magnifying lenses on stands turned to face each other rather than the blank frosted-glass tablet between them, warm gold light pooling on the empty tablet
✓ Reported by The Block (Aug 30) · Also reported by crypto.news and The Crypto Times · Underlying figures from TRM Labs and Chainalysis published research

On Tuesday morning, at ten o'clock Eastern, Judge Stephen S. Schwartz of the U.S. Court of Federal Claims will hear argument in a case that most of crypto will file under procurement trivia. It is not. Chainalysis is asking a federal judge to void a $94.66 million sole-source award that Immigration and Customs Enforcement handed to TRM Labs, and to order the agency to run an open competition instead.

Strip out the acquisition vocabulary and the question underneath is simple. When a federal task force looks at a blockchain, whose software is it looking through — and how did the government decide there was only one answer?

Fifteen days from question to conclusion

The timeline is the case. Both The Block and crypto.news, working from the redacted complaint made public on August 29, describe the same sequence, and it is worth laying out at the pace it actually happened.

On May 28, ICE issued a request for information — eighteen questions — with responses due June 2. Chainalysis filed twenty pages. On June 8, the agency published a notice of intent to award the work to TRM Labs without competition. Vendors who disagreed could submit a capability statement, limited to one page, by June 11. Chainalysis submitted one. On June 12, ICE finalised its market research report concluding that TRM was the only responsible source. The contract period began July 1 and runs through June 30, 2027.

Fifteen days separate the first question from the finding that no alternative existed. Within that window, the window for a competitor to argue otherwise was three days long and one page wide.

None of that is illegal on its face. Sole-source awards are lawful when an agency genuinely establishes that one supplier alone can meet a real need, and no agency is obliged to compete a contract just because a second vendor would like it to. The question for a judge is narrower: whether ICE's conclusion had a rational basis on the record it built, or whether the record was assembled to fit a conclusion already reached.

What ICE says only TRM can do

ICE's stated justification, per The Block's reading of the filing, is that Chainalysis lacked automated real-time disruption capabilities, integrated on-chain and off-chain intelligence, and scalable victim identification and notification. The scope covers blockchain tracing, scam disruption, cybercrime investigations and support for sextortion cases for Homeland Security Task Force work.

Chainalysis raises seven claims. The most substantive is not the wounded-competitor complaint but a documentary one: that a significant number of requirements from the May 28 RFI did not appear in the final Statement of Need. In its own words from the filing, one RFI question "tracks the architecture of a single vendor's proprietary product" and "bore no resemblance to the corresponding language in the Statement of Need."

The specific capabilities Chainalysis says were in the questionnaire but absent from the formal needs document include access to a proprietary scam-reporting database of more than a million records, automated notifications to virtual asset service providers, and operational partnerships with stablecoin issuers. Its sharpest line is about asymmetry rather than any single requirement: the agency, it argues, "granted itself more space to articulate its needs than it permitted potential alternative sources" to explain how they could meet them. Twenty pages of questions answered; one page to respond to the conclusion.

Chainalysis first took this to the Government Accountability Office on July 12, then filed under seal in the Court of Federal Claims on July 27. TRM Labs has intervened to defend its award. The government has asked for a ruling by September 10.

Everything in the preceding four paragraphs is Chainalysis's account of the procurement, drawn from a complaint it wrote. ICE and TRM are contesting it. No court has found that anyone acted improperly, and a redacted filing by a disappointed bidder is the least neutral document in any procurement dispute. We are reporting what was filed, not what was proved.

The part that should interest people who don't care about contracts

These two companies are not merely vendors. They are, between them, the primary source of nearly every number the public hears about crypto crime — the figures that anchor congressional testimony, enforcement press releases, and a great deal of journalism, this desk's included.

Which makes an inconsistency in the record worth putting on the table. TRM's own published counts of the same half-year do not agree with each other.

TRM Labs on H1 2026, five weeks apart

H1 reportAI-in-Crime Index
Hacks207201
Total losses$972M
North Korea-linked~$643M~$600M
NK share of losses~66%~61%
Left: TRM's H1 2026 hacks report. Right: TRM's AI-in-Crime Adoption Index as reported by The Block, Aug 21. Same firm, same six months, different counts.

There are entirely ordinary explanations for a gap like that. Datasets get revised as attributions firm up. "Hacks" and "digital asset hacks" may be different buckets. One count may have closed earlier than the other. TRM is unusually candid about the limits of its own numbers — its H1 report states that the figures "include only hacks and exploits" and notes that North Korea also raises funds through phishing, social engineering, fraud, scams and coercion, so the $643 million is a floor on that regime's take rather than a total.

It also flags the concentration that makes any half-year number fragile: roughly $577 million of the $972 million came from two April incidents, Drift Protocol and KelpDAO. Four percent of incidents produced seventy-five percent of the losses. A single attributions call on one event moves the headline figure more than a hundred smaller ones.

The point is not that TRM is careless — the opposite; it publishes its caveats where you can read them. The point is that these are estimates produced by a commercial firm from proxies, and the industry quotes them as though they were counted the way a census is counted.

Two lenses, one chain, no referee

The competition between these firms is the closest thing the sector has to peer review. When Chainalysis and TRM publish different totals for the same period, the disagreement is legible, and anyone can ask why. That is not much of a check, but it is a check.

A sole-source award of this size does something specific to that arrangement inside one agency: it makes a single vendor's attribution methodology the operational truth for Homeland Security Task Force investigations for a year. Not because the software is wrong — nobody has shown that it is — but because attribution on a public ledger is a judgment call rendered as a label, and when only one firm's labels are in the room, there is nothing to compare them against.

Ari Redbord, TRM's global head of policy and government affairs, gave a line in the AI-in-Crime work that captures why the stakes keep rising: "AI has not invented new crimes. It removed the constraints on old ones. The skill floor collapsed, the scale ceiling lifted, and fake identity went industrial." He is right, and it is a good argument for buying the best tracing available. It is not, by itself, an argument for buying it from one company without asking.

What Tuesday actually decides

Very little about crypto, and quite a lot about process. Schwartz is not being asked which product is better. He is being asked whether ICE's sole-source justification survives review — whether the agency meaningfully considered the capability statement it invited, and whether specifications that allegedly mirror one vendor's architecture can carry a finding that only that vendor qualifies.

Chainalysis wants the award declared unlawful, performance permanently enjoined, an open competition ordered, and its legal costs recovered under the Equal Access to Justice Act. It may well lose. Bid protests usually do; the standard of review is deferential by design, and agencies are allowed to be in a hurry.

But the filing has already done something a ruling cannot undo. The fifteen-day timeline, the one-page reply window, and the gap between the questionnaire and the Statement of Need are now public, redactions and all. Whatever the judge decides about the contract, that record stands.

The Take

The uncomfortable thing here is not that one of these firms may have been treated unfairly. It is that a procurement fight is currently the most rigorous public audit anyone is running on the blockchain-intelligence industry. Two companies supply most of the numbers the world uses to describe crypto crime, those numbers are estimates built on proprietary attribution, and the only reason we are looking closely at either firm's methods this week is that they are in litigation with each other over money. That is a thin form of accountability. If a federal agency is going to spend $95 million converting one vendor's judgment into the operational picture of an entire investigative program, the case for doing so ought to survive more than three days and one page of contradiction — not because the vendor is suspect, but because a picture of the chain with nothing to check it against stops being evidence and starts being a house view. Chainalysis is not a disinterested party in making that argument. It is still the right argument.

More on the subject