U.S. Bans Crypto Addresses Tied to LockBit Ransomware Group From Financial System

CoinDeskPolicyPubblicato 2024-02-19Pubblicato ultima volta 2024-02-21

Introduzione

LockBit hit more than 2,000 different victims, who forked out north of $120 million in payments, according to a DOJ press release.

  • The Office of Foreign Asset Control named two Russian nationals and identified 10 bitcoin and ether addresses after an international operation gained control of the organization's website.
  • Law enforcement agencies said they will distribute decryption keys to victims.
27.5K

The U.S. Treasury Department's sanctions watchdog added nearly a dozen bitcoin and ether addresses to its global blacklist, alleging they were used by ransomware purveyors.

The Office of Foreign Asset Control (OFAC) named Artur Sungatov and Ivan Kondratyev, two Russian nationals indicted on charges tied to the deployment of ransomware, and identified 10 bitcoin and ether addresses (none of which containing any funds as of press time), in a statement on Tuesday, banning U.S. entities from providing any kind of financial services to the two. According to OFAC and the U.S. Department of Justice, they are part of the LockBit ransomware group, one of the world's most prolific ransomware distributors accused of stealing more than $120 million from over 2,000 victims in the past few years.

Ransomware attacks let malicious actors lock victims out of their computers and networks unless they pay a fee, often in cryptocurrency.

Advertisement
Advertisement

An international effort by the DOJ, Europol, the U.K. National Crime Agency and agencies in several other countries seized LockBit's website and various pages earlier this week in an effort dubbed Operation Cronos. The law enforcement agencies announced they would be distributing decryption keys to victims, allowing them to regain access to their devices.

According to a press release from Europol, more than 200 cryptocurrency accounts tied to LockBit have been frozen, while authorities in the U.S., U.K. and EU have all seized various parts of the ransomware group's infrastructure.

Some of the addresses listed by OFAC on Tuesday were deposit addresses for KuCoin, Coinspaid and Binance, according to data from Arkham Intelligence.

LockBit's victims included municipal entities and private companies around the world.

"The LockBit ransomware variant, like other major ransomware variants, operates in the 'ransomware-as-a-service' (RaaS) model, in which administrators, also called developers, design the ransomware, recruit other members — called affiliates — to deploy it, and maintain an online software dashboard called a 'control panel' to provide the affiliates with the tools necessary to deploy LockBit," the DOJ press release said.

Edited by Sheldon Reback.

Letture associate

Hyperliquid is Strongly Strangling HyperEVM

The article analyzes the apparent failure of HyperEVM, the application engine of the Hyperliquid blockchain, contrasting it with the success of its core trading engine, HyperCore. Hyperliquid operates on a dual-engine architecture. HyperCore is a closed, high-performance order-book exchange for perpetuals and spot trading, which dominates on-chain volume and generates massive fees. HyperEVM, launched in February 2025, is an EVM-compatible layer meant for DeFi applications like lending and DEXs, which can access HyperCore's liquidity. Despite Hyperliquid's overall strength in a bear market, a stark divergence exists: * **HyperCore (Trading):** Captures over half of on-chain perpetual volume, generating ~$56M in fees over 30 days. * **HyperEVM (Applications):** All DeFi protocols combined generate less than $60M in fees. TVL is shrinking, daily active addresses are low (~8k), and the ecosystem lacks diversity. The DEX sector is particularly anemic, with most volume concentrated in a single protocol. The article identifies four key reasons for HyperEVM's struggles: 1. **Core Monopoly on Execution:** HyperCore exclusively handles order matching. This makes native DEXs on HyperEVM redundant and limits viable applications to those leveraging its order book (e.g., staking, lending). 2. **Architectural Concentration:** Shared liquidity across interfaces naturally leads to a "winner-takes-most" outcome, explaining the high concentration in both the trading (e.g., trade.xyz) and application layers. 3. **"No Insider" Philosophy:** Hyperliquid's commitment to fair launch means it provides no grants, business development, or marketing support to ecosystem projects, stunting growth. 4. **Complex Developer Experience:** The asynchronous design between HyperEVM and HyperCore (via the CoreWriter contract) creates non-standard development hurdles, as EVM transactions don't roll back if the core action fails. The conclusion is that HyperEVM's weakness is a deliberate trade-off, not an accident. Hyperliquid prioritized building an unbeatable trading engine, sacrificing the development of a broad, independent application ecosystem. HyperEVM functions more as a tokenization layer for HyperCore's liquidity rather than a general-purpose chain. The debate isn't whether it's "dead"—it serves a niche—but whether Hyperliquid ever intended to build a thriving, diverse DeFi ecosystem beyond its core trading product.

marsbit1 h fa

Hyperliquid is Strongly Strangling HyperEVM

marsbit1 h fa

Trading

Spot
活动图片