fa
Feedback
AML Crypto: all about crypto crime

AML Crypto: all about crypto crime

رفتن به کانال در Telegram

AML Crypto about cryptojacking, hacks and blockchains, investigations and protecting your assets. Feedback: @AMLcrypto

نمایش بیشتر
کشور مشخص نشده استرمزارزها24 245
3 973
مشترکین
اطلاعاتی وجود ندارد24 ساعت
-277 روز
-15230 روز
آرشیو پست ها
Telegram is Flagging SCAM Channels Offering “Trust Management of Funds” If you’ve encountered a channel that promises to “inv
Telegram is Flagging SCAM Channels Offering “Trust Management of Funds” If you’ve encountered a channel that promises to “invest on your behalf,” “multiply your funds,” or offers to “manage your money for you,” it is very likely a scam. Such channels can now receive an official SCAM label 🚫 from Telegram.
🔎 What this label does: • Removes the channel from Telegram search, • Warns users about the risk of fraud, • Registers indicators of unethical activity within Telegram’s system.
⚖️ Why it matters: A label from Telegram can serve as an additional supporting factor, strengthening your case when: • Contacting law enforcement, • Filing fraud complaints, • Communicating with legal teams, banks, or crypto platforms, • Initiating international freezes on cryptocurrency wallets.
📩 How AML Crypto Can Help: If you’ve encountered such a channel, we will help you gather evidence, properly format your complaint, and submit it directly to Telegram.
📋 What’s Required: 1. A screen recording clearly showing: • The username of the channel or its administrator, • The offer of trust management. 2. If available – documents/proof of damages (transfers, screenshots of chats, post-transfer blocks, etc.). 📢 Helping Telegram identify scammers. Protecting users. Let’s act together. AML Crypto | Anti-Scam. Pro-Transparency. 🛡 Web | ✔ TG - Bot | 💬 Contact us

🔑 Your wallet won’t stay yours once a scammer gets your SEED phrase (The “Seed Phrase Compromise” Scheme) A seed phrase is t
+4
🔑 Your wallet won’t stay yours once a scammer gets your SEED phrase (The “Seed Phrase Compromise” Scheme)
A seed phrase is the master key to your crypto wallet and all the funds stored in it. 🪙
There are various ways scammers can gain access to your seed phrase: 🎣 Phishing websites. Scammers create fake websites that look exactly like legitimate crypto wallets. They prompt users to either enter the seed phrase for an existing wallet or “create” a new one. In both cases, the entered or generated seed phrase is captured and stored by the scammers. 🖥 “Help” via screen sharing. Pretending to be technical support, consultants, or brokers, scammers offer to assist in creating a blockchain address and ask you to share your screen. They claim they can’t see your seed phrase due to privacy settings in Zoom, Teams, or other platforms — manipulating you into generating it in their presence. 📞 Fake tech support. Scammers pose as support agents and ask for your seed phrase under the pretense of resolving wallet issues.
📂 In one case investigated by AML Crypto, scammers took things even further. They pre-created a blockchain address and embedded the associated seed phrase in a QR code. Then, using a detailed step-by-step guide, they instructed the victim to scan the QR code in the Trust Wallet app to “create” a wallet. Since everything happened on the user’s device, it felt secure — but in reality, they were activating a wallet that the scammers already fully controlled.
📸 To help you understand how this might look in practice, we’ve prepared a simulated conversation — a demonstration based on a real analyzed case. This is not a real chat, but an educational example showing how such a compromise can happen step-by-step via a QR code. 🧠 Knowing these schemes in advance is key to protecting your digital assets. How to protect yourself: 🔒 Never share your seed phrase — with anyone, under any circumstances. 🧠 Always create your wallet yourself, using only official sources. 🖥 Don’t share your screen while setting up a wallet — even if someone offers “help.” 🔍 Double-check website URLs — a single wrong character can cost you everything. 🚫 Remember: no legitimate support team will ever ask for your seed phrase. 🛡 Web | ✔ TG - Bot | 💬 Contact us

