Crypto Sleuth Links Russian OTC Desk To $4.7M Laundering

bitcoinistPublished on 2026-03-25Last updated on 2026-03-25

Abstract

ZachXBT, an anonymous blockchain investigator, has identified Russian OTC broker Aleksandr Khinkis as the central figure in a money laundering scheme involving over $4.7 million from three separate ransomware payments totaling 796 BTC. The investigation, which included an undercover Telegram conversation, revealed that Khinkis provided an exchange deposit address that became the anchor for tracing the illicit flows. The funds moved through multiple networks, including Bitcoin, Avalanche, and Tron, with some addresses later frozen by Tether. A dormant 73-BTC wallet remains under watch. Law enforcement has received the detailed transaction records, though no arrests have been announced.

A 73-bitcoin stash sitting untouched in a separate crypto wallet may be what eventually brings a Russian crypto broker to justice.

That dormant pile of digital cash, flagged by blockchain investigator ZachXBT, sits at the edge of a much larger money trail — one that reportedly spans three ransomware payments, multiple networks, and at least one undercover Telegram conversation.

Sting Operation Cracked The Case Open

ZachXBT, an anonymous on-chain investigator with a long record of tracing illicit crypto flows, identified Russian OTC broker Aleksandr Khinkis as the central figure in the alleged scheme.

According to reports, investigators posed as potential clients and contacted Khinkis directly through Telegram. He allegedly handed over an exchange deposit address — a move that gave investigators the thread they needed to pull.

That single address, starting with 0xa756, became the anchor point for the entire investigation. From it, researchers tracked roughly 75 transfers funneling more than $4.7 million into the same account. The money had been moving since at least July 2025.

Three Ransoms. Three Trails. One Broker

The alleged laundering involved three separate ransomware payments totaling 796 BTC. Each left a distinct footprint across multiple blockchain networks.

The oldest case dates back to September 2023, when five Bitcoin bridge deposit addresses were tied to a 560 BTC ransom. Those funds eventually crossed into the Avalanche network sometime in 2024.

A second payment of 72 BTC, traced to September 2025, showed more than 15% overlap with known ransomware wallets across compliance screening tools. About $1.36 million from that batch moved through instant exchanges before consolidating into a Tron wallet.

The most recent and largest payment — 164 BTC — was recorded in October 2025. Based on reports, around $3.8 million in bitcoin passed through instant exchanges before reaching Tron-linked outputs.

Bitcoin is now trading at $71,701. Chart: TradingView

Seven Tron addresses connected to that flow were frozen by Tether the following month. The frozen funds were later burned, confirming that enforcement action had been taken.

Meanwhile, an additional $16.6 million remains sitting in related addresses or platforms, with some of it already being cashed out.

Law Enforcement Now Has the Data

ZachXBT confirmed that compliance teams and law enforcement agencies have received detailed records of the traced addresses and fund movements. No arrests have been publicly announced.

Beyond the blockchain data, open-source intelligence painted a clearer picture of Khinkis as a person. Reports indicate he travels outside Russia regularly — including trips to Southeast Asia and Australia — and documents those trips openly on social media.

The 73 BTC still sitting dormant at a separate address hasn’t moved. If and when it does, investigators will almost certainly be watching.

Featured image from Pexels, chart from TradingView

Related Questions

QWho is the central figure identified in the alleged money laundering scheme, and what is his profession?

AThe central figure is Aleksandr Khinkis, a Russian OTC broker.

QWhat was the total amount of money laundered through the single crypto exchange account, and how many Bitcoin did the three ransomware payments total?

AMore than $4.7 million was laundered through the account, and the three ransomware payments totaled 796 BTC.

QWhat crucial piece of evidence did the undercover investigators obtain from Aleksandr Khinkis on Telegram?

AThe investigators obtained his exchange deposit address (0xa756...), which became the anchor point for the entire investigation.

QWhat action did Tether take regarding the seven Tron addresses connected to the most recent ransom payment?

ATether froze the funds in the seven Tron addresses, and the frozen funds were later burned.

QWhat significant amount of cryptocurrency remains untouched and is being monitored by investigators?

AA stash of 73 Bitcoin sitting in a separate wallet remains dormant and is being watched by investigators.

Related Reads

Dialogue with a Macro Analyst: AI Drains All Liquidity from U.S. Stocks, $40K Bitcoin is the True Bottom

In a recent discussion, macro strategist Luke Groman, founder of FFT LC, presented a sobering analysis of current markets. He argues that while the S&P 500 hits new highs, this is largely driven by just seven AI stocks, which are "sucking all the oxygen and liquidity out of the room." Bitcoin, which he calls the "last working smoke alarm for liquidity," is signaling trouble, having entered a difficult period. Groman explains that the AI boom is fueled by accounting practices that front-load revenue, creating an illusion of high profits while cash is being depleted. He warns this cycle could reverse sharply when construction slows. His base case is that stocks will rise in dollar terms but fall significantly when measured in gold or Bitcoin, highlighting that long-term US Treasury futures have already lost 90% of their value against gold over the past decade. He points to major structural risks, including China's dominance in rare earths—a small commodity market underpinning trillions in tech stock value—and the prolonged closure of the Strait of Hormuz, which he calls a "Suez Moment" for the US. This, combined with a shift towards a "no ticky, no washy" proof-of-work system for settling trade (using gold, not trust), signals deeper systemic distrust. Regarding US debt, Groman notes that historically, all 58 countries that reached a 130% debt-to-GDP ratio defaulted, primarily through inflation. The US crossed this threshold in 2020. He also highlights a contradiction in the AI narrative: if it's as transformative as claimed, it must destroy white-collar jobs, threatening half of US tax revenue—a reality at odds with the "no job loss" messaging from tech leaders. On Bitcoin, Groman sold most of his position near the top and hasn't fully re-entered. Citing technical analysis from Northstar Bad Charts, he suggests a potential bottom around $40,000 could materialize in Q3 or Q4. He concludes that while he may be labeled a doomsayer, his view is simply realistic, grounded in historical precedents and current macro pressures.

marsbit3h ago

Dialogue with a Macro Analyst: AI Drains All Liquidity from U.S. Stocks, $40K Bitcoin is the True Bottom

marsbit3h ago

Trading

Spot
Futures
活动图片