
By Flare Research
For five years, a service called AudiA6 sat at the center of the Russian-speaking cybercrime ecosystem and made one brazen promise: hand over your “dirty” crypto, wait an hour, and get “clean” coins back, with no questions asked, for a cut of 3-10%. It was never a mixer at all, but rather an industrial-scale money laundering operation that guaranteed laundered funds would pass exchange compliance checks. In June 2026, law enforcement across eleven countries dismantled it and arrested the two men allegedly behind it. By the US government’s accounting, roughly $389 million in cryptocurrency passed through its wallets.

Key Findings About the AudiA6 Takedown
- AudiA6 operated as a branded laundering-as-a-service product advertised across major Russian-speaking forums from 2021 to 2026, explicitly guaranteeing that returned coins would carry AML risk scores below 25%.
- The service processed approximately $389 million using a network of roughly 6,000 fraudulent exchange accounts built on stolen identities, funneling funds through legitimate platforms under fake names.
- Undercover agents tested the service six times, each time disclosing criminal origins (ransomware, theft, drug proceeds), and each time receiving confirmation that the service would process the funds.
- The operation’s downfall traced back to shared infrastructure: a single backup server in Germany linked AudiA6, the Dark2Web forum, and the real identities of its alleged operators.
- The takedown involved 11 countries and resulted in two arrests, 25 domains seized, approximately 80 vehicles and properties taken, and $900,000 in cryptocurrency frozen.
Dark Web & Threat Intelligence
Detect Stolen Identities and Compromised Credentials Before They Fuel Laundering Operations
AudiA6 relied on 6,000+ fraudulent exchange accounts built from stolen passports and leaked credentials to move $389 million in dirty crypto. Flare monitors dark web forums, illicit Telegram channels, and stealer log marketplaces to detect when your customers’ or employees’ identity data is exposed — before it’s weaponized for account fraud and money laundering.
AudiA6’s Origins and Operation
AudiA6 first surfaced on cybercrime forums in 2021, when an account using the moniker “AudiA6” posted an advertisement for a crypto exchange and mixing service to Dark2Web, a Russian-language dark web forum where members advertise and discuss criminal services.

AudiA6 account on Dark2Web
AudiA6 advertised there as a vendor, but it wasn’t a marketplace itself; it was a single, branded service, the laundering layer that sat underneath everyone else’s crime. The same advertisement was copied almost word-for-word across the other major Russian-speaking forums, including XSS, Exploit, Rutor, Darkmoney, Probiv, and Lolz, sometimes under a second moniker, “xai.” That kind of cross-forum consistency is deliberate; in this ecosystem a moniker is a brand, and AudiA6 was selling trust as much as it was selling a service.
The branding was unmistakably built around laundry. AudiA6 described its work as “washing” funds, even claiming to “wash clean with Ariel,” a reference to the detergent. Dirty crypto went in, clean crypto came out, and the company’s stated philosophy was that whatever happened to the dirty coins in between was its own business.
AudiA6’s Money Laundering Service
What set AudiA6 apart from a run-of-the-mill mixer was how openly it sold the criminal value of its service. Its advertisement, which the affidavit reproduces in full, dismissed rival mixers as “cheap scams” and argued that genuine mixing only complicates an investigation rather than ending it. AudiA6’s pitch was blunter:
“There’s only one way to cut off your tails — to take your dirty crypto and give you my clean one. What I do with your dirty crypto is my personal responsibility.”
The advertisement also made a very specific promise: that the coins it returned would carry an anti-money-laundering risk score under 25%. Exchanges, and the compliance firms they hire, score incoming crypto for how likely it is to be tied to crime, and freeze funds above a certain threshold. AudiA6 was effectively guaranteeing that laundered money would slide through legitimate exchanges without tripping their alarms, quietly turning those exchanges into unwitting participants in the scheme.

Representation of how the cryptocurrency moves through AudiA6
Undercover Operations
Between December 2022 and May 2026, undercover agents put the service to the test six times, and each time they told AudiA6, in plain Russian, exactly where the money came from. In one early contact they asked whether they could launder proceeds from ransomware and crypto scams; the reply was a one-word “yes.” In another, agents said their Ethereum came from a scam and from theft, and AudiA6 answered, “yes, no problem.” When an agent volunteered that the Bitcoin was stolen, the operator’s response was simply that it didn’t care.
The most damning exchange came in May 2026, when an agent said the funds were profit from selling cocaine on Blacksprut, a well-known dark web drug market, and that a “partner” was involved in distribution:

