Live data from Hacker News

Experts cracked laptop of crypto CEO who died with $137M, but the money was gone

businessinsider.com

121–130 of 345 posts

Re: Experts cracked laptop of crypto CEO who died with $137M, but the money was gone

#121
I am curious to know the OS on the laptop that was cracked. macOS, Linux, Windows? I would be surprised if a highly technically founder was running Windows.

Does this indicate there is a known vulnerability in the login process of the OS?

Re: Experts cracked laptop of crypto CEO who died with $137M, but the money was gone

#122

Earlier quoted context omitted.

There are actually whole cryptographic schemes people have written to prove you have control over the money you say you do. https://news.ycombinator.com/item?id=7277865

But how do you prove how much you owe? If an exchange can prove it controls 10 BTC, great. But what if it owes 20 people 1 BTC each?

That would be 20 coins - 10 they don't have.

On an exchange you have no proof.

Re: Experts cracked laptop of crypto CEO who died with $137M, but the money was gone

#123

Banks and actual currencies still have a bright future.

As far as I'm concerned, if you give your money to some dude on the internet with ZERO oversight or regulation, you're pretty much guaranteed something like this happening at some point. how is this different than giving cash to your cousin's uncle who promises to give it back "whenever you need it"?

Re: Experts cracked laptop of crypto CEO who died with $137M, but the money was gone

#124
post #108

Earlier quoted context omitted.

Which claim is "extraordinary"? That some humans pretend to die before their actual deaths? That some humans are greedy? I got a bridge I'll sell you real cheap...

Pretending to die is an extraordinarily rare occurrence, yes.

Having incentives worth $137M is a rare circumstance. In that circumstance, such an occurrence would be less rare.

Re: Experts cracked laptop of crypto CEO who died with $137M, but the money was gone

#125
post #48

My take on this is that they probably were insolvent for a long time already due to previous hacks/theft. The CEO just decided to lie about the supposedly 137M in funds 'safely' stored on his laptop. This is also what happened at MtGox, except that at MtGox they 'lost' wel over a million BTC. Edit: relevant listening: https://darknetdiaries.com/episode/9/

And this is the problem. These guys are not regulated. There is no transparency. There are no external auditors. There is no control. When we find out, it is always too late. Every "cryptocurrency bank" is a potential Enron. I fear both the involvement of Central Banks and at the same time the lack of it.

If EY (or anyone else serious about this) 'follows the money' then that would be a very interesting report to read.

Re: Experts cracked laptop of crypto CEO who died with $137M, but the money was gone

#126
post #86

Earlier quoted context omitted.

There are several documentaries on YouTube exploring how easy it is to fake death certificates in, say, Delhi. Search for ‘quacks’

didn't initially get in hits for that search term that were relevant, what am I looking for?

https://www.scamcities.com/scam-city-season-1-episode-6-new-...

Re: Experts cracked laptop of crypto CEO who died with $137M, but the money was gone

#127
post #105

Earlier quoted context omitted.

This is close enough to true for the purposes of this discussion, but in the general case you can only reliably track the flow of funds in aggregate, not the flow of any individual "coin." If addresses A and B send equal amounts of coins to C, C sends all of those coins to D, and D sends half of them to E, you can't really track the coins from A to E or from B to E. The transaction from C to D results in a single out…

You track D and E. At scale, there surely are consistent patterns.

Yes, but my example was contrived for simplicity, and really D can make a transaction with an arbitrary number of inputs and outputs sent to and from an arbitrary number of addresses belonging to an arbitrary number of users. This is what bitcoin mixers do. Now we have a bunch of inputs coming in, and a bunch of evenly sized outputs coming out (with some unevenly sized ones for change). You can still probabilistically track funds if a user did something like putting coins from D into a big mixing transaction with other users and then sending their mixed coins from address F though I to a single address J that just so happens to have the same balance D started with, and of course there are less contrived situations where patterns of behavior would be evident, but this is all probabilistic and you still aren't really tracking individual coins; discrete coins aren't stored on the blockchain, transactions with input and output balances are. If the missing funds are tracked, and this whole affair was the result of malevolence rather than incompetence, I'd bet they're either sitting in a bunch of tiny accounts that have been cycled through mixers more than once or they're going to be before they're spent (having faked your own death, you could see holding off on the mixer until you've had ample time to cover your trail thus giving the appearance of incompetence rather than malevolence for a while).

Re: Experts cracked laptop of crypto CEO who died with $137M, but the money was gone

#128

Earlier quoted context omitted.

You can just threaten to reverse any transaction they ever make.

I think double spend coins as well, but don't quote me.

You can't double spend -- you would need to generate 2 conflicting tx's with the private key. Only the person that holds the money can attempt a double spend, the miners only process and include (or exclude) transactions.

Re: Experts cracked laptop of crypto CEO who died with $137M, but the money was gone

#129
post #96

Earlier quoted context omitted.

But would they even risk raising suspicion?

I'm confused why anyone in this thread chain would think a firm like Ernst and Young would have access to zero-days?

0days are not magic. Stare enough at code and you will find them. E&Y and the other Professional Services companies have a big pentesting team, and they would have made discoveries on their own regarding system security. Any company with a large security / research team would have 0days. What they do with them, (report, sit, burn, etc) is up the organizational and individual ethics of the operator.

Re: Experts cracked laptop of crypto CEO who died with $137M, but the money was gone

#130

I am curious to know the OS on the laptop that was cracked. macOS, Linux, Windows? I would be surprised if a highly technically founder was running Windows. Does this indicate there is a known vulnerability in the login process of the OS?

If i was to guess, i would guess that it was Bitlocker vuln, CVE-2018-12037, where the bitlocker crypto implementation is left to the junk SSD 'self encrypting' feature which is found to be broken. I have my doubts they cracked Veracrypt, LUKS or filevault2 with operator supplied keys. Or they got the keys from Microsoft/Apple (filevault2 and bitlocker will escrow the keys to the OS vendor in home editions).
Post reply on HN