🔍 How Were Strategy’s Addresses Exposed? The AML Crypto Team Investigates
Today, a major development hit the news — *Arkham Intelligence* published a list of wallet addresses they claim belong to Strategy (formerly MicroStrategy). 📈 According to Arkham, these wallets hold around $50 billion in BTC — nearly 87.5% of the company’s publicly disclosed reserves.
But the real question is: how was it done? The AML Crypto team decided to investigate the hypotheses and analyze the possible reasons behind the deanonymization. 💡 Here are the three working theories we’ve identified: 1️⃣ Ties to Coinbase Prime Only Almost all of the mentioned addresses receive funds exclusively from Coinbase Prime — an institutional custody platform. Such a pattern suggests insider knowledge — even just knowing which address was used or that a transaction occurred. 2️⃣ A Signature Pattern: Satoshi Test + Large Transfer Before major deposits in the tens of millions in BTC, there’s often a tiny “satoshi test” — a 0.0001 BTC transaction. This is a recognizable pattern that can trigger clustering or address attribution in blockchain analysis tools. 3️⃣ An Address Exposed via a Tiny Transaction One of the addresses linked to Strategy was revealed through a minuscule transfer of just 0.0000069 BTC. 🔎 And yes — even a transaction that small can tell blockchain analysts more than you’d expect.
📸 Attached is a visualization from Bholder, showing how Coinbase Prime transactions fan out into wallets believed to be connected to Strategy. We specifically tracked microtransactions that may have left the trail.
🔐 At AML Crypto, we’re committed to diving deeper into cases like this. Because a transaction isn’t just a number — it’s a story waiting to be read. 🛡 Web | ✔ TG - Bot | 💬 Contact us

Continuing the topic of fake tokens — we also conducted a large-scale investigation that uncovered over 9,000 victims, tens of millions of dollars in damages, and more than 90 counterfeit tokens issued by a single perpetrator. The image shows just a fragment of the asset movement scheme we reconstructed.

🎭 Looks Real, Worth Nothing: Fake Tokens and Deception One of the AML Crypto cases involved counterfeit tokens — assets that
🎭 Looks Real, Worth Nothing: Fake Tokens and Deception One of the AML Crypto cases involved counterfeit tokens — assets that appear legitimate but have no real value. These schemes are becoming increasingly common, ranging from fake presales and P2P exchanges to “investment” projects and knockoffs of popular stablecoins.
⚠️ The core issue is that many people don’t realize that tokens labeled as USDT or ETH can actually be based on entirely different smart contracts. Visually, the name looks the same — but in reality, it's a worthless clone.
🔍 In this case, the investigation was initiated not by the victim, but by the police. We joined the process upon an official request to provide technical analysis. 🧑‍💻 A user (let’s call him John) bought a token during a “presale” via Uniswap, trusting a Telegram influencer. Everything seemed legit: screenshots, announcements, and promises of a future listing. The token was delivered — but it couldn’t be sold. It turned out to be a clone issued on a different contract. 😓 In an attempt to “recover” his losses, John tried to use the fake token in a deal — he offered it as payment to a seller on Amazon. The seller later discovered that the asset had no value and reported it to the police. John ended up being prosecuted for fraud, even though he himself was initially defrauded.
📌 How to Avoid Falling Into This Trap 1. Verify the token's smart contract — only use official sources like CoinMarketCap, Etherscan, or similar platforms to confirm authenticity. 2. Check the market price — if the token isn’t listed or actively traded on reputable exchanges, it likely has no real value. 3. Don’t trust “insider tips” on Telegram — especially if someone urges you to manually buy a token via a direct link. 4. Never use fake assets as payment — even if you’ve been scammed, trying to “pass on” your loss can result in criminal charges.
🛡 Web | ✔ TG - Bot | 💬 Contact us

📡 Interaction with One of the Blockchain Bridges Used in the Money Laundering Scheme The screenshots show correspondence bet
+1
📡 Interaction with One of the Blockchain Bridges Used in the Money Laundering Scheme The screenshots show correspondence between the AML Crypto team and representatives of a blockchain bridge that was used by the attackers to launder part of the stolen assets. 🔹 The first screenshot shows an outgoing request from AML Crypto, which includes: — The transaction hash related to the cash-out of funds — The address to which the tokens were transferred — A request for any available information about the user who initiated the transfer — A request to block any further operations from the associated account — An attached investigation report in PDF format 🔹 The second screenshot shows the response from the bridge representatives, confirming: — Receipt of the request from legal authorities — Transmission of the requested information — Willingness to continue cooperating in the investigation — The need for a formal request on official letterhead in order to provide non-public data 🧾 This case illustrates how AML Crypto’s technical investigation is complemented by legal interaction — aiming to block assets and trace leads that could help identify the perpetrator.

