
Laundering-as-a-Service (LaaS) signifies an increasing level of sophistication in financial crime operations. Similar to how organizations use Software-as-a-Service (SaaS) to address their IT requirements, criminal entities have begun to outsource the intricate, high-risk process of money laundering to specialized external providers.
Below is a deep dive into how this ecosystem operates and into the landmark cases in which law enforcement successfully dismantled these operations.
In the past, a criminal group had to run its own money laundering schemes. Today, they simply pay a fee (usually a percentage of the volume) to a LaaS provider. These providers offer a "menu" of services designed to break the digital or physical paper trail.
Following, we have descriptive elements of Laas:
Placement & Layering: LaaS providers employ automated mixers or tumblers to divide substantial amounts of cryptocurrency into numerous small transactions, integrating these with legitimate funds from other users.
Money Mule Recruitment: Professional LaaS groups manage vast networks of "money mules"—individuals (often recruited via fake "work-from-home" ads) who use their personal bank accounts to receive and transfer illicit funds.
Shell and Shelf Company Factories: Some providers specialize in generating "ready-made" shell companies with established bank accounts and fake tax histories to provide a veneer of legitimacy for corporate transfers. Also, LaaS providers use aged shell accounts that are ready to be purchased to give their customers the façade of longevity (i.e. ‘shelf-companies’).
Digital Obfuscation: Criminals employ sophisticated strategies such as Chain Hopping, which involves quickly exchanging cryptocurrencies across multiple blockchains, and also rely on Privacy Coins like Monero to avoid detection through blockchain analysis.
Law enforcement agencies have shifted from pursuing individual offenders to dismantling the LaaS infrastructure on which they depend. If we study historical cases, the following can be considered worth learning from.
ChipMixer ranked among the most active cryptocurrency tumblers globally. Users could deposit Bitcoin, which the platform would break down into smaller, uniform units and blend with funds from other participants.
This case presents a comprehensive account of how a single "Laundering-as-a-Service" (LaaS) provider became a financial hub for numerous high-profile cybercriminals. It details the actions of an accomplished engineer who developed a proprietary system that facilitated over $3 billion in transactions until authorities successfully dismantled it in 2023.
The narrative begins with Minh Quốc Nguyễn, who did not conform to the traditional image of a gangster. Holding a PhD in electronic engineering and possessing specialized knowledge in cryptographic research and cyber reconnaissance, he operated within the realm of digital anonymity rather than fortified physical spaces. In 2017, he founded ChipMixer and adopted a philosophy that challenged conventional regulations; he openly criticized Anti-Money Laundering (AML) laws on Bitcoin forums, describing them as mechanisms for governmental surveillance. He positioned ChipMixer as a tool for preserving privacy rights, rather than facilitating illicit activity.
Nguyen's "service" operated with greater complexity than a traditional mixer. He developed a system named "Chipping," which allowed for the division of Bitcoin into smaller, standardized units such as 0.001 BTC or 0.01 BTC. These units were then combined with numerous others from thousands of users, effectively obscuring transactional trails from external observers and blockchain analytics. As a result, potentially tainted funds would be exchanged for a receipt—a private key to a pre-funded wallet—that appeared clean. This approach represented a highly advanced LaaS solution, offering immediate anonymity and rendering transactions virtually untraceable.
By 2020, ChipMixer had turned into the backbone of the global criminal network. High-profile offenders relied on ChipMixer. The investigation eventually exposed just how massive its user base was:
Ransomware Organizations: Groups such as LockBit, REvil, and SunCrypt processed victim payments via ChipMixer.
Government-Sponsored Cyber Operations: Russian military intelligence (GRU) utilized the platform to acquire infrastructure for its "Drovorub" malware.
Major Financial Crimes: North Korean cyber actors laundered hundreds of millions in stolen funds from cryptocurrency exchanges.
Illicit Online Markets: More than $200 million from drug and weapon transactions was transferred through ChipMixer's servers.
