HomeAtlasDashboardChartsMetalsResearchPersonsBubble MapGlobeLeadershipLensesMethodologyGlossarySource ↗
Independent research & opinion. Gradings are automated / LLM-assisted and may contain errors or hallucinations; nothing here is a statement of fact, financial advice, or an accusation of wrongdoing by any party. Claims about identifiable people or organizations reflect public records + good-faith interpretation; intent is not inferred from association. Methodology & disclaimer.

On-chain address tracking — threat actors, state actors, sanctioned entities, and government-seized wallets

Built 2026-06-12 from research/spec-onchain-threat-actor-addresses.json. Attributions verified this pass against FBI PSAs, OFAC SDN designations, Treasury releases, DOJ filings, and chain-forensics (Chainalysis/Elliptic/TRM/Arkham).

Attribution grade. Government attributions (FBI PSA, OFAC SDN, Treasury, DOJ) are high-grade primary. Chain-forensics clustering is strong but probabilistic/labeled. This block does not hand-transcribe long hex addresses (error risk) — it cites the authoritative machine-readable lists (OFAC SDN "Digital Currency Address" fields; FBI PSA IOC lists) and records cluster-level facts. Sanction status is time-varying and dated. Overlay edges excluded from the proofs.

1. Why track on-chain identities

Crypto's transparency cuts both ways: threat actors, governments, and sanctioned entities all hold traceable on-chain addresses. State-grade theft (DPRK), sanctions evasion (Russia/Iran), mixing (Tornado Cash), and state seizure (US government BTC) are all legible on-chain — a first-class data source, not a press summary.

2. North Korea — Lazarus Group (TraderTraitor / APT38)

The most prolific state-grade thief; proceeds fund the DPRK weapons program (UN Panel of Experts; US Treasury).

Address source: per-incident FBI PSA IOC lists + OFAC SDN entries; cluster tracking by Chainalysis/Elliptic/Arkham.

3. Russia — sanctioned exchanges, darknet, ransomware

4. Iran — Nobitex and a state-on-state strike

5. Mixers and the "can you sanction code?" whipsaw

6. The government as an on-chain holder (seizures → reserve)

6b. Tiering: systemic-risk vs sanctions (added 2026-06-16, #67)

The clusters above sit on two axes that are routinely conflatedsanctions status (formal coverage) and systemic risk (threat to the system). The headline finding is that they diverge: the highest-systemic-risk actor has the least complete formal coverage, so a sanctions-list-only view under-weights the biggest risks. Attributions graded as above; the tiering is a labeled analytic ranking.

TierClustersThe point
T1 — max risk, INCOMPLETE coverageDPRK/Lazarus (Bybit $1.5B, Ronin $625M): state-grade, funds weapons — but Ronin is SDN, the 51 Bybit addresses are FBI-PSA (not SDN), most hops are forensics-only. Mixers (Tornado Cash): the scaled laundering chokepoint, currently UN-sanctioned (vacated 2024 / lifted Mar 2025).the divergence — max systemic risk, min formal coverage
T2 — high risk, WELL-coveredRussia evasion exchanges/markets (Garantex, Hydra, SUEX/Chatex/Bitzlato): SDN-designated and seizedsanctions ≈ risk (and partly contained)
T3 — designated but NEUTRALIZEDIran/Nobitex: Treasury-designated, but the $90M was burned to keyless addresses (a political strike)designation > residual risk
T4 — large balance, LOW threatUS-gov seized wallets (~200k BTC; Strategic Bitcoin Reserve)size ≠ threat — a market/policy variable

The monitoring lesson: tracking only the SDN list (the 757) misses the two most systemically dangerous clusters — the forensics-tracked-not-designated DPRK hops and the currently-lifted Tornado Cash chokepoint. A risk-tiered monitor must union three sources — SDN (fetch_ofac.py) + FBI/CISA PSA IOC lists + commercial forensics — and weight by systemic risk, not designation status. The "can code be sanctioned?" whipsaw means the formal list will keep lagging the actual risk surface.

7. Limits & ingest — a designation-scope floor, not an access limit (important)

This is an attribution + source-pointer layer, not a raw address dump. Government attributions are high-grade; clustering is labeled. fetch_ofac.py (env-free) ingests the free OFAC Advanced XML (SDN + Consolidated) into data/ofac_crypto_addresses.json757 addresses (522 BTC / 127 TRON / 97 ETH / 10 LTC / 1 XMR), all from the SDN list (the Consolidated list carries none).

OFAC's own data is not access-limited. The full SDN and Consolidated lists — including the "Digital Currency Address" crypto fields — are freely downloadable in CSV, XML, and Advanced-XML (all machine-readable) and searchable for free. Current canonical endpoints (verified 2026-06): the bulk Sanctions List Service (sanctionslistservice.ofac.treas.gov/api/download/{sdn.csv, sdn.xml, sdn_advanced.xml, cons_advanced.xml, …}, which now 302-redirect to a signed S3 download), the SDN and Consolidated list portals (sanctionslist.ofac.treas.gov/Home/SdnList · /Home/ConsolidatedList), the other-lists index (ofac.treasury.gov/other-ofac-sanctions-lists), and the free search UI (sanctionssearch.ofac.treas.gov).

So the 757 is a designation-scope floor, not a paywall floor. It is a lower bound because it captures only addresses OFAC has formally designated — not because OFAC withholds data. It deliberately does not include:

So the on-chain identity picture here is a lower bound: full coverage adds the (free) FBI PSA IOC feeds plus a paid forensics subscription for un-designated clusters. Sanction status is also dated (Tornado Cash 2022 → vacated 2024 → lifted 2025), so a static list overstates what is currently designated.

Verification sources: FBI/Bybit attribution, Tornado Cash sanctions lifted, Silk Road $3.36B, Nobitex hack, US BTC holdings.

← Research index · structured data: spec-onchain-threat-actor-addresses.json · spec-onchain-threat-actor-addresses.md