Live data from Hacker News

The U.S. cracked a $3.4B crypto heist and Bitcoin’s anonymity

wsj.com

191–200 of 243 posts

Re: The U.S. cracked a $3.4B crypto heist and Bitcoin’s anonymity

#191

Earlier quoted context omitted.

The First Amendment.

Indeed, which is why you can get the Tornado source code off of github: https://github.com/tornado-repositories However, actually running the code to facilitate North Korean hackers launder money and personally profiting off of it? That's not covered by the first amendment, and I sincerely urge you to not try to find that out in the hard way.

> However, actually running the code to facilitate North Korean hackers launder money and personally profiting off of it?

Who is "running" the code?

The US government, to this date, has not made an argument that the developers of Tornado Cash, who have deployed the code to the Network, have committed a crime; at least one of them seems to be living in the US.

Nor has the government made an argument that operators of Ethereum nodes are committing a crime; they might also be considered to be running the code.

What the government has done is, through sanctions, instituted restrictions on Americans interacting financially with the smart contract. This has nothing to do with "running code"; this is operating under the assumption that the Tornado Cash smart contracts are an entity that is party to financial transactions.

Whether they have the power to sanctions non-entities like a smart contract is what the suit intends to find out.

Re: The U.S. cracked a $3.4B crypto heist and Bitcoin’s anonymity

#192
post #59

Earlier quoted context omitted.

Something something tornado cash?

It's a felony to use Tornado Cash now. And the government interprets sanctions law extraterritorially so you're not safe in other countries either.

> And the government interprets sanctions law extraterritorially so you're not safe in other countries either.

It does not; these sanctions only apply to US Persons. Secondary sanctions mean that the Treasury can additional designate non US-Persons for breaches of the primary sanctions, but that is a heavy-handed tool and unlikely to happen to people who merely use Tornado Cash; regardless, no law was broken by such a person.

Re: The U.S. cracked a $3.4B crypto heist and Bitcoin’s anonymity

#193

Earlier quoted context omitted.

But used as intended (not via a KYC exchange) it is pseudonymous, right?

Since the ledger is public, it can be analyzed for patterns from the individual transactions. The more transactions there are involving a certain party, the more likely an outside observer will be able to piece together identities for that party's overall network. KYC exchanges accelerate that process. Crypto projects like Monero (XMR) do not have this flaw, as deducing the identities of parties from the public ledge…

What if they use a mixer before major transactions and create disposable wallets to transact the funds that risk exposing their wallet?

Re: The U.S. cracked a $3.4B crypto heist and Bitcoin’s anonymity

#194
post #130

Earlier quoted context omitted.

Exactly - and that’s especially true if laws or other things change. For example, suppose that you made a donation to the political party which lost a key election to an authoritarian – are you sleeping easy at night wondering whether they have a data mining team?

I get the point you’re trying to convey but - at least in the US - you’re legally required to make donations to political candidates publicly anyway, so this isn’t really a regression over the status quo.

That's why you make your anonymous donation to the "Friends of John Smith" organisation, who is completely unaffiliated with John Smith and is merely interested in seeing him elected to office

Re: The U.S. cracked a $3.4B crypto heist and Bitcoin’s anonymity

#196

Zhong was caught because he made basic operational security errors, like address reuse (which is how he was caught by linking fraud wallet to exchange wallet) , static IP, using a KYC exchange in 2017 to convert BCH into BTC, etc. Not because Bitcoin was cracked. After being caught, Zhong voluntarily relinquished his passwords to encrypted wallets and other bitcoin, not that the crypto was cracked. I wonder how the f…

> found the digital keys to his crypto fortune hidden in a basement floor safe and a popcorn tin in the bathroom.

Apparently he didn't voluntarily give away he's secrets, they were found around his place.

Re: The U.S. cracked a $3.4B crypto heist and Bitcoin’s anonymity

#197
post #42

Earlier quoted context omitted.

they didn’t listen then and they don’t listen now. waste of effort.

Satoshi (and many other OG members of bitcointalk) knew, and tried to improve the protocol. BTC was not set in stone at the beginning. It's just at some point Satoshi disappeared, and moonfags[1] who controlled the capital (miners and exchanges) weren't interested in any technical improvements that may make regulators more angry, causing the end of most innovation in the cryptocurrency space. [1]Sorry for the very co…

Just say crypto bros. We all know someone who treats crypto like it's CrossFit. We'll get what you mean. Even a miner and exchanger is a crypto bro, even if they don't want to admit it. They're in it for the money.

