Rakh Abogados
Rakh Abogados Inherited Talent
Direct collaboration with Europol EC3

Cybercrime and Crypto-Assets: Marbella Specialists

Text

Cybercrime and crypto-assets

The rise of crypto-assets in economic activity has shifted the natural setting of certain forms of property crime — investment scams, high-frequency trading fraud, thefts from wallets, money laundering through mixing services — into a field where a criminal investigation requires, in addition to substantive knowledge of the offence itself, technical mastery of blockchain technology, exchange platforms, blockchain traceability mechanisms, and the international cooperation framework between cybercrime units.

RAKH ABOGADOS acts in this area both in defence and as a private prosecutor (acusación particular), with an established practice before the competent investigating courts (Juzgados de Instrucción), in accordance with the non-jurisdictional plenary agreement of the Second Chamber (Criminal Division) of the Tribunal Supremo (Spain's Supreme Court) of 3 February 2005 — which, for computer offences of a shifting and itinerant nature, establishes the principle of ubiquity and gives jurisdiction both to the courts of the place of the act and to those of the place of the result — and before the Specialised and Violent Crime Unit of the Cuerpo Nacional de Policía (Spain's National Police), particularly its Cybercrime Group, as well as with its regional counterparts.

Case law
  • ATS de 7 de octubre de 2005 (Sala de lo Penal, ROJ ATS 15375/2005): cita expresamente el Acuerdo del Pleno no jurisdiccional de la Sala Segunda de 3 de febrero de 2005, en cuya virtud «el delito se comete en todas las jurisdicciones en las que se haya realizado algún elemento del tipo», doctrina de la ubicuidad aplicada de forma constante a los delitos patrimoniales cometidos por medios informáticos. (Ruling expressly citing the 3 February 2005 plenary agreement: "the offence is committed in every jurisdiction where any element of it took place" — the ubiquity doctrine, consistently applied to property offences committed by computer means.)

Applicable legal framework

This firm's work in the field is carried out within a regulatory framework comprising, among other rules, articles 248 et seq. of the Criminal Code — common fraud and its computer-based form — article 395 in cases of falsification of a private document connected to and absorbed by the fraud where the harm caused is proprietary, in line with the criterion set out in STS (Second Chamber) 161/2013 of 20 February and the rulings it cites, articles 264 et seq. concerning computer offences, and article 301 et seq. concerning money laundering through crypto-assets.

On the procedural side, articles 588 ter et seq. of the Ley de Enjuiciamiento Criminal (Spain's Criminal Procedure Act) are of central application, governing the interception of electronic communications, the search of mass-storage devices, remote searches of computer equipment, and the duty of cooperation owed by obliged parties. At the supranational level, Directive (EU) 2015/849, as amended by Directive (EU) 2018/843, expressly brings custodian wallet providers and exchanges within the scope of parties obliged to prevent money laundering and terrorist financing, together with the due diligence obligations, the duty to report to SEPBLAC (Spain's anti-money-laundering authority), and the internal control obligations imposed by both directives.

Our services in cybercrime and crypto-asset offences

This firm's work in the field is principally carried out in the following areas:

Crypto-asset fraud

Defence and private prosecution in cases of investment fraud under articles 248 et seq. of the Criminal Code, in its various forms: fraudulent trading platforms and unregulated brokers promising guaranteed returns, mass withdrawals of liquidity by the project's own promoters (rug pulls), impersonation of exchanges and wallets through fraudulent links and messages (phishing) as the vehicle for the typical deception, and romance fraud preceding the request for investment (pig butchering or love crypto scams).

Case law
  • ATS 20.949/2026, de 11 de junio (Sala de lo Penal, ROJ ATS 6028/2026): resuelve una cuestión de competencia sobre una estafa de inversión en «Bitcoin y prestación de carteras de servicios» captada mediante un anuncio en Instagram, y sistematiza el principio de funcionalidad que complementa a la ubicuidad cuando la estafa se ha cometido por medios informáticos con conexión a distintos lugares, incluso en el extranjero. (Ruling on a jurisdiction dispute concerning a "Bitcoin and wallet-service" investment scam sourced through an Instagram advertisement, setting out the functionality principle that complements ubiquity where the fraud was committed by computer means connected to several places, including abroad.)

Theft, hacking and misappropriation of crypto-assets

Defence and private prosecution in cases of unlawful access to computer systems under articles 197 bis and 264 et seq. of the Criminal Code — malware, keyloggers and targeted phishing aimed at emptying wallets — as well as in cases of misappropriation under article 253 of the Criminal Code where crypto-assets have been handed over on deposit, for sale, or for safekeeping, and the person holding them disposes of them by incorporating them into their own assets. Both scenarios require a forensic blockchain analysis to identify the destination wallets and their holders.

Case law
  • ATS 109/2022, de 20 de enero (Sala de lo Penal, ROJ ATS 1627/2022): confirma la condena por un delito de apropiación indebida de ocho bitcoins depositados en una wallet de la plataforma Kraken en ejecución de un mandato de venta, con incorporación de los criptoactivos al patrimonio del mandatario. (Ruling upholding a conviction for misappropriation of eight bitcoins deposited in a Kraken wallet under a sale instruction, where the crypto-assets were incorporated into the agent's own assets.)

