Over the past week, several landmark events have occurred at the intersection of cryptocurrencies and cybersecurity. From secret payments by the U.S. government to hackers to large-scale Interpol operations — I have analyzed the key incidents that are reshaping the landscape of digital threats.
Inmate Pulled Off a Crypto Scam from Inside Prison
Bulgarian citizen Rosen Iosifov, already serving a 111-month sentence for a $5 million online auction fraud, managed to orchestrate the withdrawal of $290,000 in cryptocurrency that had previously been confiscated by the state. The incident occurred in January 2024. Using a chain of exchanges and mixers, Iosifov attempted to cover his tracks. He now faces up to 25 additional years in prison. This case is a stark reminder that even behind bars, cryptocurrencies remain a highly liquid asset requiring enhanced oversight.
Interpol Delivers Record Blow to Cybercriminals
The global Operation First Light 2026 led to the arrest of 5,811 suspects and the seizure of $293 million in assets. 97 countries participated. Law enforcement actively used the I-GRIP mechanism to freeze not only bank transfers but also crypto wallets. In Thailand, for example, a network was uncovered that laundered $122.5 million over 10 months through complex cross-chain swaps. In total, over 31,000 accounts and wallets were blocked, and the number of victims exceeded 142,000. This shows that international coordination is beginning to yield real results in the fight against crypto fraud.
Free VPNs: The Illusion of Security
Researchers from the University of Michigan and IIT Delhi analyzed 280 free VPN applications from Google Play. The results are shocking: 80% of them spy on users, transmitting advertising identifiers and GPS coordinates. 29 apps (360 million installs) allow DNS query leaks, and 5 intercept traffic via unencrypted HTTP. Moreover, 89% of services use only one authentication method, and some rely on outdated Blowfish ciphers. Essentially, users pay for "security" with their privacy.
U.S. Government Secretly Paid Ransom in Bitcoin
On June 13, 2025, the administration of Union County (Ohio) transferred 9.44 BTC (~$1 million) to hackers from the Kairos group. The attackers did not encrypt data but simply threatened to publish 2 TB of confidential information, including social security numbers and fingerprints. After a month of negotiations, the amount was reduced from $3 million to $1 million. The funds were split and sent through Bybit, OKX, and the Russian service BELQI. This confirms a global trend: hackers are abandoning complex encryption software in favor of pure extortion.
User Devices Turned into Proxy Botnets
The Lurking Lizard group infects computers and smartphones with trojans, disguising them as installers for 7-Zip, WhatsApp, and VPNs. Infected devices become nodes of residential proxies, which are rented out to other cybercriminals. One of the group's mobile apps — wirevpn — has already been downloaded over 1 million times. The infrastructure includes 230 fake domains. This creates a serious threat: legitimate user traffic may be blocked because their IP addresses are used in attacks.
My Expert Opinion: These events demonstrate that cryptocurrencies remain a double-edged sword. On one hand, they provide transparency for investigations (as in the Interpol case), on the other, they become an ideal tool for ransoms and money laundering. The trend toward "extortion without encryption" is particularly dangerous as it lowers the barrier to entry for cybercriminals. Investors and users should reconsider their security approaches: free VPNs are not protection but a threat, and storing large sums on exchanges without proper hygiene is a direct path to losses.