The U.S. Treasury Department’s Office of Foreign Assets Control sanctioned Sinbad.io on November 29, 2023, describing the Bitcoin-based mixing service as an important money-laundering tool for North Korea’s state-sponsored Lazarus Group. The designation coincided with the public disclosure that investigators had seized Sinbad servers in the Netherlands and Finland.
The combined action mattered because it joined two distinct enforcement tools: OFAC restricted dealings with the designated service under U.S. sanctions law, while European authorities disrupted infrastructure used to operate it. The result was a coordinated intervention against a service designed to make public blockchain transaction trails harder to follow.
What OFAC designated
Treasury said Sinbad operated on the Bitcoin blockchain and obscured the origin, destination and counterparties of transactions. OFAC designated the service under Executive Order 13694, as amended, for supporting specified malicious cyber activity and under Executive Order 13722 for supporting the North Korean government.
The designation required property and interests in property belonging to Sinbad that were in the United States or controlled by U.S. persons to be blocked and reported. OFAC regulations also generally prohibited transactions by U.S. persons, or transactions within or transiting the United States, involving the designated entity. Those consequences were sanctions restrictions; the November 29 action was not a judicial finding that every person who had previously used a mixer committed a crime.
Treasury attributed millions of dollars in laundered virtual currency to Sinbad’s handling of Lazarus Group proceeds. It said the service processed a significant portion of assets from three thefts: approximately $620 million from Axie Infinity in March 2022, approximately $100 million from Horizon Bridge in June 2022 and $100 million stolen from Atomic Wallet customers on June 3, 2023.
Those amounts were Treasury’s estimates of the underlying thefts, not measurements of the exact value transferred through Sinbad. “Significant portion” was not quantified in the November 29 release, so the figures cannot be added together to calculate the mixer’s Lazarus-related volume.
A parallel infrastructure seizure
The Netherlands’ Fiscal Information and Investigation Service, known as FIOD, said on November 29 that it and the Dutch Public Prosecution Service had disrupted Sinbad on November 27, 2023. Servers were seized in the Netherlands and Finland. A notice displayed on Sinbad’s website identified the FBI, FIOD and Finland’s National Bureau of Investigation as participants in the coordinated operation.
FIOD alleged that Sinbad facilitated large-scale concealment of cryptocurrency derived from crime. The agency said more than 50% of cryptocurrency mixed through the service had a criminal origin and that Sinbad lacked enforced know-your-customer or know-your-transaction controls. The announcement did not disclose the complete address set, analytical method or observation window supporting that percentage, making it an official investigative claim rather than an independently reproducible Coinburn calculation.
FIOD also emphasized that a cryptocurrency mixing service was not necessarily illegal. Mixing combines transactions to weaken the visible connection between sending and receiving addresses, which can serve privacy purposes. Dutch investigators focused instead on the alleged concealment of criminal proceeds and the service’s operational controls.
Why the action mattered
OFAC had previously sanctioned Blender.io in May 2022 and redesignated Tornado Cash in November 2022. The Sinbad action extended that policy to another mixer while pairing financial restrictions with a cross-border technical disruption.
For exchanges, wallet providers and blockchain-analytics firms, the designation created an immediate screening and compliance event involving Bitcoin addresses and a named service. For privacy advocates and protocol developers, it reinforced the unresolved boundary between legitimate transaction privacy and infrastructure that authorities alleged was materially supporting state-sponsored theft.
The record available on November 29 established the designation and server seizures. It did not establish how much cryptocurrency investigators recovered, whether every Sinbad component had been disabled, or whether any operator would be charged. Those questions remained open at the close of the date reconstructed here.
The complete source packet and revision history are retained with the newsroom record.
Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.
This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.

