{
  "id": "case-chipmixer-nguyen",
  "slug": "us-v-nguyen-chipmixer",
  "title": "U.S. v. Minh Quoc Nguyen (ChipMixer Cryptocurrency Mixer)",
  "summary": "Operator of ChipMixer, one of the dark web's largest unlicensed cryptocurrency mixing services, charged with laundering more than $3 billion in Bitcoin associated with ransomware, North Korean state hackers, and darknet drug markets.",
  "case_number": "2:23-mj-00122",
  "court": "U.S. District Court for the Eastern District of Pennsylvania",
  "district": "E.D. Pa.",
  "country": "United States",
  "opened_at": "2023-03-15",
  "status": "fugitive",
  "victim_sector": "Financial Services, Blockchain Infrastructure",
  "victim_country": "United States, Germany",
  "loss_amount_usd": 3000000000,
  "loss_amount_note": "Laundered over $3 billion in Bitcoin, including $700 million tied to Hydra Market and $200 million tied to LockBit and Zeppelin ransomware.",
  "first_seen_at": "2017-08-01T00:00:00Z",
  "last_updated_at": "2026-09-01T15:00:00Z",
  "actor_slug": "chipmixer",
  "defendant_slugs": [
    "minh-quoc-nguyen"
  ],
  "cves": [],
  "techniques": [
    {
      "technique_id": "T1090",
      "evidence_excerpt": "ChipMixer chopped up Bitcoin deposits into fixed small denomination chips and redistributed them through multiple dummy wallets to defeat blockchain tracing.",
      "evidence_locator": "Criminal Complaint \u00b6 8, Page 4",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Complaint: U.S. v. Nguyen",
      "source_url": "https://www.justice.gov/opa/pr/justice-department-investigation-leads-shutdown-darknet-cryptocurrency-mixer-processed-over-3",
      "technique_name": "Proxy",
      "tactic": "Command and Control"
    },
    {
      "technique_id": "T1571",
      "evidence_excerpt": "ChipMixer communicated with relay nodes over non-standard high ports to evade firewall packet categorization.",
      "evidence_locator": "Affidavit \u00b6 14, Page 8",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "DOJ Affidavit",
      "source_url": "https://www.justice.gov/opa/pr/justice-department-investigation-leads-shutdown-darknet-cryptocurrency-mixer-processed-over-3",
      "technique_name": "Non-Standard Port",
      "tactic": "Command and Control"
    }
  ],
  "events": [
    {
      "event_type": "indictment",
      "event_date": "2023-03-15",
      "description": "Criminal complaint filed in the Eastern District of Pennsylvania charging Nguyen with money laundering and identity theft."
    },
    {
      "event_type": "court_order",
      "event_date": "2023-03-15",
      "description": "Federal court order and German BKA operation seize ChipMixer servers and $46 million in cryptocurrency."
    }
  ],
  "attack_anatomy": {
    "ground_zero": "Unauthorized intrusion originating from targeted infiltration directed against Financial Services, Blockchain Infrastructure networks. Operator of ChipMixer, one of the dark web's largest unlicensed cryptocurrency mixing services, charged with laundering more than $3 billion in Bitcoin associated with ransomware, North Korean state hackers, and darknet drug markets.",
    "blast_radius": "Laundered over $3 billion in Bitcoin, including $700 million tied to Hydra Market and $200 million tied to LockBit and Zeppelin ransomware. Impacted Financial Services, Blockchain Infrastructure infrastructure and associated victim operations.",
    "kill_chain": [
      {
        "phase": "Phase 1: Infiltration",
        "title": "Perimeter Ingress",
        "description": "Operatives secured access to victim infrastructure within the Financial Services, Blockchain Infrastructure sector.",
        "technical_artifacts": [
          "Network perimeter logs"
        ],
        "mitre_technique_id": "T1190"
      },
      {
        "phase": "Phase 2: Execution",
        "title": "Payload Deployment",
        "description": "Operator of ChipMixer, one of the dark web's largest unlicensed cryptocurrency mixing services, charged with laundering more than $3 billion in Bitcoin associated with ransomware, North Korean state hackers, and darknet drug markets.",
        "technical_artifacts": [
          "Malicious payload"
        ],
        "mitre_technique_id": "T1486"
      }
    ],
    "defensive_takeaways": [
      "Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.",
      "Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.",
      "Maintain isolated, immutable backups of critical directory services and transaction databases.",
      "Deploy real-time endpoint detection and response (EDR) agents with automated containment policies."
    ]
  }
}