CryptaCount
EN
EnglishENDeutschDEEspañolESFrançaisFRItalianoIT日本語JA한국어KONederlandsNLPolskiPLPortuguêsPT
Log in Start Free

OFAC Sanctions Tren de Aragua Crypto Laundering Network

CryptaCount Editorial · · 9 min read
AML / KYC / LICENSING OFAC Sanctions Tren de AraguaCrypto Laundering Network

On 30 September 2026, the U.S. Department of the Treasury's Office of Foreign Assets Control (OFAC) designated 10 individuals connected to Tren de Aragua (TdA), a Venezuelan transnational criminal organization already designated as a Foreign Terrorist Organization (FTO) by the State Department in February 2025. The action exposed a financial network that used ATM jackpotting attacks to steal at least $40.73 million from U.S. financial institutions, then routed those proceeds through cryptocurrency, particularly stablecoins, to move funds across borders. For compliance teams relying on crypto accounting software and on-chain screening tools, the designation carries immediate screening, reporting, and recordkeeping obligations.

OFAC Sanctions Tren de Aragua Crypto Laundering Network

What OFAC Actually Designated

The 30 September action added 10 individuals to the Specially Designated Nationals (SDN) list. OFAC simultaneously published seven cryptocurrency addresses belonging to the alleged ringleader and his associates. Those addresses are deposit addresses at a major cryptocurrency exchange, meaning the exchange itself now holds frozen balances that were already partially addressed: Tether had previously frozen USDT balances on wallets with exposure to the newly sanctioned addresses before the formal designation was published.

The Named Individuals

The alleged network leader is Anibal Alexander Canelon Aguirre, known by the alias "Prometheus." He sits on the FBI's Ten Most Wanted Fugitives list, wanted on charges including bank fraud, burglary, money laundering, and providing material support to a terrorist organization. U.S. authorities allege he personally engineered the malware used in the jackpotting attacks and directed the conspiracy that dispatched criminal crews into the United States from staging points in Mexico and Venezuela.

Six additional individuals are designated alongside Aguirre: Carlos Javier Martinez Armenta, Alejandro Mejia Castillo, Jose Dario Galeano Bazurto, Eric Gabriel Cardenas Arzola, Oscar Leonardo Martinez Pirona, and Anthony Wuiliam Hernandez Guerrero.

The Seven Crypto Addresses

All seven published addresses are deposit addresses held at a single major exchange. Under OFAC rules, U.S. persons are prohibited from transacting with these addresses, and any assets held there must be blocked and reported to OFAC within 10 business days. Firms whose transaction monitoring flags historical transfers involving these addresses should treat them as potential SDN exposures requiring immediate escalation, regardless of whether those transfers predated the designation date.

How the ATM Jackpotting Scheme Worked

ATM jackpotting is a physical-cyber hybrid attack. Criminals gain hands-on access to a cash machine, remove its hard drive, install malware, and reinsert the drive. Once activated remotely, the malware issues a dispense command that empties the ATM without debiting any linked account. The stolen cash leaves no immediate digital trail at the point of theft.

The Ploutus Malware and Operational Structure

Court filings from a December 2025 indictment of Aguirre and associates identify the malware strain as Ploutus, deployed via Raspberry Pi devices. The process was deliberately compartmentalized: one crew photographed a target ATM and checked for silent hood alarms, a second crew performed the physical install, and a third collected the dispensed cash. Ploutus included a self-delete function that erased all evidence from the machine's drive after the cash was taken, significantly hindering forensic investigation at the ATM itself.

By August 2025, reported losses across more than 1,500 alleged attacks had reached $40.73 million. The conspiracy deployed crews from a network based in Mexico and Venezuela into the United States, and the proceeds were then converted and moved through crypto channels.

Converting Cash to Crypto

After physical theft, the network converted stolen cash into cryptocurrency, with a heavy reliance on stablecoins. On-chain analysis of the TdA-linked wallets found counterparties with direct exposure to known money laundering operations in Mexico, Colombia, and Venezuela, including a Venezuelan national charged with laundering one billion dollars and laundering infrastructure previously leveraged by Colombian and Mexican drug cartels. This is the pattern that compliance analysts describe as "shared laundering rails": different criminal enterprises, different source crimes, but the same conversion and movement infrastructure.

The Shared Laundering Infrastructure Problem

The TdA case illustrates why counterparty exposure analysis matters as much as direct wallet screening. The seven sanctioned addresses are the visible tip; the on-chain analysis reveals a web of counterparties connected to cartel laundering operations across three countries. A compliance team that screens only against the seven published addresses will miss the broader exposure that arises when their clients' wallets have interacted with those counterparties even without a direct link to a sanctioned address.

Why Stablecoins Are the Preferred Rail

The network's preference for stablecoins is operationally rational from a criminal perspective: price stability means the real-world value of proceeds does not erode during the time it takes to move funds across jurisdictions. However, stablecoins also carry a structural vulnerability for criminal networks. Issuers like Tether can freeze balances at the wallet level in response to law enforcement requests, and that is precisely what happened here before the formal OFAC designation. For compliance teams, this means stablecoin transactions require the same sanctions screening rigour as any other crypto transfer, and firms should confirm that their digital asset accounting software captures stablecoin flows at the wallet address level, not merely at the token type level.

For deeper context on how shared laundering infrastructure connects different criminal networks on-chain, see our coverage of OFAC sanctions on fentanyl networks and SDN wallet exposure, which documents a parallel pattern of criminal proceeds flowing through overlapping crypto rails.

AML and Compliance Obligations for Firms

The designation triggers a set of concrete obligations for any U.S. person or entity, and for non-U.S. firms with U.S. dollar or U.S. counterparty exposure.

