· KLEPTIK.COMGlobal Corruption Investigative Reporting Project (GCIRP)
Join
← BACK TO FILES
◆ EXCLUSIVEKLTK-2025-014CRYPTO FILES / FRAUD NETWORKS / ASSET RECOVERYOPEN FILEunited-statesglobalExclusive

THE $577 MILLION MINING MACHINE

HashFlare sold customers a share of cryptocurrency mining it largely did not have the computing power to perform. Its founders’ guilty pleas exposed how a digital dashboard can manufacture the appearance of economic activity that barely exists in the physical world.
On 13 February 2025, the U.S. Department of Justice announced that Estonian nationals Sergei Potapenko and Ivan Turõgin had pleaded guilty in federal court in Seattle to operating a massive cryptocurrency fraud scheme involving HashFlare, a
CLASSIFICATION Cryptocurrency • Ponzi Scheme • Wire Fraud • Extradition • Asset Recovery • Shell Companies • Digital Deception
PUBLISHED 2/13/20258 min · 5 sources · SCOOP 80
THE $577 MILLION MINING MACHINE
▚ KEY FINDINGS
  • The men had entered their guilty pleas the previous day.
  • Between 2015 and 2019, HashFlare generated more than:
  • from customers who believed they were purchasing contracts entitling them to a share of cryptocurrency mined by HashFlare’s computing infrastructure.
  • According to court documents cited by DOJ, HashFlare did not possess the computing capacity required to perform the vast majority of the mining it represented to customers.
  • Instead, its web-based customer dashboard displayed falsified information purporting to show mining activity and profits.

EXECUTIVE FINDING

On 13 February 2025, the U.S. Department of Justice announced that Estonian nationals Sergei Potapenko and Ivan Turõgin had pleaded guilty in federal court in Seattle to operating a massive cryptocurrency fraud scheme involving HashFlare, a purported cloud-mining business.

The men had entered their guilty pleas the previous day.

Between 2015 and 2019, HashFlare generated more than:

$577 MILLION IN SALES

from customers who believed they were purchasing contracts entitling them to a share of cryptocurrency mined by HashFlare’s computing infrastructure.

The central problem was physical.

According to court documents cited by DOJ, HashFlare did not possess the computing capacity required to perform the vast majority of the mining it represented to customers.

Instead, its web-based customer dashboard displayed falsified information purporting to show mining activity and profits.

Earlier charging records were even more specific: prosecutors alleged that HashFlare’s actual Bitcoin-mining activity amounted to less than 1% of the computing power it represented to customers.

When customers attempted to withdraw purported mining proceeds, authorities alleged that HashFlare sometimes delayed payment or supplied cryptocurrency purchased on the open market rather than cryptocurrency its systems had actually mined.

The scheme therefore exposed a deceptively simple vulnerability in digital finance:

THE CUSTOMER COULD SEE THE DASHBOARD.

THE CUSTOMER COULD NOT SEE THE MINE.

The screen showed:

  • hash rate
  • mining output
  • account balance

and returns.

But the customer had no independent way to determine whether the physical computing infrastructure necessary to generate those numbers actually existed at the represented scale.

Potapenko and Turõgin also admitted wrongdoing connected to the fraud and agreed to forfeit assets valued at more than $400 million, which DOJ said would ultimately be made available for a victim-remission process.

The defendants had spent years fighting extradition from Estonia after their 2022 arrests before ultimately being transferred to the United States in May 2024.

The central question of this dossier is therefore broader than HashFlare:

WHEN A DIGITAL PLATFORM TELLS YOU AN ASSET EXISTS, WHAT INDEPENDENT EVIDENCE PROVES IT?

THE FINDING

HashFlare did not sell customers Bitcoin directly.

It sold something more abstract:

COMPUTING CAPACITY

Customers were effectively told:

Pay us money.

We operate mining machines.

A portion of that mining power belongs economically to you.

The machines generate cryptocurrency.

Your share will appear in your account.

That arrangement is known as cloud mining.

It can be legitimate.

A real mining operator may own specialised computers and rent portions of their productive capacity to customers.

The problem is verification.

The customer usually cannot inspect:

  • the machines
  • the electricity meters
  • the mining-pool accounts
  • the facility

or the actual computational output.

The customer instead sees a website.

That creates an enormous information imbalance.

THE CLOUD-MINING MODEL

A legitimate cloud-mining business can be represented as:

The critical element is:

REAL HASH POWER

Without it, the contract has no genuine mining engine.

THE HASHFLARE MODEL

The government’s case described a materially different architecture:

currency may be purchased externally rather than generated by promised capacity.

The customer interface remains convincing.

The underlying production system does not match it.

That is the key fraud mechanism.

DIGITAL OUTPUT VERSUS PHYSICAL INPUT

Mining is digital in output.

But intensely physical in production.

Bitcoin mining requires:

  • specialised hardware
  • electricity
  • cooling
  • networking
  • facilities
  • maintenance

and measurable computational capacity.

That gives investigators an unusual advantage.

A claimed mining operation can be tested against the physical world.

THE PHYSICAL-CAPACITY TEST

If a company claims to mine cryptocurrency at scale, ask:

  • How many machines?
  • Which models?
  • What hash rate per machine?
  • Where are they located?
  • How much electricity do they consume?
  • What is the facility’s power capacity?
  • Which mining pools receive the hash power?
  • What are the wallet addresses receiving rewards?
  • How much cooling infrastructure exists?
  • What equipment purchases support the claimed fleet?

A business claiming billions in mining output should leave enormous physical evidence.

ELECTRICITY DOES NOT LIE EASILY

One of the best independent tests of a mining operation is power consumption.

Suppose a company claims:

100,000 specialised miners.

Each consumes:

3 kilowatts.

Expected load:

300 MEGAWATTS

A facility drawing 5 megawatts cannot plausibly support the represented fleet.

This makes utility records potentially more valuable than investor presentations.

HASH RATE AS AN AUDITABLE CLAIM

Mining companies frequently advertise:

TH/s;

PH/s;

EH/s.

