The United States Department of the Treasury’s Office of Foreign Assets Control (OFAC), working in tandem with advanced blockchain intelligence firms, has dealt a severe blow to the financial infrastructure of the transnational criminal organization Tren de Aragua (TdA). In a coordinated enforcement action on September 30, 2026, OFAC officially designated 10 primary targets linked to an elaborate, multi-million-dollar automated teller machine (ATM) "jackpotting" conspiracy. At the center of this expansive illicit network is Anibal Alexander Canelon Aguirre—widely known by the alias "Prometheus"—who currently holds a spot on the FBI’s Ten Most Wanted Fugitives list.
According to federal indictments, intelligence reports, and on-chain tracking data provided by blockchain analytics firm Chainalysis, Aguirre and his cell of operatives systematically drained millions of dollars from financial institutions across the United States. The stolen fiat currency was subsequently converted and funneled through digital asset networks, utilizing sophisticated cryptocurrency laundering operations to move capital seamlessly across borders. These illicit funds directly subsidized TdA, a brutal syndicate that originated in Venezuela and was designated by the U.S. State Department as a Foreign Terrorist Organization (FTO) in February 2025.
The recent sanctions target not only Aguirre but also six of his closest criminal associates: Carlos Javier Martinez Armenta, Alejandro Mejia Castillo, Jose Dario Galeano Bazurto, Eric Gabriel Cardenas Arzola, Oscar Leonardo Martinez Pirona, and Anthony Wuiliam Hernandez Guerrero. Furthermore, OFAC explicitly designated seven specific cryptocurrency addresses tied to Aguirre and his co-conspirators, which served as deposit endpoints at a major centralized digital asset exchange. As governments worldwide intensify their scrutiny of the nexus between cryptocurrency and organized crime, this case underscores both the vulnerabilities exploited by bad actors and the unprecedented visibility afforded by blockchain forensics.
Anatomy of a Cyber-Heist: The Mechanics of ATM Jackpotting
The financial engine driving the TdA operation relied heavily on a specialized form of cyber-physical bank robbery known as "jackpotting." Unlike traditional physical break-ins or digital network breaches, jackpotting requires a multi-stage conspiracy involving specialized technical tools, local reconnaissance, and physical access to targeted banking terminals.
Federal court documents unsealed in late 2025 outline how Aguirre allegedly engineered the core malware used in these attacks, identified in investigative filings as the Ploutus malware strain. Rather than deploying the malware remotely, the criminal network dispatched specialized cells into the United States from coordinating hubs in Mexico and Venezuela. These operatives executed meticulously planned operations divided into distinct phases.
First, reconnaissance crews photographed target ATMs, assessing vulnerability points and checking for silent hood alarms or active surveillance. Once a location was cleared, a second team physically breached the ATM cabinet, removed the machine’s hard drive, and connected a Raspberry Pi device or directly installed the Ploutus malware onto the storage medium before reinserting it. Finally, a third crew executed the cash-dispensing command, forcing the ATM to eject massive quantities of physical currency without debiting any customer account or leaving standard transaction logs.

To evade law enforcement and forensic investigators, the Ploutus malware was engineered with a sophisticated self-delete function. Once the cash was dispensed and collected, the malicious code automatically scrubbed itself from the ATM’s system, erasing digital footprints and complicating post-incident forensic analysis by bank security teams.
Despite these countermeasures, the scale of the operation drew intense federal scrutiny. By August 2025, cumulative reported losses from alleged ATM jackpotting attacks across the United States surpassed $40.73 million, spanning more than 1,500 distinct incidents. Investigators quickly connected the dots between these localized physical thefts and the broader financial network of Tren de Aragua.
Tracing the On-Chain Footprint: How Crypto Enabled Global Laundering
Once physical cash was successfully extracted from U.S. ATMs, the conspiracy faced the classic challenge of modern organized crime: turning millions of dollars in illicit paper money into digital, mobile, and globally accessible wealth without triggering anti-money laundering (AML) red flags. To achieve this, Aguirre and his associates relied heavily on cryptocurrency rails.
