The images in this article were generated with artificial intelligence. How we publish
The international authorities have dismantled a cryptomoneda mixing service known as Audit, noted as a central node in the laundering of funds from attacks of ransomware and other cybercrimes for a value that, according to different estimates, exceeds the $380 million(Europol estimated the operation at around €336 million). The operation, which involved prosecutors and police from more than a dozen countries supported by Europol and Eurojust, culminated in arrests, seizures of domains and assets, and the deployment of seizure banners at the sites involved.
The mechanism described by the researchers is not novel in its principle, but in its scale: AudiA6 was promoted as a "professional mixing service," and in practice it accepted illicit funds, distributed them through complex transactional routes to hide their origin and returned "clean" amounts to the shipping companies after charging commissions of 3 to 10%. The experts found thousands of fraudulent exchange accounts created with stolen or purchased identities, and about 6,000 KYC records linked to milling accounts, which allowed operators to convert movements in the block chain into cash and goods in the real world.

The success of the investigation was driven by arrests and forensic analysis of devices: after an arrest in Poland, investigators obtained evidence that led to additional arrests in Georgia; the U.S. Department of Justice issued charges against two alleged administrators, identified by name, who now face sentences of up to 20 years. The actions included the seizure of 25 domains, the search for properties, the blocking of communication channels used by the network and the freezing of goods in cryptomonedas for hundreds of thousands of euros. The official communiqués provide additional details on the investigation and the indictment: Europol and Department of Justice explain charges and evidence.
This case again demonstrates two realities of the cryptoactive ecosystem: first, that the relative usability and anonymity of certain currencies and services continue to attract financial crime operators; second, that public chains are not always a safe haven for criminals when forensic techniques and international cooperation are applied. Researchers and private companies - including blockchain analysts who had warned about AudiA6 - have shown that with tools of traceability and collaboration between platforms the washing routes can be detected and cut; see trend analysis on crypt- crime can help contextualize these risks, for example in reports such as Chainalysis on crime in cryptomonedas ( Chainalysis Crypto Crime Report).

For the exchange of cryptomonedas and digital financial service providers, the lessons are clear: strengthening KYC / AML processes is not enough if atypical operating patterns, new registration domains and milling behaviour are not monitored; sharing commitment indicators (IOCs) and domain lists with other platforms and authorities speed up network blocking and reduce the rotation of offenders between services. At the technical level, real-time monitoring of flows to and from darknet markets, identification of wallet clusters associated with mixing services and integration of off- chain signals (Telegram messaging, underground forums) improve detection.
Organizations that are potential Ransomware objectives should also take note: the detention of washing machines does not eliminate the motivation of extortion groups, so companies should strengthen preventive measures, test their controls with simulation exercises and prioritize the segregation of networks, verified backup and response plans that include contact with financial and forensic authorities. For individual users, the recommendation is to avoid any involvement with mixing services that promise to "clean up" funds and protect personal information so as not to become a victim of identity theft that facilitates the opening of fraudulent accounts.
The operation against AudiA6 marks an operational and symbolic victory: it shows that the criminal financial infrastructure can be dismantled, but it also shows the speed with which criminal groups reinvent routes and services. The response requires, in addition to arrests, a sustained strengthening of the governance of cryptoactive, increased resources for forensic analysis of chains and public-private coordination that makes traceability an effective barrier to the recycling of illicit profits.
Related
More news on the same subject.

GitLab critical alert: emergency patch fixes CVE-2026-19478 allowing to modify or eliminate public projects without credentials
GitLab published an emergency patch on August 17, 2026 to correct critical vulnerability in its self-hosted software (Community and Enterprise Edition) which, under certain cond...

When the MCP server keeps your credentials: the silent attack vector of the IA in production
The incorporation of IA agents into business processes has opened a practical way for production systems and data to be accessible from models: it is called Model Context Protoc...

Critical alert: CVE-2026-58231 in SAP Commerce Cloud could allow remote code execution; patch and urgent mitigation
A critical vulnerability that affects SAP Commerce Cloud, registered as CVE-2026-58231 and with maximum score 10.0 on the CVSS scale, it is being exploited attempts shortly afte...

The massive purchase of expired domains drives fraud, malware and streaming pirate: the business behind the dropcatch
An intelligence report on DNS published by Infoblox and disseminated by specialized media confirms that criminals are buying large-scale expired domains - the so-called dropcatc...

HoneyMyte updates CoolClient with a signed kernel driver to hide processes and protect the C2 channel
Kaspersky has published an analysis that attributes to the actor known as HoneyMyte (also Mustang Panda) an updated version of the CoolClient backdoor that incorporates a signed...

GeoServer on zero-day vulnerability alert in jsonArrayContains with real risk of remote execution
The GeoServer open source project has a zero-day vulnerability that is being actively explored by attackers, according to researchers' public alerts and the watchTowr intelligen...

AmnesiaStealer MacOS malware that steals credentials and controls real-time browser sessions
Security researchers have documented a new malware family aimed at macOS - called AmnesiaStealer - that combines a dropper in shell, an infostealer written in Rust and a remote ...