These are measures of computing power.

The numbers sound technical.

But they can be tested.

  • Claimed hash rate
  • ÷
  • known performance of installed machines
  • =

estimated machine count.

  • Estimated machine count
  • ×
  • power draw
  • =

estimated electricity requirement.

The physical infrastructure should approximately match.

THE LESS-THAN-ONE-PERCENT ALLEGATION

The original indictment alleged HashFlare’s equipment performed Bitcoin mining at a rate amounting to less than 1% of the computing power it claimed.

This is not a minor shortfall.

A company claiming 100 units of productive capacity while possessing less than one unit is not simply inefficient.

The business’s represented economic engine is almost entirely absent.

By February 2025, Potapenko and Turõgin had pleaded guilty to conspiracy to commit wire fraud, establishing criminal responsibility for the fraudulent scheme.

THE DASHBOARD

The most important fraud instrument may have been the customer dashboard.

DOJ said HashFlare’s web interface purported to show customers mining profits but instead reflected falsified data.

That raises a larger issue extending across digital finance.

Investors increasingly interact with money through interfaces.

Bank balance.

Brokerage account.

Crypto wallet.

Mining dashboard.

Investment portal.

The screen becomes the user’s reality.

THE SCREEN-AS-EVIDENCE PROBLEM

A dashboard displays:

Balance: $87,500.

The user naturally assumes:

$87,500 exists.

But the dashboard itself proves only that software displayed the number.

It does not independently prove:

  • the cash exists
  • the security exists
  • the cryptocurrency exists
  • the mining occurred

or the asset is available for withdrawal.

That distinction is critical.

INTERNAL DATA VERSUS EXTERNAL VERIFICATION

A digital financial balance can arise from two different systems.

VERIFIED SYSTEM

CLOSED SYSTEM

The second structure requires significantly more trust.

THE DASHBOARD FRAUD MODEL

If the company controls both:

  • the economic claim
  • and
  • the evidence supporting the claim,

then verification becomes circular.

HashFlare tells customer:

Mining occurred.

Customer asks:

How do I know?

HashFlare replies:

Look at your HashFlare dashboard.

That is not independent verification.

The issuer is verifying itself.

THE FTX PARALLEL

This problem is broader than mining.

FTX users saw account balances.

OneCoin members saw purported cryptocurrency value.

HashFlare customers saw mining output.

Different business models.

Same informational vulnerability:

THE PLATFORM CONTROLS THE NUMBER THE CUSTOMER RELIES UPON.

That should trigger an independent-verification requirement.

THE MINING-PROOF TEST

A genuine cloud-mining operator should potentially be able to provide evidence linking:

  • customer contracts
  • to
  • actual computing capacity
  • to
  • actual mining pools
  • to

actual blockchain rewards.

The audit chain should look like:

That creates a verifiable economic chain.

THE WITHDRAWAL TEST

A fraudulent dashboard can survive as long as customers leave balances inside the system.

The moment large numbers of users withdraw, the company must produce the actual asset.

This is where digital illusion meets financial reality.

DOJ’s case summary said that when HashFlare customers requested withdrawals, the defendants could not provide the mined cryptocurrency as promised. They either resisted withdrawal requests or paid customers with cryptocurrency purchased on the open market.

That is extremely significant.

BUYING THE “MINED” CRYPTO

Suppose customer dashboard says:

You mined 1 BTC.

But no 1 BTC was actually mined.

Customer withdraws.

Operator purchases 1 BTC from exchange.

Customer receives it.

From the customer’s perspective:

the system worked.

But economically:

the payment came from somewhere else.

That can delay discovery.

THE SUBSTITUTE-ASSET MODEL

The architecture is:

This resembles a Ponzi structure even where the customer receives the promised commodity.

The source of payment matters.

SOURCE OF RETURN

Every investment should answer:

WHAT ECONOMIC ACTIVITY GENERATED THE RETURN?

  • Mining?
  • Trading?
  • Interest?
  • Rental income?
  • Business profit?
  • New investors?
  • Company reserves?
  • Borrowed money?

If a supposed mining return is funded by cryptocurrency purchased using customer proceeds, the return is not evidence that mining occurred.

THE PONZI ELEMENT

DOJ described the wider operation as a cryptocurrency Ponzi scheme.

A Ponzi structure generally involves paying earlier investors from money supplied by later investors or other non-genuine sources rather than from the represented investment activity.

In HashFlare’s case, the government’s records indicate customers were sometimes paid with crypto purchased from the market when actual mining could not support withdrawals.

That is why source-of-return analysis is essential.

SALES: MORE THAN $577 MILLION

Between 2015 and 2019, HashFlare’s sales exceeded $577 million.

This is an extraordinary amount for a business whose represented mining capacity was, according to the original prosecution, only a fraction of what customers had been told.

The sales total raises another forensic question:

WHERE DID THE $577 MILLION GO?

FOLLOW THE MONEY

Customer payments can generally flow into:

  • operating expenses
  • equipment
  • electricity
  • employee compensation
  • marketing
  • promoter commissions
  • property
  • investments
  • crypto accounts
  • founders

or other businesses.

A genuine mining company receiving $577 million should show enormous corresponding mining investment.

If hardware and electricity expenditures are disproportionately small, the balance must be explained.

THE MINING CAPEX TEST

Mining requires capital expenditure.

Servers.

ASIC miners.

Transformers.

Electrical infrastructure.

Cooling.

Buildings.

Networking.

A genuine large-scale operator should leave:

  • supplier invoices
  • shipping records
  • customs documents
  • serial numbers
  • facility leases
  • construction records

utility connections.

These can be independently verified.

CAPEX VERSUS SALES

A key investigative ratio:

MINING CAPEX ÷ CONTRACT SALES

Suppose:

$577 million sales.

But only modest equipment investment.

That mismatch becomes a strong red flag.

A company cannot sell physical productive capacity it never acquires.

FOLLOW THE ELECTRICITY

Another ratio:

ELECTRICITY CONSUMPTION ÷ CLAIMED HASH RATE

Mining economics constrain reality.