💸 Crypto Exchange with AML Check at Entry, Zero at Exit One of the typical scenarios the AML Crypto team frequently encounters during investigations is a fake crypto exchange offering a “favorable rate” with a mandatory AML check. In one such case, the victim lost nearly 120,000 USDT. Part of the funds has already been frozen. The essence of the scheme: No phishing or hacking involved — the victim voluntarily grants access to their wallet, believing they are undergoing a routine “cleanliness” check. 💬 How the victim was deceived: - The user saw an ad for an exchange offering “cash on the same day” and a wide network of local representatives. - The first interaction left a good impression: responsive support, willingness to meet, and the option to send crypto during an in-person meeting with a courier or at an office. - After some time, the client returned and agreed to a deal — an exchange in person with a courier. - Before the courier’s dispatch, they requested an AML check and sent a link to an AML service. - The client connected their wallet. A few minutes later — the balance was wiped. - The message with instructions disappeared right after. 🔍 What actually happened: - The scammers ran an advertising campaign and responded actively to inquiries — creating the illusion of a legitimate service. - A clone of a real AML service was used, and when the victim connected their wallet, they effectively granted token management permissions. - Funds were instantly transferred to the scammers' addresses, broken down, laundered through non-KYC exchanges, bridges, and partly moved into Monero.
🧠 AML Crypto’s actions: - Identified the platforms, addresses, and exchanges involved. Sent requests for fund freezes and data to help identify the perpetrators. - Prepared a fund flow graph and tagged high-risk addresses. - Supported law enforcement with a full report, request templates, and contacts of the services used for laundering. - With the help of Tether, part of the stolen USDT was frozen.
🔒 How to protect yourself: - Verify exchanges: check reviews, use aggregators, and look for operational transparency. - Always double-check what permissions you're granting when connecting your wallet. - If funds are lost — act fast. Reaction speed is crucial for recovery.

📍Fragment of the asset movement graph:

Invested in a Lie: The Fake Broker Scheme Uncovered Here’s a real case from an AML Crypto client who fell victim to a pseudo-investment platform scam. Losses amounted to the equivalent of 602K USD. Everything appeared to be a legitimate investment, but it was actually a sophisticated and technological scheme to siphon off funds. 💬 What the Client Experienced (and How the Scam Operated): - A “personal manager” actively engaged in communication, often holding video calls. - The platform displayed deposit growth, trading activities, and transaction history. - Scammers staged scenarios like “withdrawal errors,” “regulatory checks,” and “fund freezes.” - The client was shown “care”: advised to install wallets (Trust Wallet, MetaMask), guided through creating addresses to gain access to seed phrases. - High-pressure tactics were used: “you need to deposit more to unfreeze your funds,” “we’ll withdraw everything after one final verification.” - Fake tokens and screenshots of non-existent transactions were sent as “proof.” 🔍 What Actually Happened: - All transfers went not to a legitimate investment platform but directly to blockchain addresses controlled by scammers. Funds were not invested; they immediately entered money-laundering processes. - Funds were dispersed across dozens of wallets. - Criminals used blockchain bridges between Polygon and TRON to complicate investigations. - Money passed through multiple addresses and was ultimately withdrawn to exchanges (Binance, HTX, Kyrrex, and others).
🧠 What AML Crypto Did: - Identified blockchain addresses involved in the fraud. - Gathered evidence of stolen funds moving to centralized exchanges. - Prepared a detailed report containing critical information: amounts, routes, dates, transactions—all useful for potential asset blocking. - Created templates for official requests to exchanges for law enforcement, as exchanges store critical digital footprints: account holders’ identity documents, KYC results, IP addresses, device information, phone numbers, and more. - Flagged compromised addresses — any funds originating from these can now be instantly marked as high-risk and blocked by partnered services.
📌 Conclusion and Recommendations: This case highlights how easily newcomers exploring cryptocurrencies can fall into traps, especially when fraud schemes masquerade as attractive investments. 🔒Recommendations: - Do not trust investment proposals from “managers” on messengers and social networks. - Never share seed phrases or create wallets following instructions from strangers. - Verify recipient addresses and platforms using analytical tools (btrace.amlcrypto.io). - If funds are lost, act immediately. Time is crucial for potentially blocking and recovering stolen assets. - Save correspondence, screenshots, and transaction IDs—they are essential for investigations. If you or your clients have doubts about a transaction, situation, or address, it’s better to check in advance than deal with consequences later. AML Crypto handles both individual and corporate incidents.

