Crypto Sleuth Links Russian OTC Desk To $4.7M Laundering

bitcoinistPublished on 2026-03-25Last updated on 2026-03-25

Abstract

ZachXBT, an anonymous blockchain investigator, has identified Russian OTC broker Aleksandr Khinkis as the central figure in a money laundering scheme involving over $4.7 million from three separate ransomware payments totaling 796 BTC. The investigation, which included an undercover Telegram conversation, revealed that Khinkis provided an exchange deposit address that became the anchor for tracing the illicit flows. The funds moved through multiple networks, including Bitcoin, Avalanche, and Tron, with some addresses later frozen by Tether. A dormant 73-BTC wallet remains under watch. Law enforcement has received the detailed transaction records, though no arrests have been announced.

A 73-bitcoin stash sitting untouched in a separate crypto wallet may be what eventually brings a Russian crypto broker to justice.

That dormant pile of digital cash, flagged by blockchain investigator ZachXBT, sits at the edge of a much larger money trail — one that reportedly spans three ransomware payments, multiple networks, and at least one undercover Telegram conversation.

Sting Operation Cracked The Case Open

ZachXBT, an anonymous on-chain investigator with a long record of tracing illicit crypto flows, identified Russian OTC broker Aleksandr Khinkis as the central figure in the alleged scheme.

According to reports, investigators posed as potential clients and contacted Khinkis directly through Telegram. He allegedly handed over an exchange deposit address — a move that gave investigators the thread they needed to pull.

That single address, starting with 0xa756, became the anchor point for the entire investigation. From it, researchers tracked roughly 75 transfers funneling more than $4.7 million into the same account. The money had been moving since at least July 2025.

Three Ransoms. Three Trails. One Broker

The alleged laundering involved three separate ransomware payments totaling 796 BTC. Each left a distinct footprint across multiple blockchain networks.

The oldest case dates back to September 2023, when five Bitcoin bridge deposit addresses were tied to a 560 BTC ransom. Those funds eventually crossed into the Avalanche network sometime in 2024.

A second payment of 72 BTC, traced to September 2025, showed more than 15% overlap with known ransomware wallets across compliance screening tools. About $1.36 million from that batch moved through instant exchanges before consolidating into a Tron wallet.

The most recent and largest payment — 164 BTC — was recorded in October 2025. Based on reports, around $3.8 million in bitcoin passed through instant exchanges before reaching Tron-linked outputs.

Bitcoin is now trading at $71,701. Chart: TradingView

Seven Tron addresses connected to that flow were frozen by Tether the following month. The frozen funds were later burned, confirming that enforcement action had been taken.

Meanwhile, an additional $16.6 million remains sitting in related addresses or platforms, with some of it already being cashed out.

Law Enforcement Now Has the Data

ZachXBT confirmed that compliance teams and law enforcement agencies have received detailed records of the traced addresses and fund movements. No arrests have been publicly announced.

Beyond the blockchain data, open-source intelligence painted a clearer picture of Khinkis as a person. Reports indicate he travels outside Russia regularly — including trips to Southeast Asia and Australia — and documents those trips openly on social media.

The 73 BTC still sitting dormant at a separate address hasn’t moved. If and when it does, investigators will almost certainly be watching.

Featured image from Pexels, chart from TradingView

Related Questions

QWho is the central figure identified in the alleged money laundering scheme, and what is his profession?

AThe central figure is Aleksandr Khinkis, a Russian OTC broker.

QWhat was the total amount of money laundered through the single crypto exchange account, and how many Bitcoin did the three ransomware payments total?

AMore than $4.7 million was laundered through the account, and the three ransomware payments totaled 796 BTC.

QWhat crucial piece of evidence did the undercover investigators obtain from Aleksandr Khinkis on Telegram?

AThe investigators obtained his exchange deposit address (0xa756...), which became the anchor point for the entire investigation.

QWhat action did Tether take regarding the seven Tron addresses connected to the most recent ransom payment?

ATether froze the funds in the seven Tron addresses, and the frozen funds were later burned.

QWhat significant amount of cryptocurrency remains untouched and is being monitored by investigators?

AA stash of 73 Bitcoin sitting in a separate wallet remains dormant and is being watched by investigators.

Related Reads

Cook's Curtain Call and Ternus Takes the Helm: The Disruption and Reboot of Apple's 4 Trillion Dollar Empire

Tim Cook has officially announced he will step down as CEO of Apple in September, transitioning to executive chairman after a 15-year tenure during which he grew the company’s market value from around $350 billion to nearly $4 trillion. He will be succeeded by John Ternus, a 50-year-old hardware engineering veteran who has been groomed for the role through increasing public visibility and internal responsibility. Ternus’s appointment signals a strategic shift toward hardware and engineering leadership, with Johny Srouji—head of Apple Silicon—taking on an expanded role as Chief Hardware Officer. This consolidation aims to strengthen Apple’s core technological capabilities. However, Cook’s departure highlights a significant unresolved issue: Apple’s delayed and fragmented approach to artificial intelligence. Despite early efforts, such as hiring John Giannandrea from Google in 2018, Apple’s AI initiatives—particularly around Siri—have struggled with internal restructuring and reliance on external partnerships, including with Google. The transition comes at a critical moment as Apple faces paradigm shifts with the rise of artificial general intelligence (ASI). The company’s closed ecosystem of hardware, software, and services—once a major advantage—now presents challenges in adapting to an AI-centric world where intelligence may matter more than the device itself. Ternus must quickly articulate a clear AI strategy, possibly starting at WWDC, to reassure markets and redefine Apple’s role in a new technological era. His task is not only to maintain Apple’s operational excellence but also to reinvigorate its capacity to innovate and lead in the age of AI.

marsbit2h ago

Cook's Curtain Call and Ternus Takes the Helm: The Disruption and Reboot of Apple's 4 Trillion Dollar Empire

marsbit2h ago

Trading

Spot
Futures
活动图片