A claimed output requires approximately calculable power.

The power meter becomes an audit record.

FOLLOW THE POOLS

Most large Bitcoin miners participate in mining pools.

Pools maintain records of:

  • worker activity
  • hash contribution
  • rewards

payout addresses.

These records can independently corroborate whether claimed mining occurred.

A mining business that refuses to identify pool relationships deserves scrutiny.

CUSTOMER ALLOCATION

Even where real mining exists, another question remains:

How are mined rewards allocated among customers?

The operator must maintain a reliable ledger linking:

  • total rewards
  • to
  • customer shares
  • minus

fees.

A customer dashboard should be reconcilable to external mining records.

THE POLYBIUS SCHEME

HashFlare was not the only investment product associated with Potapenko and Turõgin.

In May 2017, the defendants also promoted Polybius, which they said would become a bank specialising in virtual currency.

According to the indictment, investors contributed at least $25 million.

Polybius never became a bank and never paid the promised dividends.

This reveals a second fraud mechanism.

Mining represented an allegedly existing productive business.

Polybius represented a future institution.

SELLING THE FUTURE

Investment fraud frequently sells one of two things:

EXISTING ACTIVITY

“We already operate this profitable mine.”

FUTURE ACTIVITY

“We are building the bank that will dominate the future.”

The verification standards differ.

For an existing mine:

prove production.

For a future bank:

prove licensing, capital, governance and development milestones.

THE CRYPTO-BANK PROMISE

A genuine bank requires far more than branding.

Capital.

Licence.

Regulator.

Governance.

AML.

Risk systems.

Management.

Technology.

Correspondent relationships.

The Polybius investigation should therefore ask:

  • Was a banking licence application filed?
  • Was regulatory capital raised?
  • Were directors appointed?
  • Were banking systems built?
  • What milestones existed?

If none occurred, the investment narrative becomes difficult to sustain.

THE $25 MILLION QUESTION

The original case alleged that most of the money raised for Polybius was transferred to bank accounts and cryptocurrency wallets controlled by Potapenko, Turõgin and co-conspirators rather than used to establish the promised bank.

That creates another classic fraud test:

USE OF PROCEEDS

Investors were told money would fund X.

Where did it actually go?

USE-OF-PROCEEDS AUDIT

For every fundraising scheme:

A significant unexplained variance can be more probative than promotional statements.

SHELL COMPANIES

The original indictment alleged Potapenko and Turõgin used shell companies, false contracts and invoices to launder fraud proceeds.

Again, shell companies are not inherently illegal.

The investigative issue is whether legal entities were used to create a false commercial explanation for movement of victim money.

THE LAUNDERING ARCHITECTURE

A generic structure might look like:

The funds acquire layers of documentary explanation.

FALSE CONTRACTS

A false contract performs the same function as the sham invoices examined in the Ericsson and OneCoin dossiers.

The bank sees:

commercial payment.

The accounting ledger sees:

expense or investment.

The investigator sees:

money leaving the victim-funded business.

The question is whether the stated service existed.

DOCUMENT-TO-DOLLAR RATIO

A multimillion-dollar consulting or supply contract should create:

  • employees
  • correspondence
  • deliverables
  • invoices
  • product

performance evidence.

If those are absent, investigators should question the economic substance.

Documentation proves what someone claimed happened.

It does not prove the claim is true.

ASSET CONVERSION

The February 2025 plea record said Potapenko and Turõgin used fraud proceeds to purchase:

  • real estate
  • luxury vehicles
  • and investments,

while maintaining cryptocurrency and investment accounts.

This represents the conversion of digital fraud proceeds into conventional wealth.

The path is important:

  • CAR
  • INVESTMENT ACCOUNT
  • CRYPTO ACCOUNT

The victim begins with a digital dashboard.

The defendant ends with physical assets.

75 REAL PROPERTIES

The original indictment alleged the laundering conspiracy involved at least:

  • 75 real properties
  • six luxury vehicles
  • cryptocurrency wallets
  • and

thousands of cryptocurrency mining machines.

As of the archive date, the February 2025 guilty pleas were to conspiracy to commit wire fraud; therefore, allegations from the earlier money-laundering counts should still be identified according to their precise procedural status rather than automatically treated as admissions to every originally charged laundering allegation.

That distinction matters.

ASSET MAP

Each real-estate asset should be mapped by:

  • country
  • address
  • purchase date
  • purchase price
  • legal owner
  • beneficial owner
  • seller
  • funding account
  • mortgage
  • current status

forfeiture status.

A portfolio of 75 properties can reveal the financial geography of the scheme.

THE PROPERTY CLUSTER

Property purchases may also reveal:

  • common agents
  • lawyers
  • notaries
  • banks
  • mortgage providers
  • holding companies

and family members.

Those recurring professionals become potential investigative nodes.

Association alone is not evidence of complicity.

But concentration deserves examination.

THE LUXURY VEHICLES

Luxury cars provide another asset trail.

VIN.

Registration.

Dealer.

Purchase invoice.

Finance.

Insurance.

Legal owner.

Beneficial user.

Vehicles are portable but highly documented.

That makes them attractive status assets and useful forfeiture targets.

THE CRYPTO ACCOUNTS

Unlike real estate, cryptocurrency can move instantly.

Asset recovery therefore depends upon:

  • wallet identification
  • private-key control
  • exchange cooperation

and rapid freezing.

The government’s success in restraining or identifying more than $400 million in assets is significant because digital proceeds can otherwise disappear across jurisdictions quickly.

THE $400 MILLION FORFEITURE

As part of their guilty pleas, Potapenko and Turõgin agreed to forfeit assets valued at more than $400 million.

DOJ said those assets would be available for a future remission process to compensate victims.

This is a striking recovery ratio.

At face value:

$400 million identified assets

versus

$577 million HashFlare sales.

But this comparison should be made cautiously.

Not all sales necessarily equal compensable victim losses.

Asset values can change.

Forfeited amounts may include property connected to broader conduct.

Administrative costs and victim claims affect final distributions.

