- On September 30, 2026, Treasury's Office of Foreign Assets Control sanctioned 10 individuals and entities connected to an ATM jackpotting operation that extracted at least $40.73 million from U.S. financial institutions, with cryptocurrency serving as the primary laundering channel.
- The alleged architect of the scheme, Anibal Alexander Canelon Aguirre—known as "Prometheus"—appears on the FBI's Ten Most Wanted list for allegedly designing the malware that forces ATMs to dispense cash without authorization.
- Chainalysis examination of wallet counterparties reveals direct exposure to laundering services employed by Colombian and Mexican trafficking organizations and a Venezuelan individual facing charges for processing one billion dollars in illicit funds.
Anibal Alexander Canelon Aguirre, an FBI Ten Most Wanted fugitive, allegedly orchestrated a cryptocurrency laundering operation that moved millions of dollars stolen from U.S. automated teller machines to finance Tren de Aragua. Chainalysis is mapping the digital trail left by Aguirre, his co-conspirators, and the transnational criminal organization they serve.
Treasury's Office of Foreign Assets Control sanctioned 10 targets tied to the operation on September 30, 2026, exposing a financial network that converted stolen ATM cash into cryptocurrency and transferred it internationally to support Tren de Aragua, which the State Department designated a Foreign Terrorist Organization. The action included seven cryptocurrency addresses held by Aguirre and his network—all deposit addresses at a major exchange.
Investigation of the network connected to the sanctioned wallets uncovered counterparties with ties to established money laundering infrastructure operating out of Mexico, Colombia, and Venezuela, servicing drug traffickers, smuggling operations, and other criminal enterprises.
Aguirre, wanted for bank fraud, burglary, money laundering, and material support to terrorism, allegedly built the malware behind the ATM attacks and then used cryptocurrency transactions to launder the proceeds. OFAC also sanctioned six of his associates: Carlos Javier Martinez Armenta, Alejandro Mejia Castillo, Jose Dario Galeano Bazurto, Eric Gabriel Cardenas Arzola, Oscar Leonardo Martinez Pirona, and Anthony Wuiliam Hernandez Guerrero.
Malware deployment and crew structure behind the ATM attacks
Jackpotting attacks install malware on automated teller machines that forces them to dispense cash without debiting any account. Aguirre allegedly led a conspiracy that sent attack crews into the United States from bases in Mexico and Venezuela, stealing millions from financial institutions to fund Tren de Aragua.
A December 2025 indictment of Aguirre and his associates describes how the group deployed the Ploutus malware strain using Raspberry Pi devices. Attack teams physically opened each ATM, extracted the hard drive, loaded the malware, and reinstalled the drive. A self-delete function built into the malware wiped all evidence after dispensing the cash, complicating forensic analysis. The operation divided labor across specialized crews: one team photographed target machines and checked for hood alarms, another installed the malware, and a third collected the dispensed currency.
By August 2025, reported losses from alleged jackpotting attacks reached $40.73 million across more than 1,500 incidents.
Shared laundering infrastructure linking multiple criminal organizations
Aguirre's network exemplifies a pattern under continuous monitoring: criminal groups sourcing proceeds through different methods but converging on common laundering infrastructure.
While the origin of illicit funds varies, criminals frequently use the same conversion rails to transform stolen cash into cryptocurrency. Chainalysis analysis of the Tren de Aragua wallet network identified counterparties with exposure to major laundering operations, including a Venezuelan national charged with processing one billion dollars and a laundering network utilized by Colombian and Mexican drug cartels.
"The on-chain insights show us that criminal organizations are leveraging common infrastructure for laundering," said Chainalysis Senior Intelligence Analyst Kaitlin Martin. "These are insights that only the blockchain can provide."
The networks rely heavily on stablecoins to move criminal proceeds internationally. Stablecoins provide price stability but create exposure to advanced monitoring techniques. Real-time monitoring of these networks enables immediate freezing actions. Tether had already frozen USDT balances in several wallets with exposure to the addresses sanctioned in this action.
Six associates designated alongside Aguirre
OFAC sanctioned six individuals alongside Aguirre: Carlos Javier Martinez Armenta, Alejandro Mejia Castillo, Jose Dario Galeano Bazurto, Eric Gabriel Cardenas Arzola, Oscar Leonardo Martinez Pirona, and Anthony Wuiliam Hernandez Guerrero.
Sustained enforcement campaign targeting Tren de Aragua financial networks
The September 30 designation forms part of a sustained government campaign against Tren de Aragua's financial infrastructure. OFAC has executed multiple rounds of action against the organization since the State Department designated it a Foreign Terrorist Organization in February 2025. Since 2025, the administration has taken over 30 actions against more than 300 individuals and entities connected to transnational criminal organizations. As these groups increasingly route illicit funds through cryptocurrency—a trend documented across Latin American markets—designations will carry greater on-chain relevance. For a running list of OFAC-designated entities with identified cryptocurrency addresses, see the OFAC sanctions tracker.
Hot Stories
- Fraud Schemes Fake GIWA bridge steals $2M in Ether from DYORSWAP users
- Articles How Open-Weight AI Helps Hackers Find Code Vulnerabilities
- Investigations iOS app FomoPeek stole $579K in USDT via kernel exploits
- News Bitget confirms $351.6 million hack
- Investigations How AI Is Changing Attacks on Crypto Services
- News Bitget: reports of a possible $170M hack
- Investigations White-hat hackers exploit Liquid Network flaw to steal $320M BTC
- Investigations Symbiosis Recovers 15 BTC After Bitcoin Bridge Exploit
- Investigations Blockstream rejects ransom demand after $320M Liquid hack
- Investigations OFAC and DOJ Freeze $52M in Xinbi Crypto Laundering Network


