GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar
Chainalysis

Chainalysis

Active

Blockchain data platform

News Heat Trend

Project Overview

Chainalysis is the blockchain data platform that provides data, software, services, and research to government agencies, exchanges, financial institutions, and insurance and cybersecurity companies in over 70 countries. Its data powers investigation, compliance, and market intelligence software which has been used to solve some of the world's most high-profile criminal cases and facilitate safe consumer access to cryptocurrency.

Approximately $30 million stolen in the first 10 minutes, Coldcard vulnerability attacker prioritized highest-value wallets first

Odaily News, according to Bitcoin News monitoring, Chainalysis analysis of the Coldcard exploit involving over $38 million shows that the attacker deliberately targeted the highest-value wallets first, including one holding $1.8 million, indicating that victims had already been profiled before asset transfers began. Approximately $30 million was stolen in the initial 10 minutes, followed by around 500 wallets being drained within 25 minutes. Block's Clay Garrett stated that investigators also confirmed the attacker used a paid account with a well-known blockchain service provider to query victim addresses during the operation. The provider's internal logs match the request timestamps and sequence, but Block stated that no evidence was found suggesting the company knowingly assisted in the theft. Relevant information has been shared with authorities.

EU Sanctions "Most Prolific Ransomware Operator" Stern, Linked to Over $300 Million in Ransom Payments

the United States, the European Union, and the United Kingdom have jointly announced sanctions against a group of individuals involved in state-sponsored hacking organizations, cybercriminal groups, and their infrastructure providers. The targets are accused of causing billions of dollars in losses to global enterprises, critical infrastructure, and government agencies. Among them, the most notable is the EU's sanction against Russian cybercriminal Vitaly Nikolayevich Kovalev, also known as "Stern." The EU identified Stern as one of the core managers of the notorious Trickbot Group ransomware syndicate, which is behind high-risk ransomware variants such as Conti ransomware and Ryuk.On-chain analysis shows that wallet addresses linked to Stern have collectively received over $300 million in ransom payments, potentially making him the most prolific ransomware operator ever identified.According to the analysis, the $300 million figure represents only Stern's personal gains, while the total illicit income of the Trickbot Group could be significantly higher. On-chain fund flows indicate that Stern had transactional ties with multiple ransomware ecosystems, including Ryuk, Conti, Diavol, Karakurt, Royal, and Quantum.The investigation reveals that Stern played a role similar to a "CEO" within the Trickbot organization, responsible for budget management, personnel recruitment, infrastructure procurement, and attack planning. (Chainalysis)

Singapore police and cryptocurrency exchanges have prevented over 145 potential scam victims from losing more than $4.2 million

The Singapore Police Force's Anti-Scam Centre and Cybercrime Department, in a six-week joint anti-scam operation from April 16 to May 31, 2026, collaborated with Coinbase, Coinhako, Gemini, Independent Reserve, OKX, StraitsX, and Upbit. Using blockchain analysis tools from Chainalysis and TRM Labs, they identified potential scam victims and conducted over 145 targeted interventions via phone and in-person visits, preventing potential losses exceeding $4.2 million. Coinbase Singapore stated in a post on X on July 10 that it worked with the Singapore police to prevent over 145 individuals from losing a combined total of more than $4.2 million due to scams. The Singapore Police Force stated that it will continue to work with cryptocurrency exchanges and other private sector entities to combat cybercrime. (Bitcoin.com News).

Goldman Sachs, JPMorgan Tighten Prediction Market Trading Rules Amid Rising Insider Trading Concerns

amid growing insider trading concerns surrounding prediction markets, Goldman Sachs has prohibited its employees from trading prediction market contracts related to the bank's own events, elections, financial markets, macroeconomic data, and geopolitics. Financial institutions such as Morgan Stanley, JPMorgan Chase, and Bank of America are also formulating or updating relevant policies. Bank of America, in particular, has begun clarifying prohibited practices in prediction market trading to its employees.Previously, the U.S. Commodity Futures Trading Commission (CFTC) and the Department of Justice accused a Google employee of using non-public information to trade "Search of the Year" related contracts on Polymarket, profiting approximately $1.2 million. Legal experts note that the CFTC still lacks well-established case law in enforcing insider trading rules for prediction markets, and the wide variety of prediction market contracts further complicates regulatory oversight.Currently, Kalshi and Polymarket have respectively launched employment verification tools and collaborated with Chainalysis and Palantir to monitor suspicious trading activities. (CNBC)