Instead of arresting individual users, law enforcement agencies—including the FBI, Germany's BKA, and Europol—realized they needed to shut down the service entirely. Investigators made progress by employing advanced forensic techniques to overcome Nguyen’s multiple layers of identity theft. Nguyen had used the stolen identities of elderly Americans (people in their 60s and 70s) to pay for his servers and domain names. By tracing the small technical errors in how he managed his infrastructure, the FBI linked the PhD-holding engineer to the "administrator" account of the world's largest laundry.
The Case: In March 2023, the FBI, Europol, and German police (BKA) partnered to take down the service.
Impact: Since 2017, it had laundered more than $3 billion. Investigators found it was the main laundering hub for ransomware groups such as LockBit and REvil, as well as North Korean state-sponsored hackers.
Outcome: Authorities confiscated $46 million in cryptocurrency and seized the backend servers. Minh Quốc Nguyễn, the operator, faced charges of money laundering and identity theft.
Helix operated as a specialized laundering platform, seamlessly connected to the Grams search engine—often referred to as the "Google of the Darknet." Its purpose was to assist customers of darknet markets in cleaning their Bitcoin. The case involving Helix and Grams is notable, marking the first instance in which the U.S. government prosecuted a "crypto mixer" as an organized, unlicensed money-transmission service. This is the story of Larry Dean Harmon from Ohio, who created the darknet's own search powerhouse and established a concealed money laundering operation alongside it.
Prior to the establishment of an online laundry service, a mapping tool existed. In 2014, Larry Harmon introduced Grams, which addressed the disorder of the darknet's numerous marketplaces such as AlphaBay and Hansa. Grams operated similarly to Google, enabling users to search for specific products—for example, "high-grade heroin" or "stolen credit cards"—and to find which marketplace offered the best pricing and vendor ratings.
Harmon was more than just a search engine operator—he played a key role in building an ecosystem. He understood that Grams users worried about leaving a "paper trail" with their Bitcoin transactions. To address these concerns, Harmon created Helix, which became the ultimate "Laundering-as-a-Service" (LaaS) solution thanks to its smooth integration. Instead of merely running a website, Harmon pioneered an Application Programming Interface (API) that enabled darknet markets to integrate Helix directly into their checkout processes. When dealers on AlphaBay wanted to withdraw their profits, they simply pressed a button; the system automatically routed their funds through Helix's "tumbler" before depositing them into their wallets. By 2017, Helix had handled over 354,000 Bitcoin—worth about $311 million at the time—with Harmon acting as the discreet accountant for the world's largest digital drug marketplaces.
Harmon thought he was beyond reach, convinced that the "mixing" process would break the trail of ownership. Yet he made a key operational security mistake by linking his online activity to his real-world identity. Do you remember that Dread Pirate Roberts (Ross Ulbricht) was caught in 2013 largely due to an early operational security failure in which he used his personal email? Similar situation here. The IRS Criminal Investigation (IRS-CI) and the FBI launched an extended "follow the money" campaign, using advanced blockchain analysis to spot "peel chains," which are patterns where small amounts of Bitcoin are separated from larger transactions to cover services in the physical world. Ultimately, they traced the Bitcoin used for Helix’s server payments back to Harmon’s own accounts and those of his brother, Gary Harmon.
In February 2020, Larry Harmon was arrested in Ohio. Federal authorities charged him not only with operating a website, but also with conspiracy to commit money laundering and running an unlicensed money transmitting business. The case had significant legal implications. Harmon stated that he was a software developer offering a privacy tool, while the Department of Justice argued that by charging fees and actively marketing to individuals involved in criminal activity, he had shifted from being a coder to engaging in money laundering.
The Case: The Department of Justice accused Larry Harmon of laundering more than $300 million.
Significance: This landmark case established that running a mixer service without adequate anti-money laundering (AML) measures clearly violates the Bank Secrecy Act, regardless of whether the operator claims to be offering a privacy tool.
