Dirty Crypto, Clean Money: How Russophone Hackers Launder Billions

· Investigative Research

Digital illustration of cryptocurrency flows moving through exchanges

In 2025, illicit cryptocurrency addresses received at least $154 billion — a 162% jump from the previous year, and the figure was overwhelmingly driven by a 694% surge in funds flowing to sanctioned entities. Behind that spike sits a quieter, more mechanical story: how criminal and state-linked networks actually move dirty money through the crypto system and out the other side clean.

Russophone actors sit at the center of it. Russia's ruble-backed A7A5 stablecoin alone processed $93.3 billion in under a year, functioning as a bridge that let Russian businesses reach global markets despite sanctions. The infrastructure behind it didn't appear from nothing — Grinex, the exchange now central to this flow, is the direct successor to Garantex, the Russian exchange sanctioned back in 2022. When Garantex's online infrastructure was disrupted in March 2025, on-chain data captured the handoff in real time: a mass transfer of user funds and newly minted A7A5 tokens moving straight from Garantex wallets to Grinex — less a shutdown than a rebrand.

What makes this laundering machine hard to police isn't secrecy — it's disguise. Stablecoins now account for 84% of all illicit transaction volume, precisely because they behave like ordinary financial activity: stable in value, easy to move across borders, and functionally indistinguishable on-chain from a legitimate remittance or business payment. That blending-in is the playbook. This piece traces how it works — from the mechanics of the wash, to the exchanges and brokers built to disguise it, to what enforcement has actually managed to stop.

1. The Headline Number, in Context

Start with the number everyone is quoting: illicit crypto addresses took in at least $154 billion in 2025, according to blockchain analytics firm Chainalysis. That's a 162% increase over 2024's revised figure of roughly $57.2 billion. It's a genuinely record-breaking year for on-chain crime.

But the honest version of this story needs a second number right next to the first one: even at $154 billion, illicit activity is still estimated at less than 1% of all attributed crypto transaction volume. The crypto economy is enormous, and the overwhelming majority of it is ordinary, legal activity — trading, savings, payments, remittances. That context matters, because headlines built on the $154 billion figure alone can make crypto sound like a criminal enterprise by default. It isn't. It's a general-purpose financial rail that a small, well-organized set of actors have learned to abuse very effectively.

So why the 162% jump? Not from a broad increase in scams or ransomware. The single biggest driver was a 694% year-over-year increase in value received by sanctioned entities — meaning wallets, exchanges, and tokens tied to individuals, companies, or governments already under formal sanctions. And within that category, one country stands out disproportionately: Russia. That's the pivot point for the rest of this article. Understanding why requires looking at the specific tool Russian actors built to solve a specific problem — how do you move money internationally when your banks are cut off from the world?

2. Meet the Machine: A7A5 and the Ruble Bridge

A7A5 is a stablecoin — a cryptocurrency designed to hold a stable value, usually by being pegged to a real-world currency or asset. Most major stablecoins (like USDT or USDC) are pegged to the US dollar. A7A5 is different: it's pegged to the Russian ruble, issued through Russian-linked financial infrastructure, and built at a moment when Russian banks were being systematically cut off from SWIFT and other international payment networks by Western sanctions.

The scale is what makes A7A5 remarkable. In under a year, it processed $93.3 billion in transaction volume — acting, in effect, as a financial bridge that let Russian businesses settle international trade despite being locked out of the traditional banking system. Some of that volume is likely to be ordinary commerce: companies that legitimately need a way to pay overseas suppliers. But a token built specifically to route around sanctions is, by design, also an extremely efficient tool for anyone else who needs to move money while evading the same sanctions — including cybercriminal groups whose ransom and theft proceeds are already effectively "sanctioned" the moment they're traced.

One quirk in the data reinforces this dual-use pattern: unlike typical retail crypto tokens, A7A5 trading volume surges Monday through Friday and drops sharply on weekends — a pattern that looks far more like business and institutional settlement activity than casual retail trading. That's a signal analysts point to as evidence the token is functioning as real financial infrastructure, not just a speculative asset — which is exactly what makes it durable, and exactly what makes it hard to dislodge with sanctions alone.

Diagram showing stablecoin transaction flow between exchanges

3. Garantex to Grinex: Anatomy of a Rebrand

If A7A5 is the bridge, Grinex is the crossing point — and its origin story is a case study in what sanctions enforcement is actually up against.

