Funds from $577M HashFlare crypto Ponzi scheme move for the first time in over three years
A cryptocurrency wallet tied to the $577 million HashFlare Ponzi scheme moved 10,600 ETH worth $18.5 million for the first time in 3.5 years, signaling potential asset liquidation by convicted fraudsters even as federal prosecutors appeal to overturn their 16-month sentences. The activity underscores persistent challenges in tracking and securing criminal proceeds across decentralized networks, a concern for institutional investors evaluating counterparty and regulatory risk in crypto markets.
- HashFlare wallet moved 10,600 ETH worth approximately $18.5 million after dormancy of over three years
- Sergei Potapenko and Ivan Turõgin received 16-month sentences in February 2025, far below prosecutors’ 10-year request
- Funds were routed through instant exchange platforms HiFiSwap and Near Intents, then converted to Bitcoin
- $577M Total amount defrauded from 440,000 investors across HashFlare scheme
- 1% Actual Bitcoin mining capacity versus claimed capacity by HashFlare operation
- 16 months Prison sentence imposed versus 10 years requested by prosecutors
Federal prosecutors are mounting an appeal to overturn what they characterize as a “lenient” sentence imposed on Sergei Potapenko and Ivan Turõgin, the Estonian nationals convicted of operating HashFlare, a $577 million cryptocurrency mining fraud that defrauded approximately 440,000 investors worldwide between 2015 and 2019.
The development gains urgency following on-chain detection that a wallet previously linked to the scheme transferred 10,600 ETH worth roughly $18.5 million through instant exchange platforms beginning a conversion to Bitcoin, marking the first significant movement of suspected criminal proceeds in more than three years.
The activity was flagged by on-chain investigator ZachXBT and corroborated by security firm Cyvers, raising questions about asset security in cases involving decentralized fund flows and the practical difficulties custodians and law enforcement face in preventing liquidation of frozen criminal assets.
HashFlare claimed 1% of promised mining capacity while running a classic Ponzi operation
HashFlare launched in 2015 as a cloud mining platform offering investors contracts purporting to grant them a share of profits from Bitcoin and other cryptocurrency mining operations.
Court filings disclosed that the operation possessed only approximately 1 percent of the computing power it claimed to operate, yet the founders maintained elaborate false performance dashboards showing fabricated mining activity and inflated returns to deceive investors.
When customers attempted to withdraw funds, the founders purchased Bitcoin on open exchanges to satisfy redemptions, a hallmark Ponzi structure in which new investor capital finances withdrawals by earlier participants rather than genuine business revenue.
Between 2015 and 2019, HashFlare collected over $577 million from roughly 440,000 individual investors distributed across multiple countries. Acting U.S. Attorney Teal Luthy Miller characterized the scheme as “a mirage of cryptocurrency mining,” underscoring the deliberately constructed illusion at its core.
Beyond HashFlare, Potapenko and Turõgin engineered a parallel fraud through a venture named Polybius, pitched to investors as a blockchain-based banking platform that would eventually generate dividend payments to shareholders, despite the fact that no functional bank was ever constructed and no dividends materialized.
The founders deployed defrauded capital for personal enrichment, acquiring real estate, luxury automobiles, high-value jewelry, and chartering private aircraft, effectively treating investor funds as personal wealth.
Lenient 16-month sentence triggers federal appeal despite prosecutors seeking decade in prison
In February 2025, both Potapenko and Turõgin entered guilty pleas to conspiracy to commit wire fraud before U.S. District Judge Robert S. Lasnik, who imposed sentences of 16 months in custody, a term both men had already satisfied through pretrial detention.
Federal prosecutors had requested 10-year prison terms for each defendant, a substantial gap reflecting their assessment of the fraud’s severity and victim impact. In addition to incarceration, Judge Lasnik ordered each defendant to pay a $25,000 fine, complete 360 hours of community service, and submit to three years of supervised release contingent on their transfer back to Estonia.
Judge Lasnik cited concerns about international treaty transfer logistics as a material factor in his sentencing determination, indicating uncertainty whether approved mechanisms existed to reliably enforce supervised release conditions following the defendants’ return to Estonian jurisdiction.
The judge specifically warned that absent an approved transfer arrangement, the defendants faced potential exposure to harsher imprisonment conditions within the U.S. federal system.
Prosecutors have filed an appeal arguing that the sentence fails to adequately reflect the scheme’s scope, the number of defrauded victims, and the sophisticated mechanisms deployed to conceal fraud, positioning the case as potentially significant to sentencing precedent in large-scale cryptocurrency fraud prosecutions.
The wide divergence between the imposed sentence and prosecutorial recommendation signals judicial concern about enforceability of international sentencing arrangements, a novel consideration in cryptocurrency crime cases.
Wallet activity resumes after 3.5 years of dormancy, routing funds through instant exchange platforms
On-chain monitoring first detected movement from a cryptocurrency wallet identified as 0xff575a22975cc413771825eb84c163189a4d5d22, confirmed through transaction hash 0xd0eafd5c03b24c2f54c579745cacbffe4c6df2d19973e55d52a5f40aa1d89e0, after the address remained inactive for approximately 3.5 years.
The transfer moved 10,600 ETH, valued at approximately $18.5 million at the time of detection, to two recipient addresses before being routed through decentralized finance protocols including HiFiSwap and Near Intents, both services that facilitate rapid token swaps without traditional custodial intermediaries.
Security researchers observed that the funds began systematic conversion from Ethereum to Bitcoin immediately upon receipt at the secondary addresses, a pattern consistent with asset laundering techniques designed to obfuscate the origin and destination of criminal proceeds.
The identification and public disclosure of this activity by ZachXBT, supported by analysis from security firm Cyvers, represents a growing institutional capacity to detect illicit fund flows in real time using public blockchain data, a capability that did not exist at comparable scale during earlier cryptocurrency fraud cases.
However, the speed and efficiency with which the funds moved through decentralized exchange platforms highlights the practical limitations law enforcement faces in freezing or recovering assets once they enter protocols designed for permissionless, pseudonymous transactions.
The resumption of fund movement during active appeals proceedings raises a question about whether the defendants or associates retained access to private keys controlling the wallet, or whether third parties gained access to the address, and whether the timing relates to the sentencing controversy.
Institutional investors monitoring counterparty and custody risk must account for scenarios in which even judicially frozen or seized crypto assets can become mobile if private key access is not provably eliminated or if the controlling jurisdiction lacks technical capacity to enforce asset locks on decentralized systems.
Federal prosecutors must now clarify in their appeal filings whether the wallet activity constitutes evidence of ongoing asset concealment, whether the movement violates conditions of pretrial release or supervised release, and whether the Estonian or U.S. authorities maintain technical or legal mechanisms to halt future transfers, outstanding questions that will shape both the appellate decision and regulatory expectations for custody and recovery procedures in future high-value cryptocurrency fraud cases.