THE RECOVERY RATIO

Kleptik proposes:

RECOVERY RATIO

Assets ultimately returned to victims

÷

verified victim losses.

This should be tracked separately from:

  • forfeiture ordered
  • assets seized
  • assets restrained

assets liquidated.

Only money actually returned repairs the victim loss.

FORFEITURE IS NOT RESTITUTION

The terms are related but different.

FORFEITURE

Government removes assets connected with criminal conduct.

RESTITUTION

Court orders payment to victims.

REMISSION

Government may distribute forfeited assets to qualifying victims.

Therefore:

$400 million forfeited

does not automatically mean

$400 million paid to victims.

The last step still matters.

THE VICTIM POPULATION

DOJ said HashFlare victimised hundreds of thousands of people in the United States and abroad.

That scale creates an administrative challenge.

How do authorities verify claims from hundreds of thousands of investors across many countries?

Required evidence may include:

  • account records
  • payment receipts
  • crypto transfers
  • contracts
  • withdrawals

and recoveries already received.

GROSS PAYMENT VERSUS NET LOSS

Victim loss should generally account for money returned.

Example:

Investor paid:

$20,000.

Received withdrawals:

$7,000.

Potential net loss:

$13,000.

Using gross investment alone can overstate actual economic loss.

The remission process needs a consistent methodology.

INTERNATIONAL VICTIMS

The scheme operated globally.

That means victims may have paid through:

  • bank transfers
  • credit cards
  • cryptocurrency
  • payment processors

and local intermediaries.

Asset recovery therefore becomes internationally complex.

Country of victim.

Country of payment processor.

Country of defendant.

Country of asset.

Country of prosecution.

Each may be different.

EXTRADITION

Potapenko and Turõgin were arrested in Tallinn, Estonia, on 20 November 2022 after a U.S. grand jury returned an 18-count indictment.

They challenged extradition through Estonia’s legal system.

After the Estonian government authorised extradition and the Estonian Supreme Court declined to intervene, the men were transferred to the United States in May 2024.

This is itself an important part of the dossier.

TWO YEARS BETWEEN ARREST AND U.S. COURT

The chronology illustrates how long cross-border criminal enforcement can take.

Nearly two years can pass before trial preparation begins.

EXTRADITION AS FINANCIAL ENFORCEMENT

A fraudster may operate globally.

But prosecution requires jurisdiction over the person.

Extradition converts:

foreign suspect

into

domestic defendant.

For crypto crime, that process is increasingly central because businesses and founders may intentionally operate far from victim countries.

ESTONIA

Estonia’s role in the case should not be reduced to the defendants’ nationality.

The country also cooperated substantially with U.S. authorities.

DOJ specifically thanked:

the Cybercrime Bureau of the Estonian Police and Border Guard;

the Estonian Prosecutor General;

and the Ministry of Justice and Digital Affairs

for assistance with investigation and extradition.

This is important context.

The jurisdiction was part of the enforcement solution as well as the crime’s geography.

THE DIGITAL-ECONOMY PARADOX

Estonia is internationally associated with advanced digital government and technology entrepreneurship.

HashFlare demonstrates a wider truth:

technological sophistication can produce both:

innovation

and

sophisticated fraud.

Those are not contradictory.

The same skills enabling digital businesses can be abused to create convincing digital deception.

THE SOFTWARE-AS-TRUST PROBLEM

Users trust software because it appears precise.

Dashboard:

0.00038452 BTC mined today.

The number has eight decimal places.

It looks scientific.

Precision creates credibility.

But false data can also be precise.

That is why digital investment systems should distinguish:

COMPUTATIONAL PRECISION

from

ECONOMIC TRUTH

A perfectly calculated false input remains false.

NUMBERS AS PSYCHOLOGICAL EVIDENCE

An investor seeing:

  • daily mining increments
  • historical charts
  • projected yields
  • and account growth

receives constant reinforcement.

The fraud becomes interactive.

Instead of waiting for quarterly statements, the victim watches wealth apparently accumulate every day.

That may make digital Ponzi systems more psychologically compelling than traditional paper statements.

THE REAL-TIME ILLUSION

Traditional fraud:

statement arrives monthly.

Digital fraud:

dashboard updates continuously.

The appearance of real-time data can imply real-time underlying activity.

But the connection may not exist.

Continuous display is not continuous verification.

THE WITHDRAWAL PSYCHOLOGY

Early withdrawals are particularly powerful.

Customer invests.

Receives crypto.

Tells friends.

Reinvests.

Confidence grows.

Even if the payment was not generated by real mining, the withdrawal functions as proof in the customer’s mind.

This helps explain how Ponzi structures scale.

PROOF-OF-PAYOUT IS NOT PROOF-OF-BUSINESS

This distinction should become a permanent Kleptik principle:

A SUCCESSFUL WITHDRAWAL PROVES THE COMPANY PAID YOU.

IT DOES NOT PROVE HOW THE COMPANY EARNED THE MONEY.

That is the heart of Ponzi analysis.

THE CUSTOMER-ACQUISITION LOOP

The system can therefore grow even when underlying economic production is weak.

AFFILIATE MARKETING

A future HashFlare investigation should examine its affiliate and referral architecture.

Questions include:

  • Were customers paid for referrals?
  • How much sales growth came through affiliates?
  • Which promoters earned the most?
  • What representations did they make?
  • Did they understand actual mining capacity?

An affiliate network can amplify a digital fraud similarly to MLM.

PROMOTER KNOWLEDGE

Promoters should not be presumed complicit simply because they received commissions.

The critical distinction is knowledge.

Did the promoter:

  • believe HashFlare operated real mining?
  • receive internal capacity data?
  • ignore warnings?
  • make representations contradicted by available evidence?

The same professional-enabler framework applies.

THE CONTRACT

A cloud-mining contract should specify:

  • hash rate
  • term
  • fees
  • maintenance
  • cryptocurrency
  • payout mechanism
  • termination

and risk.

But the contract does not prove the seller owns the capacity it promises.

The central due-diligence question remains physical.

