Lese-Ansicht

Mexican cartel's crypto farm seized in mountain raid — 300 GPUs, satellite links, and industrial transformers tapped hydroelectric power

There is increasing evidence that Mexican drug cartels are diversifying into cryptocurrency mining and are using crypto platforms to diversify their income and, at the same time, launder their ill-gotten gains and fund other illegal activities. Reuters reports that local Mexican police uncovered a clandestine cryptocurrency farm in Tlaola, a town located in the leafy mountains of Puebla's Sierra Norte region. They found 300 GPUs, electricity infrastructure, and satellite equipment. The electricity-hungry operation likely drew power by secretly tapping into the grid at Presa de Necaxa, a nearby hydroelectric dam.

While this latest hidden facility found by police may seem small, Reuters notes it is the fourth such crypto farm Mexican authorities have uncovered in this region since early last year. According to a Mexico-based security analyst, the crypto farms discovered show that the cartels are increasingly sophisticated in their operations. In the latest bust, the Mexican federal authorities, the Navy, and state police seized around 300 GPUs, 80 medium-voltage terminations, a transformer, and eight satellite antennas.

It might not be surprising to hear about the Mexican cartels being tied up in crypto. Blockchain analytics firm Chainalysis, as cited by Reuters, reckons illicit crypto transactions grew from $59 billion in 2024 to $154 billion last year. The firm links the surge recorded to sanctions evasion involving governments. However, in South America, cartels are increasingly interested in using this channel to launder money. The mining operations are also integrated into the scheme, as stealing electricity is easy for organized crime. Mainstream consumer GPU mining ended in H2 2022, flooding the market with used graphics cards.

The source report doesn’t say how authorities found the crypto farm. Perhaps locals in this remote area of Puebla alerted authorities to the operation. Two folks from neighboring communities told Reuters that they could hear the crypto farm noise (transformers, cooling) from a kilometer away (0.6 miles), and the place was apparently a mere 2 km (1.2 miles) from the nearest village. The other three recently uncovered crypto farms were also near the same HEP dam, it is noted. Tlaola is a small community with around 20,000 inhabitants, so the noise levels and power consumption of crypto farms are very perceptible even if the cartels try to hide them deep in the mountains.

Remote communities, such as Tlaola, are popular locations for clandestine crypto farms because the electricity is cheap and most of them are under the protection of the cartels. For example, the Cartel Jalisco Nueva Generación (CJNG) and its armed branch, La Barredora, have the strongest presence in Puebla.

According to SILIKN, a Mexican cybersecurity firm, the use of cryptomining to launder illegal money rose by at least 55.8% last year in México. Drug cartels such as the Cartel de Sinaloa and the CJNG have set up crypto farms to mine Bitcoin (BTC), Monero (XMR), and Tether (USDT).

Similarly remote, illicit cryptomining facilities exist around the world, with Reuters recalling news of raids in Brazil, the U.S., and Thailand. Do you think there’s one near you? Please call the local police and liberate those stressed GPUs. Meanwhile, analysts expect crypto-related crime will reach new heights in the coming years.

  •  

Minecraft-spawned crypto kingpin faces 20 years for $245 million heist — mastermind's role in hacking campaign fueled their supercar, bodyguards, and private jet habit

The ringleader of a cybercrime gang, which reportedly formed after meetups in Minecraft online, has pleaded guilty to a racketeering charge. Sentencing is yet to be finalized, but 22-year-old Singaporean and Miami resident Malone Lam could face 20 years behind bars. Lam is accused of helping to steal and launder hundreds of millions of dollars in cryptocurrency. Here are the full United States District Court for the District of Columbia documents (PDF), via The Register.

According to the court documents, Lam visited the U.S. to meet fellow Minecrafters Jeandiel Serrano and Veer Chetal, for the first time in real life, in 2023. Soon, Lam’s role in the cybercriminal gang seems to have become an important one. The Singaporean reportedly found high-net-worth crypto holders to target, supported social engineering operations, leveraged technology to trigger account access alerts on target devices, and was involved in laundering the pilfered digital booty.