Garantex was a Russian crypto exchange sanctioned by the US Treasury back in 2022 for facilitating money laundering, including funds tied to ransomware and darknet marketplace activity. Sanctions restricted US persons and entities from dealing with it, and international pressure mounted for years afterward. In March 2025, law enforcement and infrastructure providers moved to disrupt Garantex's online operations directly — seizing domains and cutting off its ability to function normally.

What happened next is the part worth paying attention to. On-chain investigators watched, in near real time, as user funds and newly minted A7A5 tokens moved directly out of Garantex-linked wallets and into a new exchange: Grinex. Same user base, same liquidity, same underlying operators by most assessments — just a new name and a new domain. Rather than the enforcement action ending the operation, it triggered a rebrand, executed fast enough to preserve most of the exchange's liquidity and continuity.

This pattern — sanction the entity, watch it reappear under a new name days or weeks later — is not unique to Garantex. It's close to a standard operating procedure among Russian-linked exchanges and payment processors. In September 2024, the US Justice Department charged two Russian nationals for allegedly operating PM2BTC and Cryptex, exchanger services accused of processing hundreds of millions of dollars for ransomware actors, initial access brokers, and darknet marketplace vendors — while a third Russian platform, UAPS, was named as having provided illicit payment processing for nearly two decades. And in the UK, a joint law enforcement effort called Operation Destabilise dismantled two Russian-run laundering networks, TGR and Smart, which had washed money for ransomware crews including Evil Corp and Conti — with one network reportedly having gone as far as acquiring its own bank to obscure the money trail. Forty-five suspected launderers were arrested in the effort's first year.

Taken together, these cases show a consistent shape: sanctions disrupt branding far more reliably than they disrupt operations. The people, the liquidity, and the client relationships tend to survive; only the name on the door changes.

4. Why Stablecoins Are the Perfect Disguise

Here's the thesis of this entire article in one sentence: modern crypto laundering isn't primarily about hiding — it's about blending in.

A decade ago, the image of crypto crime involved mixers and tumblers — services designed to scramble the trail of a transaction so it couldn't be traced back to its source. Those tools still exist, but the center of gravity has shifted. Today, 84% of all illicit crypto transaction volume moves through stablecoins, not privacy coins or mixers. That's not because stablecoins are harder to trace — on-chain analysts can usually follow a stablecoin transaction just as easily as any other. It's because stablecoins don't need to hide. They look exactly like the billions of dollars of completely legitimate stablecoin transactions happening every single day: cross-border remittances, business settlements, exchange deposits, payroll for remote contractors.

Add in the practical advantages — low volatility compared to Bitcoin, fast settlement, and broad acceptance across exchanges worldwide — and stablecoins become the obvious tool for anyone who needs to move a large sum of money internationally without triggering the kind of scrutiny a sudden six-figure bank wire would attract. A ransomware payout converted into stablecoins and routed through an OTC broker looks, on the surface, identical to a mid-sized company paying an overseas vendor.

Laid side by side against the alternatives, it's easy to see why stablecoins have become the default choice:

Stablecoins vs. Bitcoin vs. Privacy Coins: Why Launderers Choose Stablecoins
Factor Stablecoins (e.g., USDT, A7A5) Bitcoin Privacy Coins (e.g., Monero)
Price volatility Low — pegged to a fiat currency High — value can swing significantly in hours High — similar volatility to Bitcoin
On-chain traceability Fully traceable, but blends in with legitimate volume Fully traceable and closely watched by forensics firms Deliberately obscured by design
Share of illicit transaction volume (2025) 84% Minority share, declining Small but persistent niche
Issuer can freeze funds Yes — centralized issuers like Tether can freeze flagged addresses No — no central issuer to intervene No — no central issuer, and tracing is harder to begin with
Exchange and merchant acceptance Very broad Broad Limited — many exchanges delist privacy coins under regulatory pressure
"Blends in" with legitimate activity Yes — used constantly for remittances and trade settlement Partially — still associated with speculation and crime in public perception No — usage itself can draw scrutiny

The pattern in that table explains the strategic shift covered in Section 6: privacy coins optimize for not being traced, but that very optimization makes them conspicuous and increasingly hard to cash out through mainstream exchanges. Stablecoins optimize for looking ordinary — and ordinary is much harder to police at scale.

