Blockchain analytics firm Chainalysis notes that on June 11, 2026, law enforcement agencies from multiple countries disrupted a sophisticated cryptocurrency laundering service known as AudiA6. This platform had become a key resource for cybercriminals, particularly those involved in ransomware campaigns and digital asset thefts. The operation highlights growing collaboration between public authorities and blockchain intelligence firms in combating illicit financial flows in the digital economy.
Led by the US Department of Justice and Secret Service, alongside Europol and other partners, the coordinated raid resulted in the arrest of two primary operators in the Republic of Georgia.
The suspects—a 37-year-old Ukrainian citizen and a 25-year-old Russian national—face charges related to managing the laundering network.
Officials also seized control of associated websites and infrastructure, replacing them with official notices, while dismantling numerous servers and domains in the United States and across Europe.
AudiA6 functioned as a professional “mixer-as-a-service,” allowing clients to deposit illicit cryptocurrency and receive cleaned funds in return for a fee ranging from 3 to 10 percent.
Blockchain tracing revealed that the service had handled roughly 10,333 bitcoin since its emergence around 2021, equivalent to approximately $389 million based on historical prices.
A substantial portion of these inflows— at least 393 BTC worth over $19 million historically—could be directly linked to ransomware groups, underground marketplaces, and other illegal activities.
The service maintained close ties to Dark2Web, a clandestine online forum that served as a hub for ransomware operators, hackers, and other threat actors.
Administrators of AudiA6 reportedly ran this forum, using it to promote their laundering capabilities and connect with potential users.
Dark2Web facilitated networking and transactions within the cybercrime community, including links to Russian-language darknet platforms like Exploit.in.
By integrating the forum with the laundering pipeline, operators provided end-to-end support for criminals seeking to cash out stolen assets without immediate detection.
At the core of AudiA6’s operations was an extensive network of over 6,000 KYC-verified money mule accounts on legitimate exchanges.
Criminals would send stolen funds to controlled wallets, after which the service would distribute and layer the assets through these fraudulent accounts.
This process typically allowed “clean” cryptocurrency to be returned to clients within about an hour.
The approach exploited centralized platforms while breaking the traceable chain on the blockchain.
Authorities noted direct connections between the network and sanctioned Russian exchanges such as Bitzlato and Garantex, underscoring its role in supporting Eastern European cybercrime rings.
This takedown echoes previous actions against similar services, such as the 2024 sanctions and seizures involving Cryptex and related platforms.
Such disruptions send ripples through the underground economy, forcing actors to seek new, often less reliable alternatives.
For cryptocurrency businesses and compliance professionals, the case emphasizes persistent risks from large-scale identity fraud and money mule schemes.
Virtual asset service providers are urged to strengthen ongoing transaction monitoring beyond initial customer checks, watching for patterns like sudden inflows from unhosted wallets followed by quick withdrawals.
Europol has shared specific domains used in account registrations, encouraging platforms to review and act on potential exposures.
The latest AudiA6 operation represents a meaningful blow to the financial infrastructure sustaining global cybercrime. Chainalysis has now concluded that as authorities and industry partners continue to share intelligence and leverage blockchain analytics, these collaborative efforts are now expected to raise the operational costs and risks for bad actors.