CONTRACTUAL RIGHT VERSUS PHYSICAL CAPACITY

An investor may legally possess a contract giving them rights to:

100 TH/s.

But if the operator has no corresponding mining hardware, the legal right is economically hollow.

This resembles fractional-reserve problems in other financial products.

Claims exceed assets.

THE CLAIMS-TO-CAPACITY RATIO

Kleptik proposes:

CLAIMS-TO-CAPACITY RATIO

Hash power sold to customers

÷

actual available hash power.

A ratio near 1 may be sustainable.

A ratio of 10 means the company sold ten times more capacity than it possessed.

A ratio above 100 would indicate extreme mismatch.

The original prosecution’s less-than-one-percent allegation suggests an enormous disparity.

OVERSUBSCRIPTION

Legitimate businesses sometimes oversell capacity based on usage patterns.

Airlines oversell seats.

Cloud-computing providers pool resources.

But mining contracts represent a claim on productive output.

If the company cannot mathematically deliver the represented computing capacity, oversubscription becomes deception.

THE OPEN-MARKET PURCHASE TEST

The fact that defendants allegedly purchased cryptocurrency on the open market to satisfy withdrawals is particularly revealing.

A mining business should primarily acquire payout crypto by:

mining it.

Repeated open-market purchases can indicate a production shortfall.

Investigators should compare:

  • mined crypto received
  • versus
  • crypto purchased externally
  • versus

customer withdrawals.

PRODUCTION-COVERAGE RATIO

ACTUAL MINED CRYPTO ÷ CUSTOMER PAYOUT OBLIGATION

A healthy mining operation should have a high ratio.

A low ratio means the operator must find payout assets elsewhere.

That can expose the fundamental business mismatch.

THE MINING-MACHINE ASSET IRONY

The original indictment said the laundering conspiracy itself involved thousands of cryptocurrency mining machines.

This creates an interesting paradox.

The defendants allegedly owned real mining equipment.

The issue was that actual capacity was dramatically lower than represented.

Fraud therefore does not always mean the underlying business is entirely fictional.

Sometimes:

A REAL BUSINESS EXISTS INSIDE A FALSELY EXAGGERATED BUSINESS.

That distinction is crucial.

FRAUD THROUGH SCALE EXAGGERATION

A company may genuinely:

mine some Bitcoin;

own some equipment;

operate a real facility.

But if it sells contracts as though it controls 100 times more capacity, the existence of genuine activity can make the deception more persuasive.

The customer sees real photographs.

Real machines.

Real employees.

Real wallets.

The false claim concerns scale.

THE 1% PROBLEM

This is why investors should never accept:

“We visited the facility and saw miners.”

Seeing 1,000 machines proves:

1,000 machines exist.

It does not prove:

100,000 machines exist.

Scale requires independent verification.

THE AUDITOR’S ROLE

A credible cloud-mining audit should potentially verify:

  • machine inventory
  • serial numbers
  • facility locations
  • ownership
  • power capacity
  • electricity consumption
  • pool accounts
  • hash rate
  • wallet rewards

customer liabilities.

The auditor needs to reconcile physical and digital records.

PROOF OF RESERVES IS NOT ENOUGH

Crypto exchanges popularised “proof of reserves.”

Mining requires something different:

PROOF OF PRODUCTION

Assets currently held do not prove the represented business generated them.

HashFlare demonstrates why source matters.

PROOF OF PRODUCTION

Potential proof:

  • mining-pool logs
  • block rewards
  • coinbase transactions
  • wallet history
  • machine telemetry

utility bills.

These records can establish whether crypto came from mining rather than market purchases.

THE POLYBIUS CONNECTION REVISITED

The coexistence of HashFlare and Polybius is analytically important.

One business allegedly exaggerated present production.

The other allegedly sold a future banking institution that never materialised.

Together they illustrate two classic fraud techniques:

FAKE PRESENT

and

FAKE FUTURE

Investors need different verification tools for each.

VERIFY THE PRESENT

Physical assets.

Current revenue.

Bank balances.

Production records.

Customers.

VERIFY THE FUTURE

Licences.

Contracts.

Capital.

Milestones.

Board.

Regulatory applications.

Progress.

A projection is not proof.

THE CORPORATE NETWORK

A future Kleptik investigation should reconstruct all companies used by Potapenko, Turõgin and associated persons.

For each:

  • jurisdiction
  • incorporation date
  • directors
  • shareholders
  • beneficial owners
  • bank accounts
  • business purpose
  • payments

assets.

The shell-company allegations make this particularly important.

FOLLOW THE PHONY INVOICES

The original indictment alleged fraudulent contracts and invoices were used to disguise movement of proceeds.

For each invoice:

issuer.

recipient.

service.

amount.

date.

supporting work.

beneficial owner.

onward transfer.

False invoices often expose the laundering layer more clearly than the customer-facing fraud.

BANKING

Hundreds of millions in sales inevitably required conventional financial institutions alongside cryptocurrency wallets.

A full money map should identify:

  • merchant processors
  • banks
  • correspondent banks
  • exchange accounts
  • crypto wallets

payment gateways.

The digital fraud still depends upon traditional finance at multiple points.

CARD PAYMENTS

If customers purchased mining contracts using credit cards, merchant-acquiring records may reveal:

  • sales volume
  • chargebacks
  • fraud complaints

processor terminations.

Chargeback history can provide an early-warning signal before criminal enforcement.

PAYMENT-PROCESSOR MIGRATION

A suspicious business may cycle through processors as complaints increase.

This migration should be mapped.

As with bank-account closures, movement after scrutiny can reveal risk.

ASSET RECOVERY

The government’s ability to identify more than $400 million in forfeitable assets is one of the most significant elements of the case.

Financial fraud often ends with victims recovering pennies.

Here, the potential recovery pool appears unusually substantial relative to the reported scheme size.

But the final recovery ratio remains unknown as of the archive date.

WHY CRYPTO CAN HELP RECOVERY

Crypto can complicate laundering.

But it can also preserve transaction history.

Once investigators attribute a wallet, they may trace years of movements.

