Connect with us

Crypto

German Law Enforcement Seizes Russian No KYC Exchanges – Chainalysis

Published

on

German Law Enforcement Seizes Russian No KYC Exchanges – Chainalysis

On September 19, 2024, the German Federal Criminal Police (BKA) seized the infrastructure of 47 Russian-language no-KYC (Know Your Customer) cryptocurrency exchanges. Dubbed “Operation Final Exchange,” the takedown stands out not only for its breadth, but also for the light it has shined on the central role instant-swap style no-KYC exchanges play in facilitating on-chain cybercrime.

As their name suggests, no-KYC exchanges have no known process for collecting customer information before allowing any level of deposit or withdrawal. They do not require a name, phone number, or email address, and make no attempt to verify this information prior to permitting transactions. As such, these services allow a range of cybercriminals to abuse their services without KYC controls to identify or disrupt illicit activity. The BKA’s Operation Final Exchange landing page calls out ransomware affiliates, botnet operators, and darknet vendors as users of the 47 targeted exchanges. Beyond that, these services offered fiat on- and off-ramping for sanctioned Russian banks, creating an avenue for sanctions evasion.

Below, we’ll dive into these exchanges’ on-chain activity, explore their nexus to sanctioned Russian banks, and discuss the disruption’s implications.

Who are these 47 No KYC Exchanges?  

Our data reveals interesting patterns about the services targeted by the BKA, with robust direct and indirect exposure to various illicit services. At least seventeen of the exchanges saw a month of more than 50% of direct inflows from illicit sources. At least twelve saw a month where more than 30% of direct inflows were from darknet marketplaces (DNMs). At least six saw at least one month where stolen funds comprised more than 30% of total direct inflows. At least five had at least one month where more than 30% of indirect inflows were from sanctioned entities. 

This exposure demonstrates that for many of these services, laundering illicit funds was a substantial part of their businesses. Indeed, as depicted in the below Chainalysis Crypto Investigations graph, the top ten services targeted by the BKA transacted with a broad array of illicit services, including, but not limited to, sanctioned entities, ransomware actors, DNMs, and darkweb escrow and breached data brokers. 

Advertisement

The chart below shows the quarterly inflows to the top ten exchanges taken down by the BKA. These services received value from a variety of sources, including periods of significant inflows from drug-related DNMs, online pharmacies, malicious cybercriminals such as ransomware gangs, and funds stolen in heists and scams.

There is also a notable increase over time in the proportion of inflows from legitimate sources, notably centralized exchanges. While this change to the composition of inflows might in other circumstances suggest that the services were in the process of cleaning up their platforms, the reality is likely more complicated. In this case, the increased inflows from otherwise legitimate sources most likely represent the growing use of these services for sanctions evasion on the part of Russian nationals, who are likely trying to leverage these no KYC exchanges to evade sanctions on Russian banks. 

How do these services work?

These services operate as instant-swap style services, in which users, without providing any personal information or going through any verification process, can swap from one currency to another. The offerings include crypto-to-crypto and fiat-to-crypto swaps, allowing users to instantly exchange popular cryptocurrencies and stablecoins, or to connect their bank account to on-/off-ramp fiat to crypto instantly.

As with other categories of the illicit crypto ecosystem, we have observed that no KYC exchanges, particularly those targeted by the BKA, often have overlapping or similar on-chain infrastructure, and in some instances even share off-chain networks, such as website shells, employees and administrators, physical locations, and ownership structures, to name a few. More often than not, these websites have no affiliated company incorporation, registration, phone numbers, physical addresses, or any indicator of jurisdictional operation. Unlike other high-risk and illicit services, most of these services do not have a social media presence, instead offering users the ability to interface with a bot on their homepages. Despite using servers based in Germany, these services cater primarily to a Russian clientele, as suggested by their default language settings in Russian and information on banking services for fiat transactions provided by sanctioned Russian banks, such as Sberbank. 

Advertisement

Connectivity to sanctioned Russian banks

Many of the 47 no KYC exchanges were Russian-language platforms offering fiat-to-crypto and crypto-to-crypto instant exchange services. As we covered in our recent analysis of Russia’s new cryptocurrency legislation, Russian-language instant exchangers can be exploited to quickly move fiat currency from sanctioned Russian banks to specified crypto wallets, enabling entities to evade sanctions. Given the dramatically increased sanctions pressure on Russian banks following the full-scale invasion of Ukraine in February 2022, instant exchangers have emerged as a convenient way to on- or off-ramp funds for sanctioned banks. Of the 47 no KYC exchanges targeted in Operation Final Exchange, all that we have identified on-chain accepted on- and off-ramping with sanctioned Russian banks.

Breadth of disruption likely to generate actionable inroads 

Most of the exchanges targeted by BKA have been active since 2021 or before, and the top three in terms of transactions processed – Xchange.cash, 60cek.org, and Bankcomat.com – have been active since 2016 or before, according to the Operation Final Exchange landing page. The longevity of these services suggests a substantial portion of customers affected will need to establish alternative financial facilitation and laundering pathways.

The disruption’s impact is likely to extend far beyond the no KYC exchanges targeted. As the BKA stated, it is now in possession of these exchanges’ development, production, and backup servers, as well as transactional details, registration data, and IP addresses. This data will likely be instrumental in generating follow-on leads for the BKA and key international law enforcement partners in the months to come. We continue to track this phenomenon closely and will flag new no KYC exchanges that emerge as key players in this space. 