Immediate Screening Steps

All seven published crypto addresses must be added to internal SDN screening lists without delay. Firms should run a retrospective sweep of transaction history against these addresses to identify any prior exposure. Where a match is found, the asset must be blocked, and OFAC must be notified within 10 business days using its online reporting portal. Firms that discover they have processed transactions involving designated addresses must also consider their voluntary self-disclosure obligations, which OFAC takes into account when calculating civil monetary penalties.

Beyond the seven addresses, firms should assess whether their counterparty risk framework captures second-degree exposure, that is, wallets that have interacted with the sanctioned addresses. Given that the TdA network used shared laundering infrastructure with cartel-linked entities, indirect exposure is a credible risk. This is precisely the kind of analysis where purpose-built crypto bookkeeping software with integrated on-chain risk scoring adds measurable value, because manual wallet-by-wallet reconstruction across thousands of transactions is not operationally feasible without tooling. Our breakdown of the on-chain AML screening decisions every compliance team should review covers the engineering trade-offs that determine how reliably a system catches exactly this kind of indirect exposure.

SAR Filing Thresholds

For U.S. Bank Secrecy Act filers, any transaction or attempted transaction of $5,000 or more that involves funds the firm knows, suspects, or has reason to suspect are linked to criminal activity, or that involve a potential sanctions violation, triggers a Suspicious Activity Report (SAR) requirement. The 30-day filing clock runs from the date the firm identifies the suspicious activity. Where the firm needs additional time to identify a subject, a 60-day extension applies. Given that several of the sanctioned individuals were already subjects of a December 2025 indictment, compliance officers should consider whether prior transactions involving these wallets already created a SAR obligation that may now need to be revisited as a late filing with explanation.

Accounting and Recordkeeping Implications

Any digital asset balance that a firm holds and that becomes subject to an OFAC block order must be reclassified in the firm's accounts. Under U.S. GAAP, a blocked asset is not freely usable and should be disclosed as restricted, with appropriate disclosure of the reason for the restriction and the regulatory context. The fair value measurement of a blocked crypto asset is a distinct question from its unrestricted market price; auditors will expect management to document how they have determined the recoverable amount, if any, of a blocked balance. Firms using crypto accounting software should confirm that their systems can flag and segregate blocked balances from active holdings to avoid misstatement in financial reports.

Broader Enforcement Context

The 30 September 2026 action is not an isolated event. OFAC has taken multiple prior actions against TdA since the State Department's FTO designation in February 2025, and the broader administration campaign has resulted in more than 30 actions against over 300 individuals and entities connected to TdA since 2025. The trajectory is clear: as TdA and similar transnational criminal organizations route more of their proceeds through crypto, OFAC designations will increasingly carry on-chain identifiers, and the volume of sanctioned crypto addresses on the SDN list will grow.

This enforcement pattern has a direct implication for compliance infrastructure. Firms that rely on infrequent, batch SDN list updates will increasingly find themselves behind the curve. Real-time or near-real-time SDN feed integration is becoming a baseline expectation, not a premium feature, for any firm with material crypto transaction volume. The TdA case also reinforces the value of proactive coordination between blockchain analytics providers and law enforcement: Tether's pre-designation freeze of exposed USDT wallets demonstrates that private-sector actors can act on intelligence before a formal designation is published, provided they have the monitoring infrastructure in place to identify the exposure.

OFAC Sanctions Tren de Aragua Crypto Laundering Network

Frequently Asked Questions

What does it mean for a crypto address to be on the OFAC SDN list?

A crypto address on the SDN list is treated the same as any other blocked property under U.S. sanctions law. U.S. persons are prohibited from transacting with it, any funds associated with it must be blocked, and the blocking must be reported to OFAC within 10 business days. The prohibition applies regardless of whether the transaction is direct or routed through intermediaries.

Does the designation affect firms outside the United States?

Non-U.S. firms with U.S. dollar exposure, U.S. counterparties, or U.S.-based operations face secondary sanctions risk if they knowingly facilitate transactions involving designated entities. Stablecoin transactions denominated in USD are particularly relevant because the underlying settlement infrastructure often involves U.S. entities or correspondent relationships.

What is the difference between a direct SDN match and counterparty exposure?

A direct match means a wallet your firm has transacted with appears on the SDN list. Counterparty exposure means a wallet your firm has transacted with has itself transacted with an SDN wallet, creating indirect linkage. OFAC's strict liability framework does not require intent, so indirect exposure can still result in enforcement action, though it is a factor considered in penalty calculations.

How should blocked crypto assets be recorded in financial statements?

Blocked assets should be separated from freely tradeable holdings and disclosed as restricted assets. Fair value measurement must reflect the asset's restricted status, which may differ materially from its open-market price. Management should document the basis for any valuation applied and ensure auditors are informed of the restriction and its regulatory source.

What SAR filing obligation arises if a firm discovers prior exposure to a newly designated address?

If prior transactions involved an address now on the SDN list, and those transactions met the $5,000 threshold with an indicator of criminal proceeds, the firm should assess whether a SAR obligation existed at the time and file retroactively if appropriate, with a narrative explaining the late identification. Firms should also consider whether to make a voluntary self-disclosure to OFAC regarding the prior transactions, as this is a mitigating factor in civil penalty calculations.

Source: Chainalysis

USGLOBAL#stablecoinsGeneralEnforcementAML/KYC & Licensing

Related articles

AML/KYC & Licensing
OFAC Sanctions Eight Houthi Crypto Addresses: AML Implications for Firms
AML/KYC & Licensing
FBI Targets Huione: The $134 Billion Illicit Marketplace Dismantled
AML/KYC & Licensing
Al-Qassam Brigades DOJ Filing: What Crypto Firms Must Know Now
AML/KYC & Licensing
Terrorist Financing Shifts to USDT on TRON: 25 Years After 9/11