Money laundering through mixers and mixing services

Tumbling or mixing services — such as WasabiWallet, or the now-dismantled BestMixer.io — operate over the Tor network and aim to break the on-chain trail by automatically distributing crypto-assets among random addresses. Analysing them requires combining knowledge of peer-to-peer architecture with the procedural handling of article 588 ter LECrim and the application of the duty of cooperation under article 588 ter e), without whose coordinated invocation the investigation stalls at the mixer.

Case law
  • ATS de 24 de octubre de 2019 (Sala de lo Penal, ROJ ATS 10964/2019): analiza la responsabilidad penal del intermediario que convierte dinero fiat en bitcoin sin verificar la identidad de quien le encarga la operación, exponiéndose a un delito de blanqueo de capitales por imprudencia grave del artículo 301 del Código Penal en su condición de «mula» económica del defraudador. (Ruling examining the criminal liability of an intermediary converting fiat currency into bitcoin without verifying the identity of the person instructing the operation, exposing them to liability for grossly negligent money laundering under article 301 of the Criminal Code as an economic "mule" for the fraudster.)

How we approach the proceedings

Collaboration with Europol and Interpol

The effectiveness of a cybercrime investigation — and very particularly where the substance of the conduct lies in the blockchain and its associated services — requires coordinating national judicial action with the work of supranational police investigation units. In this field, RAKH ABOGADOS maintains a close, well-established relationship with Europol's European Cybercrime Centre (EC3), based in The Hague, and with the International Criminal Police Organization (Interpol), having collaborated with both organisations on more than eight proceedings, whether in a defence or a private prosecution capacity.

This technical liaison is not a one-off intervention but a sustained practice of the firm in this field, which has allowed it to build up specific operational knowledge of the SIENA communication channels between competent authorities, of the H0 to H3 handling codes for information shared within Europol, of the regime governing Interpol notices and diffusions — particularly the red notice and the diffusion — and of the timeframes and formal requirements of auxilio judicial internacional (international judicial assistance) with third States.

Coordinated battery of investigative measures

Full identification of the perpetrators is achieved through a coordinated battery of investigative measures whose properly substantiated request is decisive at this stage: a letter rogatory to the exchange platform, as an information-society service obliged under article 588 ter e) LECrim, to provide the two categories of data the investigation requires — data on the authenticity and accuracy of the transaction, with the hash and block identifier, and data identifying the holder, including name, ID document, email address, connection IP addresses and linked bank accounts — together with a forensic blockchain analysis entrusted to the Cybercrime Group of the UDEV (Specialised and Violent Crime Unit) of the Cuerpo Nacional de Policía.

Reference case

This firm has taken on the lead defence in a matter involving the theft of crypto-assets with multi-jurisdictional reach. Europol's EC3 Unit issued an intelligence report on the analysis of the wallets under investigation, in which the transactions were de-anonymised through forensic blockchain work and the destination wallets to which the stolen funds had been sent, after passing through a mixing service — in this case WasabiWallet, integrated with the Tor network — were identified. The cross-match coordinated by Europol produced positive results with the counterpart authorities of other Member States, including the Greek Cyber Crime Division and the Swiss Police Judiciaire Fédérale, whose cooperation made it possible to link the main wallet with the full identity of the Moroccan nationals under investigation, establishing their address, ID document, email address, telephone handset and connection IP addresses — the main wallet having received, over its historical record, more than 1,600 bitcoins, with an asset exposure in the case exceeding one and a half million euros at the value at the time of the events.

On the basis of that identification, formal requests were made to the international exchange Binance for ownership data and for the freezing of available balances, together with an application for a European arrest warrant against the persons under investigation and for auxilio judicial internacional with the Kingdom of Morocco — the jurisdiction of nationality of the wallet holders — by means of a letter rogatory under article 177 of the Ley de Enjuiciamiento Criminal and the applicable treaties.

The result of the work carried out was the full identification of the perpetrators, establishing their personal details, addresses in the United Kingdom and Ukraine, and active handsets, and the location of the wallet ultimately receiving the funds — which, over the course of its operational history, had moved more than 23,000 bitcoins — laying the groundwork for the subsequent judicial action to recover the assets and establish liability.

Related resources

FAQs, glossary and comparisons

Frequently asked questions

Where can a crypto-asset fraud committed online from different countries be tried?

See the answer in Frequently Asked Questions →

Is it a crime to receive crypto-assets from a third party for safekeeping and keep them?

See the answer in Frequently Asked Questions →

Glossary

Auxilio judicial internacional (international judicial assistance)

A cooperation mechanism between judicial authorities of different countries for carrying out investigative measures (identifying account holders, requesting information from platforms, intercepting communications) where the matter has elements located outside Spain.

See in the Glossary →

Requisitoria (wanted notice)

A request issued by a Spanish judicial body for the location and surrender of a person whose whereabouts are unknown, which internationally can be channelled through an Interpol red notice or diffusion, or through the European Arrest Warrant itself where the person concerned is in another EU Member State.

See in the Glossary →

Ubicuidad (principle of ubiquity)

A principle established by the non-jurisdictional plenary agreement of the Second Chamber of the Tribunal Supremo of 3 February 2005: the offence is committed in every jurisdiction where any element of it took place, which allows computer offences or crypto-asset fraud committed with connections across different countries to be investigated and tried in Spain.

See in the Glossary →
Initial consultation