A ransom does not end when the victim pays. That is where the harder problem begins. A hospital wires the equivalent of tens of thousands of dollars in Bitcoin to an address it was given by people it will never meet, and in that instant the money becomes a liability for the people who extorted it. It is loud, traceable, and frozen the moment anyone important is watching. The work that follows, turning that hot transfer into clean, spendable value on the other side of a border, is the part of the ransomware business that almost never makes the headline and almost always decides whether the business is worth running at all. Analyst inference
We looked at Operation Endgame elsewhere; this follows the other end of the same chain. That campaign is the best sustained assault ever mounted on the machinery beneath ransomware, the loaders and infostealers and access brokers that manufacture the intrusion. By Europol's own account it targets "initial access malware, the tools cybercriminals use to infiltrate systems unnoticed before deploying ransomware." It strikes the very start of the attack chain. What it does not touch, by design, is the other end: the laundering path that carries the proceeds home. Confirmed reporting
End Krysha exists to walk that other end. What follows is one payment's journey through seven moves, from a victim's wallet to rubles a Russian operator can actually spend, told through the named services, the on-chain figures, and the enforcement actions that have lit each step. The point is not the plumbing for its own sake. It is to find the places where the pipe is narrow enough to squeeze.
Two ends of the same chain
Operation Endgame is aimed at the malware supply chain and the infrastructure beneath it. This dispatch follows the other dependency, the Money, to where it comes to rest: under the roof, the Krysha this publication is named for. Analyst inference
Start with the scale, because it sets the stakes. Illicit crypto addresses took in more than $150 billion in 2025 (Chainalysis and TRM Labs put it at $154 billion and $158 billion, counted differently), most of the growth tied to sanctions evasion concentrated around Russia. Ransomware is a small and shrinking slice of that: payments fell from over $1 billion in 2023 to about $813 million in 2024 and held flat or lower in 2025, even as victim counts climbed. Fewer targets pay now, but the ones who do pay more, with the median ransom jumping from roughly $12,700 to $59,600 in a year. The money that moves is more concentrated and more valuable per payment, which only raises the stakes on the steps that follow. Confirmed reporting
The through-line is stablecoins. By Chainalysis's 2026 accounting, 84 percent of all illicit transaction volume in 2025 moved in stablecoins, overwhelmingly USDT, and overwhelmingly on the Tron network. That single fact shapes every move that follows, because it tells you what the money wants to become as fast as it can: a dollar-pegged token that holds its value, settles in seconds, and crosses borders without a bank. Confirmed reporting
Move one: the payment and the split
Most ransomware today is a rental business. An operator builds and maintains the malware, the leak site, and the negotiation infrastructure; affiliates do the breaking-in and take the larger cut. The standard split runs about 80 percent to the affiliate, 20 percent to the operator, a ratio confirmed across LockBit's leaked infrastructure and used by analysts to tell affiliate wallets apart from administrator wallets. When a payment lands, the first thing that happens on-chain is this division: within minutes the operator's share and the affiliate's share peel into separate wallets and begin two separate laundering journeys. Confirmed reporting
The affiliate rarely started from nothing. The intrusion was very often bought, and this is the seam that ties the Money back to Operation Endgame's targets. Infostealers such as StealC and Amadey, and loaders such as SmokeLoader and IcedID, harvest corporate credentials by the million; those logs sell on underground markets for as little as ten dollars each; initial access brokers package the good ones into working network access and sell that on to ransomware affiliates. An estimated 1.8 billion credentials were stolen by infostealers in 2025. The malware Endgame keeps dismantling is the raw-material end of the same supply chain whose finished product is the ransom we are now following. Credible reporting
How the ransom itself is paid is a quiet tug of war. Operators increasingly prefer Monero, whose privacy by default breaks tracing at the source, and in 2025 nearly half of newly launched darknet markets accepted Monero exclusively. Yet most real ransom payments still settle in Bitcoin, because victims can actually buy Bitcoin quickly and their insurers and incident responders can handle it. The friction is real enough that some crews price it in, charging a premium to pay in Bitcoin or offering a discount to pay in Monero. When the payment does arrive in Bitcoin, it arrives fully traceable, and the clock on the next six moves starts. Credible reporting
