Financial Layer

The Long Cash-Out: how a ransom becomes rubles

Operation Endgame attacks the front of the kill chain, where malware manufactures access. This is the back of the same chain: the seven moves that turn a victim's payment into spendable money, and the handful of places that money is thin enough to break.

By Reno July 9, 2026 19 min read Open Research
The cash-out chain, ransom to fiat · illustration

A ransom does not end when the victim pays. That is where the harder problem begins. A hospital wires the equivalent of tens of thousands of dollars in Bitcoin to an address it was given by people it will never meet, and in that instant the money becomes a liability for the people who extorted it. It is loud, traceable, and frozen the moment anyone important is watching. The work that follows, turning that hot transfer into clean, spendable value on the other side of a border, is the part of the ransomware business that almost never makes the headline and almost always decides whether the business is worth running at all. Analyst inference

We looked at Operation Endgame elsewhere; this follows the other end of the same chain. That campaign is the best sustained assault ever mounted on the machinery beneath ransomware, the loaders and infostealers and access brokers that manufacture the intrusion. By Europol's own account it targets "initial access malware, the tools cybercriminals use to infiltrate systems unnoticed before deploying ransomware." It strikes the very start of the attack chain. What it does not touch, by design, is the other end: the laundering path that carries the proceeds home. Confirmed reporting

End Krysha exists to walk that other end. What follows is one payment's journey through seven moves, from a victim's wallet to rubles a Russian operator can actually spend, told through the named services, the on-chain figures, and the enforcement actions that have lit each step. The point is not the plumbing for its own sake. It is to find the places where the pipe is narrow enough to squeeze.

Two ends of the same chain

Operation Endgame is aimed at the malware supply chain and the infrastructure beneath it. This dispatch follows the other dependency, the Money, to where it comes to rest: under the roof, the Krysha this publication is named for. Analyst inference

Start with the scale, because it sets the stakes. Illicit crypto addresses took in more than $150 billion in 2025 (Chainalysis and TRM Labs put it at $154 billion and $158 billion, counted differently), most of the growth tied to sanctions evasion concentrated around Russia. Ransomware is a small and shrinking slice of that: payments fell from over $1 billion in 2023 to about $813 million in 2024 and held flat or lower in 2025, even as victim counts climbed. Fewer targets pay now, but the ones who do pay more, with the median ransom jumping from roughly $12,700 to $59,600 in a year. The money that moves is more concentrated and more valuable per payment, which only raises the stakes on the steps that follow. Confirmed reporting

The through-line is stablecoins. By Chainalysis's 2026 accounting, 84 percent of all illicit transaction volume in 2025 moved in stablecoins, overwhelmingly USDT, and overwhelmingly on the Tron network. That single fact shapes every move that follows, because it tells you what the money wants to become as fast as it can: a dollar-pegged token that holds its value, settles in seconds, and crosses borders without a bank. Confirmed reporting

The attack is the loud part. The laundering is the business.

Move one: the payment and the split

Most ransomware today is a rental business. An operator builds and maintains the malware, the leak site, and the negotiation infrastructure; affiliates do the breaking-in and take the larger cut. The standard split runs about 80 percent to the affiliate, 20 percent to the operator, a ratio confirmed across LockBit's leaked infrastructure and used by analysts to tell affiliate wallets apart from administrator wallets. When a payment lands, the first thing that happens on-chain is this division: within minutes the operator's share and the affiliate's share peel into separate wallets and begin two separate laundering journeys. Confirmed reporting

The affiliate rarely started from nothing. The intrusion was very often bought, and this is the seam that ties the Money back to Operation Endgame's targets. Infostealers such as StealC and Amadey, and loaders such as SmokeLoader and IcedID, harvest corporate credentials by the million; those logs sell on underground markets for as little as ten dollars each; initial access brokers package the good ones into working network access and sell that on to ransomware affiliates. An estimated 1.8 billion credentials were stolen by infostealers in 2025. The malware Endgame keeps dismantling is the raw-material end of the same supply chain whose finished product is the ransom we are now following. Credible reporting

How the ransom itself is paid is a quiet tug of war. Operators increasingly prefer Monero, whose privacy by default breaks tracing at the source, and in 2025 nearly half of newly launched darknet markets accepted Monero exclusively. Yet most real ransom payments still settle in Bitcoin, because victims can actually buy Bitcoin quickly and their insurers and incident responders can handle it. The friction is real enough that some crews price it in, charging a premium to pay in Bitcoin or offering a discount to pay in Monero. When the payment does arrive in Bitcoin, it arrives fully traceable, and the clock on the next six moves starts. Credible reporting

