Cryptocurrency laundromat Blender shredded by US Treasury in sanctions first

Helping North Korea? Uncle Sam would like a word


The US Treasury has sanctioned cryptocurrency mixer Blender for its role in helping North Korea's Lazarus Group launder stolen digital assets. 

As a result, among other limitations, anyone in the United States or a US person can no longer do any business with Blender without special permission from the government.

This marks the Feds' first-ever sanctions against a crypto mixer, which cybercriminals can use to cover their tracks. As the name might suggest, cryptocurrency mixing, or tumbling, can obscure the source of some digital money. The laundered coins cannot be traced back to, say, a wallet robbed of its contents, allowing crooks to spend their ill-gotten gains without being linked to their crimes.

Such services have legitimate privacy uses, though Uncle Sam isn't happy that it can be used to make life easy for criminals, and so it's cracking down on the practice.

Lazarus Group is the cybercrime gang that does the dirty work for North Korea's Reconnaissance General Bureau. In late March, when the miscreants carried out the largest-ever virtual currency heist, stealing about $620 million from video game Axie Infinity's Ronin Network, they used Blender to process over $20.5 million of the illicit proceeds.

"Virtual currency mixers that assist illicit transactions pose a threat to US national security interests," Brian Nelson, under secretary of the Treasury for terrorism and financial intelligence said in a statement today. "We are taking action against illicit financial activity by the DPRK and will not allow state-sponsored thievery and its money-laundering enablers to go unanswered."

Blender also helps several Russian-backed ransomware gangs launder money, according to the department. These include Trickbot, Conti, Ryuk, REvil, and Gandcrab.

Mix and match

Here's an example of how mixers work: after a ransomware attack or a crypto-wallet theft, the crooks take their ill-gotten gains and begin the money laundering process by "mixing" criminal proceeds, via Blender or another crypto mixer, with other netizens' funds. 

Mixing illicit proceeds with a variety of other transactions, many of which are legitimate, allows criminals to obfuscate the origin of their gains. The mixed funds are then transmitted to their final destination in the hopes of escaping Uncle Sam's watchful eye. And while the purported use for Blender and other mixing services is to increase privacy, they are very popular among thieves.

Blender has helped transfer more than $500 million in Bitcoin since its creation in 2017, according to the Treasury.

In April, the Feds attributed the Axie Infinity heist to the Lazarus Group, and fingered gang's getaway wallet address. 

Today, as well as publicizing the sanctions, Treasury officials identified four more virtual currency wallet addresses the Lazarus Group is said to have used to launder the remainder of stolen electronic cash.

A day after attributing the heist to the Lazarus Group, the US State Department offered a reward up to $5 million for information that helps disrupt North Korea's cryptocurrency theft, cyber-espionage, and other illicit state-backed activities.

The US government has also warned that Lazarus is expanding its attacks in the blockchain and crypto space. Specifically, it's sending large numbers of spear-phishing messages to employees of cryptocurrency companies on a range of communications platforms that – as with the campaigns against chemical and IT firms – often look like recruitment offers for high-paying jobs, according to the FBI, CISA, and the Treasury Department. ®


Other stories you might like

  • China reveals its top five sources of online fraud
    'Brushing' tops the list, as quantity of forbidden content continue to rise

    China’s Ministry of Public Security has revealed the five most prevalent types of fraud perpetrated online or by phone.

    The e-commerce scam known as “brushing” topped the list and accounted for around a third of all internet fraud activity in China. Brushing sees victims lured into making payment for goods that may not be delivered, or are only delivered after buyers are asked to perform several other online tasks that may include downloading dodgy apps and/or establishing e-commerce profiles. Victims can find themselves being asked to pay more than the original price for goods, or denied promised rebates.

    Brushing has also seen e-commerce providers send victims small items they never ordered, using profiles victims did not create or control. Dodgy vendors use that tactic to then write themselves glowing product reviews that increase their visibility on marketplace platforms.

    Continue reading
  • Oracle really does owe HPE $3b after Supreme Court snub
    Appeal petition as doomed as the Itanic chips at the heart of decade-long drama

    The US Supreme Court on Monday declined to hear Oracle's appeal to overturn a ruling ordering the IT giant to pay $3 billion in damages for violating a decades-old contract agreement.

    In June 2011, back when HPE had not yet split from HP, the biz sued Oracle for refusing to add Itanium support to its database software. HP alleged Big Red had violated a contract agreement by not doing so, though Oracle claimed it explicitly refused requests to support Intel's Itanium processors at the time.

    A lengthy legal battle ensued. Oracle was ordered to cough up $3 billion in damages in a jury trial, and appealed the decision all the way to the highest judges in America. Now, the Supreme Court has declined its petition.

    Continue reading
  • Infusion of $3.5bn not enough to revive Terra's 'stablecoin'
    Estimated $42bn vanished with collapse of UST, Luna – we explain what all this means

    TerraUSD, a so-called "stablecoin," has seen its value drop from $1 apiece a week ago to about $0.09 on Monday, demonstrating not all that much stability.

    The cryptocurrency token, abbreviated UST, is supposed to be pegged to the price of the US dollar. Hence the "stable" terminology.

    But UST is not a "centralized stablecoin" that's exchangeable for a fiat currency; UST for USD (US dollars). Rather, it's a "decentralized stablecoin," meaning it can be exchanged for Luna (LUNA) tokens, another cryptocurrency tied to the Terra blockchain.

    Continue reading
  • DigitalOcean tries to take sting out of price hike with $4 VM
    Cloud biz says it is reacting to customer mix largely shifting from lone devs to SMBs

    DigitalOcean attempted to lessen the sting of higher prices this week by announcing a cut-rate instance aimed at developers and hobbyists.

    The $4-a-month droplet — what the infrastructure-as-a-service outfit calls its virtual machines — pairs a single virtual CPU with 512 MB of memory, 10 GB of SSD storage, and 500 GB a month in network bandwidth.

    The launch comes as DigitalOcean plans a sweeping price hike across much of its product portfolio, effective July 1. On the low-end, most instances will see pricing increase between $1 and $16 a month, but on the high-end, some products will see increases of as much as $120 in the case of DigitalOceans’ top-tier storage-optimized virtual machines.

    Continue reading
  • GPL legal battle: Vizio told by judge it will have to answer breach-of-contract claims
    Fine-print crucially deemed contractual agreement as well as copyright license in smartTV source-code case

    The Software Freedom Conservancy (SFC) has won a significant legal victory in its ongoing effort to force Vizio to publish the source code of its SmartCast TV software, which is said to contain GPLv2 and LGPLv2.1 copyleft-licensed components.

    SFC sued Vizio, claiming it was in breach of contract by failing to obey the terms of the GPLv2 and LGPLv2.1 licenses that require source code to be made public when certain conditions are met, and sought declaratory relief on behalf of Vizio TV owners. SFC wanted its breach-of-contract arguments to be heard by the Orange County Superior Court in California, though Vizio kicked the matter up to the district court level in central California where it hoped to avoid the contract issue and defend its corner using just federal copyright law.

    On Friday, Federal District Judge Josephine Staton sided with SFC and granted its motion to send its lawsuit back to superior court. To do so, Judge Staton had to decide whether or not the federal Copyright Act preempted the SFC's breach-of-contract allegations; in the end, she decided it didn't.

    Continue reading

Biting the hand that feeds IT © 1998–2022