Two cases show the range of what happens next. When Colonial Pipeline paid 75 Bitcoin (about $4.4 million) to DarkSide in May 2021, the FBI followed the chain and clawed back 63.7 Bitcoin weeks later, a rare win that turned on the private key sitting on a server inside U.S. reach. That is the exception that proves the rule: recovery happened because the laundering had not yet left a jurisdiction anyone could touch. Contrast Change Healthcare's roughly $22 million payment to ALPHV/BlackCat in 2024, where the operator took the whole ransom, stiffed its own affiliate, and vanished, and where forensic tracing later showed $9.1 million of ALPHV's proceeds flowing into a single laundering service we will meet in the next move. Confirmed reporting
Move two: breaking the trail
Once the ransom is split, the goal is to sever the visible link between the extortion wallet and wherever the money finally lands. The oldest technique is the peel chain: the balance hops through a long sequence of fresh addresses, peeling off a small amount at each step while the remainder moves on, so that no single transaction looks like the whole ransom and the trail frays into hundreds of threads. Peel chains are cheap and easy to automate, but on their own they no longer defeat a competent analytics firm. For that, actors reach for mixers. Confirmed reporting
A mixer pools many users' coins and redistributes them, so outputs cannot be matched to inputs. For years this was the workhorse of crypto laundering, and for the last three years it has been the single most heavily targeted node in the entire pipeline. The enforcement record reads like a graveyard: Bitcoin Fog's operator convicted in 2024 after more than a decade and roughly $400 million cycled; Helix before it; ChipMixer dismantled by Europol and German authorities in March 2023 with something like 2.73 billion euros in throughput; Blender and Sinbad sanctioned by OFAC as North Korean laundering tools; Samourai Wallet's founders arrested in April 2024. Even Tornado Cash, sanctioned in 2022, saw its designation ruled unlawful by an appeals court and formally withdrawn by OFAC in March 2025, while a jury deadlocked on most of the charges against one of its developers. The tool survives in law; the deterrent effect on ordinary criminals did not. Confirmed reporting
The version of this built specifically for ransomware is the clearest case study we have, and it fell apart in public only last month. Endgame did not take it down; a separate, money-focused action did.
Two details from the AudiA6 file matter for the whole pipeline. First, its exposure was about 80 percent ransomware, which is what a purpose-built ransomware off-ramp looks like from the inside. Second, six months before the arrests, TRM Labs had already traced roughly $7 million of stolen 2022 LastPass funds out of the Wasabi mixer and into AudiA6 deposit wallets, using cluster-level demixing. The lesson is not that mixing is safe. It is that mixing is increasingly demixable, which is exactly why the smart money is leaving mixers for something harder to follow. Confirmed reporting
Move three: changing shape
The defining laundering shift of the last two years is the migration off mixers and onto cross-chain bridges and decentralized swap services. A bridge moves value from one blockchain to another; a no-identity swap service turns Bitcoin into Monero into Tron-based USDT without ever asking a name. Chained together, they let proceeds change both chain and asset several times in minutes, which frustrates single-chain tracing far more effectively than a mixer that lives on one ledger. Confirmed reporting
The numbers capture the handover cleanly. In ransomware-linked laundering specifically, TRM Labs measured mixer volume falling from about $152 million in 2021 to roughly $48 million in 2024, while bridge-related flows climbed to about $100 million in 2025 and overtook mixers for the first time in 2024. Bridge activity from ransomware wallets grew about 66 percent year on year as mixer activity fell about 37 percent. Zoom out to all illicit crypto and Elliptic's cumulative estimate for cross-chain crime reached $21.8 billion by mid-2025, roughly triple its 2023 figure. Confirmed reporting
The services doing the shape-changing are named and, for the most part, unlicensed. No-identity swap desks sit alongside decentralized cross-chain protocols such as THORChain, which lets a user move between blockchains without an intermediary that could ask for a passport. These are not ransomware-specific tools, which is exactly their value: legitimate volume gives illicit flows cover, and a bridge that serves a million honest users is a far harder thing to seize than a mixer that served only criminals. That dual-use quality is the single biggest reason this move is harder to attack than the mixer move before it. Credible reporting