That can reveal:

  • exchange deposits
  • wallet clusters
  • asset purchases

and subsequent conversions.

The blockchain remembers even when corporate records disappear.

WHY REAL ESTATE HELPS RECOVERY

Real estate is difficult to move.

Once prosecutors identify beneficial ownership, the asset can potentially be restrained.

The more fraud proceeds that were converted into property, the greater the possibility of meaningful recovery.

THE INVESTOR ACCOUNTING QUESTION

If HashFlare sold $577 million in contracts, what obligations appeared on its own balance sheet?

Were contracts treated as:

  • revenue immediately?
  • deferred revenue?
  • mining obligations?
  • customer liabilities?

The accounting classification matters.

If payments were recognised as immediate revenue while substantial future mining obligations remained, financial statements could obscure the true liability structure.

DEFERRED REVENUE

A legitimate prepaid service often creates:

cash received today

plus

obligation to provide service tomorrow.

Accounting may treat part as deferred revenue.

Cloud mining similarly creates future performance obligations.

The treatment of those obligations may reveal whether management internally understood the real capacity mismatch.

INSIDE KNOWLEDGE

The fraud-intent investigation should reconstruct:

  • internal capacity reports
  • hardware inventories
  • sales forecasts
  • customer obligations
  • withdrawal shortages
  • open-market crypto purchases
  • employee warnings

messages between founders.

The question is:

When did management know customer claims exceeded productive capacity?

THE FIRST SHORTFALL

The most revealing moment in many Ponzi schemes is the first time genuine earnings cannot meet customer withdrawals.

What happens?

Management can:

  • stop sales
  • disclose problem
  • raise capital
  • or

hide the shortfall.

That decision separates business failure from fraud.

THE COVER-UP CYCLE

The act used to hide today’s shortfall makes tomorrow’s shortfall larger.

That is the Ponzi spiral.

EXTRADITION RISK FOR TECH FOUNDERS

Potapenko and Turõgin operated from Estonia.

U.S. victims and financial activity created U.S. criminal exposure.

Their eventual extradition reinforces a recurring principle:

REMOTE BUSINESS DOES NOT MEAN REMOTE LIABILITY.

A founder cannot assume physical residence abroad prevents eventual U.S. prosecution.

THE HUMAN JURISDICTION

Corporate structures can move.

Wallets can move.

Servers can move.

The defendant remains a person with a physical location.

That makes extradition the ultimate jurisdictional bridge.

CHRONOLOGY

2015

HashFlare begins selling cloud-mining contracts.

2015–2019

HashFlare records more than $577 million in sales. The company does not possess computing capacity sufficient to perform the vast majority of mining represented to customers.

May 2017

Potapenko and Turõgin launch the Polybius investment project, representing that it would create a virtual-currency bank.

At least $25 million is raised. Polybius never becomes a bank and pays no dividends, according to the indictment.

August 2019

HashFlare stops offering virtual-currency mining contracts.

27 October 2022

A federal grand jury in the Western District of Washington returns an 18-count indictment.

20 November 2022

Potapenko and Turõgin are arrested in Tallinn, Estonia.

21 November 2022

DOJ publicly announces the arrests and indictment.

2022–2024

The defendants contest extradition in Estonia.

May 2024

Estonian legal proceedings clear the way for extradition.

30 May 2024

Potapenko and Turõgin are transferred to the United States and appear in federal court in Seattle.

12 February 2025

Both defendants plead guilty to one count of conspiracy to commit wire fraud.

13 February 2025

DOJ publicly announces the guilty pleas.

Both men agree to forfeit assets valued at more than $400 million.

8 May 2025

Sentencing is scheduled as of the archive date.

Each defendant faces a statutory maximum of 20 years’ imprisonment.

DOCUMENTARY RECORD

DOJ — 13 FEBRUARY 2025

The guilty-plea announcement establishes:

  • more than $577 million in HashFlare sales
  • hundreds of thousands of victims
  • false dashboard information
  • insufficient mining capacity

and more than $400 million in agreed forfeiture.

DOJ — 30 MAY 2024

The extradition record provides detailed allegations concerning:

  • less than 1% of represented Bitcoin mining power
  • open-market cryptocurrency purchases used to satisfy withdrawals
  • the $25 million Polybius offering

and the wider money-laundering allegations.

DOJ — NOVEMBER 2022 INDICTMENT ANNOUNCEMENT

The original arrest announcement identifies:

  • the 18-count indictment
  • HashFlare
  • Polybius
  • hundreds of thousands of victims
  • shell-company allegations
  • real estate

and luxury vehicles.

WHAT THE AUTHORITIES SAY

DOJ says Potapenko and Turõgin operated a massive cryptocurrency fraud that induced hundreds of thousands of customers to purchase cloud-mining contracts.

The company did not possess enough computing power to perform the vast majority of represented mining.

The customer dashboard reflected falsified mining information.

The defendants then used fraud proceeds to acquire property, luxury vehicles and investments.

Because both defendants pleaded guilty, the core wire-fraud conspiracy is established through their admissions.

Earlier laundering allegations and detailed factual assertions should nevertheless be described according to the precise terms admitted in their plea agreements or independently established through the record.

WHAT THE DEFENDANTS ADMITTED

Potapenko and Turõgin each pleaded guilty to:

ONE COUNT OF CONSPIRACY TO COMMIT WIRE FRAUD

on 12 February 2025.

As part of the resolution, both agreed to forfeit assets valued at more than $400 million.

The guilty pleas establish their criminal participation in the HashFlare fraud conspiracy.

Kleptik should not automatically describe every original indictment count as a conviction.

WHAT THIS DOSSIER DOES NOT ESTABLISH

This dossier does not establish that:

  • every HashFlare employee knew the mining figures were false
  • every physical mining machine associated with HashFlare was fictitious
  • every affiliate marketer knowingly participated in fraud
  • all $577 million in sales represented final uncompensated victim loss

every Estonian business or professional associated with HashFlare participated in wrongdoing;

  • the Estonian government facilitated the scheme
  • all cloud-mining products are fraudulent
  • every investor withdrawal was paid with new investor money

or every originally charged money-laundering allegation was separately admitted through the February 2025 pleas.