ABcripto: Brazilian Central Bank's 24-hour Stablecoin Lockup Proposal is "Disproportionate"

the Brazilian Association of Crypto-Economics (ABcripto) has requested the Brazilian Central Bank to suspend a proposal that would introduce a 24-hour delay for large stablecoin transfers. The association opposes the Central Bank's previous recommendation to impose a 24-hour lockup window for stablecoin transfers exceeding $10,000, stating that the measure would impact transparent market participants using regulated entities, while illicit actors would remain unaffected. ABcripto's members include Binance, Coinbase, Crypto.com, and Tether.The Brazilian Central Bank cited Chainalysis' crypto crime report, noting that illegal transaction volumes reached an all-time high in 2025. ABcripto President Julia Rosin stated that illegal actors typically avoid regulated institutions, preferring platforms that do not require identity verification, mixers, cross-chain bridges, and other less transparent structures.ABcripto also stated that the lockup measure could undermine the near-instant settlement use case for stablecoins and push users towards unregulated service providers. Currently, the Brazilian Congress is discussing specific regulations for stablecoins, and the Brazilian Central Bank plans to classify stablecoins as electronic money, rather than under the current digital asset classification. (Bitcoin.com News).

Chainalysis proposes on-chain tracking standard system, introducing "Address Clustering Ontology" to unify blockchain forensics methods

Blockchain analysis firm Chainalysis has released a new methodological proposal aimed at establishing a unified on-chain fund tracking standard framework for law enforcement agencies and investigators to identify address clusters and determine their probable control relationships.The proposal defines the on-chain analysis structure in the form of an "ontology," centralizing the systematic decomposition of the currently industry-wide non-standardized concept of "cluster" (address clustering) into wallet segments and functional roles. It describes on-chain relationships through a two-tier structure: the first layer defines the transaction graph structure, and the second layer assesses the inferred confidence level.Chainalysis states that the framework aims to enhance the interpretability and legal applicability of on-chain forensic methods and has been validated through its practical experience in cases related to the U.S. Department of Justice, including analysis applied in the Bitcoin Fog mixing service case. The company's Chief Scientist, Jacob Illum, noted that the proposal's goal is to answer "on what evidentiary basis can these addresses be considered to belong to the same entity," but emphasized that on-chain analysis alone cannot directly identify end-user identities and must still be combined with legal investigative methods involving centralized entities such as exchanges.Chainalysis stated that the standard proposal is currently open for industry discussion, aiming to promote a more unified technical standard for on-chain analysis methods in the fields of law enforcement and compliance. (CoinDesk)

EU Sanctions "Most Prolific Ransomware Operator" Stern, Linked to Over $300 Million in Ransom Payments

the United States, the European Union, and the United Kingdom have jointly announced sanctions against a group of individuals involved in state-sponsored hacking organizations, cybercriminal groups, and their infrastructure providers. The targets are accused of causing billions of dollars in losses to global enterprises, critical infrastructure, and government agencies. Among them, the most notable is the EU's sanction against Russian cybercriminal Vitaly Nikolayevich Kovalev, also known as "Stern." The EU identified Stern as one of the core managers of the notorious Trickbot Group ransomware syndicate, which is behind high-risk ransomware variants such as Conti ransomware and Ryuk.On-chain analysis shows that wallet addresses linked to Stern have collectively received over $300 million in ransom payments, potentially making him the most prolific ransomware operator ever identified.According to the analysis, the $300 million figure represents only Stern's personal gains, while the total illicit income of the Trickbot Group could be significantly higher. On-chain fund flows indicate that Stern had transactional ties with multiple ransomware ecosystems, including Ryuk, Conti, Diavol, Karakurt, Royal, and Quantum.The investigation reveals that Stern played a role similar to a "CEO" within the Trickbot organization, responsible for budget management, personnel recruitment, infrastructure procurement, and attack planning. (Chainalysis)

OFAC updates ISIS-K sanctions list, adds 134 cryptocurrency wallet addresses; Tether has frozen all TRON address balances

According to Chainalysis, the U.S. Department of the Treasury's Office of Foreign Assets Control (OFAC) updated its sanctions list against ISIS-K (Islamic State Khorasan Branch) on July 1, adding 134 cryptocurrency wallet addresses, of which 131 are on the TRON chain and 3 are Monero addresses. On-chain data shows that the aforementioned TRON wallets have cumulatively received over $1.4 million since 2023 and transferred out over $880,000, with some funds flowing to Syrian crypto exchangers. Currently, Tether has frozen the balances of all 131 TRON addresses. Additionally, on the same day, OFAC also sanctioned two Brazilian individuals and four companies related to the Latin American criminal organization "Primeiro Comando da Capital" (PCC), accusing them of using cryptocurrency to transfer over $30 million in illegal proceeds across borders from the United States to Brazil.

