The U.S. Department of the Treasury’s Office of Foreign Assets Control (OFAC) sanctioned 10 targets on Wednesday tied to an ATM jackpotting scheme run by Tren de Aragua (TdA), blacklisting 7 cryptocurrency deposit addresses belonging to ringleader Anibal Alexander Canelon Aguirre, known as "Prometheus." Prometheus is currently on the FBI’s Ten Most Wanted Fugitives list and faces federal charges in Nebraska.
Key Takeaways
- OFAC targeted 10 individuals and entities alongside 7 exchange deposit addresses linked to TdA's illicit operations.
- Jackpotting attacks using Ploutus malware caused $40.73 million in U.S. losses across over 1,500 incidents as of August 2025.
- Blockchain analytics indicate $6.1 million flowed through the sanctioned addresses, overlapping with wider cartel laundering infrastructure.
ATM Jackpotting Playbook and Fugitive Network
TdA, which was designated by the State Department as a Foreign Terrorist Organization in February 2025, relied heavily on ATM fraud as a primary revenue generator. The group executed jackpotting attacks using a specialized malware strain known as Ploutus, which forces automated teller machines to dispense cash without deducting funds from accounts before self-erasing after each incident. U.S. court filings in Nebraska identify Canelon Aguirre as the engineer behind Ploutus. U.S. authorities report that reported losses from these cyber-enabled thefts reached $40.73 million across more than 1,500 documented cases as of August 2025. OFAC also separately sanctioned senior TdA leader Juan Gabriel Rivas Nunez over ties to illicit gold mining.
Laundering Routes and Stablecoin Infrastructure
Blockchain intelligence firm TRM Labs confirmed that all 7 sanctioned crypto addresses served as deposit accounts hosted at a centralized exchange, processing approximately $6.1 million since March 2022. These addresses routed funds into interconnected wallets that transferred roughly $35 million to a financial network linked to Jorge Figueira, a Venezuelan national facing charges for allegedly laundering $1 billion. Analysis from Chainalysis revealed that the counterparties to these wallets shared operational infrastructure with major Colombian and Mexican drug cartels. As regulatory action intensifies against criminal channels, similar to how hackers shifted laundering routes after illicit flows were blocked, syndicated groups increasingly share compliance-defying rails. Direct government intervention can mirror cases where a US court blocked victims from claiming seized crypto.
Chainalysis Senior Intelligence Analyst Kaitlin Martin noted that "the on-chain insights show us that criminal organizations are leveraging common infrastructure for laundering." The networks relied heavily on stablecoins, prompting issuer Tether to previously freeze Tether (USDT) balances across exposed wallet addresses. Because OFAC applied Executive Order (E.O.) 13224 to the designations, foreign financial institutions knowingly processing significant transactions for these targets face secondary sanctions risk.
Why It Matters
This enforcement action highlights the growing convergence of traditional cybercrime, transnational street gangs, and centralized crypto exchanges. By leveraging Executive Order 13224 secondary sanctions and target exchange deposit addresses, U.S. regulators are placing direct pressure on centralized platforms to strictly enforce Know Your Customer (KYC) compliance. As criminal syndicates increasingly share stablecoin laundering pipelines, centralized issuers and exchanges will face mounting legal mandates to proactively freeze illicit assets.



