Live data from Hacker News

DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside

justice.gov

181–190 of 296 posts

Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside

#181

Earlier quoted context omitted.

I don’t think it’s an understatement to say that their reach kind of is. If sanctioned the US government could almost certainly 51% attack any given crypto and redirect funds to whoever they want. This isn’t what happened but it’s laughable to think the US government isn’t capable of tracking down the account and seizing coins.

then the hackers would just send a little bit at a time in case it gets intercepted

It was just an example. If the US government is dead set on hurting you they can and will; that’s my point.

Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside

#183

Earlier quoted context omitted.

The reason why this story doesn't make sense is because it's most likely a lie. Think about it for a second. If they wanted to discourage copycat criminals, the easiest way to do it would be to claim they seized the crypto, right? But what proof do we have that the feds actually seized anything? Is the bitcoin transaction publicly listed anywhere where we can audit what happened? And even if you see the coins were mo…

> what proof do we have that the feds actually seized anything? I'm sure the feds will sell the bitcoin in the fullness of time, like this: https://www.usmarshals.gov/assets/2020/febbitcoinauction/

Won't they hand them back to the pipeline owner who paid the ransom?

Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside

#185
post #97
post #76

Earlier quoted context omitted.

Really informative video but this is talking about hashing functions. Private keys are created differently using (some) shared information between the private and public keys. If there was one area I could see the us investing their time and effort since RSA came out it's here. Don't get me wrong, it would be out there if they could crack even one key but like I said, if anyone can it's them.

No. If anyone had the ability to crack bitcoin addresses, they would not spend that technology on something as inconsequential as this. It would be saved for national defense issues

Completely agree but it could be perceived as a show of strength.

Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside

#186
post #76

Earlier quoted context omitted.

Really informative video but this is talking about hashing functions. Private keys are created differently using (some) shared information between the private and public keys. If there was one area I could see the us investing their time and effort since RSA came out it's here. Don't get me wrong, it would be out there if they could crack even one key but like I said, if anyone can it's them.

Bitcoin keys are ECDSA (secp256k1) keys. The same scheme is used in many other areas of computer security; it would be incredibly foolish for the NSA to reveal an exploit they're sitting on, even indirectly.

Would it really be that foolish though? Could it not be perceived as a show of strength? That's why America stole them back in the first place right? $4m isn't a lot to the company hacked or to the USA. Why go to the trouble of stealing them back at all?

Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside

#187

I am guessing that the key pair generation process was faulty. The FBI found an exploit in a wallet used by the hackers allowing the private key to be predicted. The prefix is bc1,which is uncommon. A few weeks ago there was such a vulnerability with Cake Wallet. Or they installed malware on the hacker's computers and were able to log the private key as it was generated. Or the hackers foolishly stored the key pairs…

Almost certainly what's not secure is the endpoint, wherever the keys were stored. That shouldn't really be news. The endpoints are always the weakest links in an encrypted channel.

Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside

#188

Earlier quoted context omitted.

Colonial paid 75 BTC, and they recovered 63.7 BTC.

I'm guessing the rest was fees/etc coming out of the crypto tumblers they used?

Apparently the take was sliced 85/15 affiliate to developer.

Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside

#189
post #4

There are more technical details in the linked affidavit (page 6 and 7): https://www.justice.gov/opa/press-release/file/1402056/downl... They kept following transactions on the blockchain, but it's not clear how the private key became in the posession of the FBI.

>Based on ... I have probable cause to believe that the aforementioned property may be seized... Forgive me if this is a dumb question; I have not used a blockchain explorer for anything consequential. Isn't that wallet just the last place it ended up? So, you have chain of custody but does that prove that the owner of that wallet is the "target"?

I think generally speaking, someone in possession of stolen property isn't entitled to keep that property even if they had nothing to do with the theft and had no reason to believe it was stolen. That prevents them from being guilty of a crime - but authorities can still come seize the property without compensating them at all for their loss.

In a way it's similar to getting stuck with counterfeit money. You didn't do anything wrong, but no one is going to just hand you the replacement real money you "deserve" - you just got unlucky.

Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside

#190
post #102

Earlier quoted context omitted.

They didn't use any tumblers, that's how they got caught. edit: it says so in the article: As alleged in the supporting affidavit, by reviewing the Bitcoin public ledger, law enforcement was able to track multiple transfers of bitcoin and identify that approximately 63.7 bitcoins, representing the proceeds of the victim’s ransom payment, had been transferred to a specific address

I think tumblers can be traced if they are backfired or monitored. Though perhaps that requires more assumptions than the fact that they were incompetent and didn’t use any.

Honest question: what would a backdoored mixer look like? If it had a list of trapdoor addresses (or checked addresses in real-time) and made last-minute transaction changes, say. Would any criminal risk complaining if it identified them? Does the tumbler’s reputation have a mechanism for angry criminal user stories?

The tumblers seem like a centralized chokepoint for criminals trying to launder.

Post reply on HN