Live data from Hacker News

Feds arrest couple, seize $3.6B in hacked Bitcoin funds

washingtonpost.com

141–150 of 901 posts

Re: Feds arrest couple, seize $3.6B in hacked Bitcoin funds

#141

It seems that Tornado Cash ( https://tornado.cash/ ) could have been used to launder the funds. I wonder if: - Laundering happened before Tornado Cash existed, so Tornado Cash was not used - They used something like Tornado Cash, but the funds were still traceable

Another possibility is Ironfish( https://ironfish.network/ ), but I don't know how much liquidity there exists in either of these. I don't think you could launder/hide $4bn through either of these. Perhaps slowly over a long period of time.

Ironfish is just a testnet so there is zero liquidity there because it isn't even launched.

Tornado cash has about $700mm right now deposited in it, with the vast majority of that being in the 100 ETH deposit pool.

They absolutely could have done it over time. They could have bridged the Bitcoin using the RenVM protocol to receive renBTC, done a combination of selling the renBTC and let arbitrageurs provide the liquidity as the couple would have had to sell a little below market. They could then deposit the ETH in Tornado.cash. Simultaneously to speed things up, they could have deposited the renBTC into an onchain staking protocol to borrow against it, using the borrowed proceeds as their liquidity, and possibly even just forgetting about the collateral and letting the protocol take it eventually.

Even though they would be a large part of the Tornado.cash pool, it would actually only be "for now" because there are several other heists of large seizes that are turned away from Tornado.cash because it is too small. So liquidity begets liquidity. I would content that even if they had become 60% of the pool, boosting its size to $1.5bn, that it would have attracted many more deposits, I could see Tornado.cash being a $3bn pool by now, given the size of heists that I know of.

Tornado.cash of course is not good enough to reintegrate back into the economy, under your name. So then they could have employed the reintegration.

With clean money they earned from salary, they could have created a random token on the Ethereum network, lets call it SHIBA INU (SHIB), made sure to keep a bunch of the tokens for themselves, and then withdrawn tornado cash notes to 100,000 addresses which programmatically bought SHIB, and pumped the token 52885982.4% and just been a lucky trader that cashes out with long term capital gains they pay. They would have had many more billions doing that.

Its too bad that people could try to throw a "conspiracy to commit" charge at me too, the moment I use Tornado Cash or launch an erc20 token now, but its more important to me that my speech isn't chilled so that you all can have a better discussion about it.

Re: Feds arrest couple, seize $3.6B in hacked Bitcoin funds

#142
post #111

Earlier quoted context omitted.

Keys are conspicuously easy to hide. My PGP master key that I've been using for some time is hidden on two devices which would be difficult to identify much less locate and are encrypted as well.

They're easy to hide as long as the federal government isn't trying to tie you to 4.5 billion worth of something.

Even with the fervor of the federal government they'd be easy to hide.

A USB is tiny, and you can shrink it's footprint with USB-C. You can also buy USB keys with tamper-proof housings that will blow a fuse if opened to be physically compromised. Coupled with strong post-quantum crypto, that key is relatively secure, even if physically discovered.

That's just the technical bit. You can also split the key in half and transfer the other half somewhere, which creates legal protection. You could also create a housing for the key so it's not easily discoverable.

If all that sounds a bit extra, circle back to that the perpetrator has 4.5 Billion worth of something.

Re: Feds arrest couple, seize $3.6B in hacked Bitcoin funds

#143

Earlier quoted context omitted.

Well, the police had a search warrant, so the police could have found them if they had had them in their possession anyway. Sure, they could have destroyed them, losing the money but maybe not getting arrested?

vitalik (ethereum founder) used an interesting system. He split the key in 2. Wrote both on paper. Gave 1 paper to family and kept the other. Even if the police raid him (hypothetically), they cannot raid the houses of his family and friends at the same time This way the police or anybody else cannot get your private key.

or you end up with a useless half key or your trusted accomplice helps in the investigation

Re: Feds arrest couple, seize $3.6B in hacked Bitcoin funds

#144

Earlier quoted context omitted.

When a few billion is at stake, you think they'd make the effort to memorize the keys. Or at least encrypt them.

