Samourai Wallet crypto mixer’s co-founders sentenced to prison

The two co-founders of cryptocurrency mixing service Samourai Wallet will each spend about a half-decade in prison after pleading guilty to knowingly handling more than $237 million in illegal transactions through the platform.

U.S. prosecutors on Thursday announced the sentencings in New York of Keonne Rodriguez and William Lonergan Hill. The pair had pleaded guilty in late July to participating in a conspiracy “to operate a money transmitting business in which they knowingly transmitted criminal proceeds.”

Samourai Wallet handled funds from “drug trafficking, darknet marketplaces, cyber-intrusions, frauds, sanctioned jurisdictions, murder-for-hire schemes, and a child pornography website,” prosecutors said Thursday.

Rodriguez, 37, and Hill, 67, were sentenced to four years and five years in prison, respectively. They forfeited more than $6.3 million to authorities, representing the fees Samourai Wallet earned for the illegal transactions, prosecutors said. Both also were sentenced to three years of supervised release and ordered to pay fines of $250,000.

Their arrests were announced in April 2024, with the Department of Justice (DOJ) reporting that Samourai’s domain and servers were seized with the help of authorities in Iceland. Rodriguez was arrested in the U.S., and Hill was detained in Portugal and later extradited.

Founded in 2015, Samourai Wallet was oriented around two features: “Whirlpool,” which mixed bitcoin among Samourai users, and “Ricochet,” which enabled users to “introduce additional and unnecessary intermediate transactions — known as ‘hops’ — between sending and receiving addresses,” prosecutors said.

Rodriguez and Hill “actively promoted Samourai to criminal users and encouraged criminal activity,” prosecutors said, citing activity on dark web markets, messaging services and public social media.

The $237 million directly tied to illicit activity by prosecutors represents just a fraction of Samourai’s overall cryptocurrency transactions.

“[F]rom Ricochet’s launch in 2017 and Whirlpool’s inception in 2019, more than 80,000 Bitcoin—valued at over $2 billion at the time—passed through these services,” the DOJ said.

Recent actions against cryptocurrency mixers include the seizure of the eXch platform in May by German police, the arrests in December 2024 of Russian nationals accused of running the Blender and Sinbad services, and the sentencing of an Ohio man in November 2024 for running the Helix mixer.

Operators of the cryptocurrency mixer Tornado Cash continue to face pressure from international law enforcement. Co-founder Roman Storm was convicted in August of conspiring to operate an unlicensed money-transmitting business.

Get more insights with the

Recorded Future

Intelligence Cloud.

Learn more.

No previous article

No new articles

Joe Warminsky

Joe Warminsky

is the news editor for Recorded Future News. He has three decades of experience as an editor and writer in the Washington, D.C., area. He previously he helped lead CyberScoop for more than five years. Prior to that, he was a digital editor at WAMU 88.5, the NPR affiliate in Washington, and he spent more than a decade editing coverage of Congress for CQ Roll Call.

 

Total
0
Shares
Previous Post

Russia blacklists S.T.A.L.K.E.R. game developer, accusing it of aiding Ukraine’s war effort

Next Post

Tsundere Botnet Expands Using Game Lures and Ethereum-Based C2 on Windows

Related Posts

Your Digital Footprint Can Lead Right to Your Front Door

You lock your doors at night. You avoid sketchy phone calls. You’re careful about what you post on social media. But what about the information about you that’s already out there—without your permission? Your name. Home address. Phone number. Past jobs. Family members. Old usernames. It’s all still online, and it’s a lot easier to find than you think. The hidden safety threat lurking online Most
Read More

China-Linked APT31 Launches Stealthy Cyberattacks on Russian IT Using Cloud Services

The China-linked advanced persistent threat (APT) group known as APT31 has been attributed to cyber attacks targeting the Russian information technology (IT) sector between 2024 and 2025 while staying undetected for extended periods of time. "In the period from 2024 to 2025, the Russian IT sector, especially companies working as contractors and integrators of solutions for government agencies,
Read More

Two High-Severity n8n Flaws Allow Authenticated Remote Code Execution

Cybersecurity researchers have disclosed two new security flaws in the n8n workflow automation platform, including a crucial vulnerability that could result in remote code execution. The weaknesses, discovered by the JFrog Security Research team, are listed below - CVE-2026-1470 (CVSS score: 9.9) - An eval injection vulnerability that could allow an authenticated user to bypass the Expression
Read More