For four years, if a ransomware gang needed to turn stolen crypto into spendable, untraceable cash, there’s a good chance they went through a service calling itself AudiA6. Send in dirty bitcoin, get clean bitcoin back within the hour, minus a cut. No questions asked, by design.
On June 10, 2026, that stopped. A coordinated law enforcement operation across 11 countries shut AudiA6 down, arrested two of its alleged administrators, and seized the infrastructure behind it. Blockchain analysis tied the service to roughly $389 million in cryptocurrency since 2021, and to a client list that reads like a most-wanted list of ransomware gangs.
Here’s what AudiA6 actually was, how the case came together, and why taking down one laundering service matters more than the headline number suggests.
Quick answer: AudiA6 was a cryptocurrency laundering service that let cybercriminals, ransomware gangs especially, exchange stolen crypto for “clean” funds in about an hour, for a fee. Law enforcement from the US, Europol, and partners across 11 countries dismantled it on June 10, 2026, arresting two alleged administrators in Georgia. Blockchain records tie the service to around 10,333 bitcoin, worth roughly $389 million at the time of the transactions, moving through it since 2021.
What AudiA6 Actually Was
AudiA6 marketed itself as a “professional cryptocurrency mixing service.” In practice, prosecutors say it was built almost entirely around taking illegally obtained crypto and handing back a “clean” version with no visible link to the crime it came from. One of its own advertisements on the Dark2Web forum put the pitch about as bluntly as it gets: send in your dirty crypto, get clean crypto back.
The fee for that service ran somewhere between 3% and 10% of whatever you sent through, depending on the source, with one specific Dark2Web ad quoting a rate of up to 5%. In exchange, AudiA6 promised to return the cleaned funds within about an hour.
The same two administrators also ran Dark2Web, an underground forum used to advertise laundering services and, according to the criminal complaint, connect users willing to pay for crimes committed against specific targets. AudiA6 was one of Dark2Web’s flagship offerings.
How the Laundering Actually Worked
A traditional cryptocurrency mixer just pools coins together to muddy the trail. AudiA6 went a step further and built what investigators describe as an industrial-scale identity fraud operation to support it.
Stolen crypto went into wallets controlled by AudiA6. From there, the funds were layered through more than 6,000 fraudulent cryptocurrency exchange accounts, each one verified using stolen or purchased real identities to pass KYC checks (the “know your customer” identity verification that legitimate exchanges require). These accounts, known as money mule accounts, moved the funds around inside legitimate, regulated exchanges before sending it back out the other side looking clean.
Investigators say many of the people recruited to open these accounts were connected to Russian-speaking intermediaries who specialized in sourcing identities for exactly this purpose. Europol has since published several of the domains used to register the fraudulent accounts, so exchanges can screen for and block them going forward.
The Takedown: Who Got Arrested and How
The case that ended AudiA6 didn’t start with the AudiA6 investigation itself. It started with the arrest of a Ukrainian national in Poland back in September 2025, on an unrelated matter connected to the network. Digital forensics on that person’s devices gave investigators the thread they needed to identify who was actually running the operation.
That thread led to Batumi, Georgia, where authorities arrested two men this June: Ruslan Igorevich Tkachuk, 37, a Ukrainian national, and Alexander Vladimirovich Ledenev, 25, a Russian national. US prosecutors in the Eastern District of Pennsylvania charged both with conspiracy to launder monetary instruments, and are seeking their extradition. If convicted, they each face up to 20 years in prison.
The operation itself, carried out on June 9-10, involved authorities from the US Secret Service, IRS Criminal Investigation, Europol and Eurojust, and law enforcement partners in Australia, Canada, France, Georgia, Germany, Iceland, Japan, Poland, Switzerland, and the UK. Between them, they searched three properties, seized 25 domains and servers spread across the US, Iceland, Germany, and France, blocked the network’s Telegram accounts, seized about $99,000 in cryptocurrency outright, and froze another roughly $798,000. Both the AudiA6 and Dark2Web websites, on the clear web and the dark web alike, now show a law enforcement seizure notice instead of a working service.
The Undercover Work Behind the Case
Part of what makes this case solid isn’t just blockchain analysis, it’s old-fashioned undercover work. Federal agents ran six separate transactions through AudiA6 between December 2022 and May 2026, posing as criminals looking to launder money.
According to the criminal complaint, agents were direct about where the money supposedly came from, and the operators didn’t blink. At one point, when an undercover agent asked whether proceeds from cocaine sales were something AudiA6 could handle, an operator reportedly answered plainly: “Everything like that needs to go through a mixer.” In other words, yes, and here’s how.
