On September 30, 2026, the Office of Foreign Assets Control (OFAC) sanctioned a Tren de Aragua money laundering network built on ATM jackpotting, adding seven TRON addresses to the Specially Designated Nationals (SDN) List. The wallets are already drained, so the compliance value of this action is not asset freezing. It is historical exposure, and that changes what your team needs to do next.
OFAC designated 10 targets tied to a Tren de Aragua (TdA) fraud scheme that steals from U.S. banks through ATM jackpotting, plus a separate TdA leader involved in gold mining. The action was taken pursuant to Executive Order 13581, as amended, and Executive Order 13224, as amended. Seven of the named individuals carry TRON addresses now monitored in Scorechain. The full entry, including all seven Digital Currency Address identifiers, is published in the OFAC recent actions and SDN List update for September 30, 2026.
Tren de Aragua is a designated Foreign Terrorist Organization (FTO), a status the U.S. Department of State assigned on February 20, 2025, and OFAC had already sanctioned the group as a transnational criminal organization on July 11, 2024. The September action builds on that record rather than opening it. What is new here is the on-chain dimension: for the first time in this line of TdA actions, the designation attaches specific TRON wallet addresses to named members of the laundering crew.
An SDN designation means the listed persons and their property are blocked. U.S. persons are generally prohibited from transacting with them, and any exposure to a listed address is a direct sanctions match rather than an inferred risk. Because TdA is also designated under counterterrorism authority, foreign financial institutions that handle significant transactions for these targets risk secondary sanctions as well. Treasury set out the enforcement context in its announcement, Treasury Sanctions Financial Network of Foreign Terrorist Organization, Tren de Aragua.
ATM jackpotting is a cyberattack that forces an automated teller machine to dispense all of its cash without debiting any account. Criminals break into a target machine, install malware, then trigger it remotely so the ATM empties itself. The proceeds are physical cash, which is where the laundering begins.
Within TdA, the crews behind these attacks are prolific. As of August 2025, reported losses from alleged ATM jackpotting attacks in the United States totaled 40.73 million US dollars across more than 1,500 attacks. Since October 21, 2025, the Department of Justice has indicted 98 individuals for their roles in the scheme, with charges that include providing material support to a foreign terrorist organization. The network operates out of Mexico and Venezuela and funnels the laundered proceeds back to TdA members across several countries.
The malware at the center of these attacks belongs to the Ploutus family, purpose-built to seize control of an ATM's dispensing function. It is the bridge between a physical theft in a U.S. city and a stablecoin transfer on TRON, which is the part that matters for compliance teams.
The network is allegedly engineered by Anibal Alexander Canelon Aguirre, known by the aliases Prometheus and The Engineer. He is described by prosecutors as the developer of the malware used in the jackpotting attacks, and in March 2026 he became the first cybercriminal ever added to the FBI's Ten Most Wanted Fugitives list. A federal arrest warrant was issued for him in the District of Nebraska on December 9, 2025. Reports in September 2026 indicated he had been detained in Venezuela, though U.S. authorities disclosed few details, and official notices continued to list him as wanted as of this designation.
Six associates were designated alongside him for their roles in the same scheme: Carlos Javier Martinez Armenta, Alejandro Mejia Castillo, Jose Dario Galeano Bazurto, Eric Gabriel Cardenas Arzola, Oscar Leonardo Martinez Pirona, and Anthony Wuiliam Hernandez Guerrero. Each is charged in the U.S. District Court for the District of Nebraska with offenses that include material support to TdA and money laundering conspiracy.
Cash taken from a drained ATM has to be moved and disguised before it reaches the organization. The network converts it into Tether (USDT) on the TRON blockchain, then routes it between associates' wallets to obscure its origin before it reaches TdA. USDT on TRON is the settlement asset of choice because it is fast, liquid, and dollar-denominated.
The path, in practice, runs in four stages:
That on-chain segment is where a designation like this one gains its teeth, because every hop leaves a permanent record that screening and investigation tools can read.
