Crypto news report · source clearly identified
Sality Botnet Dismantled After Eight Years of Stealing Bitcoin and Ethereum
CrowdStrike and the U.S. Department of Justice isolated more than 15,000 infected machines in a coordinated takedown of the Sality botnet across four countries.

A joint operation by cybersecurity firm CrowdStrike and the U.S. Department of Justice has taken down the Sality botnet, which operated for eight years and was used to steal Bitcoin and Ethereum from compromised systems.
Scope of the takedown
The effort isolated over 15,000 infected computers spanning four countries, disrupting the botnet’s ability to continue illicit cryptocurrency theft.
Impact on stolen assets
Sality was known for targeting Bitcoin (BTC) and Ethereum (ETH) wallets, siphoning funds from victims over its operational lifespan. The takedown halts further exfiltration of these assets.
Law enforcement and industry collaboration
The operation highlights the growing cooperation between law enforcement agencies and private cybersecurity firms to combat crypto‑related malware threats.
What’s next for affected users
Owners of compromised machines are advised to run reputable anti‑malware tools, change wallet credentials, and monitor their cryptocurrency accounts for unauthorized activity.
Source & attribution
News Source
- Publisher
- Decrypt
- Original date
- September 2, 2026, 11:30 AM
- Original headline
- Sality Botnet Dismantled After Eight Years of Stealing Bitcoin and Ethereum