Chainalysis proposes on-chain tracking standard system, introducing "Address Clustering Ontology" to unify blockchain forensics methods

Blockchain analysis firm Chainalysis has released a new methodological proposal aimed at establishing a unified on-chain fund tracking standard framework for law enforcement agencies and investigators to identify address clusters and determine their probable control relationships.The proposal defines the on-chain analysis structure in the form of an "ontology," centralizing the systematic decomposition of the currently industry-wide non-standardized concept of "cluster" (address clustering) into wallet segments and functional roles. It describes on-chain relationships through a two-tier structure: the first layer defines the transaction graph structure, and the second layer assesses the inferred confidence level.Chainalysis states that the framework aims to enhance the interpretability and legal applicability of on-chain forensic methods and has been validated through its practical experience in cases related to the U.S. Department of Justice, including analysis applied in the Bitcoin Fog mixing service case. The company's Chief Scientist, Jacob Illum, noted that the proposal's goal is to answer "on what evidentiary basis can these addresses be considered to belong to the same entity," but emphasized that on-chain analysis alone cannot directly identify end-user identities and must still be combined with legal investigative methods involving centralized entities such as exchanges.Chainalysis stated that the standard proposal is currently open for industry discussion, aiming to promote a more unified technical standard for on-chain analysis methods in the fields of law enforcement and compliance. (CoinDesk)

Chainalysis: Gray-market peptide suppliers accelerate shift to Bitcoin and stablecoins, with Q1 crypto inflows surging 159% year-on-year

According to The Block, blockchain analytics firm Chainalysis’ latest report states that as the gray-market peptide industry’s scale exceeds an annualized $100 million, leading suppliers are accelerating adoption of Bitcoin and stablecoins as primary settlement instruments. In Q1 2026, cryptocurrency inflows into this industry reached $32 million—a 159% quarter-on-quarter surge. Due to widespread bans imposed by traditional banks and credit card payment channels on prescription-grade compounds and unregulated substances, numerous Chinese chemical manufacturers have turned to cryptocurrencies for transactions, with high-value orders especially favoring stablecoins to hedge against price volatility risk.

Chainalysis: Gray Market Peptide Suppliers Increasingly Using Bitcoin and Stablecoins

Chainalysis has released a report stating that as demand for gray market peptide products (such as weight loss drugs like semaglutide) grows rapidly, related suppliers and buyers are increasingly using cryptocurrencies for transactions, with leading suppliers primarily relying on Bitcoin and stablecoins.The report shows that crypto funds flowing into this sector reached $32 million in the first quarter of 2026, a 159% increase from $12 million in the previous quarter, with the annualized scale already exceeding $100 million.Chainalysis points out that demand for peptide products is driven by trends in medical aesthetics, health and wellness, and the popularity of GLP-1 drugs. However, since these products often involve prescription-grade compounds or unregulated substances, traditional banks and credit card processors typically restrict their transactions, prompting the market to shift towards crypto payments.The agency also noted that some leading suppliers have adopted more professional on-chain fund management methods. Particularly among suppliers with average single deposits exceeding $1,000, the proportion of stablecoins has significantly increased, likely to mitigate the risk of large supply chain orders being affected by crypto market volatility.