🚨 Exchanges and wallets use AML checks. Do you? Just because you're not checking crypto wallets, doesn’t mean others aren’t checking yours. Regulations are tightening, criminals are always active, and crypto account blockages are happening more often. Don’t make the same mistake as others — use AML checks like the market professionals do. ✅ AML Crypto’s Telegram bot — instant and easy wallet checks in just a couple of clicks. Start with 3 free checks! 👉 Check your wallet now! Make sure your assets are protected.

💥 Legal Expert Recommends DeFi Platforms Return Lazarus Swap Fees After ByBit Hack In light of recent events related to the Lazarus attack, legal expert Dr. Rasit Tavus, founder and CEO of LegalBlock, raises an important question: should DeFi platforms return swap fees associated with illicit transactions, such as those involving stolen funds from Bybit?
🔑 Key Takeaways: - Centralized platforms are required to comply with international AML standards and are accountable for preventing money laundering. For instance, companies like Binance have already returned illicit swap fees to the US Treasury. - DeFi platforms, however, operate differently. They are not directly legally liable for transactions, but if a platform fails to act and allows illicit swaps to occur, returning the fees becomes a justifiable action. - In the case of ThorChain, where millions of dollars in fees were generated from suspicious transactions, returning these funds would be a logical step, especially considering the platform did not take measures to prevent laundering.
⚖️ What does this mean for DeFi? While DeFi platforms are not legally obligated to return funds, they must avoid profiting from prolonged illicit activities. Returning swap fees in such cases would be an important step in protecting the reputation and trust within the industry. This issue is gaining momentum, and we may see more precedents in the future where DeFi platforms will be required to adopt such practices. API for getting the blacklist: https://btrace.amlcrypto.io/api/v2/bybit_blacklist

🚨 New Data on the ByBit Hack as of March 20: Hackers Begin Using Mixers to Launder Funds Ben Zhou, CEO of ByBit, has shared
🚨 New Data on the ByBit Hack as of March 20: Hackers Begin Using Mixers to Launder Funds Ben Zhou, CEO of ByBit, has shared new details regarding the investigation into the largest cryptocurrency hack, valued at $1.4 billion. The hackers involved in the incident have started actively using mixers to conceal the stolen funds: 🔑 Key Points: - Hackers have begun using mixers: Wasabi, CryptoMixer, Railgun, TornadoCash. - 88.87% of the funds remain traceable, 7.59% have gone "dark," and 3.54% have been frozen. - 86.29% of the funds (440,091 ETH, approximately $1.23B) have been converted into 12,836 BTC, spread across 9,117 wallets (average 1.41 BTC per wallet). - A portion of the funds (193 BTC) was sent through Wasabi Mixer, then transferred via various P2P platforms.
💡 The Mixer Problem: Currently, the most challenging task is decoding transactions that have passed through mixers. This requires significant efforts, and the ByBit team is urging bounty hunters to assist in analyzing these transactions.
Forecast: As hackers continue to use mixers, the number of such transactions will grow. Therefore, it is crucial to involve more experts and bounty hunters capable of decoding this data for the investigation. The ByBit team is calling on anyone who can help with the investigation to reach out via Lazarus Bounty. API for getting the blacklist: https://btrace.amlcrypto.io/api/v2/bybit_blacklist

🚨 OKX Suspends DEX Aggregator Due to Lazarus Attacks, Media Reports, and Blockchain Explorer Issues OKX has temporarily susp
🚨 OKX Suspends DEX Aggregator Due to Lazarus Attacks, Media Reports, and Blockchain Explorer Issues OKX has temporarily suspended its DEX aggregator. This decision is related to the need to fix incomplete tagging on blockchain explorers and implement new security features following coordinated media attacks and attempts by the Lazarus group to misuse their DeFi services. 🔑 Key points from the exchange's announcement: - As part of the updates, OKX is pausing the creation of new wallets for users in certain regions, but all existing wallets remain accessible. - The company is actively working on enhancing security and updating the system to prevent further abuses. - A real-time hacker address tracking system has also been implemented to block them within the platform's ecosystem. Additionally, OKX continues to improve blockchain explorers to ensure they properly display transaction data via their DEX and avoid mistakenly identifying the aggregator as the point where trades actually happen.