This is also why blockchain forensics increasingly focuses less on "can we trace this transaction" and more on "can we identify the human intermediaries" — the brokers, exchanges, and payment processors who connect illicit wallets to real-world cash. That's the subject of the next section.

5. Who's Actually Moving This Money

The Russophone cybercrime ecosystem is not one group — it's an economy of specialists, and laundering is just one service line among many. The same networks that develop and distribute infostealer malware like Lumma and RedLine, resell stolen credentials on underground markets, run bulletproof hosting for criminal infrastructure, and broker initial network access for ransomware crews also rely on a parallel layer of financial specialists whose only job is turning stolen or extorted crypto into spendable cash.

A case made public in March 2026 shows how small that layer can actually be. Blockchain investigator ZachXBT, posing as a client on Telegram, traced how a single Russian OTC broker, Aleksandr Khinkis, allegedly helped launder more than $4.7 million tied to at least three separate ransomware payments totaling 796 BTC — some dating back to a 2023 incident. The laundering route didn't rely on a single trick; it blended OTC brokerage, cross-chain bridging from Bitcoin into Avalanche, instant-swap services, and even parking funds in decentralized finance lending protocols before eventually cashing out through stablecoins — all funneling through one exchange deposit account. Tether reportedly froze some of the related addresses after the ransom incidents came to light, illustrating one of the few structural advantages investigators have: unlike Bitcoin, centralized stablecoin issuers can freeze funds after the fact.

Separately, in April 2026, a US-based operator named Iurii Gugnin pleaded guilty to processing roughly $530 million in payments on behalf of sanctioned Russian banks and clients while defrauding US financial institutions about the true nature of the transactions — a reminder that this ecosystem doesn't only run through obviously "criminal" infrastructure. Sometimes it runs through seemingly ordinary payment processing businesses operating inside the same financial system everyone else uses.

What connects the Khinkis case, the PM2BTC and Cryptex prosecutions, and the TGR/Smart network takedown in the UK is the same structural insight: the choke point in this economy is rarely the malware or the initial hack. It's the small number of human brokers and exchange accounts that every laundering trail eventually has to pass through. Reducing readers' exposure to this space starts with understanding it, which is why resources like Torzle's investigative breakdown of how social engineering and deception ecosystems operate exist — mapping how these networks recruit, deceive, and move money is a prerequisite to defending against them.

6. Can It Be Stopped? Enforcement and Its Limits

Follow the enforcement timeline closely enough and a pattern starts to feel less like a string of victories and more like a long game of whack-a-mole, played at a global scale.

Garantex gets sanctioned in 2022. It keeps operating for three more years. Its infrastructure finally gets disrupted in March 2025 — and within what appears to be days, its liquidity, its user base, and very likely its operators resurface as Grinex. PM2BTC and Cryptex get sanctioned and their domains seized in September 2024 — but the underlying demand for Russian-language, sanctions-resistant crypto exchange services doesn't disappear with them; it simply looks for the next platform. TGR and Smart get dismantled by UK and international law enforcement in Operation Destabilise, with 45 arrests and millions in cash seized — a genuine win, and one worth taking seriously, but one laundering network's takedown doesn't shrink the $154 billion figure by much on its own.

The honest picture is this: enforcement is winning individual battles, and those battles matter — arrests happen, domains get seized, funds occasionally get frozen or recovered (UK authorities alone recovered 61,000 BTC in seizures tied to broader crypto crime enforcement in the past year). But the underlying infrastructure — OTC brokers, exchange accounts, bridging services, and now sanctioned-currency-backed stablecoins like A7A5 — regenerates faster than any single agency can dismantle it, because the demand driving it (sanctions evasion, ransomware monetization, state-linked financial pressure) hasn't gone away. If anything, geopolitical pressure has made that demand more acute, not less.

Where progress is real is in attribution and speed. Blockchain forensics firms and independent investigators like ZachXBT can now trace a laundering route from a ransom payment to an exchange deposit address in days, not years — a dramatic shift from a decade ago. Stablecoin issuers freezing funds after the fact, as Tether did in the Khinkis case, is a structural advantage that doesn't exist with Bitcoin or privacy coins. The fight isn't unwinnable. But it is, for now, a fight against an ecosystem that treats every takedown as a rebranding opportunity.

