Share this article

Federal Officials Recover Bitcoin Ransom From Colonial Pipeline Attack

Colonial paid $4.4 million in bitcoin after its systems fell victim to a ransomware attack last month.

Updated Sep 14, 2021, 1:07 p.m. Published Jun 7, 2021, 6:50 p.m.
Deputy Attorney General Lisa Monaco announced that federal officials had seized a bitcoin wallet that held proceeds from the Colonial Pipeline ransomware attack.
Deputy Attorney General Lisa Monaco announced that federal officials had seized a bitcoin wallet that held proceeds from the Colonial Pipeline ransomware attack.

Federal officials have recovered $2.3 million in bitcoin that Colonial Pipeline paid to a criminal outfit during a ransomware attack, the Department of Justice announced Monday.

STORY CONTINUES BELOW
Don't miss another story.Subscribe to the Crypto Daybook Americas Newsletter today. See all newsletters

Colonial Pipeline paid about $4.4 million in bitcoin to the attackers, linked to the Darkside ransomware group, after its payment systems were frozen last month. The company had to halt fuel transportation across the East Coast of the U.S., sparking fears of a gas shortage in a dozen states. Deputy Attorney General Lisa Monaco said Monday that the company contacted law enforcement, allowing federal agents to track and seize a bitcoin wallet.

"The Department of Justice has found and recovered the majority of the ransom paid," Deputy Attorney General Lisa Monaco said in a press briefing.

An affidavit filed by an FBI agent provided further details. According to public court documents, the agent, whose name was redacted, tracked the bitcoin Colonial sent to Darkside across several transactions recorded on the bitcoin ledger, using a block explorer.

About 63.7 BTC was sent to an address controlled by the FBI.

The bitcoin appears to come from the affiliate that deployed Darkside's ransomware, not Darkside itself, said Tom Robinson, chief scientist at Elliptic. He told CoinDesk the funds appear to have been seized at 1:40 p.m. ET.

In a blog post, Robinson said 15% of the total payment went to Darkside itself.

"The private key for the Subject Address is in the possession of the FBI in the Northern District of California," the affidavit said.

FBI Deputy Director Paul Abbate said federal officials had seized a bitcoin wallet that held the proceeds from the Colonial attack. It appears that the perpetrators still have about $2 million in crypto.

"Victim funds were seized from that wallet, preventing Darkside actors from using them," he said.

The funds were seized as part of a ransomware task force created by the DOJ.

"The sophisticated use of technology to hold businesses and even whole cities hostage for profit is decidedly a 21st century challenge. But the old adage 'follow the money' still applies. And that's exactly what we do," Monaco said.

CNN first reported the news.

Ransomware attacks have been on the rise recently, with a number of high-profile and critical infrastructure firms falling victim to the cyberattack. In her opening remarks, Monaco warned companies to take steps immediately to secure their systems or risk falling victim.

The U.S. Department of Justice did not immediately share further details.

UPDATE (June 7, 2021, 22:03 UTC): Updated with details from DOJ officials and additional commentary.

More For You

Protocol Research: GoPlus Security

GP Basic Image

What to know:

  • As of October 2025, GoPlus has generated $4.7M in total revenue across its product lines. The GoPlus App is the primary revenue driver, contributing $2.5M (approx. 53%), followed by the SafeToken Protocol at $1.7M.
  • GoPlus Intelligence's Token Security API averaged 717 million monthly calls year-to-date in 2025 , with a peak of nearly 1 billion calls in February 2025. Total blockchain-level requests, including transaction simulations, averaged an additional 350 million per month.
  • Since its January 2025 launch , the $GPS token has registered over $5B in total spot volume and $10B in derivatives volume in 2025. Monthly spot volume peaked in March 2025 at over $1.1B , while derivatives volume peaked the same month at over $4B.

More For You

Bitcoin’s Deep Correction Sets Stage for December Rebound, Says K33 Research

(Unsplash)

K33 Research says market fear is outweighing fundamentals as bitcoin nears key levels. December could offer an entry point for bold investors.

What to know:

  • K33 Research says bitcoin’s steep correction shows signs of bottoming, with December potentially marking a turning point.
  • The firm has argued that the market is overreacting to long-term risks while ignoring near-term signals of strength, like low leverage and solid support levels.
  • With likely policy shifts ahead and cautious positioning in futures, K33 sees more upside potential than risk of another major collapse.