Outcome: In 2021, Harmon admitted guilt and agreed to give up assets valued at over $200 million.
The Bitcoin Fog case exemplifies law enforcement's patience and persistence, revealing how years of digital evidence finally led to the downfall of the darknet’s longest-running money-laundering service and its founder.
Back in 2011, cryptocurrencies were in their early days—a "Wild West" era. Bitcoin had been around for just two years and was mostly considered a novelty among tech enthusiasts. However, Roman Sterlingov, a Russian-Swedish citizen, recognized its potential for business. He founded Bitcoin Fog, presenting it as the most reliable, secure, and professional solution for anonymizing transactions.
Sterlingov managed operations discreetly over a decade. He provided more than just a mixer; he established a financial service catering to individuals seeking anonymity. Unlike other platforms that ceased functioning after brief periods due to exit scams, Bitcoin Fog maintained consistent reliability and became a trusted resource within the darknet market.
Ten Years of "Fogging" showed that Bitcoin Fog operated as a traditional custodial mixer, providing laundering-as-a-service (LaaS). Users deposited Bitcoin into an address managed by Fog. After holding the funds and delaying payment, the service would return different coins drawn from its extensive reserves of both "clean" and "dirty" Bitcoin. Throughout its decade of operation, Bitcoin Fog facilitated the processing of more than 1.2 million Bitcoin, with an estimated transactional value of $400 million at the time; this sum would equate to several billion dollars in current market terms. Its client list included some of the most infamous names in darknet history, such as Silk Road, AlphaBay, and Hansa. It wasn't just drugs; the Fog cleaned money for hackers, identity thieves, transnational criminal organization and distributors of child sexual abuse material (CSAM)
The Case: In late 2024, Roman Sterlingov received a prison sentence exceeding 12 years.
Investigation Detail: IRS-Criminal Investigation and the FBI utilized blockchain analytics to link Sterlingov's accounts to his operation, overcoming challenges posed by coin mixing.
Outcome: The jury convicted him of laundering approximately $400 million, connected to narcotics offenses and child exploitation.
The Tornado Cash case stands out as the most contentious and legally important episode in the evolution of "Laundering-as-a-Service" (LaaS). It highlights the intersection between Decentralized Finance (DeFi) and national security, raising a provocative question: Is an automated software protocol merely a tool, or does it serve as a criminal accomplice? Unlike earlier examples, Tornado Cash operated as a decentralized protocol—smart contracts on the Ethereum blockchain—which created a novel dilemma: Can code be arrested?
Back in 2019, Tornado Cash was launched by developers Roman Storm, Roman Semenov, and Alexey Pertsev. Unlike earlier mixers such as Bitcoin Fog or Helix—which relied on websites operated by individuals—Tornado Cash functioned as a collection of Smart Contracts on the Ethereum blockchain. From a LaaS viewpoint, it represented "version 3.0." This mixer was non-custodial, so its creators never directly managed users' funds. Instead, the platform’s code operated like a "black box," allowing people to deposit Ethereum and then use advanced Zero-Knowledge Proofs to withdraw it to an unrelated address, effectively breaking any transaction trail.
In 2022, the perception of Tornado Cash changed dramatically—from being seen as a "privacy tool" to being labeled a "national security threat." Investigations by the U.S. Treasury Department revealed that the Lazarus Group, a North Korean government-supported hacking organization, relied heavily on Tornado Cash to launder funds. North Korea managed to clean more than $450 million in stolen cryptocurrency via this protocol, using it to support their weapons programs. For the U.S. government, Tornado Cash was no longer regarded merely as software; it became recognized as an essential asset for a hostile nation.
The Office of Foreign Assets Control (OFAC) imposed sanctions on the Tornado Cash smart contracts, marking a notable departure from conventional practice, where sanctions are typically directed at individuals or organizations. In this instance, the U.S. government extended its restrictions to software code itself. As a result, any American who engaged with the Tornado Cash addresses—even for legitimate privacy purposes—became subject to violations of federal law. Subsequently, Alexey Pertsev was detained by Dutch authorities in Amsterdam.