The legal status must remain precise.

RIGHT OF REPLY

Before publication, Kleptik should seek comment from:

Sergei Potapenko and counsel

Ivan Turõgin and counsel

HashFlare representatives, if any corporate representative remains available

Polybius-related entities or representatives

For future investigative extensions:

  • mining-pool operators
  • electricity providers
  • equipment suppliers
  • payment processors
  • banks
  • crypto exchanges
  • property-holding companies
  • and
  • professional service providers

should receive transaction-specific questions where material criticism is contemplated.

Association with a defendant or service to a company does not establish knowledge of fraud.

UNANSWERED QUESTIONS

The guilty pleas establish the fraud.

They do not yet reveal every layer of the machine.

1. ACTUAL HASH RATE

What was HashFlare’s verified mining capacity each year from 2015 through 2019?

2. CLAIMED HASH RATE

How much capacity had customers collectively purchased?

3. CLAIMS-TO-CAPACITY RATIO

At peak, how many times larger were customer contracts than real infrastructure?

4. MACHINES

Exactly how many mining machines existed?

5. LOCATIONS

Where were the mining facilities?

6. ELECTRICITY

What power consumption did the facilities record?

7. MINING POOLS

Which pools received HashFlare’s genuine hash power?

8. BLOCKCHAIN REWARDS

How much crypto can be verified as actually mined?

9. OPEN-MARKET PURCHASES

How much cryptocurrency was purchased externally to satisfy customer withdrawals?

10. CUSTOMER DASHBOARD

Who designed the software generating falsified mining output?

11. INTERNAL DATABASE

Was dashboard data directly connected to genuine pool activity or generated independently?

12. FIRST SHORTFALL

When did management first know real mining could not satisfy customer obligations?

13. AFFILIATES

How much of the $577 million in sales came through referral or affiliate commissions?

14. POLYBIUS

Where did the at least $25 million raised for the proposed virtual-currency bank ultimately go?

15. SHELL COMPANIES

Which entities allegedly received fraud proceeds under false contracts or invoices?

16. BANKS

Which institutions processed the largest volumes?

17. CRYPTO EXCHANGES

Which exchanges received defendant-controlled proceeds?

18. 75 PROPERTIES

What is the complete ownership and funding history of the real estate identified in the original indictment?

19. $400 MILLION

How much of the agreed forfeiture will ultimately be converted to money available for victims?

20. THE CENTRAL QUESTION

How did hundreds of thousands of technologically sophisticated investors accept an internally generated dashboard as proof of an externally occurring mining operation?

That question matters far beyond HashFlare.

KLEPTIK INTELLIGENCE ASSESSMENT

ASSESSMENT: ESTABLISHED

Sergei Potapenko and Ivan Turõgin pleaded guilty to conspiracy to commit wire fraud arising from the HashFlare cryptocurrency-mining scheme.

ASSESSMENT: ESTABLISHED

HashFlare generated more than $577 million in sales between 2015 and 2019 while lacking sufficient computing capacity to perform the vast majority of mining represented to customers.

ASSESSMENT: ESTABLISHED

HashFlare’s customer dashboard displayed falsified information purporting to represent mining profits.

ASSESSMENT: STRONGLY SUPPORTED BY ORIGINAL CHARGING RECORD

Actual Bitcoin-mining activity represented less than 1% of the computing power HashFlare claimed, according to the original indictment.

This specific percentage should be attributed to the indictment unless independently confirmed in the plea factual record.

ASSESSMENT: ESTABLISHED

The defendants agreed to forfeit assets valued at more than $400 million.

ASSESSMENT: HIGH CONFIDENCE

The central deception depended upon the difference between digital representation and independently verifiable physical production.

Customers could observe the dashboard but not the underlying mining infrastructure.

ASSESSMENT: HIGH CONFIDENCE

Cloud-mining due diligence should rely on physical capacity, electricity consumption, mining-pool data and blockchain rewards rather than company-generated dashboards alone.

ASSESSMENT: HIGH CONFIDENCE

The use of externally purchased cryptocurrency to satisfy purported mining withdrawals, as alleged in the original case record, demonstrates why proof of payout does not establish proof of production.

ASSESSMENT: MODERATE-TO-HIGH CONFIDENCE

HashFlare’s longevity was likely assisted by the technical credibility created by an active dashboard, real cryptocurrency payouts and the existence of at least some genuine mining infrastructure.

The precise contribution of each factor requires additional evidence.

ASSESSMENT: OPEN

The final percentage of verified victim losses that will be recovered through the more-than-$400-million forfeiture pool remained unknown as of the archive date.

THE KLEPTIK VIEW

HashFlare sold computation.

That should have made the business easier to verify than many investment schemes.

A computer exists or it does not.

A mining rig consumes electricity or it does not.

A pool records hash power or it does not.

A blockchain records rewards or it does not.

Yet hundreds of thousands of customers still relied upon something far easier for the company to control:

A SCREEN.

The screen displayed numbers.

The numbers moved.

Mining appeared to occur.

Profits accumulated.

Withdrawals sometimes arrived.

That combination creates enormous psychological confidence.

Customers may reasonably think:

I can see my mining.

But they cannot.

They can see the company’s representation of their mining.

Those are not the same thing.

HashFlare therefore belongs beside FTX and OneCoin in a broader Kleptik category:

THE CLOSED-LOOP PROOF PROBLEM

The company makes the claim.

The company maintains the database.

The company operates the dashboard.

The company tells the customer the dashboard proves the claim.

Independent verification disappears.

That architecture becomes especially dangerous when the underlying activity occurs somewhere customers cannot easily inspect.

A server farm.

A trading algorithm.

A private investment account.

A reserve wallet.

An offshore fund.

The user sees output.

Not production.

HashFlare also demonstrates why payouts can be deceptive.

A customer requests Bitcoin.

Bitcoin arrives.

That feels like proof.

