Live data from Hacker News

Feds arrest couple, seize $3.6B in hacked Bitcoin funds

washingtonpost.com

231–240 of 901 posts

Re: Feds arrest couple, seize $3.6B in hacked Bitcoin funds

#231
post #18

Earlier quoted context omitted.

Computer Fraud and Abuse Act covers any unauthorized access regardless of how the credentials were obtained or... magically guessed.

In the scenario outlined there would be no unauthorized access to any systems, whether owned by Bitfinex or anyone else, so I really don't see how the CFAA could possibly apply here. As for the cryptocurrency network itself, the protocol is that anyone who has the private key is authorized to spend the corresponding funds—how the key was obtained is irrelevant. Of course, correctly guessing a 256-bit random private k…

[deleted]

Re: Feds arrest couple, seize $3.6B in hacked Bitcoin funds

#232

Earlier quoted context omitted.

When a few billion is at stake, you think they'd make the effort to memorize the keys. Or at least encrypt them.

The file the feds found had 2,000 addresses - so there's a non-trivial amount of 12 word phrases to remember.

You only need to remember a big random number (can be a long phrase from a book you like), and a rule that generates keys, e.g. (keyid, seed) -> hash(keyid + seed). Needless to say, you never write the seed phrase down. At most you keep a vague pointer to the author of that book.

Re: Feds arrest couple, seize $3.6B in hacked Bitcoin funds

#233
post #215

Ilya Lichtenstein (YC S11) is the co-founder of YC-backed MixRank. Heather Morgan, his wife, is apparently a serial entrepreneur, investor, and "contributor" to Forbes.

Her Forbes bio:

Heather R. Morgan is an international economist, serial entrepreneur, and investor in B2B software companies. She is an expert in persuasion, social engineering, and game theory.

Re: Feds arrest couple, seize $3.6B in hacked Bitcoin funds

#234
post #223

Earlier quoted context omitted.

Let's be fair to these individuals and not presume guilt. In the US, it's "innocent until proven guilty". Media is so quick to assume the person is guilty just because of an allegation.

That's the standard for our criminal justice system, not for us as individuals. It sounds from the release that the justice department has a boatload of compelling evidence against them.

> "It sounds from the release that the justice department has a boatload of compelling evidence against them."

You'd hope that before someone is arrested, the prosecutor has ample evidence to prove guilt.

I don't understand your point.

These individuals have not been proven guilty yet. Why are you editorializing their presumed guilt in this matter.

Note: I have no affiliation with these individuals nor case.

Re: Feds arrest couple, seize $3.6B in hacked Bitcoin funds

#235

fwiw, it appears one of the named here is a YC Alum: https://news.ycombinator.com/user?id=il https://www.linkedin.com/in/unrealdutch/

This is just unreal. this guy was living a double life of being the greatest criminal ever. So among our community was a $4 billion hacker, just nonchalantly posting. I don't think he will be commenting anytime soon again if this really is him https://news.ycombinator.com/threads?id=il like your neighbor being a serial killer or something

I'm really amused that he is currently listed as a mentor for 500 Startups. I wonder how good his advice has been?

Re: Feds arrest couple, seize $3.6B in hacked Bitcoin funds

#236
post #99

Earlier quoted context omitted.

I don't understand the math but I think I have seen that style of secret management where any 3 of say 10 secrets can access something but no 2 or any 1 secret can do it. It would seem to solve a lot of just organizational problems where "jan is out of the office today" and nobody can do the thing ... but if access is spread out among 10 people ... 3 probably are in the office when needed. Granted I've never seen it…

I have used it. It works. Tooling is still pretty poor. Every use, we ended up bringing the necessary people into a room, booting up an offline laptop from a sha-summed live USB, QR code scanning each of our secrets, combining them, then using the key to sign whatever we needed to sign, photographing the signature as a QR code. We use software from 2008 because an OS stack contains code from tens of thousands of deve…

Yeah it seems very much like an elegant solution whose usage would be a bit of its own kind of beast to deal with.

Re: Feds arrest couple, seize $3.6B in hacked Bitcoin funds

#238

Does this mean users who lost everything on bitfinex will be contacted and could possibly recover their coins? Can you imagine waking up to realize you are rich because the feds seized the coins and are returning to you.

Fascinating way to HODL to the token indeed.

Re: Feds arrest couple, seize $3.6B in hacked Bitcoin funds

#239

Sometimes I wonder what the chances are that certain (highly privileged) staff at Google (or other similar data storage or e-mail companies) could run a query across Google Drive looking for a specific public key. Much like a malware scanner, just looking for "a key", just to see if there is an account matching. Unofficially, of course. A rogue employee perhaps. And, what if, in such a case, the employee (in the best…

Google already scans drives for copyright infringement.

Re: Feds arrest couple, seize $3.6B in hacked Bitcoin funds

#240

Earlier quoted context omitted.

Ironfish is just a testnet so there is zero liquidity there because it isn't even launched. Tornado cash has about $700mm right now deposited in it, with the vast majority of that being in the 100 ETH deposit pool. They absolutely could have done it over time. They could have bridged the Bitcoin using the RenVM protocol to receive renBTC, done a combination of selling the renBTC and let arbitrageurs provide the liqui…

Excellent post! I have a question: is it possible to write scripts to do the above automatically? Or does it have to be a manual process? Few people understand the ecosystem thoroughly (I admit that I do not), so few people can implement the manual process properly. One mistake equals 0 privacy. Also, would they be allowed to use renVM since everyone knew that these accounts contained bad bitcoin?

It is possible to write scripts to do this automatically, and randomized activity.

There is a push for more and more permissionless bridges. All the bridge builders and their communities shy away from that obvious discussion because they do host and earn basis points from any crypto that passes over the bridge, even if it is obviously from a heist. It would put a bridge, especially that bridge, in a tough spot if these hackers did too much too soon, the hackers would have needed to be watching bridge technology and from this indictment it just looks like they werent.

Post reply on HN