The AMLCrypto.io team conducted an investigation into the Bybit exploit incident on the Binance Smart Chain network. The inve
+2
The AMLCrypto.io team conducted an investigation into the Bybit exploit incident on the Binance Smart Chain network. The investigation began with addresses verified on the Lazarus Bounty website. Major fund flows associated with the attacker’s addresses in the BSC network were analyzed. *Legend on the graph №1 ⚫️ - addresses affiliated with Bybit exploiter 🟠 - bridges addresses 🟣 - dex addresses During the investigation, it was discovered that the attackers use a method of looping funds through specific addresses. These addresses can be conditionally divided into HOP levels, which represent transaction stages based on their position in the chain. When the funds reach the final HOP level, the attacker sends them back to HOP-1, after which they pass through all levels again, but in a different sequence. To visually illustrate this process, the AMLCrypto.io team has prepared a simplified visualization of fund movements: *Legend on the graph №2 ⚫️ - addresses affiliated with Bybit exploiter 🟠 - bridges addresses For the investigation, the address 0x9c249b3db6345367b43b2ced4c07d4ffa1fb5e11, verified by LazarusBounty, was analyzed. This address received [201,216 USDC from the Ethereum network]. The funds moved through more than 40 transactions, looping between 33 addresses before being withdrawn to OKX DEX. Below is a simplified visualization of the fund looping scheme used by the attacker in the Binance Smart Chain network. Explanation of the Video: 🟠 Orange paths illustrate the movement of funds from the Ethereum network to the OKX DEX service. 🔵 Blue paths represent branches along this route. They show one of the possible ways funds move through multiple attacker-controlled addresses before reaching OKX DEX. In the blockchain, these blue paths are formed for each attacker’s address involved in the scheme.
A notable pattern is the periodic splitting of the fund flow into multiple addresses by the attacker. At certain points, funds are simultaneously held across multiple addresses before being transferred further down the chain. All these transactions occur within the same second, indicating a high level of automation and ruling out the possibility of manual fund transfers.

The AML Crypto team conducted an investigation into the Bybit exploit incident on the Arbitrum network. The investigation beg
The AML Crypto team conducted an investigation into the Bybit exploit incident on the Arbitrum network. The investigation began with addresses verified by the LazarusBounty website, which is affiliated with the Bybit team. *Legend on the graph: 🟣 - decentralized and centralized addresses ⚫️ - Bybit exploiter addresses 🟠 - bridge and centralized services addresses 🔴 - verified Bybit exploiter addresses by Bybit Full-size graph During the investigation, new tactics used by malicious actors were identified, revealing sophisticated schemes for concealing the movement of illicit funds. Analysis of the behavior of involved addresses showed that, on most addresses linked to the Bybit exploit, the perpetrator actively employs Thorchain Staking. This method not only helps obscure the origin of assets but also effectively mixes them with legitimate flows, significantly complicating the tracking and analysis of the transaction chain.
Staking is the process of locking up cryptocurrency to support the operation of a blockchain and earn rewards. It is available in networks that use Proof-of-Stake (PoS) and its variations.
Additionally, it was established that a significant portion of the funds obtained through attacks was transferred to the Arbitrum network using services such as Maya Protocol, Chainflip, Unizen Pro, and Cow Protocol. These platforms facilitate the rapid movement of assets across different blockchains, making them a convenient tool for obscuring the traces of illicit transactions. After passing through a series of transit addresses, the funds continue moving and are withdrawn through OKX DEX, Across Protocol, and Maya Protocol into various networks. The majority of these funds are directed into the Ethereum ecosystem, which may indicate further attempts to integrate them into legitimate financial flows via decentralized exchanges, staking platforms, or mixing services. API for getting the blacklist: https://btrace.amlcrypto.io/api/v2/bybit_blacklist