Two forces sit behind the shift. One is enforcement: every mixer takedown taught operators that a service living on one chain is a fixed target. The other is the same stablecoin gravity noted at the start. Somewhere in this move, volatile Bitcoin or Ether becomes Tron-based USDT, because value that has to sit in wallets and cross venues cannot be exposed to a 20 percent price swing mid-laundry. The tension is that USDT on Tron is freezable by Tether at the token level, as the North Korea and Iran freezes have shown, so actors race to convert and move before an attribution catches up. It usually does not catch up in time. The $1.5 billion Bybit theft in February 2025, the largest crypto heist on record, was laundered at speed through swap services and bridges including Tron-based routes, and most of it was gone before the freezes landed. The same rails that carried state-scale theft, North Korea alone stole more than $2 billion in crypto in 2025, are the rails a ransomware affiliate rents for a single mid-six-figure payout. Confirmed reporting
Move four: the settlement floor
By now the money is stablecoins on Tron, several hops removed from the ransom, and it needs a venue that will hold it, trade it, and stand ready to turn it into local currency. For the Russian-speaking ecosystem that venue has, for years, been a high-risk exchange, and the archetype was Garantex. We have written the full reconstitution story elsewhere; what matters here is the shape it left behind. Confirmed reporting
Garantex moved more than $96 billion across its life and kept growing after its first sanctioning. When a coalition seized it in March 2025, the operation was back within days as Grinex, a successor incorporated three months in advance, and the customer balances rode across on a ruble-backed token called A7A5. When Grinex itself went dark in April 2026 after a convenient "hack," the displaced volume did not scatter. It re-concentrated onto a short, named set of venues, most operating from inside Russia: ABCeX (roughly $11 billion processed, run from Moscow's Federation Tower), Rapira, Bitpapa, Exmo, and Aifory Pro. Credible reporting
Underneath the exchange brands is the part that does not rebuild in a week. A7A5 is a ruble-pegged stablecoin issued by A7, a Moscow cross-border payments firm co-owned by the sanctioned financier Ilan Shor and the sanctioned, defense-linked Promsvyazbank. It cleared roughly $93 billion in its first year, has since passed $100 billion in reported turnover, and in October 2025 was approved for Russian foreign-trade settlement. This is the settlement floor: exchange front-ends are interchangeable, but the rail beneath them is banking access, correspondent relationships, and state alignment, none of which a rebrand replaces. When you follow a laundered ransom to its resting venue, you are really following it to this rail. Confirmed reporting
Move five: back into cash
Stablecoins in a Russian exchange account are not yet spendable in the physical world. The last technical move is the off-ramp, the conversion of crypto into fiat someone can hold, and here the ecosystem runs three parallel exits. Confirmed reporting
The first is the cash desk. High-risk exchanges operate walk-in offices, most visibly in Moscow's Federation Tower and in Kazan, Rostov, and Yekaterinburg, where crypto becomes banknotes over a counter. When Russian security forces raided these offices in September 2025, targeting Rapira and the ABCeX-linked Mosca, they seized more than $10 million in cash, 100 million rubles, and 200,000 euros at a single location. The raids are their own tell, and we return to them in the next section, because the offices were open again within weeks. Confirmed reporting
The second is the courier network, and it is the one that best captures how frictionless cash-out has become. The International Consortium of Investigative Journalists (ICIJ) and its November 2025 "Coin Laundry" investigation documented 001k, a service offering crypto-to-cash hand-delivery in more than 300 cities worldwide, including Montreal, New York, Los Angeles, and Miami, with no money-transmitting license. It has received more than $14.8 billion in cryptocurrency since August 2022. Identity verification is a photograph of the serial number on a five-dollar bill, presented again at the handoff. In an undercover test, a reporter exchanged 2,000 USDT for cash with no ID at all. Downstream, 001k's flows resolve into hundreds of millions at major exchanges and more than a billion at WhiteBIT. Confirmed reporting