Chainalysis Tracks THORChain Attack Source: Proficient Money Laundering Skills, Cross-Chain Fund Transfer Weeks Before Attack

Odaily Chainalysis posted on X platform, stating that prior to the THORChain theft, wallets suspected to be linked to the attacker had been transferring funds through Monero, Hyperliquid, and THORChain for several consecutive weeks. As early as late April, the attacker-associated wallets deposited funds into Hyperliquid positions via Hyperliquid and the Monero privacy bridge. These funds were subsequently converted to USDC and transferred to Arbitrum, then bridged to Ethereum. Some of the ETH was then moved to THORChain to stake as RUNE for a newly joined node, which is believed to be the source of the attack.Subsequently, the attacker bridged a portion of the RUNE back to Ethereum and split it into four chains. One chain went directly to the attacker, passing through intermediate wallets before transferring 8 ETH to the wallet that would ultimately receive the stolen funds, just 43 minutes before the attack. The funds from the other three chains flowed in reverse. Between May 14 and 15, these wallets bridged the ETH back to Arbitrum again, deposited it into Hyperliquid, and transferred it into Monero via the same privacy bridge, with the final transaction occurring less than 5 hours before the attack commenced. As of Friday afternoon, the stolen funds remain untouched, but the attacker has demonstrated sophisticated cross-chain money laundering capabilities. The Hyperliquid to Monero path may be the next move.

Approximately $30 million stolen in the first 10 minutes, Coldcard vulnerability attacker prioritized highest-value wallets first

Odaily News, according to Bitcoin News monitoring, Chainalysis analysis of the Coldcard exploit involving over $38 million shows that the attacker deliberately targeted the highest-value wallets first, including one holding $1.8 million, indicating that victims had already been profiled before asset transfers began. Approximately $30 million was stolen in the initial 10 minutes, followed by around 500 wallets being drained within 25 minutes. Block's Clay Garrett stated that investigators also confirmed the attacker used a paid account with a well-known blockchain service provider to query victim addresses during the operation. The provider's internal logs match the request timestamps and sequence, but Block stated that no evidence was found suggesting the company knowingly assisted in the theft. Relevant information has been shared with authorities.

EU Sanctions "Most Prolific Ransomware Operator" Stern, Linked to Over $300 Million in Ransom Payments

the United States, the European Union, and the United Kingdom have jointly announced sanctions against a group of individuals involved in state-sponsored hacking organizations, cybercriminal groups, and their infrastructure providers. The targets are accused of causing billions of dollars in losses to global enterprises, critical infrastructure, and government agencies. Among them, the most notable is the EU's sanction against Russian cybercriminal Vitaly Nikolayevich Kovalev, also known as "Stern." The EU identified Stern as one of the core managers of the notorious Trickbot Group ransomware syndicate, which is behind high-risk ransomware variants such as Conti ransomware and Ryuk.On-chain analysis shows that wallet addresses linked to Stern have collectively received over $300 million in ransom payments, potentially making him the most prolific ransomware operator ever identified.According to the analysis, the $300 million figure represents only Stern's personal gains, while the total illicit income of the Trickbot Group could be significantly higher. On-chain fund flows indicate that Stern had transactional ties with multiple ransomware ecosystems, including Ryuk, Conti, Diavol, Karakurt, Royal, and Quantum.The investigation reveals that Stern played a role similar to a "CEO" within the Trickbot organization, responsible for budget management, personnel recruitment, infrastructure procurement, and attack planning. (Chainalysis)

G7: Calls for Joint Action Against North Korean Cryptocurrency Theft and Cybercrime

leaders of the Group of Seven (G7) issued a statement at the G7 summit in Évian-les-Bains, France, once again calling for joint action to combat North Korean cryptocurrency theft and cybercrime. United Nations security researchers have linked North Korea's cryptocurrency theft to the funding of its weapons programs.Previously, attacks suspected to be linked to North Korean hackers included a $285 million attack on Drift Protocol in April and a $36 million breach on Humanity Protocol in June. According to Chainalysis data, North Korean hackers stole at least $2 billion in cryptocurrency in 2025, bringing their historical total theft amount to at least $6.75 billion. (Cointelegraph)

Chainalysis Tracks THORChain Attack Source: Proficient Money Laundering Skills, Cross-Chain Fund Transfer Weeks Before Attack

Odaily Chainalysis posted on X platform, stating that prior to the THORChain theft, wallets suspected to be linked to the attacker had been transferring funds through Monero, Hyperliquid, and THORChain for several consecutive weeks. As early as late April, the attacker-associated wallets deposited funds into Hyperliquid positions via Hyperliquid and the Monero privacy bridge. These funds were subsequently converted to USDC and transferred to Arbitrum, then bridged to Ethereum. Some of the ETH was then moved to THORChain to stake as RUNE for a newly joined node, which is believed to be the source of the attack.Subsequently, the attacker bridged a portion of the RUNE back to Ethereum and split it into four chains. One chain went directly to the attacker, passing through intermediate wallets before transferring 8 ETH to the wallet that would ultimately receive the stolen funds, just 43 minutes before the attack. The funds from the other three chains flowed in reverse. Between May 14 and 15, these wallets bridged the ETH back to Arbitrum again, deposited it into Hyperliquid, and transferred it into Monero via the same privacy bridge, with the final transaction occurring less than 5 hours before the attack commenced. As of Friday afternoon, the stolen funds remain untouched, but the attacker has demonstrated sophisticated cross-chain money laundering capabilities. The Hyperliquid to Monero path may be the next move.