That kind of documented, repeated willingness to knowingly launder criminal proceeds is a big part of why prosecutors are confident going into court.
Which Ransomware Gangs Actually Used It
Blockchain intelligence firm TRM Labs traced funds from at least 20 distinct ransomware groups flowing into AudiA6 over the years. The three largest senders were ALPHV BlackCat (about $9.1 million), Qilin (about $7.1 million), and LockBit (about $4.4 million), the same LockBit that had already pulled in over $200 million in ransom payments before international law enforcement disrupted its infrastructure back in February 2024. Akira, Chaos/Blacksuit, RansomHub, and a handful of other groups also routed funds through the service consistently over time.
AudiA6 also turns up in the paper trail of specific, well-known breaches. Researchers at TRM Labs had already flagged AudiA6 back in December 2025, independent of this law enforcement action, after tracing roughly $7 million in cryptocurrency stolen during the 2022 LastPass breach as it moved from a separate mixing service into AudiA6’s wallets. Europol also connects the platform to more than 15 international investigations in total, including funds tied to the Swissborg hack.
Why This Bust Matters More Than It Looks
It’s tempting to read a story like this as one more takedown in a long line of them, since cybercrime infrastructure gets seized fairly regularly. But the data behind AudiA6 points at something bigger.
According to TRM Labs, somewhere between 600 and 760 different services receive ransomware-linked crypto in any given year. Despite that huge number of options, the top five services alone typically handle somewhere between 42% and 57% of all that laundering volume, a concentration pattern that’s held for years even as individual services get shut down. That number actually climbed back up to 51% in 2025, after dipping when past enforcement action disrupted a few major players.
What that means in plain terms: ransomware gangs don’t have infinite good options for cashing out. They gravitate toward a small handful of services that are reliable and willing to look the other way, which means every time law enforcement removes one of those handful, it genuinely dents the whole ecosystem’s plumbing, not just one platform’s business.
There’s a shift worth watching, too. Cryptocurrency mixers took in roughly $152 million in ransomware-linked funds back in 2021. After a string of enforcement actions, including the shutdown of ChipMixer in 2023, that dropped to around $48 million by 2024. Criminals didn’t stop laundering money, they moved to cross-chain bridges instead, tools that let you swap crypto between different blockchains. Bridge-based laundering hit about $100 million in 2025, overtaking mixers for the first time. Bridges are trickier for investigators, since most of their traffic is completely legitimate, which makes a single targeted takedown much harder to pull off than shutting down a mixer that exists purely to launder crime proceeds.
The Bigger Picture
AudiA6’s takedown fits a pattern that’s become familiar: ransomware gangs steal the money, but they still need somewhere trustworthy, from a criminal’s perspective, to actually spend it. That’s exactly the kind of centralized weak point our look at the Ransom Busters honeytrap scam also touched on, criminals depending on infrastructure and relationships just as much as legitimate businesses do, and that dependency is exactly where law enforcement keeps finding leverage.
For everyday readers, the practical takeaway isn’t dramatic. You’re not going to accidentally interact with a service like AudiA6. But it’s a useful reminder of how much of the ransomware economy runs on a surprisingly small backbone of laundering infrastructure, and why a single well-built case, backed by blockchain analysis and old-fashioned undercover work, can genuinely knock a dent in it.
Frequently Asked Questions
What was AudiA6?
A cryptocurrency laundering service, marketed as a mixer, that took stolen or illegally obtained crypto and returned “cleaned” funds to clients for a fee, typically within about an hour.
How much money did AudiA6 launder?
Blockchain analysis in the US criminal complaint traces roughly 10,333 bitcoin, worth about $389 million at the time of the transactions, moving through AudiA6 wallets since 2021.
Who was arrested?
Ruslan Igorevich Tkachuk, 37 (Ukrainian) and Alexander Vladimirovich Ledenev, 25 (Russian), both arrested in Batumi, Georgia, and charged with conspiracy to launder monetary instruments. US prosecutors are seeking extradition.
What was Dark2Web?
An underground cybercrime forum run by the same two administrators, used to advertise AudiA6’s laundering services and, according to prosecutors, to connect people willing to pay for crimes against specific targets.
Which ransomware groups used AudiA6?
At least 20 groups, according to TRM Labs, with ALPHV BlackCat, Qilin, and LockBit sending the largest amounts.
Does shutting down one laundering service actually help?
More than it might seem. A small handful of services handle the majority of ransomware cash-outs each year, so removing one of the major ones creates a real, if temporary, bottleneck for criminal groups trying to spend their proceeds.