The file the feds found had 2,000 addresses - so there's a non-trivial amount of 12 word phrases to remember.

you would only need to memorize one seed to spawn infinite key pairs

Re: Feds arrest couple, seize $3.6B in hacked Bitcoin funds

#145
post #15

Shouldn't all true crypto believers hate this news? It's the government trying to enforce their opinion of who should own those Bitcoins, thereby taking power away from the owner that the network has decided on, which would be "whoever has the cryptographic keys".

Seems like a win to me. The government had to physically go to their house and arrest them to get to their funds, whereas normally all they had to do was call up their bank and had their money frozen. Not to mention, this threat could have been easily mitigated by keeping your funds in a multsig wallet, with the keys distributed in multiple redundant locations.

It's similar to privacy and surveillance.

To secretly monitor a single individual's communications, law enforcement should have to get probable cause, present their case to a judge and obtain a court order.

Dragnet surveillance of all communications all the time is a Very Bad Thing.

Financial surveillance and seizure is currently at the Very Bad Thing stage and bitcoin helps move us back toward a better balance between the rights of the individual and the interests of the state.

Re: Feds arrest couple, seize $3.6B in hacked Bitcoin funds

#146

> “After the execution of court-authorized search warrants of online accounts controlled by Lichtenstein and Morgan, special agents obtained access to files within an online account controlled by Lichtenstein,” the press release said. “Those files contained the private keys required to access the digital wallet that directly received the funds stolen from Bitfinex, and allowed special agents to lawfully seize and rec…

Tornado only works for eth. they would need a bridge. they were done-in by I am assuming to be a weak password, enough entropy would have made it uncrackable

good point. If they had tried to use a bridge to convert their bad bitcoin with good ethereum, would they have been denied service since everyone knew that these btc were bad?

As to your 2nd point, I agree. Another mistake was uploading private keys to google drive.

Re: Feds arrest couple, seize $3.6B in hacked Bitcoin funds

#147
post #15

Shouldn't all true crypto believers hate this news? It's the government trying to enforce their opinion of who should own those Bitcoins, thereby taking power away from the owner that the network has decided on, which would be "whoever has the cryptographic keys".

Seems like a win to me. The government had to physically go to their house and arrest them to get to their funds, whereas normally all they had to do was call up their bank and had their money frozen. Not to mention, this threat could have been easily mitigated by keeping your funds in a multsig wallet, with the keys distributed in multiple redundant locations.

> Not to mention, this threat could have been easily mitigated by keeping your funds in a multsig wallet, with the keys distributed in multiple redundant locations.

And if you're released from prison and recover your Bitcoin, you will be arrested again for contempt of court or a similar charge.

Re: Feds arrest couple, seize $3.6B in hacked Bitcoin funds

#148
post #111

Earlier quoted context omitted.

Well, the police had a search warrant, so the police could have found them if they had had them in their possession anyway. Sure, they could have destroyed them, losing the money but maybe not getting arrested?

Keys are conspicuously easy to hide. My PGP master key that I've been using for some time is hidden on two devices which would be difficult to identify much less locate and are encrypted as well.

strong passwords. aes256 with even just 7 word password chosen from a 1000-word dictionary cannot be cracked with existing tech

Re: Feds arrest couple, seize $3.6B in hacked Bitcoin funds

#149
post #90
post #34

Earlier quoted context omitted.

Random example but my passwords look something like chOf$Tyl83fhn@54R. I keep them written down because they are hard to remember. My threat model is no one. Seems so amateur to use a simple password that could be brute forced. Especially with so much on the line.

>Seems so amateur to use a simple password that could be brute forced. Especially with so much on the line. There's selection bias going on because only dumb criminals get caught, so you only hear about the dumb opsec practices of those criminals. Conversely, you'll never hear about the opsec practices of that professional crew with perfect opsec that hacked an exchange/difi contract and disappeared into thin air.

Until the least bright member of the crew makes a mistake, gets caught, and turns in the rest. Being perfect is difficult to maintain forever, though it's possible in principle. It might require the thief to live like a grad student even though he has billions of dollars/euros worth of stolen wealth; being flashy attracts attention and if nothing else, the tax authorities.
Post reply on HN