Goldman Sachs, JPMorgan Tighten Prediction Market Trading Rules Amid Rising Insider Trading Concerns

amid growing insider trading concerns surrounding prediction markets, Goldman Sachs has prohibited its employees from trading prediction market contracts related to the bank's own events, elections, financial markets, macroeconomic data, and geopolitics. Financial institutions such as Morgan Stanley, JPMorgan Chase, and Bank of America are also formulating or updating relevant policies. Bank of America, in particular, has begun clarifying prohibited practices in prediction market trading to its employees.Previously, the U.S. Commodity Futures Trading Commission (CFTC) and the Department of Justice accused a Google employee of using non-public information to trade "Search of the Year" related contracts on Polymarket, profiting approximately $1.2 million. Legal experts note that the CFTC still lacks well-established case law in enforcing insider trading rules for prediction markets, and the wide variety of prediction market contracts further complicates regulatory oversight.Currently, Kalshi and Polymarket have respectively launched employment verification tools and collaborated with Chainalysis and Palantir to monitor suspicious trading activities. (CNBC)

OFAC updates ISIS-K sanctions list, adds 134 cryptocurrency wallet addresses; Tether has frozen all TRON address balances

According to Chainalysis, the U.S. Department of the Treasury's Office of Foreign Assets Control (OFAC) updated its sanctions list against ISIS-K (Islamic State Khorasan Branch) on July 1, adding 134 cryptocurrency wallet addresses, of which 131 are on the TRON chain and 3 are Monero addresses. On-chain data shows that the aforementioned TRON wallets have cumulatively received over $1.4 million since 2023 and transferred out over $880,000, with some funds flowing to Syrian crypto exchangers. Currently, Tether has frozen the balances of all 131 TRON addresses. Additionally, on the same day, OFAC also sanctioned two Brazilian individuals and four companies related to the Latin American criminal organization "Primeiro Comando da Capital" (PCC), accusing them of using cryptocurrency to transfer over $30 million in illegal proceeds across borders from the United States to Brazil.

Chainalysis proposes on-chain tracking standard system, introducing "Address Clustering Ontology" to unify blockchain forensics methods

Blockchain analysis firm Chainalysis has released a new methodological proposal aimed at establishing a unified on-chain fund tracking standard framework for law enforcement agencies and investigators to identify address clusters and determine their probable control relationships.The proposal defines the on-chain analysis structure in the form of an "ontology," centralizing the systematic decomposition of the currently industry-wide non-standardized concept of "cluster" (address clustering) into wallet segments and functional roles. It describes on-chain relationships through a two-tier structure: the first layer defines the transaction graph structure, and the second layer assesses the inferred confidence level.Chainalysis states that the framework aims to enhance the interpretability and legal applicability of on-chain forensic methods and has been validated through its practical experience in cases related to the U.S. Department of Justice, including analysis applied in the Bitcoin Fog mixing service case. The company's Chief Scientist, Jacob Illum, noted that the proposal's goal is to answer "on what evidentiary basis can these addresses be considered to belong to the same entity," but emphasized that on-chain analysis alone cannot directly identify end-user identities and must still be combined with legal investigative methods involving centralized entities such as exchanges.Chainalysis stated that the standard proposal is currently open for industry discussion, aiming to promote a more unified technical standard for on-chain analysis methods in the fields of law enforcement and compliance. (CoinDesk)

Chainalysis: Gray-market peptide suppliers accelerate shift to Bitcoin and stablecoins, with Q1 crypto inflows surging 159% year-on-year

According to The Block, blockchain analytics firm Chainalysis’ latest report states that as the gray-market peptide industry’s scale exceeds an annualized $100 million, leading suppliers are accelerating adoption of Bitcoin and stablecoins as primary settlement instruments. In Q1 2026, cryptocurrency inflows into this industry reached $32 million—a 159% quarter-on-quarter surge. Due to widespread bans imposed by traditional banks and credit card payment channels on prescription-grade compounds and unregulated substances, numerous Chinese chemical manufacturers have turned to cryptocurrencies for transactions, with high-value orders especially favoring stablecoins to hedge against price volatility risk.

