Summary
- OFAC designated 10 targets in a Tren de Aragua ATM jackpotting scheme that stole at least $40.73 million from U.S. financial institutions. The network used cryptocurrency to launder the proceeds.
- The scheme’s alleged leader, Anibal Alexander Canelon Aguirre (aka “Prometheus”), is one of the FBI’s Ten Most Wanted Fugitives. He allegedly engineered the malware that “jackpotted” ATMs.
- Our analysis of the network surrounding the TdA wallets found their counterparties had exposure to major laundering operations utilized by Colombian and Mexican gangs, and Venezuelan launderers.
One of the FBI’s Ten Most Wanted Fugitives allegedly used cryptocurrency to launder millions of dollars stolen from U.S. ATMs as part of a financing scheme for the criminal organization Tren de Aragua (TdA). Chainalysis is tracing the on-chain footprint of that fugitive (Anibal Alexander Canelon Aguirre, nicknamed “Prometheus”), his associates, and the transnational criminal group.
On September 30, 2026, the U.S. Department of the Treasury’s Office of Foreign Assets Control (OFAC) designated 10 targets tied to the scheme, exposing a financial network that used cryptocurrency transactions to launder cash stolen from ATMs and move it across borders in support of TdA, a Foreign Terrorist Organization (FTO). As part of the action, OFAC designated seven crypto addresses belonging to Aguirre and his associates, which are deposit addresses at a major crypto exchange.
Our investigators analyzed the network surrounding and supporting the now-sanctioned wallets. What we found: counterparties with exposure to known money laundering operations based in Mexico, Columbia, and Venezuela that have been used by a wide variety of illicit actors involved in drug trafficking, smuggling, and other illicit enterprises.
At the center of the ring was Aguirre (aka “Prometheus”), an FBI fugitive wanted for bank fraud, burglary, money laundering, and providing material support to terrorists. He allegedly engineered the malware behind the attacks on ATMs, and then used crypto transactions to launder the stolen funds. Six associates of Aguirre are also designated: Carlos Javier Martinez Armenta, Alejandro Mejia Castillo, Jose Dario Galeano Bazurto, Eric Gabriel Cardenas Arzola, Oscar Leonardo Martinez Pirona, and Anthony Wuiliam Hernandez Guerrero.
How Tren de Aragua targeted ATMs to steal millions
“Jackpotting” is a cyberattack in which criminals install malware on automated teller machines (ATMs) and force them to dispense cash without debiting any account. According to OFAC, Aguirre led a conspiracy that deployed crews to the United States from a network based in Mexico and Venezuela, stealing millions of dollars from financial institutions in support of TdA.
According to a December 2025 indictment of Aguirre and his associates, the group infected ATMs with the Ploutus malware strain which they deployed via Raspberry Pis. The attackers physically broke into each ATM, removed its hard drive, installed the malware, and reinserted the drive. The malware included a self-delete function that erased all traces after the cash was dispensed, making forensic detection harder. Separate crews handled each phase of an attack: one team photographed the target ATM and checked for silent hood alarms, another installed the malware, and a third collected the cash.
As of August 2025, reported losses from alleged jackpotting attacks totaled $40.73 million across more than 1,500 attacks.
Inside Tren de Aragua’s crypto money laundering networks
Aguirre’s case illustrates a pattern we track closely: the use of shared laundering infrastructure that ties various criminal groups together.
While cases may differ in how the illicit proceeds are sourced, criminals often rely on common laundering rails to turn stolen cash into crypto. That’s what happened here. Our analysis of the network surrounding the TdA wallets found their counterparties had exposure to major laundering operations, including a Venezuelan national charged with laundering one billion dollars, and a laundering network that was leveraged by Colombian and Mexican drug cartels.
“The on-chain insights show us that criminal organizations are leveraging common infrastructure for laundering,” said Chainalysis Senior Intelligence Analyst Kaitlin Martin. “These are insights that only the blockchain can provide.”
Our investigators found these networks heavily use stablecoins to export their criminal proceeds around the world. This offers them price stability; but it also leaves them susceptible to our advanced monitoring techniques. Our real-time monitoring of networks like these allow for instant freezing actions. Indeed, Tether previously froze USDT balances on several wallets with exposure to the addresses sanctioned today.
