The past week brought a series of high-profile cybersecurity incidents directly impacting the cryptocurrency industry. From secret ransom payments by government agencies to large-scale police operations, let's break down the key events.

Prisoner Outwits Justice: Withdrawing Confiscated $290,000

Bulgarian citizen Rosen Iosifov, serving a 111-month sentence for online auction fraud via the RG Coins exchange, managed to orchestrate the withdrawal of previously confiscated $290,000 in cryptocurrency. The incident occurred in January 2024, right from behind bars. Using a chain of mixers and several exchanges, Iosifov attempted to obscure the trail. He now faces up to 25 additional years in prison for concealment of property and conspiracy.

Operation First Light 2026: Interpol Strikes

Interpol's global special operation, First Light 2026, concluded with impressive results. From January 15 to April 30, law enforcement from 97 countries coordinated attacks on transnational fraud networks. The outcome: 5,811 arrests, seizure of $293 million in assets, and blocking of over 31,000 bank accounts and crypto wallets. The I-GRIP system played a key role, enabling instant freezing of transactions, including cryptocurrency ones. Particularly notable was a case in Thailand, where $122.5 million in illegal funds from "romance scams" passed through a single crypto wallet over 10 months.

Free VPNs: Protection or Espionage?

Researchers from the University of Michigan and partners audited 280 free VPN apps from Google Play. The findings are shocking: over 80% of services transmitted data to advertising networks, and 29 apps allowed DNS request leaks. One app sent precise GPS coordinates of the device. Critical vulnerabilities included tunnel interception via HTTP and the use of outdated Blowfish encryption. Experts warn: "Verified" badges in app stores are merely marketing.

US Paid Ransom: 9.44 BTC to Kairos Group

On June 13, 2025, a US government entity (presumably the Union County administration, Ohio) paid hackers from the Kairos group a ransom of 9.44 BTC (~$1 million). The attack's uniqueness lies in the fact that the attackers did not encrypt data but stole 2 TB of information and threatened its publication. After negotiations, the sum was reduced from $3 million to $1 million. The funds were fragmented and sent through Bybit, OKX, and the Russian service BELQI. Experts note a shift in tactics: pure extortion is becoming more popular than complex encryption.

Lurking Lizard: Your Computer as Someone Else's Proxy

The Lurking Lizard group infects user devices through fake installers for 7-Zip, WhatsApp, and VPNs, turning them into residential proxy nodes. The infrastructure includes over 230 domains and has been operational since August 2022. The mobile app wirevpn — Fast Unlimited Proxy has already been downloaded 1 million times. These proxies are then rented out to other cybercriminals to conceal attack traces. The problem is becoming systemic: legitimate user traffic is blocked due to their IPs being used in criminal schemes.

My Expert Opinion: We are witnessing a fundamental transformation of cyber threats. The shift from encryption to pure extortion and the conversion of user devices into attack infrastructure are new challenges requiring a reassessment of security approaches at both the state level and for ordinary users. Cryptocurrencies remain the preferred tool for ransoms, but tracking mechanisms are becoming increasingly effective.