Mining Pools Are the New Mixers For Cybercriminals: Chainalysis

Hackers have a new way to recycle their ill-gotten crypto gains.

AccessTimeIconJun 15, 2023 at 1:00 p.m. UTC
10 Years of Decentralizing the Future
May 29-31, 2024 - Austin, TexasThe biggest and most established global event for everything crypto, blockchain and Web3.Register Now

Ransomware hackers have a new money-laundering trick: mining new coins to replace “tainted” ones, blockchain analytics firm Chainalysis said in a blog post on Thursday.

The firm located 372 exchange deposit wallets that received both mining profits and ransomware proceeds, Chainalysis wrote. These addresses altogether have received $158.3 million from ransomware-related wallets since 2018.

  • Big Tech Comes to Small Town: A Bitcoin Mining Story in Spur
    Big Tech Comes to Small Town: A Bitcoin Mining Story in Spur
  • What's the Biggest Misconception People Have About Bitcoin Mining?
    What's the Biggest Misconception People Have About Bitcoin Mining?
  • Ransomware Payments Reached $1.1B in 2023: Chainalysis
    Ransomware Payments Reached $1.1B in 2023: Chainalysis
  • What You Need to Know About the Bitcoin Halving
    What You Need to Know About the Bitcoin Halving
  • “Overall, the data suggests that mining pools may play a key role in many ransomware actors’ money laundering strategy,” Chainalsysis wrote

    This fashion of money laundering is becoming increasingly popular, with ransomware-related wallets sending more and more funds to mining pools since 2018.

    Chainalsysis gives an example of a deposit wallet on an unnamed popular crypto exchange that received large amounts of crypto from ransomware incidents and mining pools. Of the $94.2 million worth of cryptocurrency sent to that deposit address, $19.1 million has come from ransomware addresses and $14.1 million has come from mining pools, Chainalysis calculated.

    Although the funds always came to the exchange via intermediary wallets, Chainalysis found instances in which the wallet receiving ransomware proceeds sent funds directly to the mining pool wallet, which then sent the coins to the exchange. This might mean that both the ransomware- and mining-related wallets belong to the same owner, who is using mining as a way to launder criminal funds, Chainalysis wrote.

    “In this scenario, the mining pool acts similarly to a mixer in that it obfuscates the origin of funds (reminder: you can’t trace crypto through services, mining pools included) and creates the illusion that the funds are proceeds from mining rather than from ransomware,” the blog post reads.

    The BitClub Network scam, which pretended to be operating a crypto mining business until its operators were indicted by the DOJ in 2020, also used this scheme, Chainalysis wrote. The wallets attributed to BitClub used the same set of deposit address on two exchanges as “a Russia-based Bitcoin mining operation,” Chainalysis wrote, without naming the mining firm.

    This might have been a trick to make exchanges believe that the funds are coming from mining, not from crime, Chainalsysis wrote. Exchange deposit addresses that received money both from scams and mining pools received a little less than $1.1 billion worth of crypto since 2018, according to the firm.

    The North Korean hacking group APT43, also referred as Archipelago, is also investing the crypto it steals into mining, cyber security firm Mandiant said in a report earlier this year. This way, the hackers replace the coins tainted by criminal association with new, “clean” ones.

    Edited by Ben Schiller.


    Please note that our privacy policy, terms of use, cookies, and do not sell my personal information has been updated.

    CoinDesk is an award-winning media outlet that covers the cryptocurrency industry. Its journalists abide by a strict set of editorial policies. In November 2023, CoinDesk was acquired by the Bullish group, owner of Bullish, a regulated, digital assets exchange. The Bullish group is majority-owned by; both companies have interests in a variety of blockchain and digital asset businesses and significant holdings of digital assets, including bitcoin. CoinDesk operates as an independent subsidiary with an editorial committee to protect journalistic independence. CoinDesk employees, including journalists, may receive options in the Bullish group as part of their compensation.

    Anna Baydakova

    Anna Baydakova was CoinDesk's investigative reporter with a special focus on Eastern Europe and Russia. Anna owns BTC and an NFT.

    Learn more about Consensus 2024, CoinDesk's longest-running and most influential event that brings together all sides of crypto, blockchain and Web3. Head to to register and buy your pass now.