/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

A look at the newly launched Bitcoin mixer Sinbad.io, which appears to have become the preferred outlet for North Korean hackers to launder stolen crypto

The world's most prolific crypto thieves have used Sinbad.io to launder tens of millions.  Its creator, “Mehdi,” answers WIRED's questions. Tweets: @a_greenberg Tweets: Andy Greenberg / @a_greenberg : https://sinbad.io/, a newly launched Bitcoin mixer, has quickly become North Korean hackers' preferred outlet for laundering tens of millions in stolen crypto. I interviewed Sinbad's creator, who insists he's running a legitimate privacy service. https://www.wired.com/...

Wired Andy Greenberg

Context & Ripple Effects

Sinbad.io launched in October 2022 as a Bitcoin mixer pitched by its creator "Mehdi" as a legitimate privacy service, but blockchain researchers traced tens of millions in stolen crypto through it — much of it attributed to North Korea's Lazarus hackers, whose earlier playbook relied on automated "peeling" transactions rather than mixing services.

The story matters because it captures the moment a fresh mixer becomes the industry's default laundering venue, with its operator publicly denying what the on-chain data shows — a pattern that ended nine months later when the US sanctioned and seized Sinbad.

First-order effects

  • Lazarus-linked thieves gain a working outlet for laundering tens of millions at scale, while Mehdi faces the immediate problem that his customer base is publicly identified as state-sponsored hackers.
  • Blockchain researchers and victims' exchanges get a new clustering target: once a mixer is flagged as the preferred Lazarus venue, funds touching it become toxic across compliance desks.

Second-order effects

  • As mixers like Sinbad attract scrutiny, North Korean hackers diversify into less-flagged channels such as renting cloud compute to mine fresh coins, spreading their laundering across methods instead of concentrating it in one service.
  • Every high-profile mixer adoption hands Western regulators a concrete case study, accelerating pressure on other mixing services and on exchanges to freeze tainted flows.

Third-order effects

  • If the pattern holds, mixer operators are treated as criminal enterprises rather than neutral toolmakers — culminating in the DOJ indicting three Russian citizens for running Sinbad.io and Bender.io alongside ransomware gangs.
  • The longer-term effect is a cat-and-mouse structure in which each launderer's preferred venue is short-lived, pushing illicit flows toward distributed or novel techniques while legitimate privacy tools inherit the stigma of their criminal users.

The trend: Crypto laundering is cycling through increasingly short-lived mixer platforms, with each one's exposure triggering sanctions, seizures, and operator prosecution that push state-sponsored thieves toward new methods.

Discussion

  • @a_greenberg Andy Greenberg on x
    https://sinbad.io/, a newly launched Bitcoin mixer, has quickly become North Korean hackers' preferred outlet for laundering tens of millions in stolen crypto. I interviewed Sinbad's creator, who insists he's running a legitimate privacy service. https://www.wired.com/...