The third is the mule network, the exit AudiA6 industrialized with its 6,000 verified accounts at mainstream exchanges. Real people, or stolen identities, hold accounts that absorb the regulatory risk while the operator moves value through them. The UK's Operation Destabilise mapped this at the wholesale level: the linked TGR and Smart networks laundered for Evil Corp, Conti, and Ryuk, went as far as buying a bank in Kyrgyzstan, and have drawn more than 128 arrests and over 25 million pounds seized. All three exits ultimately touch ruble banking rails through sanctioned institutions, Sberbank, VTB, Gazprombank, Promsvyazbank, and A7A5's cross-border settlement that steps around the international banking system entirely. Confirmed reporting
Move six: the roof
Everything to this point is technical, and technical steps can be attacked technically. The seventh move is not technical. It is the reason the whole chain terminates in Russia rather than anywhere the money could be seized: the krysha, the protection that lets these operators run in the open. This is the dependency our Endgame reading identified as the one no infrastructure campaign can reach, and following the money is what makes its shape visible. Analyst inference
The evidence is strongest, and closest to active protection rather than passive tolerance, at the settlement rail. A7A5 is co-owned by a sanctioned state-linked bank, Promsvyazbank, which finances Russian defense. The token was approved for national foreign-trade settlement by government decision, with its operators openly targeting a fifth of the country's international payments. The UK, designating the A7 network in May 2026, described it as moving more than $90 billion into Russia's economy and financing procurement for the war. A state does not co-own, authorize, and route trade through a laundering rail it merely tolerates. Confirmed reporting
The September 2025 Moscow raids look, at first, like the opposite of protection. Read against what followed, they read more like management. Officers seized cash and hardware, the press covered it, and the targeted exchanges resumed operating within weeks, one lawyer noting drily that year-end quotas needed "case outcomes." The pattern of raid-and-restore is more consistent with an ecosystem the state can squeeze at will than with one it intends to shut. For the broad exchange layer the honest label remains tolerated safe harbor with selective extraction; for the A7 rail specifically, the ownership and the trade mandate point past tolerance toward active alignment. Analyst inference
What comes next
Two trajectories are already visible, and both are directional rather than certain. The first is method. The move from mixers to bridges is not a destination but a heading: as bridge tracing improves, the next step is toward privacy by default, Monero and no-identity swap desks, which is why nearly half of the darknet markets launched in 2025 accepted Monero alone. Expect the laundering path to keep trading throughput for opacity wherever enforcement makes throughput risky. Credible reporting
The second is law, and it pushes the other way. Two instruments could reach the settlement floor that seizures cannot. New stablecoin legislation, led by the US GENIUS Act, moves freeze capability and anti-laundering duties onto the issuers themselves, which would turn Tether's discretionary freezes into standing obligations and shorten the window operators depend on. And the FATF Travel Rule, if it is finally implemented evenly rather than in patches, would force identity to travel with every transfer between regulated venues, closing the seams the nested and mule networks live in. FATF spent 2026 warning that uneven adoption is the gap. Credible reporting
Neither instrument reaches Moscow. Both press on the parts of the chain that sit in reach: the issuers, the compliant venues, the correspondent banks. Analyst inference
Where the chain breaks
Trace all seven moves and the leverage points fall out of the geometry. The pipeline is long, but it is not evenly strong, and three properties decide where pressure pays. Analyst inference
The first is concentration. Ransomware proceeds do not exit through hundreds of doors evenly. TRM Labs finds that the top five cash-out services absorb between 42 and 57 percent of ransomware off-ramp volume in any year, about 51 percent in 2025, and the top ten handle as much as three quarters. That concentration dipped when enforcement disrupted key nodes, then rebounded, which cuts both ways: the network regenerates, but it regenerates back into a small, identifiable target set. A handful of venues convert most of the money. That is not a weakness the ecosystem can design away, because concentration is what makes an off-ramp liquid enough to be useful. Confirmed reporting
