← All Articles

United States of America v. Approximately 23,067,340 USDT Alleges the seized USDT facilitated money laundering

In March 2025, U.S. law enforcement froze 91 Tether wallets holding approximately 23,067,340 USDT, and seized approximately 5,011.03 BNB from a Binance account, alleging the assets were used by Garantex, a Russia-based cryptocurrency exchange, to launder proceeds from illicit activities. The complaint alleges Garantex processed $31,000,000,000 in USDT on the Tron blockchain, including $14,000,000,000 in USDT transfers by the top 20 Garantex Tron users (Compl. ¶64).

The United States filed a verified complaint for forfeiture in rem seeking forfeiture of the assets under 18 U.S.C. § 981(a)(1)(A) as property involved in violations of 18 U.S.C. § 1956(h) (conspiracy to commit concealment money laundering). The complaint alleges Garantex failed to obtain KYC information or allowed transactions with known criminal proceeds despite obtaining KYC (Compl. ¶2), and pooled criminal and non-criminal proceeds to disguise the source of illicit funds, including ransomware payments, hacking proceeds, and transactions tied to sanctioned entities.

The Binance account, registered to Stanislav Drugalev (deceased), was last accessed on January 28, 2025, and is alleged to have been used by Garantex for liquidity through a nested exchange relationship with CryptoMax, a platform operated in connection with Garantex.

Garantex’s Role in Ransomware and Darknet Market Transactions

The complaint alleges Garantex processed funds tied to multiple ransomware groups, including approximately $166,000 from a $311,220 payment to the Conti ransomware group on June 26, 2021, and approximately $170,000 from a $430,000 Conti payment on June 30, 2021. In February 2024, Garantex received approximately $226,000 from a $1 million ransom paid to the Black Basta ransomware group.

Between March 2021 and October 2023, Garantex processed approximately $634,000 from and $380,000 to the Blacksprut darknet market. From December 2022 to December 2023, it processed $24,000 from and $155,000 to the Kraken Market darknet market. In March 2022, Garantex processed approximately $380 from a website tied to child sexual abuse material. In June 2022, $105 million in digital currency was stolen from a U.S.-based blockchain network, and Garantex processed $7,400,000 of the stolen funds via DCE 2 (Compl. ¶70).

The Office of Foreign Assets Control designated Garantex on April 5, 2022, citing $100 million in illicit transactions, including $6 million from Conti ransomware and $2.6 million from the Hydra darknet market. Garantex’s overall transaction volume in bitcoin since 2019 totaled $2.4 billion.

Post-Sanctions Operations and Evasion Tactics

After the Office of Foreign Assets Control sanctioned Garantex on April 5, 2022, the exchange processed $1.7 billion in USDT on the Ethereum blockchain and $27,000,000,000 on the Tron blockchain (Compl. ¶64). Between April 2022 and March 2025, Garantex and DCE 5 conducted over 5,800 transactions totaling $88 million on the Tron blockchain.

Beginning in early 2023, Garantex began changing its operational wallets daily to evade detection. On December 10, 2023, a Garantex Telegram administrator posted about OFAC’s wallet-blocking process. Before the sanctions, Garantex flagged 15,000 deposits with a high-risk score but rejected only 1.6%; after sanctions, it flagged 219 high-risk deposits but rejected none. The complaint alleges Garantex used nested exchanges, including CryptoMax, to obscure transaction trails, receiving approximately $71 million in deposits via Garantex between June 2019 and March 2024 (Compl. ¶66).

The complaint also alleges Garantex’s nested exchange, CryptoMax, had 42.18% of its deposits tied to darknet markets.

The 91 frozen Garantex Tether wallets processed $331 million in transactions between January 2024 and March 2025. Of these, $5 million had direct or indirect exposure to illicit services, and $3.5 million was flagged for direct or indirect exposure to high-risk services. One frozen address transacted with addresses tied to child exploitation and human trafficking, while another transacted with addresses flagged for investment fraud, hacked or stolen funds, and banned substances. The complaint states that frozen address TFSs1G4sNF3Ak3FmP1uXi3ZVtgqWZLGQJq transacted with addresses tied to child exploitation and human trafficking (Compl. ¶62e), and frozen address TL1EGyHiNSPAWktmgb8kNavSCfzQg8aSDP transacted with addresses flagged for investment fraud, hacked/stolen funds, consumer complaints, and banned/controlled substances (Compl. ¶62d).

The complaint alleges the seized 5,011.03 BNB originated from Garantex’s primary bitcoin wallets, part of an OFAC-sanctioned cluster (Compl. ¶71).

The complaint alleges Garantex executives Aleksej Besciokov and Aleksandr Mira Serda were indicted on February 27, 2025, in United States v. Besciokov et al. for conspiracy to commit money laundering through Garantex.

Garantex's website ceased operations in March 2025, and U.S. law enforcement seized its domains on March 6, 2025. The complaint states, "Garantex is operating normally" in a mass email sent to customers on April 8, 2022 (Compl. ¶8).

The allegations described here are taken from the filing and remain unproven; no responsive pleading is reflected in the source document.

David Brunk is a civil litigation attorney. He can be reached at david@newmanbrunk.com.

From the Complaint Public Court Record

IN THE UNITED STATES DISTRICT COURT FOR THE EASTERN DISTRICT OF VIRGINIA Alexandria Division UNITED STATES OF AMERICA, Plaintiff, v. APPROXIMATELY 23,067,340 USDT SEIZED FROM THE TETHER OPERATING WALLETS SET FORTH IN ATTACHMENT A, and APPROXIMATELY 5,011.03 BNB SEIZED FROM A BINANCE D/B/A NEST SERVICES LTD. ACCOUNT WITH USER ID XXXX5216, Defendants in Rem. Civil No. 1:26- cv-_____ VERIFIED COMPLAINT FOR FORFEITURE IN REM COMES NOW the plaintiff, United States of America, by and through counsel, and brings this complaint and alleges as follows in accordance with Supplemental Rule G(2) of the Federal Rules of Civil Procedure: NATURE OF THE ACTION 1. The United States brings this action in rem seeking the forfeiture of all right, title, and interest in the defendants in rem identified in the case caption above (collectively, the “Defendant Property”). 2. The United States’ claim arises from a concealment money laundering conspiracy carried out by the operators of Garantex, a sanctioned Russian cryptocurrency exchange. At times, Garantex failed to obtain know-your-customer (“KYC”) information. At other times, PageID# 1

2 Garantex obtained KYC information, but its operators nonetheless continued to allow transactions involving known criminal proceeds. Garantex was a favored cryptocurrency exchange for cybercriminals and cybercrime organizations, including those involved in ransomware, hacking, and terrorism financing, among others. The Defendant Property was contained within Garantex operating wallets that facilitated Garantex’s operations. And as described in more detail below, Garantex consistently pooled the criminal proceeds it held with non-criminal proceeds with the purpose of disguising the nature, location, source, ownership, and control of those criminal proceeds. 3. The Defendant Property constitutes property involved in violations of 18 U.S.C. § 1956(h) (conspiracy to commit concealment m

Questions about this topic: david@newmanbrunk.com

Practice areas