Section 3 · Lesson 3.3
Darknet, extortion and theft
This is the "heavy" category of criminal sources — money backed by specific crimes: trade in prohibited goods, extortion via ransomware, hacks of exchanges and bridges. These are the funds that most often pass through mixers and settle on the wallets of ordinary users who have no idea about the origin of the coins they received. Let's examine each channel and understand why exchanges catch such funds with particular care.
Darknet markets: the heirs of Hydra
Darknet markets (DNMs) are anonymous trading platforms on the Tor network where cryptocurrency is used as the primary means of payment for prohibited goods and services. The largest in history was the Russian-language Hydra, taken down in April 2022 in a joint operation by German and US authorities (servers seized, the platform added to OFAC sanctions). Billions of dollars passed through Hydra.
Nature abhors a vacuum: after Hydra fell, its audience and vendors migrated to successor platforms (Mega, Blacksprut, Kraken DNM and others). The mechanics are similar everywhere:
- Buyer's deposit. The customer pays crypto into an internal market address (the platform's escrow wallet).Often through a network of "intermediary swap services" to hide the original source.
- Internal settlement. The market holds funds in escrow until the deal is confirmed, then transfers them to the vendor minus a commission.The market's internal wallets are clusters that analysts tag as "darknet market".
- Vendor's withdrawal. The vendor withdraws the proceeds — and this is exactly where criminal funds enter "normal" circulation: onto exchanges, into swap services, to P2P traders.Often, before withdrawal, the money is run through a mixer to break the trail.
Why this matters. A wallet that received funds directly from darknet market addresses, or one or two hops away from them, carries high risk. Even if your client honestly sold something legitimate to a P2P trader who turned out to be linked to a DNM, the "paint" carries over to the client. That is why tracing several hops back is mandatory.
Ransomware: the economics of digital extortion
Ransomware is one of the most lucrative forms of cybercrime. The scheme: attackers encrypt a victim's data (a company, a hospital, a government agency) and demand a ransom in cryptocurrency for the decryption key. Well-known families include Conti, LockBit, BlackCat/ALPHV, Ryuk.
- The ransom addressThe victim is given a specific BTC/crypto address. Every incoming payment to it is, by definition, criminal funds. Such addresses regularly end up in analysts' databases and sometimes on sanctions lists.
- Splitting and launderingThe ransom received is quickly split, run through mixers and chains of wallets to "cool it off" and cash it out through high-risk exchanges.
- The sanctions angleA number of ransomware groups are linked to sanctioned individuals and states. Paying a ransom to such groups can itself breach sanctions — OFAC has explicitly warned businesses about this.
Victim pays the ransom
→
Mixer / chain
→
Cash-out via an exchange
Hacks and drainers: theft as a source
A separate large category is stolen funds. This includes hacks of centralised exchanges, exploits of DeFi protocols, attacks on cross-chain bridges and wallet drainers.
- Hacks of exchanges and protocols. The classic is Mt.Gox, but even in the 2020s attacks on nine-figure sums are regular. Exploiting a smart contract vulnerability allows someone else's funds to be drained in a single transaction.Stolen funds are almost always "parked" on intermediate addresses first, and then laundered slowly.
- Bridge attacks. Bridges between blockchains hold enormous liquidity pools and have become a favourite target. Ronin Bridge ($625 million), Harmony Bridge, Wormhole are the largest cases, many attributed to Lazarus.OFAC promptly adds funds from hacked bridges to the SDN — a double risk of theft + sanctions.
- Wallet drainers. Malicious scripts and phishing sites that trick a user into a signature that empties their wallet. A mass phenomenon — thousands of small victims whose funds flow to the addresses of drainer services.More on the mechanics of approval phishing in the next lesson on scams.
Lazarus Group: where all the lines converge
Caution. Lazarus Group — the DPRK's state hacking structure — ties together every theme of this lesson and the previous one. It is Lazarus that is behind the largest hacks of bridges and exchanges; it is Lazarus that uses mixers (Tornado Cash, Sinbad) for laundering more intensively than anyone; and it is because of Lazarus that OFAC sanctioned these mixers. Exposure to Lazarus funds is the highest level of alarm, because here AML risk merges with an accusation of financing the nuclear programme of a hostile state. No legitimate platform would knowingly accept such funds.
How these funds enter circulation and why exchanges catch them
Understanding the "money's path" helps to structure a check. Criminal funds from all three channels (darknet, ransoms, theft) go through a similar laundering life cycle:
- Placement. Funds are withdrawn from the source address to intermediate wallets.Sometimes immediately split across dozens of addresses — the peel-chain technique.
- Layering. Many transfers, mixers, swaps between tokens and blockchains (chain hopping) — everything to muddle the trail.It is at this stage that direct visibility of the source is lost — but not indirect visibility, if you do deep tracing.
- Integration. The "laundered" funds are moved onto an exchange, into a swap service or to a P2P trader in order to cash out or convert to fiat.This is the bottleneck where the platform's compliance is the last barrier.
Why this matters. Exchanges catch such funds especially actively for three reasons. First, regulatory pressure: by accepting crime, an exchange risks its licence and fines. Second, reputation: an incident with "dirty" money scares off institutional clients and partner banks. Third, freeze risk: if an exchange has accepted funds with a sanctions trail, its own correspondent accounts and stablecoin reserves can be blocked. That is why the integration stage is where checks are strictest — and it is exactly why your task as an AML operator is to detect the trail BEFORE the funds touch a platform.
Practical benchmark. When checking, look in the wallet's history for contacts with clusters tagged "darknet market", "ransomware", "stolen funds", "exploit". Even an indirect link (2–3 hops) with a significant share of funds is grounds for high risk. The combination "source-theft + passing through a mixer" = an almost guaranteed stop.
Lesson summary
- Three "heavy" channelsDarknet markets, ransomware payouts, hacks/theft — direct criminal sources.
- A common life cyclePlacement → layering (mixers) → integration via exchanges. Best caught before integration.
- Lazarus ties it all togetherTheft + mixers + sanctions in one subject — the highest level of risk.
- Tracing hops is mandatoryThe "paint" of crime carries through intermediate wallets to your client.
The next lesson is about the more widespread, "everyday" threats that almost every crypto user faces: scams, fake tokens, "dust" and phishing that drains wallets.
This material is for educational purposes only and does not constitute legal advice.