Chainalysis: Gray Market Peptide Suppliers Increasingly Using Bitcoin and Stablecoins

Chainalysis has released a report stating that as demand for gray market peptide products (such as weight loss drugs like semaglutide) grows rapidly, related suppliers and buyers are increasingly using cryptocurrencies for transactions, with leading suppliers primarily relying on Bitcoin and stablecoins.The report shows that crypto funds flowing into this sector reached $32 million in the first quarter of 2026, a 159% increase from $12 million in the previous quarter, with the annualized scale already exceeding $100 million.Chainalysis points out that demand for peptide products is driven by trends in medical aesthetics, health and wellness, and the popularity of GLP-1 drugs. However, since these products often involve prescription-grade compounds or unregulated substances, traditional banks and credit card processors typically restrict their transactions, prompting the market to shift towards crypto payments.The agency also noted that some leading suppliers have adopted more professional on-chain fund management methods. Particularly among suppliers with average single deposits exceeding $1,000, the proportion of stablecoins has significantly increased, likely to mitigate the risk of large supply chain orders being affected by crypto market volatility.

Chainalysis: Crypto Industry Compliance Standards Improve, but Gaps in Indirect Monitoring Persist

Chainalysis has released a report indicating that overall compliance standards in the crypto industry are improving, but significant deficiencies remain in the monitoring of indirect fund flows.The report shows that among new institutions entering the crypto industry in 2026, approximately 47% adopted alert standards that would have ranked among the strictest top 10% in the industry five years ago. Chainalysis states that while industry standards for "direct monitoring" (funds coming directly from known illicit sources) have become largely unified, gaps remain in "indirect monitoring" (funds flowing through intermediate addresses).Data indicates that in 2020, only about 10% of institutions met top-tier industry compliance requirements. However, since 2023, this proportion has significantly increased, with newcomers generally adopting stricter monitoring standards. Nevertheless, for risk categories such as ransomware, scam shops, and darknet markets, industry thresholds for indirect monitoring are still commonly 10 to 20 times higher than those for direct monitoring. (Cointelegraph)

Related news

Approximately $30 million stolen in the first 10 minutes, Coldcard vulnerability attacker prioritized highest-value wallets first

Odaily News, according to Bitcoin News monitoring, Chainalysis analysis of the Coldcard exploit involving over $38 million shows that the attacker deliberately targeted the highest-value wallets first, including one holding $1.8 million, indicating that victims had already been profiled before asset transfers began. Approximately $30 million was stolen in the initial 10 minutes, followed by around 500 wallets being drained within 25 minutes. Block's Clay Garrett stated that investigators also confirmed the attacker used a paid account with a well-known blockchain service provider to query victim addresses during the operation. The provider's internal logs match the request timestamps and sequence, but Block stated that no evidence was found suggesting the company knowingly assisted in the theft. Relevant information has been shared with authorities.

2026 World Cup Generates $20 Billion in On-Chain Prediction Market Volume, with Over 400,000 Wallets Participating in Betting

blockchain analytics firm Chainalysis has disclosed that the 2026 FIFA World Cup generated $20 billion in blockchain prediction market volume, along with $24 million in digital collectible transactions, with over 400,000 wallets participating in on-chain betting. The aforementioned $20 billion in volume includes transactions both before and during the tournament, with betting volume during the five-week World Cup period reaching approximately $5.7 billion. World Cup-related markets accounted for about 63% of all prediction market activity during that period. Chainalysis stated that users from every continent except Antarctica participated in the World Cup prediction markets, with the United States and China generating the highest attributable transaction volume, followed by Canada, Thailand, and the United Kingdom. Chainalysis disclosed that among wallets participating in the World Cup prediction markets, those associated with illicit actors accounted for less than 1%. However, it identified approximately $5.4 million in funds flowing from sanctioned entities and other illegal sources. During the tournament, fans traded approximately $24 million worth of NFTs through FIFA Collect, and the platform distributed over 100,000 match tickets.

