The US Treasury sanctioned seven TRON wallets on Sept. 30 that allegedly laundered money for Tren de Aragua’s ATM jackpotting crews, who used malware to make cash machines dispense money. The wallets received about $6.1 million, and the alleged malware engineer, known as “Prometheus,” is on the FBI’s Ten Most Wanted list.
Seven TRON wallets received $6.1 million in crypto
The latest sanctions expose a cryptocurrency network that allegedly helped move proceeds from ATM jackpotting operations associated with Tren de Aragua.
TRM Labs identified seven TRON addresses linked to individuals designated by OFAC. The largest recorded inflows went to a wallet attributed to Eric Gabriel Cardenas Arzola, which received approximately $2.1 million.
Investigators found that the addresses shared similar transaction patterns. Each received cryptocurrency from multiple sources through deposit addresses maintained by a centralized cryptocurrency exchange. Most of the wallets have reportedly remained inactive for several months.
The latest transaction identified by TRM occurred in July 2026, when the address associated with Cardenas Arzola received additional funds.
However, investigators also traced cryptocurrency movements beyond the seven sanctioned addresses. According to TRM, funds from these wallets were transferred to other addresses associated with Tren de Aragua. Those addresses subsequently sent approximately $35 million to a network linked by US authorities to Venezuelan national Jorge Figueira.
Figueira has been charged with allegedly laundering approximately $1 billion in illicit funds. He has not been convicted, and the charges remain allegations.
The investigation also highlights the importance of centralized exchanges in tracing suspicious transactions. Because all seven addresses were hosted by an exchange, investigators may be able to identify the underlying accounts and examine their transaction histories.
US treasury targets alleged ATM jackpotting operation
The sanctions stem from an alleged criminal operation involving ATM jackpotting, a cyberattack that uses malicious software to force cash machines to dispense money without deducting funds from customers’ bank accounts.
According to the US Treasury, criminals typically identify vulnerable ATMs through surveillance before installing malware that allows them to bypass security systems. Once activated remotely, the malicious software can force machines to release cash until their reserves are depleted or the operation is interrupted.
The alleged network operated from Mexico and Venezuela while targeting financial institutions in the United States. Investigators say cryptocurrency transactions were among the methods used to launder the stolen money before distributing it to members and associates of Tren de Aragua.
The scale of the alleged operation is reflected in Treasury’s reported figures. As of August 2025, more than 1,500 suspected ATM jackpotting attacks linked to the network had generated approximately $40.73 million in reported losses across the United States.
The latest sanctions specifically identify Anibal Alexander Canelon Aguirre, known as “Prometheus,” as the alleged engineer behind the malware used in the attacks. He is also listed among the FBI’s Ten Most Wanted Fugitives.
Six alleged associates were designated alongside him, with OFAC linking each of the seven individuals to one of the sanctioned TRON addresses.
The individuals face federal charges in Nebraska, including conspiracy to commit bank fraud, bank burglary and money laundering, as well as providing material support to Tren de Aragua.
However, the charges remain allegations, and the defendants are presumed innocent unless proven guilty.
The US Department of Justice has also reported indicting 98 individuals over alleged involvement in ATM jackpotting schemes since October 21, 2025, underscoring the scale of the ongoing investigation.
TRON’s growing role in stablecoin transactions raises scrutiny
The sanctions come as TRON continues to process substantial volumes of stablecoin transactions, particularly those involving Tether’s USDT.
During the second quarter of 2026, TRON processed approximately $2.1 trillion in USDT transfers, while its stablecoin market capitalization reached a record $89.2 billion. Data published by Messari in August placed the network’s USDT supply at approximately $87.9 billion at the end of the quarter.
However, the network’s extensive use in legitimate financial transactions has also made it a recurring focus of investigations into illicit cryptocurrency activity.
In September, Tether froze $39.3 million in USDT across 10 TRON addresses associated with the Xinbi Guarantee network, which TRM identified as a major illicit cryptocurrency marketplace in Southeast Asia.
Other enforcement actions have also involved TRON-based wallets. In July 2026, OFAC added more than 130 TRON addresses linked to the Islamic State’s Khorasan Province to its sanctions list. Tether subsequently froze funds associated with the designated addresses.
More recently, US prosecutors sought the forfeiture of $61.2 million in USDT held across 10 TRON addresses allegedly connected to sanctioned Iranian oil sales. Tether had already frozen the wallets.
These cases demonstrate how blockchain-based transactions can provide investigators with records for tracing cryptocurrency movements across multiple addresses.
The latest ATM attacks investigation adds another example of authorities using those records to identify financial networks allegedly connected to organized crime.
Crypto exchanges face increased compliance pressure
The designation of the seven TRON addresses carries immediate implications for cryptocurrency exchanges and financial institutions that may have processed transactions involving the wallets.
Unlike self-custody wallets, which are controlled directly by their owners, exchange-hosted deposit addresses are associated with accounts maintained by centralized service providers. This arrangement could help the exchange identify the customers behind the addresses and investigate related transactions.
TRM Labs has advised virtual asset service providers and financial institutions to screen the sanctioned addresses and review historical transactions for potential exposure.
The firm also recommends examining indirect transactions because funds allegedly moved from the designated wallets to other addresses associated with Tren de Aragua.
The sanctions were imposed under US Executive Order 13224, which allows authorities to target individuals and entities accused of supporting terrorism. Foreign financial institutions that knowingly facilitate significant transactions on behalf of designated individuals may face secondary sanctions, including restrictions on access to US correspondent banking accounts.
For cryptocurrency exchanges, the latest action reinforces the importance of transaction monitoring, sanctions screening and investigations into suspicious wallet activity.
TRM Labs said it would continue monitoring transactions involving the designated addresses and the broader financial network associated with Tren de Aragua.
As regulators intensify efforts to disrupt illicit cryptocurrency flows, the case illustrates how blockchain analytics can help authorities trace funds beyond the wallets initially identified in criminal investigations.