7. Conclusion: Hiding vs. Blending In

The throughline of this entire investigation is a shift in strategy, not just scale. A decade ago, laundering crypto meant hiding it — mixers, tumblers, privacy coins, anything to break the on-chain trail. Today, the far more effective approach is to not hide at all, but to blend in: move dirty money through the exact same rails, the exact same stablecoins, and often the exact same exchange accounts as billions of dollars of completely legitimate activity every day.

That's what makes Russophone laundering networks worth watching closely right now. A7A5 and the Garantex-to-Grinex rebrand aren't isolated incidents — they're a preview of where sanctions-resistant financial infrastructure is headed globally, built by actors with every incentive to make it durable. Expect more purpose-built, currency-pegged stablecoins, more OTC brokers acting as the human choke point between crime and cash, and more rebrands the moment enforcement lands a hit.

For readers and researchers trying to understand this landscape rather than navigate it, the goal isn't to follow the money into these systems — it's to understand the mechanics well enough to recognize them. That's the same principle behind investigative resources on the broader dark web ecosystem, including Torzle's guide explaining the actual differences between the surface, deep, and dark web, its roundup of the privacy tools researchers rely on in 2025, and its comparison of the best privacy protection apps for everyday security. Understanding the playbook is the first step toward defending against it — for regulators, for investigators, and for anyone trying to make sense of where illicit finance is actually headed.

Blockchain forensics investigators analyzing transaction data on screens

Key Takeaways

  • Illicit crypto addresses received at least $154 billion in 2025 — a 162% increase, driven almost entirely by a 694% surge in sanctioned-entity activity.
  • Despite the record figure, illicit activity remains under 1% of total attributed crypto transaction volume.
  • Russia's ruble-pegged A7A5 stablecoin processed $93.3 billion in under a year, functioning as a sanctions-evasion bridge for Russian businesses and, by extension, criminal actors.
  • Garantex, sanctioned in 2022, resurfaced as Grinex within days of a March 2025 enforcement action — funds and tokens moved directly between the two.
  • Stablecoins now account for 84% of all illicit transaction volume because they blend in with legitimate financial activity rather than trying to hide.
  • Human intermediaries — OTC brokers, exchange operators, payment processors — are the real choke point in these networks, as shown by the Khinkis, PM2BTC/Cryptex, and TGR/Smart cases.
  • Enforcement is improving in speed and attribution, but the underlying infrastructure regenerates faster than agencies can dismantle it.

Frequently Asked Questions

What does "laundering crypto" actually mean?

It means converting cryptocurrency that came from a crime — a ransomware payment, a stolen fund, a scam — into money or assets that appear clean, so it can be spent or moved without immediately being flagged as tied to criminal activity. On the blockchain, this usually means moving funds through multiple wallets, exchanges, or currencies to obscure the original source before eventually cashing out.

Why are stablecoins used more than Bitcoin for laundering now?

Stablecoins hold a steady value, move quickly across borders, and are widely accepted — which makes them look identical to ordinary legitimate transactions. Bitcoin's price volatility and its long association with crime actually make it a less convenient laundering tool by comparison.

What is dark web monitoring, and how does it relate to this?

Dark web monitoring is the practice of tracking activity on dark web forums, marketplaces, and leak sites to identify stolen data, compromised credentials, or emerging criminal infrastructure before it causes harm. It's a related but distinct discipline from blockchain forensics — one tracks where stolen goods and access are sold, the other tracks where the resulting money goes. Researchers often use both together to build a full picture of a criminal network.

Can law enforcement actually recover laundered crypto?

Sometimes. Recovery is easiest with centralized stablecoins, whose issuers can freeze funds at flagged addresses, and in cases where investigators can identify a real-world custodial exchange holding the funds. UK authorities, for example, recovered 61,000 BTC in a single case tied to broader crypto crime enforcement. Recovery becomes far harder once funds pass through decentralized exchanges, cross-chain bridges, or jurisdictions unwilling to cooperate.

Is all crypto activity linked to Russia illicit?

No. The vast majority of crypto transaction volume — including much of the activity flowing through Russian-linked stablecoins and exchanges — is ordinary commerce by businesses and individuals working around a banking system cut off by sanctions. The illicit share, while a real and growing problem, is a minority of that overall volume.