US Treasury Sanctions More North Korea-Linked ETH Wallets Over $600M Ronin Hack

The three new wallets join an Ethereum address added to the sanctions list last week.

AccessTimeIconApr 22, 2022 at 6:04 p.m. UTC
Updated May 11, 2023 at 5:22 p.m. UTC

U.S. government officials are throwing a wider sanctions dragnet over alleged North Korean crypto wallets.

On Friday, the Treasury Department's Office of Foreign Asset Control (OFAC) added three Ethereum addresses to its sanctions list, joining an address listed last week that the federal government tied to the theft of around $600 million in crypto from Axie Infinity's Ronin bridge. All three addresses had received sizable inbound transfers of stolen ether (ETH) from the originally sanctioned wallet over the past week.

The operators of the Ronin exploit wallet, said by the FBI and OFAC to be North Korea's Lazarus hacking group, have been laundering funds by moving them from a sanctioned address to an intermediary address before sending the funds to Tornado Cash, a mixer designed to obfuscate the source and destination of funds moved through the service.

This pattern repeated on Friday, when funds moved from one of the newly sanctioned addresses to another intermediary before once again landing at Tornado Cash.

None of the sanctioned addresses have directly interacted with Tornado Cash.

The nature of Tornado Cash makes it difficult for the operators of the service to blacklist addresses, as OFAC requires any entities touching the U.S. financial system to do. The mixer adopted a compliance tool offered by blockchain analytics firm Chainalysis that lets it blacklist certain addresses, but only on the user-facing decentralized app that Tornado Cash's operators can influence. Individuals can still use the protocol itself to bypass this compliance tool.

Also, at least as of last week, the Chainalysis tool only listed the originally sanctioned address.

A representative for Tornado Cash previously told CoinDesk that "OFAC is the judge of what addresses need to be banned."

"It’s a guessing game so far. I assume only 1 address has been identified by OFAC that should be sanctioned relating to that event. Which means Chainalysis update[s] whatever is in sanction’s list," the representative said.

Officials have accused the Hermit Kingdom of mounting an aggressive hacking spree against the crypto economy.

This is a developing story and will be updated.


Please note that our privacy policy, terms of use, cookies, and do not sell my personal information has been updated.

The leader in news and information on cryptocurrency, digital assets and the future of money, CoinDesk is a media outlet that strives for the highest journalistic standards and abides by a strict set of editorial policies. CoinDesk is an independent operating subsidiary of Digital Currency Group, which invests in cryptocurrencies and blockchain startups. As part of their compensation, certain CoinDesk employees, including editorial employees, may receive exposure to DCG equity in the form of stock appreciation rights, which vest over a multi-year period. CoinDesk journalists are not allowed to purchase stock outright in DCG.

CoinDesk - Unknown

Danny is CoinDesk's Managing Editor for Data & Tokens. He owns BTC, ETH and SOL.

CoinDesk - Unknown

Nikhilesh De is CoinDesk's managing editor for global policy and regulation. He owns marginal amounts of bitcoin and ether.

Learn more about Consensus 2024, CoinDesk’s longest-running and most influential event that brings together all sides of crypto, blockchain and Web3. Head to to register and buy your pass now.