Chainalysis investigators conducted an in-depth on-chain analysis of the wallets and deposit addresses tied to the designated TdA operatives. The findings revealed that the digital assets were routed through shared laundering infrastructure that serviced a wide variety of transnational criminal enterprises. Specifically, the wallets maintained transactional exposure to major laundering operations previously utilized by Colombian and Mexican drug cartels, as well as a separate, massive case involving a Venezuelan national charged with laundering approximately one billion dollars in illicit funds.
"The on-chain insights show us that criminal organizations are leveraging common infrastructure for laundering," noted Kaitlin Martin, Senior Intelligence Analyst at Chainalysis. "These are insights that only the blockchain can provide."
A defining characteristic of the TdA financial network was its heavy reliance on stablecoins—digital currencies pegged to traditional fiat currency, such as the U.S. dollar—to export criminal proceeds across Latin America and beyond. While stablecoins provide criminal groups with price stability free from the volatility of cryptocurrencies like Bitcoin or Ethereum, their transparent, public-ledger nature also exposes them to advanced blockchain monitoring and rapid intervention by issuers and law enforcement.
Demonstrating the efficacy of public-private cooperation in the digital asset ecosystem, stablecoin issuer Tether proactively froze USDT balances across multiple wallets that exhibited direct transactional exposure to the addresses eventually sanctioned by OFAC. This real-time freezing capability illustrates how blockchain analytics can disrupt criminal cash flows before funds are fully obfuscated or converted back into traditional financial systems.

Chronology of Enforcement: A Systematic Crackdown on TdA Finances
The designation of Aguirre and his network represents a critical milestone in a broader, sustained U.S. government campaign targeting the financial foundations of Tren de Aragua. The chronology of this crackdown highlights a methodical escalation by federal regulators and international law enforcement agencies:
- February 2025: The U.S. State Department officially designates Tren de Aragua as a Foreign Terrorist Organization (FTO), recognizing its evolution from a Venezuelan prison gang into a sophisticated, multi-national syndicate engaged in drug trafficking, human smuggling, extortion, and cyber-enabled financial crimes.
- August 2025: Cumulative financial losses attributed to the nationwide ATM jackpotting campaign surpass $40.73 million across more than 1,500 incidents, prompting the Department of Justice and the FBI to prioritize the dismantling of the technical cells behind the Ploutus malware deployment.
- December 2025: Federal prosecutors in the United States formally unseal indictments against Anibal Alexander Canelon Aguirre ("Prometheus") and key members of his conspiracy, detailing the multi-million-dollar ATM jackpotting scheme and its direct ties to TdA leadership.
- May 2026: Broad federal investigations highlight the expanding convergence of Latin American drug cartels and transnational gangs in utilizing cryptocurrency for cross-border money laundering, prompting increased regulatory warnings for crypto compliance teams.
- September 30, 2026: OFAC issues a sweeping sanctions package designating 10 targets tied directly to the TdA financing network. The action includes seven specific cryptocurrency deposit addresses controlled by Aguirre and his six primary associates, alongside synchronized asset-freezing actions by private sector stablecoin issuers.
Broader Implications for Compliance and National Security
The integration of cryptocurrency tracking into the takedown of Tren de Aragua signals a permanent shift in how law enforcement combats transnational organized crime. Historically, traditional financial investigations into cash-heavy crimes like ATM theft stalled once physical currency crossed international borders into cash-based economies. However, the modern necessity of laundering millions of dollars quickly has driven groups like TdA into the digital asset ecosystem, inadvertently leaving a permanent, immutable ledger of their financial transactions.
For cryptocurrency exchanges, decentralized finance (DeFi) protocols, and traditional financial institutions alike, these developments emphasize the critical importance of robust blockchain intelligence and real-time compliance monitoring. As criminal networks increasingly share laundering infrastructure across disparate enterprises—linking Venezuelan gang members, Colombian drug cartels, and Mexican smuggling rings—compliance teams must look beyond isolated wallet addresses to understand interconnected risk topologies.
The U.S. administration’s aggressive posture since 2025—marked by over 30 distinct sanctions actions against more than 300 individuals and entities involved in transnational crime—demonstrates a zero-tolerance policy toward illicit financial networks. With key figures like Aguirre ("Prometheus") remaining targets of global manhunts, and their financial lifelines systematically severed through on-chain tracking, the case serves as a powerful testament to the evolving capabilities of modern forensic investigators in the digital age.



