Treasury Sanctions Russian Cyber Operation That Used Crypto to Purchase Stolen U.S. Government Tools

February 25, 2026 256 views

The U.S. Department of the Treasury has sanctioned a Russian exploit brokerage network that allegedly used cryptocurrency to purchase stolen U.S. government cyber tools, marking the first enforcement action under the Protecting American Intellectual Property Act. The designation signals increased regulatory scrutiny of crypto's role in cybersecurity threats and could impact compliance requirements for blockchain professionals.

Details of the Enforcement Action

The Treasury's Office of Foreign Assets Control designated Russian national Sergey Sergeyevich Zelenyuk and his company, Operation Zero, along with multiple associates and affiliated firms. The sanctions block any U.S.-based property or interests belonging to the designated parties and prohibit U.S. persons from conducting transactions with them.

According to Treasury, Zelenyuk operated from St. Petersburg, building a business that acquired and resold software exploits—tools that leverage vulnerabilities to gain unauthorized system access. Operation Zero obtained at least eight proprietary cyber tools developed by a U.S. defense contractor for exclusive government use. These tools were stolen by Peter Williams, a former contractor employee who pleaded guilty in October 2025 to theft of trade secrets after selling the materials to Operation Zero for millions of dollars in cryptocurrency.

Treasury Secretary Scott Bessent emphasized the government's commitment to protecting American intellectual property, stating the action reflects broader efforts to safeguard national security. The sanctions were issued under Executive Order 13694, which targets malicious cyber-enabled activities threatening U.S. interests.

Broader Network and Crypto Connections

The designation extends to several associates, including Marina Evgenyevna Vasanovich, Zelenyuk's assistant, and Special Technology Services LLC FZ, a UAE-based firm controlled by Zelenyuk. Two additional individuals face sanctions for material support, including Oleg Vyacheslavovich Kucherov, identified as a suspected member of the Trickbot cybercrime group linked to ransomware attacks on U.S. agencies and healthcare providers.

Operation Zero advertised bounties worth millions of dollars in cryptocurrency for exploits targeting U.S.-built operating systems and encrypted messaging platforms. Rather than disclosing vulnerabilities to affected software companies, the firm sold them to customers in non-NATO countries, including foreign intelligence services.

Implications for Web3 Professionals

While Treasury confirmed cryptocurrency facilitated these transactions, the agency did not publish specific wallet addresses or impose blockchain-specific designations. Web3 professionals working in compliance, security, and protocol development should monitor how regulators increasingly scrutinize crypto's role in national security matters, as enforcement patterns may shape future compliance frameworks and due diligence requirements across the industry.