U.S. Bans Crypto Addresses Tied to LockBit Ransomware Group From Financial System

CoinDeskPolicyPublicado a 2024-02-19Actualizado a 2024-02-21

Resumen

LockBit hit more than 2,000 different victims, who forked out north of $120 million in payments, according to a DOJ press release.

  • The Office of Foreign Asset Control named two Russian nationals and identified 10 bitcoin and ether addresses after an international operation gained control of the organization's website.
  • Law enforcement agencies said they will distribute decryption keys to victims.
27.5K

The U.S. Treasury Department's sanctions watchdog added nearly a dozen bitcoin and ether addresses to its global blacklist, alleging they were used by ransomware purveyors.

The Office of Foreign Asset Control (OFAC) named Artur Sungatov and Ivan Kondratyev, two Russian nationals indicted on charges tied to the deployment of ransomware, and identified 10 bitcoin and ether addresses (none of which containing any funds as of press time), in a statement on Tuesday, banning U.S. entities from providing any kind of financial services to the two. According to OFAC and the U.S. Department of Justice, they are part of the LockBit ransomware group, one of the world's most prolific ransomware distributors accused of stealing more than $120 million from over 2,000 victims in the past few years.

Ransomware attacks let malicious actors lock victims out of their computers and networks unless they pay a fee, often in cryptocurrency.

Advertisement
Advertisement

An international effort by the DOJ, Europol, the U.K. National Crime Agency and agencies in several other countries seized LockBit's website and various pages earlier this week in an effort dubbed Operation Cronos. The law enforcement agencies announced they would be distributing decryption keys to victims, allowing them to regain access to their devices.

According to a press release from Europol, more than 200 cryptocurrency accounts tied to LockBit have been frozen, while authorities in the U.S., U.K. and EU have all seized various parts of the ransomware group's infrastructure.

Some of the addresses listed by OFAC on Tuesday were deposit addresses for KuCoin, Coinspaid and Binance, according to data from Arkham Intelligence.

LockBit's victims included municipal entities and private companies around the world.

"The LockBit ransomware variant, like other major ransomware variants, operates in the 'ransomware-as-a-service' (RaaS) model, in which administrators, also called developers, design the ransomware, recruit other members — called affiliates — to deploy it, and maintain an online software dashboard called a 'control panel' to provide the affiliates with the tools necessary to deploy LockBit," the DOJ press release said.

Edited by Sheldon Reback.

Lecturas Relacionadas

Hyperliquid está apagando deliberadamente a HyperEVM

**Resumen: ¿Hyperliquid está matando a HyperEVM?** La cadena Hyperliquid tiene dos motores: HyperCore, un motor de intercambio centralizado y de alto rendimiento que domina el mercado de *perpetuals* on-chain, y HyperEVM, un entorno compatible con Ethereum para aplicaciones DeFi, lanzado en 2025. Existe una gran disparidad entre ambos. **1. Desequilibrio masivo:** El núcleo de intercambio (HyperCore) genera unas 10 veces más en tarifas (~$56M en 30 días) que toda la capa de aplicaciones en HyperEVM (~$6M). La mayoría del TVL de la cadena (unos $12B) y los usuarios activos (60k-70k diarios) se concentran en el lado del trading, mientras que HyperEVM lucha con baja actividad (~8k direcciones activas) y un TVL en contracción. **2. ¿Por qué HyperEVM no despega?** * **Arquitectura restrictiva:** El emparejamiento de órdenes y la liquidez son monopolio de HyperCore. Las DEX en HyperEVM son redundantes; solo sobreviven aplicaciones que orbitan alrededor del libro de órdenes principal (staking líquido, préstamos, trading de *basis*). * **Concentración inevitable:** La liquidez compartida lleva naturalmente a la monopolización en cada nicho (ej., PRJX concentra el 92.3% del volumen DEX en HyperEVM). * **Falta de incentivos:** El equipo mantiene una estricta política de "sin ventajas internas", sin financiación o apoyo activo al ecosistema, lo que frena el desarrollo. * **Experiencia de desarrollo compleja:** La interacción asíncrona entre HyperEVM y HyperCore añade una capa de dificultad técnica que disuade a los desarrolladores generalistas. **3. Conclusión:** HyperEVM no está "muerto" técnicamente, pero su rol es claramente secundario. Hyperliquid priorizó estratégicamente su motor de trading de alto rendimiento, condenando a HyperEVM a ser una capa de tokenización y utilidades financieras especializadas, en lugar de un ecosistema de aplicaciones diverso e independiente. La pregunta no es si HyperEVM ha fracasado, sino si Hyperliquid alguna vez quiso que tuviera éxito como una cadena de propósito general.

marsbitHace 1 hora(s)

Hyperliquid está apagando deliberadamente a HyperEVM

marsbitHace 1 hora(s)

Trading

Spot
活动图片