Feds, Chainalysis Reveal $169m In Bitcoin Controlled By 911 S5 Botnet

Blockchain forensics firm Chainalysis has discovered $169 million in Bitcoin connected to the 911 S5 botnet, facilitating the arrest of Chinese national Yunhe Wang.

Crypto analysis firm Chainalysis has traced $169 million in Bitcoin linked to the notorious 911 S5 botnet, a revelation that played a crucial role in the recent arrest of Yunhe Wang, a Chinese national allegedly involved in controlling the botnet.

In a blog post, the New York-headquartered firm said the botnet’s illicit operations enabled it to generate substantial revenue through crypto subscriptions sold to cybercriminals engaging in activities like password spraying attacks, financial fraud, identity theft, and child exploitation.

“911 S5 was a service that provided residential proxy services, often to bad actors who frequently paid for these services in cryptocurrencies such as Bitcoin.”

Chainalysis

Despite voluntarily shutting down in July 2022, 911 S5 retained significant on-chain funds. Working alongside agents from the Defense Criminal Investigative Service, Chainalysis uncovered deposit addresses at centralized exchanges and other parts of the botnet’s financial ecosystem.

Feds, Chainalysis reveal $169m in Bitcoin controlled by 911 S5 botnet - 1
The network of 911 S5’s crypto addresses | Source: Chainalysis

According to the firm, at least one cold storage wallet associated with 911 S5 contains 4,322.25 BTC, worth approximately $169 million. Chainalysis says the wallet also has connections to various crypto mixers and a Russian bulletproof hosting provider Black Host previously associated with ransomware strains like Dharma and Phobos.

Further analysis revealed that funds from this wallet were transferred to addresses controlled by Wang, some of which were flagged by the Office of Foreign Assets Control. As per Chainalysis, U.S. authorities managed to identify 49 addresses linked to the malicious network.

Leveraging blockchain transaction data, investigators also discovered previously unknown addresses on the TRON blockchain, exposing a wider network of 911 S5 wallets. While the scale of the 911 S5 network on TRON remains unclear, it’s apparent that the identified assets have yet to be seized, with U.S. law enforcement agencies monitoring their movements.

RECENT NEWS

Crypto Treasuries Chase A New Kind Of Capital

There is a peculiar irony at the heart of the crypto treasury movement. Companies that staked their futures on digital a... Read more

What Strategy's Bitcoin Sale Really Tells Us

There is a moment in every bull run when the narrative starts to fray. Not with a crash, not with a scandal, but with so... Read more

The Clock Is Ticking On UK Stablecoins

The world is not waiting for Britain to make up its mind. While the United States and the European Union have spent the ... Read more

From Cypherpunk To Citadel

How Crypto Moved from the Wild West to the Mainstream Financial SystemA long-form analysis of Bitcoin's journey from fri... Read more

Tether Plots Global Expansion

Stablecoin leader seeks to transform itself from crypto plumbing provider into a broad “freedom tech” conglomerateTe... Read more

World Liberty Seeks Federal Trust Charter

World Liberty Financial, the crypto venture backed by the Trump family, has applied for a US national bank trust charter... Read more