The U.S. Department of the Treasury's Office of Foreign Assets Control (OFAC) has imposed sanctions on three entities within the virtual currency ecosystem for their role in laundering illicit funds for cybercriminals. The sanctioned entities are the virtual currency exchange Cortexchange and two cryptocurrency mixing services, ChainScrub and HelixMix. These organizations have been added to OFAC's Specially Designated Nationals (SDN) list for knowingly facilitating financial transactions for ransomware operators, including notorious groups like LockBit and Qilin, and other dark web actors. This action is a key part of the U.S. government's strategy to disrupt the ransomware business model by targeting the financial infrastructure that allows threat actors to profit from their crimes. The sanctions effectively sever these entities from the U.S. financial system.
As a result of this action, all U.S. persons and entities must comply with the following:
Virtual asset service providers (VASPs) in the U.S. must now screen their customer lists and transactions against the updated SDN list to ensure they are not servicing these sanctioned entities or their associated cryptocurrency wallet addresses.
The sanctions are effective immediately as of the announcement on April 25, 2026. All U.S. persons must cease any dealings with the sanctioned entities right away.
Violations of OFAC sanctions can result in severe penalties:
These penalties apply to any U.S. person or entity found to be transacting with the sanctioned parties.
For organizations in the financial and virtual asset sectors:
In response to the OFAC sanctions against Cortexchange, ChainScrub, and HelixMix, all compliant Virtual Asset Service Providers (VASPs) must enhance their Virtual-Asset Account Monitoring. This involves more than just checking against a static list. VASPs should use blockchain analytics tools to proactively identify customers who have interacted with the newly sanctioned entities, both historically and in real-time. This includes tracing funds 'one hop' or 'two hops' away from the sanctioned wallets to identify users attempting to obfuscate their connections. Accounts receiving funds from mixers like ChainScrub or HelixMix should be flagged for enhanced due diligence or off-boarding. This D3FEND technique is the practical implementation of the sanctions, turning the legal designation into concrete action within the cryptocurrency ecosystem to isolate bad actors.
OFAC adds Cortexchange, ChainScrub, and HelixMix to the Specially Designated Nationals (SDN) list.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
Help others stay informed about cybersecurity threats