This website contains links to third-party sites that are not under the control of Chainalysis, Inc. or its affiliates (collectively “Chainalysis”). Access to such information does not imply association with, endorsement of, approval of, or recommendation by Chainalysis of the site or its operators, and Chainalysis is not responsible for the products, services, or other content hosted therein. 

This material is for informational purposes only, and is not intended to provide legal, tax, financial, or investment advice. Recipients should consult their own advisors before making these types of decisions. Chainalysis has no responsibility or liability for any decision made or any other acts or omissions in connection with Recipient’s use of this material.

Advertisement

Chainalysis does not guarantee or warrant the accuracy, completeness, timeliness, suitability or validity of the information in this report and will not be responsible for any claim attributable to errors, omissions, or other inaccuracies of any part of such material.

Crypto

Report Shows Massive Increase in Iranian Bitcoin Adoption Amid Nationwide Unrest

Published

on

Report Shows Massive Increase in Iranian Bitcoin Adoption Amid Nationwide Unrest

A new report from blockchain analytics firm Chainalysis indicates there has been a massive increase in Bitcoin adoption in Iran over the past month, as the country deals with nationwide unrest and protests. The report specifically looks at the increase in withdrawals from crypto exchanges to unknown Bitcoin addresses, which indicates the local population is avoiding centralized financial infrastructure in the country in favor of the decentralized, peer-to-peer digital cash system.

In terms of specifics, the report shows a 262% increase in the amount of withdrawals valued at more than $10,000 into what are thought to be self-custodial bitcoin wallets since the nationwide protests began. According to the report, reasons for the increased interest in self-custodial bitcoin include the collapse in value in the Iranian rial and the potential increased need for citizens to operate outside of government-controlled financial channels.

The report also indicates spikes in Iranian crypto activity were seen during other major domestic and geopolitical events such as the Kerman bombings in January 2024, Iran’s missile strikes against Israel in October 2024, and the 12-day war. Nobitex, which is by far Iran’s largest and most popular exchange, was also hacked for $90 million during the 12-day war.

“This pattern of increased BTC withdrawals during times of heightened instability reflects a global trend we’ve observed in other regions experiencing war, economic turmoil, or government crackdowns,” says the report.

To Chainalysis’s point, this is not the first time a sharp increase in Bitcoin adoption has been noticed in a country dealing with some sort of crisis. In the past, Chainalysis has issued reports involving increased adoption in Ukraine amid war with Russia, Argentina and Venezuela’s respective currency devaluations, and more.

Advertisement

More recently, countries like Venezuela and Russia have used bitcoin and stablecoins like Tether’s USDT to avoid economic sanctions. According to another recent report from Chainalysis, this sort of sanctions avoidance was behind crypto’s record year of $154 billion worth of illicit financial use.

Unrest has persisted in Iran since late December, as protesters are fed up with the devaluation of the Iranian rial and other economic hardships. These grievances are compounded by longer-term issues such as corruption, repression, and general government mismanagement. In this way, the use of Bitcoin itself can also be seen as a form of protest where people are simply opting out of the traditional financial system.

Ironically, the Iranian regime has also been found to have used crypto for avoiding sanctions and laundering funds. In fact, the same Chainalysis report just released also indicates the Islamic Revolutionary Guard Corps (IRGC) accounts for roughly half of all crypto activity taking place in Iran, which is estimated at $7.78 billion. A recent report from TRM Labs also indicated two crypto exchanges in the United Kingdom were effectively fronts for the Iranian regime, and another past report from Elliptic shows Iran has been involved in bitcoin mining for purposes of monetizing their energy resources.

This situation illustrates the conundrum for authoritarian regimes around the world when it comes to Bitcoin, as the features that make it useful for the regime to avoid restrictions in the US-controlled global banking system also enable it to be used for the local population to gain greater financial freedom.

Bitcoin is not the only technology that has proven helpful for Iranians during the protests, as the existence of Starlink is one of the only reasons information has been able to get out of the country amid government-imposed internet blackouts. While mesh-networking based Bitchat has seen increased adoption in other countries dealing with turmoil recently, a forked version of the app called Noghteha has gained notoriety in Iran. Although, there has been controversy with Noghteha due to its closed source aspects and collection of donations.

Advertisement
Continue Reading

Crypto

Analyst Calls Silver Generational Bottom, Sees Long-Term Bull Market Ahead

Published

on

Analyst Calls Silver Generational Bottom, Sees Long-Term Bull Market Ahead
Silver prices surged sharply, reigniting bullish forecasts, generational-bottom calls, and debate over how far the rally can run as investors weigh upside potential against timing profits in an emerging long-term commodities cycle.
Continue Reading

Crypto

Best Cryptocurrency Stocks To Follow Now

Published

on

Best Cryptocurrency Stocks To Follow Now
Galaxy Digital, Bitfarms, HIVE Digital Technologies, Digi Power X, and Soluna are the five Cryptocurrency stocks to watch today, according to MarketBeat’s stock screener tool. “Cryptocurrency stocks” are shares of publicly traded companies whose business models or balance sheets are materially tied
Continue Reading

Trending