LIVE
Hong Kong VATP Licence: SFO, AMLO, Capital, and Application RequirementsMAS DPT Licence Singapore: PSA, DTSP, CMS and Application RequirementsFCA Crypto Authorisation in 2026: Who Must Apply Before the 2027 Regime?MiCA Stablecoin Rules in 2026: ARTs, EMTs, Reserves, and RedemptionJapan Crypto Regulation in 2026: FSA Exchange Rules and Market IntegrityXRP Falls 2.29% as Macro Risks Hit Sentiment, ETF Hopes Support PriceBest Regulated Crypto Exchanges in 2026Sality Botnet Dismantled After Crypto TheftCFTC seeks CME lawsuit dismissal over Kalshi Bitcoin perpetual futuresTether Sued Over Alleged Unlawful Freeze of $42.4M in USDTHong Kong VATP Licence: SFO, AMLO, Capital, and Application RequirementsMAS DPT Licence Singapore: PSA, DTSP, CMS and Application RequirementsFCA Crypto Authorisation in 2026: Who Must Apply Before the 2027 Regime?MiCA Stablecoin Rules in 2026: ARTs, EMTs, Reserves, and RedemptionJapan Crypto Regulation in 2026: FSA Exchange Rules and Market IntegrityXRP Falls 2.29% as Macro Risks Hit Sentiment, ETF Hopes Support PriceBest Regulated Crypto Exchanges in 2026Sality Botnet Dismantled After Crypto TheftCFTC seeks CME lawsuit dismissal over Kalshi Bitcoin perpetual futuresTether Sued Over Alleged Unlawful Freeze of $42.4M in USDT
Homepage/Crypto News/Sality Botnet Dismantled After Crypto Theft
CRYPTO NEWS

Sality Botnet Dismantled After Crypto Theft

·2 MIN READ·
MakeThe CC Presspreferred onGoogle

Sality, a botnet that authorities say spent eight years quietly stealing Bitcoin and Ethereum, has finally been taken down in an international cyber operation.

KEY FINDINGS - EVIDENCE LEVEL: MULTI-SOURCE
3Key sections mapped in this report
0Internal references connected to related coverage
3External source domains cited in the article
2 minEstimated time to read the full report

The Takedown That Finally Hit Sality

The Sality malware was disrupted in a coordinated international cyber takedown, according to the U.S. Justice Department. For related coverage, see Coinbase Crypto Perpetuals Canada: Regulated Launch.

Sality is a botnet, a network of infected machines controlled remotely and, in this case, pointed at victims’ crypto. For related coverage, see Crypto Groups Push SEC for Tailored Rules on Novel ETFs.

The operation to break it was described as international in scope, the kind of cross-border effort that mirrors other recent crypto enforcement moves such as when the FBI seized crypto and took over fundraising sites tied to illicit funding. For related coverage, see CFTC seeks CME lawsuit dismissal over Kalshi Bitcoin perpetual futures.

Why Bitcoin and Ethereum Put This in the Crypto Lane

This is not a market story. It is a theft story.

The operation was built to steal Bitcoin and Ethereum, the two assets at the center of the case, as reported by Decrypt.

The victims here lost digital assets, not paper value. The malware’s payload was the crypto itself, siphoned from compromised machines rather than shaken loose by any price swing.

That places Sality alongside a growing list of criminal operations that treat wallets, not banks, as the target. Enforcement has been racing to keep up, from token freezes like the disputed USDT freeze that landed Tether in court to direct seizures.

An Eight-Year Run Shows How Sticky This Malware Can Be

The most striking number in this case is time. Sality ran for eight years before the takedown landed.

Eight years is a long life for any piece of malware, and it speaks to how persistent and hard to kill crypto-targeting botnets have become.

That durability is the real drama. A theft engine survived nearly a decade, quietly draining Bitcoin and Ethereum, before an international effort finally pulled the plug.

So how many wallets did Sality reach before the lights went out?

Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.

SOURCE TRANSPARENCY
  • External Source - Referenced domain: justice.gov
  • External Source - Referenced domain: theccpress.com
  • External Source - Referenced domain: decrypt.co
  • Byline - Reported by Adriana Mavrenko
  • Coverage Desk - Primary editorial category: Crypto News
  • Media Asset - Featured image served from the WordPress media library