Two cases show the range of what happens next. When Colonial Pipeline paid 75 Bitcoin (about $4.4 million) to DarkSide in May 2021, the FBI followed the chain and clawed back 63.7 Bitcoin weeks later, a rare win that turned on the private key sitting on a server inside U.S. reach. That is the exception that proves the rule: recovery happened because the laundering had not yet left a jurisdiction anyone could touch. Contrast Change Healthcare's roughly $22 million payment to ALPHV/BlackCat in 2024, where the operator took the whole ransom, stiffed its own affiliate, and vanished, and where forensic tracing later showed $9.1 million of ALPHV's proceeds flowing into a single laundering service we will meet in the next move. Confirmed reporting

Move two: breaking the trail

Once the ransom is split, the goal is to sever the visible link between the extortion wallet and wherever the money finally lands. The oldest technique is the peel chain: the balance hops through a long sequence of fresh addresses, peeling off a small amount at each step while the remainder moves on, so that no single transaction looks like the whole ransom and the trail frays into hundreds of threads. Peel chains are cheap and easy to automate, but on their own they no longer defeat a competent analytics firm. For that, actors reach for mixers. Confirmed reporting

A mixer pools many users' coins and redistributes them, so outputs cannot be matched to inputs. For years this was the workhorse of crypto laundering, and for the last three years it has been the single most heavily targeted node in the entire pipeline. The enforcement record reads like a graveyard: Bitcoin Fog's operator convicted in 2024 after more than a decade and roughly $400 million cycled; Helix before it; ChipMixer dismantled by Europol and German authorities in March 2023 with something like 2.73 billion euros in throughput; Blender and Sinbad sanctioned by OFAC as North Korean laundering tools; Samourai Wallet's founders arrested in April 2024. Even Tornado Cash, sanctioned in 2022, saw its designation ruled unlawful by an appeals court and formally withdrawn by OFAC in March 2025, while a jury deadlocked on most of the charges against one of its developers. The tool survives in law; the deterrent effect on ordinary criminals did not. Confirmed reporting

The version of this built specifically for ransomware is the clearest case study we have, and it fell apart in public only last month. Endgame did not take it down; a separate, money-focused action did.

U.S. DOJ / Europol · Dismantling of the AudiA6 laundering service (excerpt), June 10–11, 2026
ServiceAudiA6, operated alongside the Dark2Web criminal forum: a mixer-and-swap "mixer-as-a-service" Launderedapprox. EUR 336 million (about $389M) between 2022 and 2025 Ransomware shareroughly 80% of traced illicit exposure; 20 distinct ransomware groups served Methodlayering through 6,000+ KYC-verified money-mule accounts at mainstream exchanges; obfuscated funds returned in about an hour Named flowsALPHV/BlackCat $9.1M, Qilin $7.1M, LockBit $4.4M, others Operatorstwo administrators arrested in Batumi, Georgia; extradition sought CoalitionDOJ (E.D. Pa.), U.S. Secret Service, Europol, 11 countries
Source: DOJ, Europol, Eurojust, and TRM Labs statements, June 2026. Public enforcement record, reproduced for analysis.
Fig. 3 · One ransom's path to a launderer (documented flow)
Victim
Change Healthcare
Feb 2024
$22M
Operator
ALPHV / BlackCat
keeps all; affiliate stiffed
$9.1M
Launderer
AudiA6
mixer-as-a-service
Layer
6,000+ mule accounts
mainstream exchanges
Exit
Fiat cash-out
bank & payment rails
The $9.1M is ALPHV/BlackCat's aggregate traced flow into AudiA6, of which Change Healthcare was the largest known feeder, not a provable one-to-one transfer of the $22M ransom. The affiliate exit-scam is why the usual 80/20 split does not appear on this path. Sources: DOJ and Change Healthcare disclosures (2024); TRM Labs (2026).

