In the spring of 2021, the largest fuel pipeline on the U.S. East Coast shut down for several days — and lines formed at the gas pumps. The cause was not a terrorist attack or an accident, but a line of malicious code. The company paid the extortionists a ransom of 75 bitcoin, believing the money would dissolve forever into the dark depths of the blockchain. A month later, most of it was recovered. This case is a short but striking demonstration of the principle we discussed in the previous case study: even a ransom in cryptocurrency is traceable — and recoverable.
▶ Video case study: Colonial Pipeline (English narration).
On 7 May 2021 the hacker group DarkSide (operating out of Russia) encrypted the networks of Colonial Pipeline — the operator of the fuel line supplying a significant part of the U.S. East Coast. The ransomware attack paralyzed the company: to avoid risking safety, the operator was forced to halt the flow of fuel.
The consequences went far beyond an IT incident. Fuel supply disruptions triggered panic, lines at gas stations, and rising prices — a rare case where a cyberattack directly hit the everyday lives of millions of people. It was precisely the scale of this blow that turned the Colonial Pipeline case into a showcase proceeding: the state was motivated to respond loudly and visibly.
Under the pressure of circumstances, the company made a decision that security experts generally do not recommend, but which in a crisis looked like the only quick way out: to pay the ransom. Colonial Pipeline transferred 75 BTC to the extortionists — about 4.4 million dollars at the time.
From DarkSide's point of view this was a well-honed scheme: encrypt critical infrastructure, demand a ransom in bitcoin — "untraceable," as many think — and vanish. The extortionists' logic rests on the assumption that cryptocurrency is anonymous and that the money received can neither be traced nor recovered. The Colonial Pipeline case publicly demolished that logic.
What happened next was something the extortionists did not expect. The FBI did not "look for the money on the darknet" — instead, investigators did exactly what the blockchain allows: they traced the ransom's movement across the public ledger, transaction by transaction, wallet to wallet.
But tracing the path is only half the job. As we already know from the Bitfinex story, seeing the coins on the blockchain and gaining control over them are different things. A bitcoin transfer cannot be undone; to seize the coins, a private key is needed. And here the investigation held a decisive trump card: access to the private key of a wallet belonging to an affiliate (partner) of the DarkSide group. The ransomware-as-a-service model works such that the attack is often carried out not by the "head" group itself but by its affiliate partner, who receives a share of the ransom. It was the wallet of exactly such an affiliate that was accessed.
With the key in hand, investigators, by court order, seized about 63.7–69.6 BTC — roughly 2.3 million dollars, that is, a significant part of the paid ransom. For the world of cyber-extortion, where paid money was traditionally considered irretrievably lost, this was a turning point.
"Today we turned the tables on DarkSide."
— Lisa Monaco, U.S. Deputy Attorney General.
This short phrase — "we turned the tables" — captures the essence of the case precisely. The extortionists counted on the rules of the game being on their side: anonymous crypto, encrypted infrastructure, a helpless victim. But it turned out the other way around: the very cryptocurrency they considered a reliable hiding place became the evidence and the channel for recovering the money.
The Colonial Pipeline case is often recalled when discussing the myth of "untraceable" cryptocurrency. Let's break down what lessons it offers the wallet-screening specialist.
First: a ransomware ransom is a traceable money flow. Unlike a suitcase of cash passed hand to hand, a crypto ransom is recorded forever on the blockchain. This means that funds tied to known extortion campaigns end up in label databases and sanctions lists. A wallet that received coins from such a source carries a toxic "fingerprint" — and a competent AML check is obliged to see it.
Second: the speed of response has grown. Note the timelines. In the Bitfinex case, six years passed between the theft and the seizure. Here — mere weeks passed from the 7 May attack to the announcement of the recovery. Blockchain-analytics tools and coordination between investigators and the industry have reached a level where "hot" money can be traced almost in real time.
Third: the key is still the point of control. As in the Bitfinex case, the physical recovery of the funds became possible only thanks to access to the private key. The blockchain is immutable: a transfer cannot be "rolled back." The only way to actually take the coins is to gain control over the keys of the wallet where they sit. This once again underscores why in compliance it is so important to understand who controls the keys to a given address.
We have examined two cases where the trail led to individual criminals and partners. In the next case study the adversary will be of a different class — a state-run hacker group of an entire country: how Lazarus stole $625M through the Ronin bridge.
The facts are presented from open sources. The materials are for educational purposes.