How Ben Zhou and Bybit Handled the Largest $1.4 Billion Hack On February 21, 2025, the cryptocurrency exchange Bybit fell victim to the largest hack in the history of crypto, amounting to $1.4 billion. This incident was a true test for Ben Zhou, CEO and co-founder of Bybit, who found himself at the center of a crisis requiring immediate decisions and a swift response. Such situations can either strengthen or damage a leader’s reputation. Here’s how Bybit and Ben Zhou tackled this challenge: - Immediate Response: Upon learning of the hack, Ben Zhou took charge right away and began responding within 30 minutes. He actively used his X account and organized a two-hour live stream, providing real-time updates and reassuring users. - Platform Continuity: Despite the crisis, Bybit continued to offer its services, including withdrawals, processing more than 350,000 requests within the first 12 hours after the hack. - Securing Emergency Funding: The exchange secured emergency funding and successfully replenished its asset reserves, maintaining a 1:1 ratio to protect customer funds. - Industry Support: In response to the incident, competing cryptocurrency exchanges and other industry players joined forces with Bybit, identifying and blocking hacker addresses, and helping to prevent further movement of the stolen funds. - Independent Audit: To ensure transparency and financial stability, Bybit enlisted Hacken to conduct a reserves audit, confirming that all assets were fully backed 1:1. - Collaboration with Law Enforcement: In response to the incident, Bybit actively collaborated with law enforcement, which helped provide a swift and effective response to the breach. - Ben Zhou’s Response: Ben Zhou not only responded swiftly to the hack but also actively shared information with users and investors, building their trust. - User Support: Within 12 hours of the hack, more than 350,000 withdrawal requests were processed, and the exchange continued to operate normally, providing users access to their assets. Ben Zhou, co-founder and CEO of Bybit, previously worked in the financial sector, and in 2018, he founded Bybit, which quickly became one of the world’s largest cryptocurrency platforms. His experience in the financial industry helped him navigate the crisis, but the hack incident has undoubtedly been an important lesson for the entire industry. This situation highlights the importance of crisis management, constant readiness for attacks, and the need for transparency and cooperation between platforms, analytics firms, and law enforcement agencies in handling major incidents.
The information is based on an article on Cointelegraph, thanks to the author for providing the data. The full version and all details can be found at this link
API for getting the blacklist: https://btrace.amlcrypto.io/api/v2/bybit_blacklist

DAY 15. 2025-03-07

Bybit and OKX's Response to the Hack: Collaboration to Reduce Untraceable Funds Today, Bybit CEO Ben Zhou thanked Hong Fang,
+1
Bybit and OKX's Response to the Hack: Collaboration to Reduce Untraceable Funds Today, Bybit CEO Ben Zhou thanked Hong Fang, President of OKX, for their assistance in reducing the untraceable stolen funds from Bybit. In his tweet, Ben stated that, following active cooperation with OKX's team, the untraceable amount had been reduced to 3985 ETH, and they will continue working together to further lower this figure. Hong Fang emphasized that OKX is actively updating blacklist addresses and that all transactions in self-custody wallets should be traceable. He also suggested centralizing requests via email (safety@okx.com) to ensure more efficient communication and offered help from OKX's Web3 team in analyzing chains and bridges to trace the funds. API for getting the blacklist: https://btrace.amlcrypto.io/api/v2/bybit_blacklist

DAY 13. 2025-03-05

Lazarus Group appears to have extensive experience and tools to launder funds According to the analysis of attacks by Lazarus
Lazarus Group appears to have extensive experience and tools to launder funds According to the analysis of attacks by Lazarus Group, the cybercriminals have extensive experience and tools to launder stolen funds. In March 2022, they carried out the largest hack in crypto history, stealing more than $620 million from the cross-chain bridge Ronin Bridge. This incident was part of a larger trend of attacks on DeFi protocols, especially cross-chain bridges. Almost immediately after the attack, Lazarus began transferring the stolen funds to Tornado Cash, using this mixer to subsequently launder them and cover their tracks. These actions confirm that the group has deep knowledge of blockchain anonymization and continues to refine their methods of evading surveillance. It is noteworthy that the Lazarus group uses blockchain addresses in the process of laundering funds where the cryptocurrency has been stored for more than a year. This may indicate several important aspects of their strategy: 1. Use of "dormant" funds The use of old addresses that have remained inactive for a long time may be part of a well-thought-out scheme. Such funds may have belonged to Lazarus since previous attacks or were acquired through third parties, which makes them more difficult to trace. 2. Connection to previous incidents The fact that old funds are involved in the laundering process may indicate their connection to earlier cybercrimes. Perhaps these assets are part of previously stolen funds that were stored for a long time for later use. 3. Cold Mixing Technique Lazarus may have prepared these funds in advance, waiting for the right moment to move them and mix them with new flows of stolen assets. This method reduces the likelihood of identifying links between different attacks. 4. Breaking Trails and Complicating Analysis Involving old funds in new transactions creates additional obstacles for analysts and blockchain monitoring systems. It makes it difficult to automatically determine the origin of assets and can confuse algorithms focused on analyzing recent transactions. 5. Possible Use of "Sleeping" Funds Lazarus may have distributed funds to "dormant" wallets in advance, counting on the fact that investigators would not be interested in these addresses. After a long period of inactivity, such funds may be perceived as "forgotten" or "abandoned", making their sudden movement less obvious. API for getting the blacklist: https://btrace.amlcrypto.io/api/v2/bybit_blacklist