Two details from the AudiA6 file matter for the whole pipeline. First, its exposure was about 80 percent ransomware, which is what a purpose-built ransomware off-ramp looks like from the inside. Second, six months before the arrests, TRM Labs had already traced roughly $7 million of stolen 2022 LastPass funds out of the Wasabi mixer and into AudiA6 deposit wallets, using cluster-level demixing. The lesson is not that mixing is safe. It is that mixing is increasingly demixable, which is exactly why the smart money is leaving mixers for something harder to follow. Confirmed reporting

Move three: changing shape

The defining laundering shift of the last two years is the migration off mixers and onto cross-chain bridges and decentralized swap services. A bridge moves value from one blockchain to another; a no-identity swap service turns Bitcoin into Monero into Tron-based USDT without ever asking a name. Chained together, they let proceeds change both chain and asset several times in minutes, which frustrates single-chain tracing far more effectively than a mixer that lives on one ledger. Confirmed reporting

The numbers capture the handover cleanly. In ransomware-linked laundering specifically, TRM Labs measured mixer volume falling from about $152 million in 2021 to roughly $48 million in 2024, while bridge-related flows climbed to about $100 million in 2025 and overtook mixers for the first time in 2024. Bridge activity from ransomware wallets grew about 66 percent year on year as mixer activity fell about 37 percent. Zoom out to all illicit crypto and Elliptic's cumulative estimate for cross-chain crime reached $21.8 billion by mid-2025, roughly triple its 2023 figure. Confirmed reporting

Fig. 1 · The trail changes shape: ransomware-linked laundering, mixers vs bridges (TRM Labs)
$152M
Mixers2021
TRM Labs
$48M
Mixers2024
TRM Labs
$100M
Bridges2025
TRM Labs
Enforcement pushed mixer use down; bridges absorbed the displaced flow and overtook mixers in 2024. Single-vendor series (TRM Labs, June 2026); figures are ransomware-attributed, not total market. Shown to convey direction, not precision.

The services doing the shape-changing are named and, for the most part, unlicensed. No-identity swap desks sit alongside decentralized cross-chain protocols such as THORChain, which lets a user move between blockchains without an intermediary that could ask for a passport. These are not ransomware-specific tools, which is exactly their value: legitimate volume gives illicit flows cover, and a bridge that serves a million honest users is a far harder thing to seize than a mixer that served only criminals. That dual-use quality is the single biggest reason this move is harder to attack than the mixer move before it. Credible reporting

Two forces sit behind the shift. One is enforcement: every mixer takedown taught operators that a service living on one chain is a fixed target. The other is the same stablecoin gravity noted at the start. Somewhere in this move, volatile Bitcoin or Ether becomes Tron-based USDT, because value that has to sit in wallets and cross venues cannot be exposed to a 20 percent price swing mid-laundry. The tension is that USDT on Tron is freezable by Tether at the token level, as the North Korea and Iran freezes have shown, so actors race to convert and move before an attribution catches up. It usually does not catch up in time. The $1.5 billion Bybit theft in February 2025, the largest crypto heist on record, was laundered at speed through swap services and bridges including Tron-based routes, and most of it was gone before the freezes landed. The same rails that carried state-scale theft, North Korea alone stole more than $2 billion in crypto in 2025, are the rails a ransomware affiliate rents for a single mid-six-figure payout. Confirmed reporting

Move four: the settlement floor

By now the money is stablecoins on Tron, several hops removed from the ransom, and it needs a venue that will hold it, trade it, and stand ready to turn it into local currency. For the Russian-speaking ecosystem that venue has, for years, been a high-risk exchange, and the archetype was Garantex. We have written the full reconstitution story elsewhere; what matters here is the shape it left behind. Confirmed reporting

Garantex moved more than $96 billion across its life and kept growing after its first sanctioning. When a coalition seized it in March 2025, the operation was back within days as Grinex, a successor incorporated three months in advance, and the customer balances rode across on a ruble-backed token called A7A5. When Grinex itself went dark in April 2026 after a convenient "hack," the displaced volume did not scatter. It re-concentrated onto a short, named set of venues, most operating from inside Russia: ABCeX (roughly $11 billion processed, run from Moscow's Federation Tower), Rapira, Bitpapa, Exmo, and Aifory Pro. Credible reporting

Underneath the exchange brands is the part that does not rebuild in a week. A7A5 is a ruble-pegged stablecoin issued by A7, a Moscow cross-border payments firm co-owned by the sanctioned financier Ilan Shor and the sanctioned, defense-linked Promsvyazbank. It cleared roughly $93 billion in its first year, has since passed $100 billion in reported turnover, and in October 2025 was approved for Russian foreign-trade settlement. This is the settlement floor: exchange front-ends are interchangeable, but the rail beneath them is banking access, correspondent relationships, and state alignment, none of which a rebrand replaces. When you follow a laundered ransom to its resting venue, you are really following it to this rail. Confirmed reporting

Move five: back into cash

Stablecoins in a Russian exchange account are not yet spendable in the physical world. The last technical move is the off-ramp, the conversion of crypto into fiat someone can hold, and here the ecosystem runs three parallel exits. Confirmed reporting

