The U.S. Treasury Department sanctioned Chinese nationals Tian Yinyin and Li Jiadong on March 2, 2020 for allegedly helping North Korea’s Lazarus Group launder cryptocurrency stolen from exchanges. The Justice Department concurrently unsealed a two-count indictment charging both men with conspiracy to launder monetary instruments and operating an unlicensed money-transmitting business.

The coordinated action mattered because it connected blockchain tracing, exchange records, conventional bank accounts and sanctions enforcement in a single national-security case. Authorities were not merely identifying wallets associated with a theft. They alleged that identifiable intermediaries converted cryptocurrency into fiat currency and gift cards while using accounts at regulated exchanges and banks.

The criminal charges were allegations, not findings of guilt. The Justice Department stated that both defendants were presumed innocent unless proven guilty beyond a reasonable doubt. OFAC’s designation was a separate administrative sanctions action.

What authorities alleged

Treasury said Tian and Li received approximately $91 million from accounts controlled by the Democratic People’s Republic of Korea following an April 2018 cryptocurrency-exchange intrusion. It attributed another $9.5 million received by the pair to a separate exchange hack. According to Treasury, the men moved assets among addresses they controlled to obscure their origin.

The indictment supplied a narrower transaction measurement. It alleged that Tian and Li conducted $100,812,842.54 in cryptocurrency transactions from approximately July 2018 through April 2019, primarily involving virtual currency traceable to the exchange theft. That figure represents the government’s alleged transaction total over the stated period; it is not an independently calculated estimate of criminal proceeds or victim losses.

The indictment also alleged that Tian converted approximately $1,448,694.74 worth of bitcoin into prepaid Apple iTunes gift cards through 8,823 transactions. Accounts associated with the defendants were allegedly linked to bank accounts in China, providing routes for converting digital assets into fiat currency.

The exchange theft and forfeiture case

Treasury valued the cryptocurrency stolen in the principal exchange intrusion at approximately $250 million at the time of the theft. It said an exchange employee had unwittingly downloaded North Korea-attributed malware, enabling unauthorized access to customer information and private keys.

A civil forfeiture complaint filed on March 2 named 113 virtual-currency accounts and addresses allegedly used by the defendants and unnamed co-conspirators. The Justice Department said a portion of the targeted assets had already been seized but did not provide an event-day aggregate value for the seized portion.

The complaint and indictment described efforts to defeat exchange controls through falsified identification documents and doctored photographs. They also alleged the use of hundreds of automated cryptocurrency transactions intended to complicate tracing. Those assertions came from federal pleadings and had not been tested at trial on March 2.

What the sanctions changed

OFAC designated Tian and Li under cyber-related and North Korea-related executive orders. Their property and interests in property within the United States, or controlled by U.S. persons, consequently had to be blocked and reported. U.S. persons were generally prohibited from dealings involving their blocked property, while foreign financial institutions risked additional exposure for knowingly facilitating significant transactions or services for them.

The action demonstrated the practical limits of treating public blockchain addresses as anonymous in every circumstance. Transaction histories could be combined with exchange account information, identity records and banking activity to identify alleged operators behind clusters of transfers.

It did not establish that every transaction passing through a named account was independently criminal, nor did it prove the government’s attribution of the hacks. The verified event-day conclusion was that U.S. authorities had moved from tracing alleged North Korean cryptocurrency thefts to sanctioning and charging two named intermediaries accused of converting and transmitting the proceeds.

Later context

On March 5, 2020, blockchain-analysis company Chainalysis said its software had assisted the government’s investigation. That interested-party account provides later methodological context but does not replace the allegations and legal actions documented in the March 2 government records.

Primary sourceU.S. Treasury — Sanctions Individuals Laundering Cryptocurrency for Lazarus Group

The complete source packet and revision history are retained with the newsroom record.

Automated desk disclosure

Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.

Financial-risk note

This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.