Tren de Aragua associates laundered theft through crypto
Six associates of Aguirre (aka Prometheus) are also designated: Carlos Javier Martinez Armenta, Alejandro Mejia Castillo, Jose Dario Galeano Bazurto, Eric Gabriel Cardenas Arzola, Oscar Leonardo Martinez Pirona, and Anthony Wuiliam Hernandez Guerrero.
OFAC’s expanding campaign against Tren de Aragua financing
Today’s action is part of a sustained government campaign against TdA’s financial infrastructure. OFAC has taken multiple rounds of action against TdA since the State Department designated it as an FTO in February 2025. More broadly, the administration has taken over 30 actions against more than 300 individuals and entities tied to transnational criminal organizations since 2025. As these groups increasingly route illicit funds through crypto, a trend we have documented across Latin American markets, compliance teams and investigators should expect these designations to carry increasing on-chain relevance. For a running list of OFAC-designated entities with identified cryptocurrency addresses, see our OFAC sanctions tracker.
FAQs
What is ATM jackpotting?
ATM jackpotting is a cyberattack in which criminals install malware on automated teller machines and force them to dispense cash without debiting any account. Attackers typically gain physical access to the ATM, install malware on its hard drive, activate it remotely, and send a dispense command that empties the machine.
Who is Prometheus, the FBI’s Most Wanted fugitive linked to ATM jackpotting?
Prometheus is the alias of Anibal Alexander Canelon Aguirre, one of the FBI’s Ten Most Wanted Fugitives. He allegedly engineered the malware used in ATM jackpotting attacks, identified in court filings as Ploutus, and led a conspiracy that stole millions of dollars from U.S. financial institutions in support of Tren de Aragua. OFAC designated him on September 30, 2026.
What is Tren de Aragua?
Tren de Aragua (TdA) is a transnational criminal organization that originated in Venezuela. The U.S. State Department designated it as a Foreign Terrorist Organization (FTO) in February 2025. TdA engages in drug trafficking, human trafficking, extortion, and financial crimes including ATM jackpotting across the Western Hemisphere.
How did Tren de Aragua use cryptocurrency to launder ATM jackpotting proceeds?
According to OFAC, the TdA network used cryptocurrency transactions to launder the cash stolen from ATM jackpotting attacks and move it across borders. Chainalysis analysis found that the network’s wallets had counterparties with exposure to major money laundering operations based in Mexico, Colombia, and Venezuela, and that the network relied heavily on stablecoins to move criminal proceeds.
What is Ploutus malware?
Ploutus is a malware strain designed to force ATMs to dispense cash. In the TdA scheme, attackers deployed Ploutus via Raspberry Pi devices, physically removing an ATM’s hard drive to install the malware and reinserting it. The malware included a self-delete function that erased all traces after the attack to avoid forensic detection.
How much money was stolen in ATM jackpotting attacks linked to Tren de Aragua?
As of August 2025, reported losses from alleged ATM jackpotting attacks in the United States totaled $40.73 million across more than 1,500 attacks. The Department of Justice investigation established links between the defendants in these schemes and Tren de Aragua.
What cryptocurrency addresses were sanctioned in the TdA designation?
OFAC designated seven crypto addresses belonging to Aguirre and his associates as part of the September 30, 2026 action. These are deposit addresses at a major crypto exchange. Tether had previously frozen USDT balances on wallets with exposure to the sanctioned addresses.
What laundering networks did Tren de Aragua use?
Chainalysis analysis found that counterparties of the TdA wallets had exposure to laundering operations used by Colombian and Mexican drug cartels, as well as a Venezuelan national charged with laundering one billion dollars. The network relied on shared laundering infrastructure, including stablecoins, that services multiple criminal organizations across Latin America.
This website contains links to third-party sites that are not under the control of Chainalysis, Inc. or its affiliates (collectively “Chainalysis”). Access to such information does not imply association with, endorsement of, approval of, or recommendation by Chainalysis of the site or its operators, and Chainalysis is not responsible for the products, services, or other content hosted therein.
This material is for informational purposes only, and is not intended to provide legal, tax, financial, or investment advice. Recipients should consult their own advisors before making these types of decisions. Chainalysis has no responsibility or liability for any decision made or any other acts or omissions in connection with Recipient’s use of this material.
Chainalysis does not guarantee or warrant the accuracy, completeness, timeliness, suitability or validity of the information in this report and will not be responsible for any claim attributable to errors, omissions, or other inaccuracies of any part of such material.