The second is traceability, which has moved the other way from what operators assume. The AudiA6 demix, the Bybit tracing, and the routine unmasking of bridge flows all point the same direction: the on-chain record is permanent, and analytics keep catching up to obfuscation after the fact. Tether's freezes prove the choke can close when attribution is good, $344 million of Iranian-linked USDT in April 2026, $28 million in the Garantex action, 131 Tron wallets in July 2026. The constraint on freezing is not willingness, it is attribution speed, and attribution is the thing that improves every year. Confirmed reporting
The third property is the one that caps all the others: the jurisdictional ceiling. Core operators sit in Russia, beyond extradition, behind the roof, and no amount of on-chain brilliance reaches them there. But the pipeline is not staffed only by untouchable principals. The mid-tier, the mule coordinators, the swap-service operators, the launderers-for-hire, increasingly sit in places that do cooperate. AudiA6's administrators were arrested in Georgia. That is the model the record actually supports: not the fantasy of reaching Moscow, but the discipline of taking the affiliate and service layer wherever it strays into reach, and of attacking the settlement rail with the financial tools that do bite, as the UK did in extending correspondent-banking prohibitions to crypto exchanges for the first time in May 2026. Confirmed reporting
There is a structural reason to prefer this target over the ransomware brands themselves. TRM Labs argues that the cybercrime services layer, the access brokers, the hosting, the laundering desks, is inherently more disruptible than the ransomware groups it supports, because a single service quietly underwrites many groups at once and its operators run weaker security than the crews they serve. Take down one off-ramp whose flow is eighty percent ransomware, and you degrade twenty groups in a morning, which is precisely what the AudiA6 action did. The off-ramp is where the many separate crimes of many separate crews briefly become one shared, visible, seizable thing. Analyst inference
Set against this is the honest counter-argument, and it is strong: every takedown so far has produced a rebrand rather than a collapse. Garantex became Grinex in days. Mixer enforcement pushed volume into bridges rather than out of existence. The A7A5 rail has absorbed sanctions from three jurisdictions and kept clearing. Displacement is real at every layer where the underlying function still has somewhere to live. Confirmed reporting
Which returns the argument to where the Endgame piece left it. Attacking the malware degrades the machine that makes the money. Attacking the money degrades the machine that cleans it. Neither reaches the roof, and while the roof stands, both grow back. But the money layer has a property the malware layer does not: it is concentrated, it is traceable, and part of it is standing in extraditable jurisdictions right now. The ransom that started this journey is, by the end, sitting as rubles behind a state that will not give it up. Getting there took seven moves, and at least three of them happened somewhere a determined investigator could have been waiting. Analyst inference
Sourcing & confidence
This dispatch draws on government actions (DOJ, OFAC, FinCEN, Europol, Eurojust, UK FCDO and NCA), on-chain analysis from Chainalysis, TRM Labs, and Elliptic, and the ICIJ "Coin Laundry" investigation, cross-checked against our own exchange profiles. Aggregate figures from different firms are kept separate and never averaged. Confidence labels follow standard analytic practice.
Confirmed · multiple independent sources, including official designation or indictment language.
Credible · single strong source or consistent industry reporting, not yet officially confirmed.
Analyst inference · End Krysha's own assessment, drawn from the evidence above.
- Chainalysis, 2026 Crypto Crime Report (illicit volume; 84% stablecoin share) and Crypto Ransomware 2026 (payment trend, payment rate, median).
- TRM Labs, disruption opportunities in the ransomware ecosystem (off-ramp concentration; mixer vs bridge flows; 80/20 RaaS split).
- Europol / Eurojust, Operation Endgame (initial-access malware framing) and the ICIJ Coin Laundry investigation (001k, $14.8B, courier cash-out).
- DOJ (E.D. Pa.) and TRM Labs, AudiA6 / Dark2Web dismantling, June 2026 (EUR 336M; 20 ransomware groups; 6,000 mule accounts; Wasabi-to-AudiA6 LastPass demix).
- Elliptic, State of Cross-Chain Crime 2025 ($21.8B cumulative) and Russia-linked services filling the Garantex gap.
- OFAC and UK FCDO designations of Garantex, Grinex, A7 / A7A5 (Aug 2025; UK package May 2026); UK NCA, Operation Destabilise (TGR / Smart mule networks).
- Forward outlook: TRM Global Crypto Policy Outlook 2025/26; FATF 2026 statements on stablecoin misuse and uneven Travel Rule adoption; US GENIUS Act (stablecoin issuer obligations, 2025).