The U.S. Secret Service has seized the domain name of Russian crypto exchange Garantex, in collaboration with the Department of Justice’s Criminal Division, the FBI, and Europol, citing the platform’s use by ransomware gangs and hackers.

Other law enforcement authorities also participated in this operation: the Dutch National Police, the German Federal Criminal Police Office, the Frankfurt General Prosecutor's Office, the Estonian National Police and the Finnish National Bureau of Investigation.
It is worth noting that the US had previously imposed sanctions on the service in question.
See also: What is crypto wallet draining and how to avoid it
Garantex was also forced to suspend its services due to the blocking of Tether in its digital wallets after the European Union imposed sanctions, as part of the 16th package of sanctions against Russia, which targets 542 individuals and entities.
“ We have bad news. Tether has entered the war against the Russian crypto market and they have blocked our wallets with an amount of more than 2.5 billion rubles ,” the Garantex team reported on Telegram yesterday
“We are temporarily suspending all services while the entire team resolves this issue. We are fighting and not giving up! Please be aware that USDT in Russian wallets is now at risk“.
After seizing Garantex's garantex[.]org domain, the US Secret Service also changed the name servers to ns1.usssdomainseizure.com and ns2.usssdomainseizure.com.
See also: Fake CS2 streams steal crypto and Steam accounts
In April 2022, the Treasury Department's Office of Foreign Assets Control (OFAC) had imposed sanctions on the Russian crypto exchange service Garantex after over $100 million in transactions were linked to dark web markets and cybercriminals.
“The majority of Garantex’s operations are conducted in Moscow and the Federation Tower and St. Petersburg, Russia, where other sanctioned virtual currency exchanges also operated,” OFAC said at the time.
Garantex lost its license to provide virtual currency services in February 2022 after the Estonian Financial Intelligence Unit found links between Garantex and wallets used for criminal activities. The service also failed to comply with anti-money laundering and countering the financing of terrorism (AML/CFT) policies.
However, according to OFAC, Garantex continues to provide services to customers through illegal means.
See also: StaryDobry: New malware campaign infects gamers with cryptominer

Garantex domain seizure
Why this matters:
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
🔹 Ransomware Operations Shutdown – Many ransomware gangs require crypto payments to remain anonymous. Closing their financial channels makes it more difficult for them to operate.
🔹 Warning for other crypto exchanges – Services that enable money laundering, terrorist financing, or ransomware payments may face similar actions.
🔹 Part of a larger crackdown – The US is aggressively targeting crime in the crypto industry, including seizing funds from North Korean hackers and pressuring platforms to enforce anti-money laundering rules.
Source: www.bleepingcomputer.com
