Quick overview: a federal court in the Southern District of Florida ordered the forfeiture of approximately $8.37 million in cryptoassets and physical property associated with Angelo Martino, a former ransomware negotiator convicted in a BlackCat/ALPHV conspiracy. The case is especially significant because the alleged insider was hired to protect victims while secretly helping attackers raise ransom demands.

1. Event overview: the negotiator was working for the attackers

Public reports published after July 19, 2026 described a forfeiture order in United States v. Martino, case number 1:26-cr-20065. Martino, 41, previously worked for DigitalMint, a Chicago-based incident-response and ransomware-negotiation company. According to U.S. Department of Justice materials and court reporting, he disclosed victim insurance limits and negotiating positions to BlackCat/ALPHV participants beginning in April 2023.

Five victim companies whose negotiations he handled reportedly paid approximately $75.3 million in ransoms. Martino pleaded guilty to conspiracy to commit extortion affecting interstate commerce, received a 70-month federal prison sentence in early July 2026, and became subject to the reported forfeiture. Two co-defendants, Ryan Goldberg and Kevin Martin, had previously pleaded guilty and received prison terms of about four years.

A critical distinction is necessary: this is a post-conviction forfeiture development in an older ransomware case, not a new exchange hack or an individual wallet theft occurring within the previous 24 hours.

How the insider scheme reportedly worked

Intelligence leakage: confidential insurance ceilings, maximum payable amounts and negotiation strategies were allegedly shared with attackers so demands could be set near each victim's limit.

Direct participation: prosecutors said Martino and two other former cybersecurity professionals participated in at least ten ransomware attacks rather than merely passing information.

Profit sharing and conversion: proceeds were reportedly divided and converted into BTC, XMR, XRP, XLM and SOL, as well as real estate, vehicles and a motorboat.

Case timeline

From April 2023, Martino allegedly used his negotiator role to disclose client information and assist BlackCat. Goldberg and Martin pleaded guilty in December 2025. Court documents were unsealed in March 2026, Martino pleaded guilty in April, and he was sentenced in early July. Reports concerning the approximately $8.37 million forfeiture circulated on July 19.

2. Attack and asset flow

The reported flow can be summarized as attack, insider-assisted ransom inflation, victim payment, profit sharing into multiple assets, and post-conviction forfeiture:

Reported BlackCat attack, insider-assisted ransom inflation, profit sharing and judicial forfeiture flow
Reported BlackCat attack, insider-assisted ransom inflation, profit sharing and judicial forfeiture flow

Third-party reports listed approximately 90.319 BTC, 7,999.873 XMR, 56,174 XRP, 39,760 XLM and a smaller SOL position, together with two properties, vehicles and a motorboat. Decimal amounts and execution status vary slightly between reports and should be checked against the final forfeiture order and original DOJ records.

3. How cryptoasset forfeiture works

1. Seeing an asset is not the same as controlling it

A complete forfeiture chain requires on-chain location, attribution to a controlled person or entity, acquisition of the private key or another control point, and lawful disposition. Blockchain analysis can identify where assets moved, but legal and practical control is required before they can be transferred or liquidated.

2. Why privacy-focused XMR could still be forfeited

Monero uses ring signatures, stealth addresses and confidential transactions to obscure amounts and counterparties. If nearly 8,000 XMR was included in a forfeiture order, investigators likely obtained an off-chain control point such as a seized device, seed phrase, private key, exchange account or identifiable fiat gateway. Privacy technology complicates chain analysis; it does not eliminate device, custody or cash-out exposure.

3. Traceability differs by asset

BTC, XRP, XLM and SOL use publicly visible ledgers that can often be reconstructed with address labels and exchange KYC records. XMR is substantially harder to analyze directly, so lawful seizure commonly depends more heavily on off-chain evidence and control. The reported multi-asset outcome illustrates how transparent-chain tracing and off-chain evidence can operate together.

4. Forfeiture is not the same as victim repayment

A forfeiture order transfers criminal proceeds or instrumentalities to the government. Restitution is a separate process for compensating victims. A reported forfeiture therefore does not mean the money has already reached affected companies.

4. Delta perspective: the forensic response logic

Preserve the starting evidence: retain addresses, transaction hashes, timestamps, account records and communications in their original form.

Reconstruct the full flow: follow funds across assets, chains, swaps and consolidation points rather than relying on one screenshot or transaction.

Cluster related addresses: use behavior, co-spend evidence and transaction patterns to identify wallets likely controlled by the same actor.

Identify reachable cash-out points: determine whether funds entered KYC-based exchanges, OTC desks or other entities capable of preserving records and responding to lawful requests.

Produce compliance-grade evidence: organize the timeline and supporting data into a report that platforms, counsel and investigators can act upon.

Privacy assets, mixers and cross-chain bridges can materially increase the difficulty of tracing. Not every transfer can be penetrated solely from public-chain data, which is why prevention, access controls and rapid evidence preservation remain essential.

5. Action checklist for companies and individuals

Apply least-privilege access, information separation and background checks when retaining external incident-response or ransomware-negotiation providers. Preserve transaction and account evidence immediately after an incident. Keep large holdings in appropriate cold-storage arrangements, regularly review historic approvals, and distinguish forfeiture announcements from completed restitution. Treat advance-fee promises of guaranteed recovery as a serious secondary-scam warning.

6. Industry implications: the largest vulnerability may not be code

The case shows that a trusted crisis-response professional can become a critical insider threat. Ransomware governance therefore requires technical controls, contractual oversight, conflict checks and auditable information access. It also demonstrates that crypto crime enforcement increasingly depends on combined on-chain forensics, lawful platform cooperation and fiat on/off-ramp controls rather than any single tracing technology.

Key concepts

Forfeiture order: a court order transferring criminal proceeds or instrumentalities to the government; it does not itself prove that assets have been liquidated or returned.

Restitution: the separate judicial process used to compensate victims.

Privacy coin: an asset such as XMR that obscures transaction amounts and counterparties through privacy-enhancing cryptography.

Address clustering: analytical methods that group addresses likely controlled by one actor.

KYT: transaction-level anti-money-laundering monitoring used to assess counterparties and fund flows.

Frequently asked questions

Q: Was this a new crypto theft?

No. It was a forfeiture development following conviction in an existing ransomware case.

Q: Will the reported $8.37 million go directly to victims?

Not automatically. Forfeiture and restitution are separate legal processes, and timing depends on court orders and execution.

Q: How could Monero be forfeited if it is difficult to trace?

Investigators may obtain control through seized devices, private keys, custodial accounts or identifiable cash-out infrastructure even where public-chain tracing is limited.

Q: Are all reported asset quantities final?

The conviction, sentence and insider conduct are supported by official and mainstream reporting, while exact quantities and execution status should be verified against the final order and original DOJ publication.

Q: Can stolen assets always be recovered?

No. Outcomes depend on traceability, reachable custody points, preserved evidence and lawful cooperation. No legitimate provider can guarantee recovery.

Q: Is it still safe to hire an external ransomware negotiator?

External specialists can remain valuable, but organizations should use vetted providers, least-privilege access, dual authorization, conflict checks and auditable communications.

Q: How quickly should a professional forensic team be contacted?

Evidence should ideally be preserved and reachable cash-out points assessed within the first 24 to 72 hours.

Risk and compliance notice: this article is provided for security, anti-fraud and investor-education purposes. It is not investment or legal advice and does not promise recovery, unfreezing or any particular enforcement outcome. Report theft or fraud through lawful channels, preserve original evidence and remain alert to secondary recovery scams.