Bitcoin Battle

Burning Bitcoin for Geopolitical Fun and Profit

Conference Paper (2025)
Author(s)

Kris Oosthoek (TU Delft - Electrical Engineering, Mathematics and Computer Science)

Kelvin Lubbertsen (TU Delft - Technology, Policy and Management)

Georgios Smaragdakis (TU Delft - Electrical Engineering, Mathematics and Computer Science)

Research Group
Cyber Security
DOI related publication
https://doi.org/10.1109/ICBC64466.2025.11114529 Final published version
More Info
expand_more
Publication Year
2025
Language
English
Research Group
Cyber Security
Bibliographical Note
Green Open Access added to TU Delft Institutional Repository as part of the Taverne amendment. More information about this copyright law amendment can be found at https://www.openaccess.nl. Otherwise as indicated in the copyright section: the publisher is the copyright holder of this work and the author uses the Dutch legislation to make this work public.
Publisher
IEEE
ISBN (electronic)
9798331541354
Event
7th IEEE International Conference on Blockchain and Cryptocurrency, ICBC 2025 (2025-06-02 - 2025-06-06), Pisa, Italy
Downloads counter
59
Reuse Rights

Other than for strictly personal use, it is not permitted to download, forward or distribute the text or part of it, without the consent of the author(s) and/or copyright holder(s), unless the work is under an open content license such as Creative Commons.

Abstract

This study empirically analyzes the transaction activity of Bitcoin addresses linked to Russian intelligence services, which have liquidated over 7 Bitcoin (BTC), i.e., equivalent to approximately US$300,000 based on the exchange rate at the time. Our investigation begins with an observed anomaly in transaction outputs featuring the Bitcoin Script OP_RETURN operation code, tied to input addresses identified by cyber threat intelligence sources and court documents as belonging to Russian intelligence agencies. We explore how an unauthorized entity appears to have gained control of the associated private keys, with messages embedded in the OP_RETURN outputs confirming the seizure. Tracing the funds' origins, we connect them to cryptocurrency mixers and establish a link to the Russian ransomware group Conti, implicating intelligence service involvement. This analysis represents one of the first empirical studies of large-scale Bitcoin misuse by nation-state cyber actors.

Files

Bitcoin_Battle_Burning_Bitcoin... (pdf)
(pdf | 3.59 Mb)
- Embargo expired in 02-03-2026
License info not available