The first is the cash desk. High-risk exchanges operate walk-in offices, most visibly in Moscow's Federation Tower and in Kazan, Rostov, and Yekaterinburg, where crypto becomes banknotes over a counter. When Russian security forces raided these offices in September 2025, targeting Rapira and the ABCeX-linked Mosca, they seized more than $10 million in cash, 100 million rubles, and 200,000 euros at a single location. The raids are their own tell, and we return to them in the next section, because the offices were open again within weeks. Confirmed reporting

The second is the courier network, and it is the one that best captures how frictionless cash-out has become. The International Consortium of Investigative Journalists (ICIJ) and its November 2025 "Coin Laundry" investigation documented 001k, a service offering crypto-to-cash hand-delivery in more than 300 cities worldwide, including Montreal, New York, Los Angeles, and Miami, with no money-transmitting license. It has received more than $14.8 billion in cryptocurrency since August 2022. Identity verification is a photograph of the serial number on a five-dollar bill, presented again at the handoff. In an undercover test, a reporter exchanged 2,000 USDT for cash with no ID at all. Downstream, 001k's flows resolve into hundreds of millions at major exchanges and more than a billion at WhiteBIT. Confirmed reporting

The third is the mule network, the exit AudiA6 industrialized with its 6,000 verified accounts at mainstream exchanges. Real people, or stolen identities, hold accounts that absorb the regulatory risk while the operator moves value through them. The UK's Operation Destabilise mapped this at the wholesale level: the linked TGR and Smart networks laundered for Evil Corp, Conti, and Ryuk, went as far as buying a bank in Kyrgyzstan, and have drawn more than 128 arrests and over 25 million pounds seized. All three exits ultimately touch ruble banking rails through sanctioned institutions, Sberbank, VTB, Gazprombank, Promsvyazbank, and A7A5's cross-border settlement that steps around the international banking system entirely. Confirmed reporting

The exchange is a front-end. The rail is banking access. Only one of them rebuilds in a week.

Move six: the roof

Everything to this point is technical, and technical steps can be attacked technically. The seventh move is not technical. It is the reason the whole chain terminates in Russia rather than anywhere the money could be seized: the krysha, the protection that lets these operators run in the open. This is the dependency our Endgame reading identified as the one no infrastructure campaign can reach, and following the money is what makes its shape visible. Analyst inference

The evidence is strongest, and closest to active protection rather than passive tolerance, at the settlement rail. A7A5 is co-owned by a sanctioned state-linked bank, Promsvyazbank, which finances Russian defense. The token was approved for national foreign-trade settlement by government decision, with its operators openly targeting a fifth of the country's international payments. The UK, designating the A7 network in May 2026, described it as moving more than $90 billion into Russia's economy and financing procurement for the war. A state does not co-own, authorize, and route trade through a laundering rail it merely tolerates. Confirmed reporting

The September 2025 Moscow raids look, at first, like the opposite of protection. Read against what followed, they read more like management. Officers seized cash and hardware, the press covered it, and the targeted exchanges resumed operating within weeks, one lawyer noting drily that year-end quotas needed "case outcomes." The pattern of raid-and-restore is more consistent with an ecosystem the state can squeeze at will than with one it intends to shut. For the broad exchange layer the honest label remains tolerated safe harbor with selective extraction; for the A7 rail specifically, the ownership and the trade mandate point past tolerance toward active alignment. Analyst inference

What comes next

Two trajectories are already visible, and both are directional rather than certain. The first is method. The move from mixers to bridges is not a destination but a heading: as bridge tracing improves, the next step is toward privacy by default, Monero and no-identity swap desks, which is why nearly half of the darknet markets launched in 2025 accepted Monero alone. Expect the laundering path to keep trading throughput for opacity wherever enforcement makes throughput risky. Credible reporting

The second is law, and it pushes the other way. Two instruments could reach the settlement floor that seizures cannot. New stablecoin legislation, led by the US GENIUS Act, moves freeze capability and anti-laundering duties onto the issuers themselves, which would turn Tether's discretionary freezes into standing obligations and shorten the window operators depend on. And the FATF Travel Rule, if it is finally implemented evenly rather than in patches, would force identity to travel with every transfer between regulated venues, closing the seams the nested and mule networks live in. FATF spent 2026 warning that uneven adoption is the gap. Credible reporting

Neither instrument reaches Moscow. Both press on the parts of the chain that sit in reach: the issuers, the compliant venues, the correspondent banks. Analyst inference