Lam’s crypto fraud gang reportedly totaled 12 members, and this criminal fraternity operated for about two years. Documents indicate that the individual crypto thefts ranged from $800,000 to tens of millions of dollars. One crypto heist purportedly netted $245 million from a single victim.

Cybergang members enjoyed lavish lifestyles due to their swindling successes. The court documents mention members of the gang owning “a fleet of 31 exotic cars, ranging in value from $100,000 up to $3,800,000.” They would also run up nightclub service bills of up to $500,000 a night, buy luxury watches, clothing, and more. As well as rent prestigious homes in locations like Los Angeles, the Hamptons, and Miami – traveling around in private jets and protected by a team of security guards.

Court document screenshot of car fleet

(Image credit: Future)

Lam was arrested in September 2024, though, so they didn’t really get to enjoy that lavish luxury lifestyle for very long. Since that time, their suspected criminal activities have been under deeper investigation. The last members of the ‘Minecraft crew’ threw in the towel around May 2025. Lam has now pleaded guilty to RICO violations, and a status hearing is scheduled for December 8 this year; the Singaporean faces up to 20 years in jail. The Register notes that another member of Lam’s fold, Marlon Ferro, was handed a 6.5-year sentence back in May. Ferro’s role was effectively a ‘physical plan B,’ and they reportedly took part in multiple physical burglaries at the behest of the gang if/when social engineering attacks weren’t enough.

  •  

Hackers drain $320 million in Bitcoin from Liquid Network, emptying roughly 95% of federation wallet — attackers claim they’re the ‘good guys’ and will return funds after the vulnerability is fixed

Hackers reportedly claiming to be good actors have drained about $320 million worth of Bitcoin from Liquid Network's federation wallet, according to a CoinDesk report. In an X post on September 6, Liquid — a Bitcoin sidechain developed by blockchain infrastructure company Blockstream — confirmed that 4,000 BTC, roughly 95% of the entire wallet's balance, had been withdrawn.

Interestingly, the post referred to those behind the exploit as “purported white-hat hackers,” echoing the hackers’ own claim, after they self-identified as “whitehats” in a message embedded in a Bitcoin transaction. They also reportedly requested an audience with Liquid via the on-chain message, promising to return the money once the vulnerability that enabled the exploit is fixed.

“Please fix the bug first,” the on-chain message said. "The chain is under risk at latest commit right now. Make sure every node is patched. Then we will transfer the money back safely after confirming the fix.” Liquid responded on-chain with its security team's contact and has reportedly moved communications to an encrypted channel. Meanwhile, the platform said it has suspended transactions and warns of service disruptions as federation members work to restore service.

Launched in 2018, Liquid is a federated sidechain designed to move Bitcoin faster and more privately than the main chain. Users lock BTC on Bitcoin and receive an equivalent token, L-BTC, on Liquid, which settles blocks roughly every minute and finalizes in about two minutes. Rather than relying on miners, the network is secured by a federation of more than 80 exchanges, brokers, and other financial firms. The block signing and the multisig wallet holding the pegged-in Bitcoin are handled by 15 rotating functionaries that require 11 signatures to move funds.

The mechanics behind the exploit are also unusual, as nothing appears to have been stolen in the conventional sense. For example, in January, the Solana-based platform Step Finance lost roughly $40 million after attackers compromised devices belonging to its executive team, gaining access to the keys that guarded its treasury wallets. According to Liquid, the coins left through the Peg-out Authorization Key (PAK), belonging to SideSwap, a decentralized exchange built on the sidechain.

However, Liquid said that the key had not been compromised, nor had any others. SideSwap gave a matching account, stating a customer sent 4,000 L-BTC to its peg-out service at 14:05 UTC, the service processed the order as it would any other, and the Liquid Federation paid out 3,996 BTC to the customer's Bitcoin address twenty-three minutes later. According to SideSwap, its systems had no way of distinguishing those coins from any other L-BTC.

The incident lands in what has already been a punishing stretch for crypto infrastructure. Recently, the trading platform Drift suspended deposits and withdrawals after a suspected $270 million hack in April. In 2025, roughly $17 billion worth of Bitcoin was stolen, driven largely by impersonation schemes and AI-assisted scams.

  •