Re: The U.S. cracked a $3.4B crypto heist and Bitcoin’s anonymity

#198

Earlier quoted context omitted.

But used as intended (not via a KYC exchange) it is pseudonymous, right?

If you trade in and out for cash, in person with a counterparty, from a self-hosted wallet that you never use to send or receive from any other wallet that's connected to an exchange... then yes. The use case for this is mainly moving money over borders.

Let's game this out. Bob and Alice are the first parties.

You trade in cash, in person, probably in a public place. Say that Alice then gets in trouble for the drug dealing they also do (or maybe the government just pings her for not doing KYC and being licensed to do financial transactions), it could be years later. The authorities seize Alice's computers and subpoena "localbitcoins", or the whatsapp/telegram/signal chat that you had to organise the meetup. They might even have a list of addresses that Alice used for transactions at this point. Alice may or may not have had good OpSec, Bob doesn't know.

From that there a myrriad options to identify Bob and Bob's addresses.

In your example you don't use an exchange, but that's not the only method of identifying Bob. Mass survelliance and metadata gathering noticed 100 phones within the location and timeframe Bob and Alice were supposed to meet. Bob had to take a phone to do the actual transfer of bitcoin (or any altcoin), so just leaving it at home wouldn't work. They also know the amount Alice transferred to Bob and the rough timeframe that it was completed and put into the ledger. Bob was also seen drawing out roughly the right amount from the ATM an hour before the meeting. Of the 100 phones, most haven't drawn out that much money recently.

So they can correlate a set of phones with a set of addresses. Even if Bob is not completely unmasked at this point. He has the money in but has to get the money out as well. Bob wanted as you say, to move money across the border. In order to do that Bob must cross the border[0] and meet with Charlie to do the reverse of the transfer. Only a handful of those 100 phones crossed borders shortly after meeting with Alice.

As soon as the money in that address moves again the cross reference with the locations of the tagged phones and discover that they know Charlie because he's done a KYC with an exchange and installed their app (even if he doesn't use that address for the transaction). They ask Charlie some pointed questions about whether he is following KYC procedures in his financial dealing and he caves and gives up the chat logs confirming your meeting, or maybe they just install NSO spyware on his phone and watch to find all the other people Charlie is dealing with.

So...

In a perfectly isolated one off instance maybe that's pseudonymous. In any real world transaction it's extremely unlikely that a state can't use it's resources to unmask the participants. In a one shot, the rules might be one way, but in multi-shot there are always factors that will serve to unmask the participants, and in reality you have to do those transactions over and over until you slip up and just combine them with a KYC exchange account and it doesn't even require that level of effort on the part of the state. OpSec is hard, as they say.

[0]: there is an alternative where only the bitcoin transaction crosses the border in return for something of value, either physical or digital, both have alternative paths that can be tracked in similar ways.

Re: The U.S. cracked a $3.4B crypto heist and Bitcoin’s anonymity

#199

Earlier quoted context omitted.

Are Bitcoin ATM's still a thing? There used to be one in a coffee shop near where I lived. If I deposited cash and wore a facemask and sunglasses, how would anyone ever know who did the transaction?

They require a phone number and an ID in some cases. Their exchange rates are normally not great either.

Bad exchange rates are the cost of money laundering, along with the eventual jail sentence.

Re: The U.S. cracked a $3.4B crypto heist and Bitcoin’s anonymity

#200

Earlier quoted context omitted.

How is that helpful? Get Bitcoin from crime Wash into monero? Pray the tumbler is legit? Wash back into Bitcoin Now what? Bitcoins from tumblers are suspect everywhere with kyc requirements. Sell off books to a Russian oligarch or North Korea I guess?

Mint some pixel art into NFTs and then purchase them with your anonymous filthy lucre wallet(s). Cash out after selling your subjective value art.

This scheme is so obvious that authorities are monitoring such trades and people have been convicted for money laundering by self-trading NFTs this way.

As always, you can definitely get away with this for smaller amounts, but if you go big and/or repeat it for a long time, this has all the potential to come back to you.

Post reply on HN