In August 2023, the U.S. Department of Justice unsealed indictments against Roman Storm and Roman Semenov. The government asserted that the developers were not merely passive coders but actively participated as profit-seeking founders, benefiting from the service through governance tokens. It was further contended that they were aware that North Korean actors used the tool and nevertheless chose not to implement substantive "Know Your Customer" (KYC) or anti-money laundering measures. Lastly, authorities argued that the defendants maintained sufficient oversight of the "Relayer" network and website front-end to be classified as operating a "money-transmitting business."
The Case: The U.S. Department of the Treasury's Office of Foreign Assets Control (OFAC) imposed sanctions on the protocol, and the Department of Justice (DOJ) filed indictments against founders Roman Storm and Roman Semenov.
The Charge: Authorities alleged that the founders were aware their service was being utilized by the Lazarus Group (North Korea) to launder over $450 million in stolen assets, yet they continued enhancing the platform’s anonymity features without implementing any "know-your-customer" (KYC) measures.
Significance: This case established a new precedent for LaaS enforcement by holding developers of automated laundering tools accountable, rather than solely focusing on operators of centralized platforms.
The story of Laundering-as-a-Service (LaaS) shows two worlds advancing at different paces. Criminals use code, artificial intelligence, and decentralized systems to hide their actions. Meanwhile, law enforcement takes a careful approach, using the blockchain’s lasting record to uncover those who believed they could stay hidden.
The evolution of LaaS from a "shady guy in a basement" to a "smart contract in the cloud" has stripped financial crime of its human face, but it has not made it invincible. As we head further into 2026, the battle has shifted into the realm of Predictive Analytics and AI.
Law enforcement, national security, and compliance investigators are increasingly analyzing patterns rather than simply tracking financial transactions. For LaaS providers, maintaining differentiation is a persistent challenge; for investigators, identifying human errors among vast amounts of automated data is the primary objective. As digital operations become more streamlined, the consequences of apprehension, including substantial forfeitures and extended prison sentences, have risen considerably. While the story of LaaS continues to evolve, the period characterized by straightforward anonymity has concluded.
Reviewed sources:
Browder, Alexander. Confronting the Illicit-Finance Hydra in Crypto Markets: Protecting Retail Investors and Disrupting Hostile Government Exploitation. Henry Jackson Society. 2026.
DOJ Archives. Operator of Helix Darknet Cryptocurrency “Mixer” Sentenced in Money Laundering Conspiracy and Ordered to Forfeit Over $400M in Assets. Friday, November 15, 2024 https://www.justice.gov/archives/opa/pr/operator-helix-darknet-cryptocurrency-mixer-sentenced-money-laundering-conspiracy-and
DOJ Archives. Ohio Resident Pleads Guilty to Operating Darknet-Based Bitcoin ‘Mixer’ That Laundered Over $300 Million. Wednesday, August 18, 2021 https://www.justice.gov/archives/opa/pr/ohio-resident-pleads-guilty-operating-darknet-based-bitcoin-mixer-laundered-over-300-million
DOJ Press Reales. Justice Department Investigation Leads to Takedown of Darknet Cryptocurrency Mixer that Processed Over $3 Billion of Unlawful Transactions. Wednesday, March 15, 2023.
DOT. Press Release. U.S. Treasury Sanctions Notorious Virtual Currency Mixer Tornado Cash. August 8, 2022. https://home.treasury.gov/news/press-releases/jy0916
EUROPOL News. Europol and partners shut down ‘Cryptomixer’. https://www.europol.europa.eu/media-press/newsroom/news/europol-and-partners-shut-down-cryptomixer
FATF. Professional Money Laundering. FATF Report. 2028.
Global Investigations Review. The Guide to Anti-Money Laundering - Second Edition Money laundering through digital assets. GRI. 2025.