Cointime

Download App
iOS & Android

Fraud Shop Genesis Market Shut Down in International Law Enforcement Operation, Sanctioned by OFAC

Validated Project

On April 4, 2023, authorities shut down popular fraud shop Genesis Market and arrested hundreds of its users around the world in a coordinated international law enforcement effort dubbed Operation Cookie Monster. Additionally, OFAC sanctioned the criminal marketplace the next day on April 5.

Fraud shops like Genesis are an important part of the cybercriminal ecosystem. Typically operating on the dark web, they facilitate the sale of stolen data and personally identifiable information (PII), which in turn can be used for several different forms of cybercrime, including scamming, identity theft, and ransomware. Below, we’ll break down Genesis Market’s role in the cybercriminal ecosystem plus its on-chain activity, and show you how today’s law enforcement action makes the internet a safer place.

What was Genesis Market?

Genesis Market was a fraud shop catering to users around the world. Its marketplace allowed for the sale of several different forms of stolen PII such as credentials for email addresses, social media accounts, bank accounts, and cryptocurrency service accounts, all available to be perused in a searchable database. In many cases, Genesis could provide active session cookies for these accounts that allowed buyers to bypass multi-factor authentication. The screenshot below shows a typical listing on Genesis.

The listing is for a single, compromised victim device, and shows the services that device accessed and for which the seller has user credentials. Those services include three cryptocurrency exchanges (whose names we’ve blurred out) meaning a buyer of this user’s data could potentially steal any funds the victim holds in those accounts. Victims like the one shown above typically have had their machines compromised by information stealing malware, which can access credentials stored in web browsers like Chrome and Firefox. In addition to individual users’ PII, Genesis also offered compromised remote access credentials that could allow cybercriminals like ransomware gangs to break into organizations’ computer networks.

Genesis Market’s on-chain activity

Genesis Market has received tens of millions of dollars’ worth of cryptocurrency during its lifetime, primarily in Bitcoin. Most of its incoming funds since May came from mainstream exchanges, with crypto ATMs also contributing a significant amount.

We also see a few spikes in value received from services we’ve labeled risky, most of which are exchanges with low or no KYC. The Chainalysis Reactor graph below shows a number of actors sending funds to Genesis, including ransomware attackers, underground money laundering services, and other cybercriminals.

Note the relatively low amounts sent from each of these clusters. Credentials purchased on Genesis could cost as little as $1 or less, so while $15 sent from a credit card broker may not seem like a huge deal, it could represent serious financial losses for 15 individuals.

Shutting down Genesis makes all internet users safer

Data sellers like Genesis aren’t necessarily the first thing you think of when it comes to cybercrime, but these sorts of ancillary service providers are crucial to enabling scamming, hacking, and ransomware attacks. For that reason, we commend all of the agencies around the world who contributed to the shutdown of Genesis.

While Genesis’ OFAC designation doesn’t list any of the service’s cryptocurrency addresses, Chainalysis has identified hundreds of thousands of Genesis addresses, with more likely to come as our data improves over time. We’ve already labeled these addresses as belonging to a sanctioned entity in all of our products, and any Chainalysis KYT users with exposure prior to designation would have received alerts for its previous category — fraud shop — per their alert preferences. We will share any other relevant updates on this case as is possible.

This material is for informational purposes only, and is not intended to provide legal, tax, financial, or investment advice. Recipients should consult their own advisors before making these types of decisions. Chainalysis has no responsibility or liability for any decision made or any other acts or omissions in connection with Recipient’s use of this material.

Chainalysis does not guarantee or warrant the accuracy, completeness, timeliness, suitability or validity of the information in this report and will not be responsible for any claim attributable to errors, omissions, or other inaccuracies of any part of such material.

Read more: https://blog.chainalysis.com/reports/genesis-market-fraud-shop-shutdown-sanction/

Comments

All Comments

Recommended for you

  • ETH breaks through $2100

    market shows ETH breaking through $2100, currently at $2100.24, with a 24-hour increase of 7.65%. The market is highly volatile, please manage your risks accordingly.

  • BTC falls below $66,000

    the market shows BTC falling below 66,000 USD, currently at 65,996.42 USD, a 24-hour decline of 2.35%, with significant market fluctuations, please manage your risk properly.

  • YesGo Makes Its Public Debut: Joining Forces with Ecosystem and Industry Leaders to Usher in a New Era of On-Chain Native Commerce

    Hong Kong, February 11, 2026 – As one of the most visionary cross-sector dialogues held during Hong Kong Consensus Week, the YesGo Ecosystem Partner Meeting concluded successfully yesterday. This closed-door event, spearheaded by YesGo and co-hosted by Nexus Chain and compliant digital asset exchange CoinMy, brought together a select group of global ecosystem partners, industry KOLs, and media representatives.

  • The number of Americans filing for unemployment benefits last week was 227,000.

     initial jobless claims in the United States last week were 227,000, estimated at 224,000, previous value was 231,000.

  • BTC breaks through $68,000

     the market shows BTC breaking through $68,000, currently at $68,023.93, with a 24-hour decline of 1.36%. The market is highly volatile, please manage your risk accordingly.

  • [Consensus HK] ENI CEO Arion Ho: Decentralization is an Engineering Choice, Not a Slogan

    At the Consensus Hong Kong 2026 summit, ENI Founder and CEO Arion Ho joined the DeFi Lead at CoinDesk and executives from Paradigm and Blockdaemon to debate the future of DeFi decentralization. Ho delivered a sharp critique of the industry’s current trajectory, asserting that decentralization should never be about "slogan-style freedom," but is fundamentally a rigorous engineering choice.

  • Trump praised the non-farm payroll data and urged the Federal Reserve to cut interest rates to the "lowest in the world."

    US President Trump posted on social media, "Employment data is excellent, far exceeding expectations! The US should pay much less interest on borrowing costs (bonds!). We have once again become the world's number one power, and therefore deserve the lowest interest rates ever. This will bring at least one trillion dollars in interest savings annually — the budget will not only be balanced but will have a substantial surplus. Wow! The golden age of America has arrived!!!"

  • BTC falls below $67,000

    the market shows BTC falling below $67,000, currently at $66,991.58, with a 24-hour decline of 3.41%. The market is highly volatile, please manage your risk accordingly.

  • BTC falls below $69,000

     the market shows BTC fell below 69,000 USD, currently at 68,996.18 USD, with a 24-hour decline of 2.21%. The market is highly volatile, please manage your risk accordingly.

  • BTC falls below $70,000

     the market shows BTC falling below $70,000, currently at $69,990, with a 24-hour decline of 1.04%. The market is highly volatile, please manage your risk accordingly.