Where the chain breaks

Trace all seven moves and the leverage points fall out of the geometry. The pipeline is long, but it is not evenly strong, and three properties decide where pressure pays. Analyst inference

The first is concentration. Ransomware proceeds do not exit through hundreds of doors evenly. TRM Labs finds that the top five cash-out services absorb between 42 and 57 percent of ransomware off-ramp volume in any year, about 51 percent in 2025, and the top ten handle as much as three quarters. That concentration dipped when enforcement disrupted key nodes, then rebounded, which cuts both ways: the network regenerates, but it regenerates back into a small, identifiable target set. A handful of venues convert most of the money. That is not a weakness the ecosystem can design away, because concentration is what makes an off-ramp liquid enough to be useful. Confirmed reporting

Fig. 2 · Concentration is the target: share of ransomware off-ramp volume (TRM Labs)
42%
Top 5services, 2023
TRM Labs
51%
Top 5services, 2025
TRM Labs
~68%
Top 10services, 2025
TRM Labs
A small set of services converts most ransomware proceeds; the share fell under enforcement pressure in 2023, then rebounded. Single-vendor series (TRM Labs, June 2026). Top-10 bar is the midpoint of a stated 62 to 75 percent range.

The second is traceability, which has moved the other way from what operators assume. The AudiA6 demix, the Bybit tracing, and the routine unmasking of bridge flows all point the same direction: the on-chain record is permanent, and analytics keep catching up to obfuscation after the fact. Tether's freezes prove the choke can close when attribution is good, $344 million of Iranian-linked USDT in April 2026, $28 million in the Garantex action, 131 Tron wallets in July 2026. The constraint on freezing is not willingness, it is attribution speed, and attribution is the thing that improves every year. Confirmed reporting

The third property is the one that caps all the others: the jurisdictional ceiling. Core operators sit in Russia, beyond extradition, behind the roof, and no amount of on-chain brilliance reaches them there. But the pipeline is not staffed only by untouchable principals. The mid-tier, the mule coordinators, the swap-service operators, the launderers-for-hire, increasingly sit in places that do cooperate. AudiA6's administrators were arrested in Georgia. That is the model the record actually supports: not the fantasy of reaching Moscow, but the discipline of taking the affiliate and service layer wherever it strays into reach, and of attacking the settlement rail with the financial tools that do bite, as the UK did in extending correspondent-banking prohibitions to crypto exchanges for the first time in May 2026. Confirmed reporting

There is a structural reason to prefer this target over the ransomware brands themselves. TRM Labs argues that the cybercrime services layer, the access brokers, the hosting, the laundering desks, is inherently more disruptible than the ransomware groups it supports, because a single service quietly underwrites many groups at once and its operators run weaker security than the crews they serve. Take down one off-ramp whose flow is eighty percent ransomware, and you degrade twenty groups in a morning, which is precisely what the AudiA6 action did. The off-ramp is where the many separate crimes of many separate crews briefly become one shared, visible, seizable thing. Analyst inference

Set against this is the honest counter-argument, and it is strong: every takedown so far has produced a rebrand rather than a collapse. Garantex became Grinex in days. Mixer enforcement pushed volume into bridges rather than out of existence. The A7A5 rail has absorbed sanctions from three jurisdictions and kept clearing. Displacement is real at every layer where the underlying function still has somewhere to live. Confirmed reporting

Which returns the argument to where the Endgame piece left it. Attacking the malware degrades the machine that makes the money. Attacking the money degrades the machine that cleans it. Neither reaches the roof, and while the roof stands, both grow back. But the money layer has a property the malware layer does not: it is concentrated, it is traceable, and part of it is standing in extraditable jurisdictions right now. The ransom that started this journey is, by the end, sitting as rubles behind a state that will not give it up. Getting there took seven moves, and at least three of them happened somewhere a determined investigator could have been waiting. Analyst inference

Sourcing & confidence

This dispatch draws on government actions (DOJ, OFAC, FinCEN, Europol, Eurojust, UK FCDO and NCA), on-chain analysis from Chainalysis, TRM Labs, and Elliptic, and the ICIJ "Coin Laundry" investigation, cross-checked against our own exchange profiles. Aggregate figures from different firms are kept separate and never averaged. Confidence labels follow standard analytic practice.

Confirmed · multiple independent sources, including official designation or indictment language.
Credible · single strong source or consistent industry reporting, not yet officially confirmed.
Analyst inference · End Krysha's own assessment, drawn from the evidence above.

RansomwareMoney LaunderingCash-OutMixersBridgesA7A5Off-RampsOperation EndgameFinancial Layer