COINTURK NEWSCOINTURK NEWSCOINTURK NEWS
  • Crypto Tracker App
  • Bitcoin
  • Altcoin
  • Ethereum
  • Advertise
  • Contact
  • TURTURTUR
  • ESESES
Search
© 2024 COINTURK NEWS. All Rights Reserved.
Reading: Europol froze over $47 million in crime-linked crypto assets during Operation Endgame
Share
Font ResizerAa
COINTURK NEWSCOINTURK NEWS
Font ResizerAa
Search
  • Crypto Tracker App
  • Bitcoin
  • Altcoin
  • Ethereum
  • Advertise
  • Contact
  • TURTURTUR
  • ESESES
Follow US
© 2025 >> COINTURK NEWS
Powered by LK SOFTWARE
COINTURK NEWS > Cryptocurrency News > Europol froze over $47 million in crime-linked crypto assets during Operation Endgame
Cryptocurrency News

Europol froze over $47 million in crime-linked crypto assets during Operation Endgame

In Brief

  • 🚨 Europol froze over $47 million in crime-linked crypto assets in $BTC during a major cybercrime takedown.

  • ⚡ Malware networks targeting wallets and account data were disrupted across multiple countries.

  • 🛡️ Key crypto wallets and credentials were recovered in the crackdown on international cyber gangs.

İlayda Peker
İlayda Peker 1 hour ago
Share
SHARE

Europol announced that, in the final phase of Operation Endgame, more than €41 million worth of crime-related crypto assets—equivalent to approximately $47 million—were frozen. The international operation, which lasted two weeks and involved several countries, dealt a significant blow to a cybercriminal infrastructure focused on targeting crypto wallets and account information through malware.

Contents
Major takedown of malware networksServers and domains dismantledCrypto wallets a primary targetAuthorities issue warnings for users

Major takedown of malware networks

The operation dismantled the infrastructure behind three notorious malware families: SocGholish, Amadey, and StealC. According to Europol, these tools had been used to steal passwords and crypto wallet data, fueling fraud, account takeovers, and ransomware campaigns across the globe.

Europol stated that in the operation’s last stage, criminally sourced crypto assets valued at over €41 million were identified, flagged, and frozen.

Amadey was reported to provide initial access to target systems, enabling installation of additional malware. SocGholish—linked to the Russian cybercriminal group Evil Corp—spread via fake browser update alerts embedded on compromised websites. Authorities noted that these two malware tools typically started attack chains, leading to emptied wallets or ransomware incidents as the attacks unfolded.

Glossary: An infostealer is a type of malware that covertly collects saved passwords, wallet files, private keys, and recovery phrases from infected devices. CaaS refers to “Cybercrime-as-a-Service,” where criminal tools and infrastructure are made available for rent.

Servers and domains dismantled

Law enforcement agencies deactivated 326 servers and 142 domain names as part of the coordinated effort. Approximately 27 million stolen credentials, from over 385,000 compromised systems, were recovered. Nearly 15,000 infected websites—mostly belonging to small businesses—were also cleaned during the operation.

ItemData
Frozen crypto assetsOver €41 million
Servers taken down326
Domains deactivated142
Credentials recoveredAround 27 million
Compromised systemsMore than 385,000

Microsoft, which supported the operation, reported that over 140,000 computers were found to be infected with Amadey and StealC malware in just the first two weeks of May. The company’s Digital Crimes Unit revealed that, over the past nine months, five separate organizations backing the Cybercrime-as-a-Service model have been dismantled.

Crypto wallets a primary target

Experts warn that infostealer malware has become a leading method for crypto theft. Attackers can covertly siphon wallet files, private keys, and recovery phrases directly from victims’ devices, often without any signs of attack. In addition to classic phishing, criminals employed tactics like fake AI tools, gaming platform themes, and pirated game plugins to distribute malware.

Microsoft pointed out that, although Amadey and StealC were developed by different groups, they operated on shared infrastructure, which allowed the company to target both within a single criminal network.

An earlier phase of Operation Endgame revealed that login credentials for more than 100,000 crypto wallets had been compromised but had yet to be exploited. With this latest phase, authorities continue efforts to disrupt attackers’ control and have identified more than 18,000 victimized computers so far.

Authorities issue warnings for users

Officials emphasized that while such operations can significantly disrupt malware networks, eliminating malicious software entirely remains challenging, as cybercriminal operators often regroup and adapt. Notably, a new version of StealC was reported to have emerged this month.

Europol and its partners are directing victims to services like Have I Been Pwned, enabling individuals to check whether their login credentials or crypto wallet data may have fallen into attackers’ hands and to take protective measures if necessary.

You can follow our news on X, Telegram, Facebook & Coinmarketcap
Disclaimer: The information contained in this article does not constitute investment advice. Investors should be aware that cryptocurrencies carry high volatility and therefore risk, and should conduct their own research.

You Might Also Like

Crypto Fear and Greed Index plunges to 12! What are the implications for BTC and the markets?

US lawmakers urged the SEC to clarify AI-powered trading tool rules, citing investor risk

Glassnode reported 10.83 million BTC held at a loss as Bitcoin fell below $59,100, hitting an all time high

Russia’s crypto regulation faces delay past July 1! What changes could shake up $BTC and ETH investors?

Iran-linked $3.84 billion crypto flow uncovered on CoinEx! What are the regulatory implications?

İlayda Peker 25 June, 2026 - 6:22 pm 25 June, 2026 - 6:12 pm
Share This Article
Facebook Twitter
Share
İlayda Peker
By İlayda Peker
Follow:
Uluslararası İlişkiler ve Siyaset Bilimi Mezunu, Kitap sever.
Previous Article Joseph Lubin announced Ethereum is close to key upgrades to boost Layer 1 and Layer 2 interoperability
Next Article Coinbase named Luxembourg as its main EU hub under MiCA after regulatory approval
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Stay Connected

8.1k Like
21.1k Follow
1.1k Follow

Latest News

Abracadabra announced emergency measures after MIM stablecoin fell to $0.50 from its $1 peg
Stablecoin
Crypto Fear and Greed Index plunges to 12! What are the implications for BTC and the markets?
Cryptocurrency News
Coinbase named Luxembourg as its main EU hub under MiCA after regulatory approval
Coinbase
//

COINTURK was launched in March 2014 by a group of technology enthusiasts who believe that Bitcoin will be as important as the internet in the world of the future thanks to the amazing technology underlying it.

CRYPTOCURRENCY LIVE PRICES

  • Bitcoin (BTC) Live Price
  • Ethereum (ETH) Live Price
  • Ripple (XRP) Live Price
  • Solana (SOL) Live Price
  • Dogecoin (DOGE) Live Price
  • Cardano (ADA) Live Price
  • Chainlink (LINK) Live Price

OUR PARTNERS

  • COINMARKETCAP
  • COINGECKO
  • BITCOINHABER
  • BH NEWS
  • 21MILYON
  • NEWSLINKER

OUR COMPANY

  • About Us
  • Cookie Policy
  • Advertising
  • Contact
COINTURK NEWSCOINTURK NEWS
Follow US
COINTURK NEWS 2026
Powered by LK SOFTWARE
Welcome Back!

Sign in to your account

Lost your password?