Live data from Hacker News

Feds arrest couple, seize $3.6B in hacked Bitcoin funds

washingtonpost.com

781–790 of 901 posts

Re: Feds arrest couple, seize $3.6B in hacked Bitcoin funds

#781

fwiw, it appears one of the named here is a YC Alum: https://news.ycombinator.com/user?id=il https://www.linkedin.com/in/unrealdutch/

This is just unreal. this guy was living a double life of being the greatest criminal ever. So among our community was a $4 billion hacker, just nonchalantly posting. I don't think he will be commenting anytime soon again if this really is him https://news.ycombinator.com/threads?id=il like your neighbor being a serial killer or something

A hacker? On Hacker News? Well, I would never.

Re: Feds arrest couple, seize $3.6B in hacked Bitcoin funds

#782
post #566

Earlier quoted context omitted.

jeez man, not every comment has to be a profound statement. I thought it was pretty interesting.

Just curious, what did you think was pretty interesting about it? The fact that one human knew another? The fact that someone on HN knew this person? Not trying to troll, is there something here I'm missing?

The prototypical HN comment.

Re: Feds arrest couple, seize $3.6B in hacked Bitcoin funds

#783
post #754

Earlier quoted context omitted.

You don’t need splitting the private key. Bitcoin has multisig setup. For example, you can setup your wallet such that 6 out of 10 private keys need to sign in order to transfer funds. Spread that 10 private keys out. Or 3 out of 10. Or 2 out of 5. Any n out of m.

You're right, gathering multisigs would be much safer than gathering SSS shares because you wouldn't be carrying around bits of the private key.

Any single SSS share does not disclose any additional information about the private key (i.e. it is not like splitting the key itself into parts).

Re: Feds arrest couple, seize $3.6B in hacked Bitcoin funds

#784

Earlier quoted context omitted.

>why do we need a distributed ledger? well the most obvious answer to that question is, we don't.

Why do we need fiat currency where self-interested parties inflate the currency & pay themselves?

Isn't crypto plagued with the same problems? Sure fiat isn't perfect but it doesn't look like crypto is solving any of those problems, as exemplified here.

Re: Feds arrest couple, seize $3.6B in hacked Bitcoin funds

#785

> “digital currency heists executed through complex money laundering schemes could undermine confidence in cryptocurrency,” said U.S. Attorney Matthew M. Graves Well now you US prosecutors aren't reading hacker news!

now you ^know

Re: Feds arrest couple, seize $3.6B in hacked Bitcoin funds

#786

Shouldn't all true crypto believers hate this news? It's the government trying to enforce their opinion of who should own those Bitcoins, thereby taking power away from the owner that the network has decided on, which would be "whoever has the cryptographic keys".

"Shouldn't all true crypto believers hate this news?"

I for one am very sad about this news but much more sad about the reaction of "crypto OGs"

Re: Feds arrest couple, seize $3.6B in hacked Bitcoin funds

#787

Earlier quoted context omitted.

A fancy (or even basic) dictionary attack has a very high chance of working.

It doesn't unless you chose something stupid like "correct horse battery staple" or "word + word + number". 7 words chosen from 1000 word dictionary password encrypted AES 256 cannot be cracked with existing technology, 8 words impossible with future tech.

That depends entirely on the hash function being used.

With a bad choice like SHA256, a 7 word passphrase could be cracked in as little as a few months with a single ASIC. The US government probably has a bunch of them already, so I think that an 8 word passphrase is already within reach for current tech.

Of course, with a real key derivation function like Argon2id, things would look much better.

Re: Feds arrest couple, seize $3.6B in hacked Bitcoin funds

#788

Earlier quoted context omitted.

Is it illegal to sell your artwork at an auction, and a criminal happens to be the one to buy it? I honestly don't know. is the onus on an artist or on an "auction house" to vet buyers. If post sale it turns out the money was fraudulent, does the artist need to pay it back? In crypto terms. You the artist simply put a NFT up for auction at OpenSea. You the scammer happened to purchase the artwork on OpenSea. However…

In a closely related scenario, if you sell a kilogram of gold to a buyer who pays in counterfeited US currency, then the secret service will seize the $50,000 and you will not be compensated. Doing business with criminals can bite you, even if you were not participating in a criminal enterprise.

I don’t think thats quite the whole story though. The feds would have no obligation to make you whole but you would almost certainly have a civil cause of action vs the buyer for the full amount, if you could ever collect. So don’t do business with people who can disappear or avoid court judgements.

Re: Feds arrest couple, seize $3.6B in hacked Bitcoin funds

#789
post #510

Earlier quoted context omitted.

Is it me or should he have literally just gotten a hardware wallet, transferred everything to that account, then burned the old key? Of course that txn would show up on-chain, but if you don't have possession of the private key for the first account, and no digital device has ever "seen" the hardware account then he would've been fine. This is assuming the key piece of evidence was his private key, and he wouldn't ha…

With a hardware wallet there is still a paper trail that you bought the device. So the feds will be looking for them. Printing the paper wallets, putting them in a $1 glass jar with a silica packet and burying in your back yard would have been 100 times smarter.

There is zero link between a hardware wallet's private key and the original account that purchased the wallet.

Re: Feds arrest couple, seize $3.6B in hacked Bitcoin funds

#790

Earlier quoted context omitted.

This is just unreal. this guy was living a double life of being the greatest criminal ever. So among our community was a $4 billion hacker, just nonchalantly posting. I don't think he will be commenting anytime soon again if this really is him https://news.ycombinator.com/threads?id=il like your neighbor being a serial killer or something

that money was never real, they never had a chance of spending even 0.1% of it. lol does anyone really think they could have accessed and spent that much money, in any way?

they did take a small yet real PPP money :)

https://www.thedailybeast.com/heather-morgan-rapping-tech-ce...

“The only other significant deposit to the account was an approximately $11,000 U.S. Small Business Administration Paycheck Protection Program (PPP) loan advance provided in response to the COVID-19 crisis,” the complaint states.

Post reply on HN