EU Sanctions "Most Prolific Ransomware Operator" Stern, Linked to Over $300 Million in Ransom Payments

the United States, the European Union, and the United Kingdom have jointly announced sanctions against a group of individuals involved in state-sponsored hacking organizations, cybercriminal groups, and their infrastructure providers. The targets are accused of causing billions of dollars in losses to global enterprises, critical infrastructure, and government agencies. Among them, the most notable is the EU's sanction against Russian cybercriminal Vitaly Nikolayevich Kovalev, also known as "Stern." The EU identified Stern as one of the core managers of the notorious Trickbot Group ransomware syndicate, which is behind high-risk ransomware variants such as Conti ransomware and Ryuk.On-chain analysis shows that wallet addresses linked to Stern have collectively received over $300 million in ransom payments, potentially making him the most prolific ransomware operator ever identified.According to the analysis, the $300 million figure represents only Stern's personal gains, while the total illicit income of the Trickbot Group could be significantly higher. On-chain fund flows indicate that Stern had transactional ties with multiple ransomware ecosystems, including Ryuk, Conti, Diavol, Karakurt, Royal, and Quantum.The investigation reveals that Stern played a role similar to a "CEO" within the Trickbot organization, responsible for budget management, personnel recruitment, infrastructure procurement, and attack planning. (Chainalysis)

Singapore police and cryptocurrency exchanges have prevented over 145 potential scam victims from losing more than $4.2 million

The Singapore Police Force's Anti-Scam Centre and Cybercrime Department, in a six-week joint anti-scam operation from April 16 to May 31, 2026, collaborated with Coinbase, Coinhako, Gemini, Independent Reserve, OKX, StraitsX, and Upbit. Using blockchain analysis tools from Chainalysis and TRM Labs, they identified potential scam victims and conducted over 145 targeted interventions via phone and in-person visits, preventing potential losses exceeding $4.2 million. Coinbase Singapore stated in a post on X on July 10 that it worked with the Singapore police to prevent over 145 individuals from losing a combined total of more than $4.2 million due to scams. The Singapore Police Force stated that it will continue to work with cryptocurrency exchanges and other private sector entities to combat cybercrime. (Bitcoin.com News).

Goldman Sachs, JPMorgan Tighten Prediction Market Trading Rules Amid Rising Insider Trading Concerns

amid growing insider trading concerns surrounding prediction markets, Goldman Sachs has prohibited its employees from trading prediction market contracts related to the bank's own events, elections, financial markets, macroeconomic data, and geopolitics. Financial institutions such as Morgan Stanley, JPMorgan Chase, and Bank of America are also formulating or updating relevant policies. Bank of America, in particular, has begun clarifying prohibited practices in prediction market trading to its employees.Previously, the U.S. Commodity Futures Trading Commission (CFTC) and the Department of Justice accused a Google employee of using non-public information to trade "Search of the Year" related contracts on Polymarket, profiting approximately $1.2 million. Legal experts note that the CFTC still lacks well-established case law in enforcing insider trading rules for prediction markets, and the wide variety of prediction market contracts further complicates regulatory oversight.Currently, Kalshi and Polymarket have respectively launched employment verification tools and collaborated with Chainalysis and Palantir to monitor suspicious trading activities. (CNBC)

ABcripto: Brazilian Central Bank's 24-hour Stablecoin Lockup Proposal is "Disproportionate"

the Brazilian Association of Crypto-Economics (ABcripto) has requested the Brazilian Central Bank to suspend a proposal that would introduce a 24-hour delay for large stablecoin transfers. The association opposes the Central Bank's previous recommendation to impose a 24-hour lockup window for stablecoin transfers exceeding $10,000, stating that the measure would impact transparent market participants using regulated entities, while illicit actors would remain unaffected. ABcripto's members include Binance, Coinbase, Crypto.com, and Tether.The Brazilian Central Bank cited Chainalysis' crypto crime report, noting that illegal transaction volumes reached an all-time high in 2025. ABcripto President Julia Rosin stated that illegal actors typically avoid regulated institutions, preferring platforms that do not require identity verification, mixers, cross-chain bridges, and other less transparent structures.ABcripto also stated that the lockup measure could undermine the near-instant settlement use case for stablecoins and push users towards unregulated service providers. Currently, the Brazilian Congress is discussing specific regulations for stablecoins, and the Brazilian Central Bank plans to classify stablecoins as electronic money, rather than under the current digital asset classification. (Bitcoin.com News).