Translated message exchange between undercover agent and AudiA6
That single transaction, run by an agent in Philadelphia, anchors the “sting money laundering” count in the complaint.
AudiA6’s Tactics, Techniques, and Procedures
For all its talk of severed “tails” and untraceable pools of funds, AudiA6’s actual method was surprisingly conventional, and ultimately its undoing.
A customer would send Bitcoin to an AudiA6 wallet. From there, the coins moved to an account at a cryptocurrency exchange, opened under a fake or purchased identity, where they were swapped for the dollar-pegged stablecoin USDT. The USDT passed to a second AudiA6 wallet, through a second exchange, and finally out to the customer’s chosen address, minus commission. The whole loop took about an hour.
Fraudulent Accounts and Stolen Identities
The fraudulent accounts were the engine of the operation. Backups recovered during the investigation included a customer-management database listing roughly 6,000 cryptocurrency-exchange logins, alongside a folder of scanned passports and “selfie” photos: the stolen and purchased identities used to satisfy exchanges’ know-your-customer checks. Europol later described this as a sprawling network of money mules, many recruited by Russian-speaking intermediaries. When an exchange froze a suspicious account, the operators would pose as software developers, call the money payment for legitimate work, and supply forged documents to free it up.
Risk Scoring and Communication
AudiA6 also knew precisely what it was handling. One recovered table logged thousands of risk scores the service ran on incoming coins, and roughly half came back above the 25% line, with some flagged as 100% associated with stolen funds. Like many operations that prize anonymity, AudiA6 steered customers off its barely-functional website and into private chats over Telegram, Jabber, and Tox to actually do business.
The Fatal Flaw
The fatal flaw was the part of the pitch that wasn’t true. AudiA6 advertised that it drew clean funds from separate, unconnected pools. In reality, it ran everything through accounts it controlled, and exchange records tied those accounts together. Once agents had the records, the chain could be followed link by link, which is exactly what happened.
The Inevitable End
AudiA6’s downfall came from the same place its laundering ran: the infrastructure.
Like most criminal sites, AudiA6 hid behind Cloudflare, whose records pointed investigators to a server hosted in Iceland. Iceland turned over a copy in late 2023, and it held the AudiA6 websites, the messaging and email tooling, a customer-management system, and the back end of Dark2Web, the first hard link between the laundering service and the forum. That server backed itself up to a storage box at a German host, and German records showed the box was rented by one Alexandr Ledenev of Batumi, Georgia. Inside were tidy folders for AudiA6, for Dark2Web, for the escrow service, and one labeled “white” (cybercrime slang for legitimate cover), which held the files of a Georgian car-rental business.
Identifying the Operators
That car-rental folder led to Ruslan Igorevich Tkachuk, a 37-year-old Ukrainian national, whose Georgian residence card sat in one of the backed-up emails. Agents tied the “AudiA6” and “xai” handles to a Ukrainian phone number and a Google account whose Drive held Tkachuk’s ID and spreadsheets of stolen card and gift-card data referencing AudiA6’s own servers. The storage box itself, and the recovery email behind it, led to Alexander Vladimirovich Ledenev, a 25-year-old Russian national who exchanged test messages with the AudiA6 and Dark2Web servers and whom the forum’s “owner” had once described as Dark2Web’s technical creator under the alias “Azazello.” The shared backup box, holding servers each man had rented separately, is what investigators say binds the two together.
The Takedown
The endgame began, according to Europol, with the arrest of a Ukrainian national in Poland in September 2025, whose seized devices helped identify the people at the top. On June 10, 2026, a coordinated takedown drew on agencies from Australia, Canada, France, Georgia, Germany, Iceland, Japan, Poland, Switzerland, the United Kingdom, and the United States. The sweep produced:
- Two arrests in Georgia
- Three properties searched
- 25 domains seized
- Around 80 vehicles and properties seized
- Roughly $900,000 in cryptocurrency frozen or taken
Telegram accounts went dark, the AudiA6 and Dark2Web sites were replaced with a seizure banner, and the US unsealed charges in Philadelphia the next day. Tkachuk and Ledenev each face up to 20 years; both remain in Georgian custody as the US seeks their extradition.
What AudiA6 Means for Security Teams
AudiA6 belongs to a now-familiar lineage of money-laundering takedowns, sitting alongside operations like Hydra Market, ChipMixer, Bitzlato, and Garantex. Each of them served as the plumbing that let other people’s crime pay out. What makes AudiA6 a useful case study is how nakedly it commercialized that role. This wasn’t a privacy tool that criminals happened to abuse; it was laundering sold as a product, with a price list, a commission structure, and an explicit guarantee that dirty money would clear an exchange’s compliance checks.
The operation also illustrates a quieter risk for the legitimate side of the industry. By gaming AML risk scores and pushing tainted funds through real exchanges under stolen identities, AudiA6 turned compliant platforms into unwitting links in the chain, a reminder that exchange-side controls are only as strong as the identities behind the accounts they trust.
Actionable Takeaways for Defenders
- Monitor for compromised credentials tied to exchange accounts. AudiA6’s operation relied on 6,000+ fraudulent exchange logins built from stolen identities. Security teams at financial and crypto platforms can prioritize detecting accounts opened with leaked or stolen identity documents.
- Watch for identity document exposure. The passport scans and selfie photos used to bypass KYC checks likely originated from infostealer infections and data breaches. Organizations can monitor for their customers’ exposed identity data to flag potential account fraud.
- Track forum chatter for laundering service advertisements. Services like AudiA6 advertise openly across Russian-speaking forums. Monitoring these communities provides early warning about which laundering infrastructure threat actors are using, and which platforms may be at risk of abuse.
- Treat low AML risk scores with appropriate skepticism. AudiA6’s entire model was built on manufacturing clean-looking scores. Compliance teams can layer behavioral analytics on top of risk scoring rather than relying on scores alone.
In the end, the irony writes itself. AudiA6 built its entire brand on the claim that it alone could sever the “tails” connecting coins to their criminal origins. The trail it promised to erase ran straight through the exchange records, the rented servers, and the backup folders that eventually brought it down. Whether the two men in Batumi ever see a Philadelphia courtroom now rests on an extradition fight, but the service they allegedly built is finished.
Dark Web & Threat Intelligence
Detect Stolen Identities and Compromised Credentials Before They Fuel Laundering Operations
AudiA6 relied on 6,000+ fraudulent exchange accounts built from stolen passports and leaked credentials to move $389 million in dirty crypto. Flare monitors dark web forums, illicit Telegram channels, and stealer log marketplaces to detect when your customers’ or employees’ identity data is exposed — before it’s weaponized for account fraud and money laundering.