Across the seven designated TRON addresses, Scorechain measures combined throughput of approximately 6.08 million US dollars over roughly 3,900 transactions, almost entirely in USDT on TRON. All seven are directly attributed to their named individuals, flagged under the Sanction List risk indicator, and scored 1 on Scorechain's risk scale.
That score sits at the most severe end. Scorechain's risk score runs from 0 to 100, where a lower score means higher risk, so a score of 1 is a critical-risk result and a confirmed sanctions match, not a probabilistic signal.
The designation attaches one TRON address to each of the seven named individuals, and volume is concentrated in a few wallets rather than spread evenly across the network:
All seven addresses carry the same Scorechain classification: directly attributed, Sanction List indicator, score 1, critical risk. Three wallets account for most of the measured flow, with Cardenas Arzola the volume center.
The detail that defines this action: every one of the seven addresses has been emptied. The combined remaining balance is under 40 US dollars. There is effectively nothing left to freeze.
When a sanctioned wallet holds no funds, there is no freeze to execute, so the exposure is entirely historical. Any past transaction your institution had with one of these addresses is now a confirmed sanctions touch that has to be identified, reviewed, and reported. The work is lookback and documentation, not asset seizure.
The lookback window is wider than a recent designation might suggest. On-chain activity across these addresses runs from March 2022 to July 2026, and five of the seven wallets stopped moving funds during 2025. A review that only covers the last few months will miss most of the relevant activity. Lookbacks should cover the full period back to early 2022.
This is the practical lesson that a same-day headline tends to bury. A drained wallet is not a closed case. It is a historical-exposure question that every counterparty-facing institution with TRON activity in the past four years now has to answer.
A wallet named directly in an SDN entry is a confirmed sanctions match, not a risk signal that needs a judgment call. That distinction sets the response, and it attaches the moment the list updates. For compliance teams, the immediate steps are clear:
Scorechain's database was updated automatically for this designation, so the seven entities are already screenable and monitorable in the platform without any manual list maintenance on your side.
Crypto asset service providers (CASPs) in the European Union carry sanctions-screening obligations under the Sixth Anti-Money Laundering Directive (AMLD6) and the Markets in Crypto-Assets Regulation (MiCA), independent of any direct US nexus. Because this network is tied to a Foreign Terrorist Organization and settles through widely held USDT on TRON, exposure can surface on any book with TRON stablecoin activity. An EU CASP does not need a US counterparty to have a documented exposure question here.
ATM jackpotting is a cyberattack in which criminals install malware on an automated teller machine and trigger it remotely, forcing the machine to dispense all of its cash without debiting any account. The stolen cash is physical, and in this case it was laundered through USDT on the TRON blockchain.
The September 30, 2026 designation attaches seven TRON addresses, one to each of seven named individuals in the Tren de Aragua ATM jackpotting network. All seven are on the TRON blockchain and are monitored in Scorechain under the Sanction List risk indicator at score 1, critical risk.
Prometheus is the alias of Anibal Alexander Canelon Aguirre, also called The Engineer, the alleged developer of the malware used in the network's ATM jackpotting attacks. In March 2026 he became the first cybercriminal added to the FBI's Ten Most Wanted Fugitives list.
Because the addresses hold almost no funds, there is nothing to freeze, so the response is historical. Teams should add the seven addresses to screening, set them to the Sanction List indicator, and run a full-history exposure review from March 2022 to July 2026, since five of the seven wallets went quiet during 2025.
Yes. EU crypto asset service providers face sanctions-screening obligations under AMLD6 and MiCA regardless of a US connection. With the network tied to a Foreign Terrorist Organization and settling in USDT on TRON, any book with TRON stablecoin activity can carry documented exposure.
A drained wallet is a lookback question, and answering it quickly is the difference between a clean review and a reportable gap. Scorechain has already flagged the seven designated addresses, so you can screen for direct exposure and trace indirect exposure across four years of TRON activity from one place. Book a demo to see how Scorechain surfaces historical sanctions exposure across a designated network.































