Live data from Hacker News

North Korean hackers stole a record $1.7B of crypto last year

economist.com

51–60 of 203 posts

Re: North Korean hackers stole a record $1.7B of crypto last year

#51

"mixers—large digital pools where crypto owners can deposit funds to obscure their origins." I have a quibble with articles about cryptocurrency fraud. They always get around to mixers and then they define it as if it were some relatively legitimate thing, like an odd bank. "large digital pools", "deposit funds". You have to get to the last phrase ("obscure their origins") to understand what mixers really are. A prop…

I don't understand why technology that provides a modicum of privacy must be demonized. It must be for money laundering and criminals. It can't have a legitimate use case. Is it used for nefarious activities? Of course, but not exclusively so.

If 99% of BTC mixers' volume is helping laundering international drug trade money, arms or human trafficking, it's not exactly hard to demonize mixing itself. I have no data to base this on, but I assume that privacy absolutists are a tiny, tiny drop in the pool of blood and crime.

Re: North Korean hackers stole a record $1.7B of crypto last year

#52

As a blockchain security guy, it's really easy to spot the occasional North Korean heists on Ethereum. The big tells are: 1. They hack computers not code. Their normal plan is to steal keys by compromising users and computers. This is in contrast to the normal "hack" that works by finding and exploiting bugs in code. 2. They immediately exfiltrate the stolen money back to the real world via bazillions of mule account…

> Their normal plan is to steal keys by compromising users and computers. This is in contrast to the normal "hack" that works by finding and exploiting bugs in code.

That's the primary way hacks are conducted by most hackers. Hackers are primarily social engineers, not technical. Technical hackers are extremely rare regardless of nationality.

Re: North Korean hackers stole a record $1.7B of crypto last year

#53

"mixers—large digital pools where crypto owners can deposit funds to obscure their origins." I have a quibble with articles about cryptocurrency fraud. They always get around to mixers and then they define it as if it were some relatively legitimate thing, like an odd bank. "large digital pools", "deposit funds". You have to get to the last phrase ("obscure their origins") to understand what mixers really are. A prop…

I don't understand why technology that provides a modicum of privacy must be demonized. It must be for money laundering and criminals. It can't have a legitimate use case. Is it used for nefarious activities? Of course, but not exclusively so.

Please give an example

Re: North Korean hackers stole a record $1.7B of crypto last year

#54
post #53

Earlier quoted context omitted.

I don't understand why technology that provides a modicum of privacy must be demonized. It must be for money laundering and criminals. It can't have a legitimate use case. Is it used for nefarious activities? Of course, but not exclusively so.

Please give an example

Signal: https://www.nytimes.com/2022/12/28/opinion/jack-dorseys-twit...

Re: North Korean hackers stole a record $1.7B of crypto last year

#55

As a blockchain security guy, it's really easy to spot the occasional North Korean heists on Ethereum. The big tells are: 1. They hack computers not code. Their normal plan is to steal keys by compromising users and computers. This is in contrast to the normal "hack" that works by finding and exploiting bugs in code. 2. They immediately exfiltrate the stolen money back to the real world via bazillions of mule account…

> 1. They hack computers not code. Their normal plan is to steal keys by compromising users and computers. This is in contrast to the normal "hack" that works by finding and exploiting bugs in code.

I'm just a 'regular security guy' but in that link you posted they detail that after the initial phishing compromise "The attacker managed to leverage that access to penetrate Sky Mavis IT infrastructure and gain access to the validator nodes." They don't detail the bugs that got them access to the nodes but this didn't give them control of the network so "the attacker found a backdoor through our gas-free RPC node, which they abused to get the signature for the Axie DAO validator. ...Sky Mavis requested help from the Axie DAO to distribute free transactions ... Axie DAO allowlisted Sky Mavis to sign various transactions on its behalf. This was discontinued in December 2021, but the allowlist access was not revoked."

Sounds like a pretty classic hack to me. They got into the network, got access to some important servers (how? they should be totally segregated from the corporate network). Then found a depreciated endpoint that allowed them blindly sign transactions. This is bread and butter for any pentesting work, makes me wonder if any of these web3 orgs are hiring security firms to test their systems and not just smart-contracts.

Re: North Korean hackers stole a record $1.7B of crypto last year

#56

Earlier quoted context omitted.

The crypto currency world is hyper focused on stopping this, considering it is one of the main avenues that statists attack crypto with now that the environmental nag is gone since the switch to Proof of Stake. I would say, conservatively, the traditional banking and real estate markets are 10,000x worse than crypto markets, but are un-policed because it's hidden, unlike the public blockchain networks. The few scams…

> The crypto currency world is hyper focused on stopping this Can you explain how? I'm super curious because the whole point of crypto is you can't reverse transactions, and therefore crypto is only ever as secure as computer security generally, and there's nothing crypto can do about computer security generally. Or are people coming up with some new paradigm here that fixes this somehow?

> Can you explain how?

By posting long tirades on Internet forums that surmise: "We have top men working on it right now. Top... men.."

Re: North Korean hackers stole a record $1.7B of crypto last year

#57
post #51

Earlier quoted context omitted.

I don't understand why technology that provides a modicum of privacy must be demonized. It must be for money laundering and criminals. It can't have a legitimate use case. Is it used for nefarious activities? Of course, but not exclusively so.

If 99% of BTC mixers' volume is helping laundering international drug trade money, arms or human trafficking, it's not exactly hard to demonize mixing itself. I have no data to base this on, but I assume that privacy absolutists are a tiny, tiny drop in the pool of blood and crime.

Would privacy absolutists even use BTC? I was under the impression that every transaction was out in the open and permanent.

Re: North Korean hackers stole a record $1.7B of crypto last year

#58
post #53

Earlier quoted context omitted.

I don't understand why technology that provides a modicum of privacy must be demonized. It must be for money laundering and criminals. It can't have a legitimate use case. Is it used for nefarious activities? Of course, but not exclusively so.

Please give an example

If you don't want to link your 'public' wallet with your cold wallets. General privacy on a chain where everyone can see everything.

Re: North Korean hackers stole a record $1.7B of crypto last year

#59
post #53

Earlier quoted context omitted.

Please give an example

Signal: https://www.nytimes.com/2022/12/28/opinion/jack-dorseys-twit...

Signal is not a crypto mixer. The argument here is about the frequency a certain service is used for crime.

For example, library records generally have a fair amount of privacy. Criminals sometimes consult libraries. Crime is not the dominant use of libraries.

Mixers have a fair amount of privacy. Mixers are used by criminal, and crime is overwhelmingly the dominant use of mixers.

To rebut this you’d need to show large and innocent use cases which use mixers. Not an unrelated app.

Re: North Korean hackers stole a record $1.7B of crypto last year

#60
post #57
post #51

Earlier quoted context omitted.

If 99% of BTC mixers' volume is helping laundering international drug trade money, arms or human trafficking, it's not exactly hard to demonize mixing itself. I have no data to base this on, but I assume that privacy absolutists are a tiny, tiny drop in the pool of blood and crime.

Would privacy absolutists even use BTC? I was under the impression that every transaction was out in the open and permanent.

The answe is no but they can make a trade off using something like monero. BTC's only read advantage is the network effects. As far as the tech is concerned it is mediocre compared with other ledgers.
Post reply on HN