But the investigative question is not:

Did you get paid?

It is:

WHERE DID THE MONEY THAT PAID YOU COME FROM?

If a mining company pays using Bitcoin it bought on an exchange rather than Bitcoin it mined, the withdrawal proves only that the company had access to Bitcoin.

It does not prove mining occurred.

The same principle applies to every investment product.

A dividend does not prove profit.

An interest payment does not prove lending income.

A crypto withdrawal does not prove reserves.

A rental distribution does not prove rental income.

A payout proves payment.

Nothing more.

HashFlare’s physical infrastructure provides another lesson.

Fraud does not always require a completely fictional company.

Some mining equipment apparently existed.

That can make the deception stronger.

Visitors may see machines.

Photos look real.

Technical staff exist.

The operation sounds plausible.

But seeing one unit of capacity does not prove one hundred units exist.

The deception may lie in scale.

That is why serious due diligence has to reconcile:

CLAIM

with

CAPACITY

with

OUTPUT

with

CASH FLOW.

For HashFlare:

  • How much mining was sold?
  • How much equipment existed?
  • How much electricity was consumed?
  • How much crypto was actually mined?
  • How much was purchased externally?
  • How much was owed to customers?

Those five questions may explain the entire business.

And they produce a broader rule for digital finance:

NEVER ALLOW THE PLATFORM TO BE THE ONLY WITNESS TO ITS OWN PERFORMANCE.

If a company claims to mine:

verify the mine.

If it claims to trade:

verify the custodian.

If it claims reserves:

verify the assets.

If it claims revenue:

verify the customers.

If it claims a bank is being built:

verify the licence.

The more sophisticated the dashboard looks, the more important independent evidence becomes.

Because software can make imaginary economics look mathematically precise.

THE DASHBOARD IS NOT THE ASSET.

THE NUMBER IS NOT THE PROOF.

FOLLOW THE MACHINES.

KLEPTIK METHODOLOGY

This dossier is dated 13 February 2025 and is intentionally fixed to the legal and evidentiary position existing on that date.

Later sentencing decisions, final forfeiture orders, victim distributions or subsequent litigation are not retrospectively incorporated into the historical narrative.

The principal evidentiary sources are:

  • the U.S. Department of Justice’s 13 February 2025 guilty-plea announcement
  • the Western District of Washington case record
  • the May 2024 extradition record
  • and

the original November 2022 charging materials.

Kleptik distinguishes between:

  • facts admitted through guilty pleas
  • allegations contained in the original indictment
  • assets agreed for forfeiture
  • final victim loss
  • and

analytical conclusions.

Potapenko and Turõgin pleaded guilty to one count each of conspiracy to commit wire fraud.

Therefore, broader original allegations concerning specific laundering transactions, shell companies and every originally charged asset should not automatically be described as separately adjudicated criminal facts unless incorporated into the plea record or independently established.

For cloud-mining investigations, Kleptik should verify claims through independent datasets wherever possible.

The preferred evidence hierarchy is:

PHYSICAL CAPACITY
Machine inventory, serial numbers, facilities and electrical infrastructure.

UTILITY DATA
Power draw consistent with represented mining activity.

POOL DATA
Hash-rate contribution independently recorded by mining pools.

BLOCKCHAIN DATA
Rewards traceable to identified mining activity.

FINANCIAL DATA
Hardware purchases, electricity costs and customer liabilities.

INTERNAL PLATFORM DATA
Dashboard records and customer ledgers.

Internally generated dashboard data should never outrank independent physical or blockchain evidence.

For victim-loss analysis, Kleptik distinguishes:

  • gross contract purchases
  • withdrawals already received
  • net investor loss
  • asset forfeiture

and amounts ultimately remitted.

For asset tracing, properties and vehicles should be connected to fraud proceeds through transaction-specific evidence.

Association with a defendant is not sufficient.

For professional-service providers, mining suppliers, banks, payment processors and exchanges, the fact that they serviced HashFlare or a related entity does not establish knowledge of fraud.

Material criticism requires evidence of knowledge, control failures or participation.

Where the report uses technical calculations such as estimated mining capacity, assumptions concerning machine efficiency, electricity consumption and hash rate should be disclosed so readers can reproduce the analysis.

Subjects facing new allegations beyond the adjudicated fraud should receive a meaningful right of reply.

EVIDENTIARY LABELS

ESTABLISHED — GUILTY PLEA
Conduct admitted by Potapenko or Turõgin in federal court.

ORIGINAL INDICTMENT ALLEGATION
Claim contained in the 2022 indictment but not automatically treated as independently adjudicated through the later plea.

PHYSICAL-CAPACITY INDICATOR
Evidence concerning hardware, facilities or electricity relevant to actual mining capability.

PRODUCTION INDICATOR
Mining-pool or blockchain evidence relevant to real cryptocurrency output.

DASHBOARD CLAIM
Information generated internally by the investment platform and requiring external corroboration.

SOURCE-OF-RETURN INDICATOR
Evidence identifying whether customer payouts arose from represented business activity or another funding source.

FORFEITURE VALUE
Assets defendants agreed to surrender; not equivalent to final victim reimbursement.

KLEPTIK VERIFIED
Fact independently corroborated through primary records.

KLEPTIK ASSESSMENT
Analytical conclusion derived from identified evidence.

INVESTIGATIVE LEAD
Matter requiring additional transaction, capacity or asset-level verification.

UNVERIFIED
Information insufficiently corroborated for factual publication.

DOCUMENT STATUS

KLTK-2025-014

Subject: HashFlare / Sergei Potapenko / Ivan Turõgin / Cloud-Mining Fraud
Archive date: 13 February 2025
Status at archive date: Guilty pleas entered; sentencing pending; more than $400 million in forfeitable assets agreed
Historical treatment: Fixed to report date

© KLEPTIK — Investigations into Power, Money and the Systems Designed to Hide Both

▚ THE KLEPTIK BRIEF

Follow the money — in your inbox.

A regular briefing on corruption, sanctions and illicit finance. No spam, unsubscribe anytime.