Live data from Hacker News

DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside

justice.gov

71–80 of 296 posts

Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside

#71

Earlier quoted context omitted.

The warrant does not imply that the coins were on an exchange. The warrant only indicates that they needed legal authority to seize coins, wherever they are. It seem more likely that the FBI/NSA had and gained some access to the gang's infrastructure and seized the money. Transmitting ransom money to an exchange without any type of tumbler or atomic swapping, that it's not a realistic scenario. Maybe they tried to us…

The warrant is for a location in Northern California and they needed a warrant to get it. Use your head man, this means they literally went to a Federal Judge and said "hey we have probable cause that this address is on Coinbase" and the Judge was like "wow that is pretty probable" and then they took the warrant to Coinbase who was like "oh damn that's legit ..... can we squirm out of dealing with this .... no ... oh…

>The warrant is for a location in Northern California and they needed a warrant to get it.

Not neccessarily.

https://www.justice.gov/opa/press-release/file/1402056/downl...

The FBI in Northern California simply needed permission to use the Private Key they already had to access the bitcoin address.

The court that has jurisdiction over these types of crimes is in Northern California.

Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside

#72
post #66

Earlier quoted context omitted.

When your government greenlights criminal activities against their enemies it helps a lot. Many* cyber criminals act as mercs for hire, and are in fact hired for official government operations against the US. It's simply not true that political boundaries don't factor in. They're a massive part - most obviously, consider extradition or whether the attacker's government will cooperate with the US. * I say many, but it…

It is absolutely trivial for an attacker in the US or anywhere to make their ransomware attack appear to come from Russia (to someone who doesn’t know that).

I don't see how that's relevant to the incentives of foreign enemies attacking us. As I said, there are many. It basically stops being criminal activity.

Do you really think that's not the case, or that that isn't going to considerably skew where these attacks come from?

Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside

#73
post #8

The most interesting and unknown question is how the DOJ/FBI came to be in possession of the private key.

If they carried out the attack they would have had the private key in their possession.

That was exactly my thought.

Especially together with 'FBI Director Compares Ransomware to 9/11' articles like https://www.foxbusiness.com/technology/fbi-chris-wray-ransom...

Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside

#74
I am guessing that the key pair generation process was faulty. The FBI found an exploit in a wallet used by the hackers allowing the private key to be predicted. The prefix is bc1,which is uncommon. A few weeks ago there was such a vulnerability with Cake Wallet.

Or they installed malware on the hacker's computers and were able to log the private key as it was generated.

Or the hackers foolishly stored the key pairs on a server

Bitcoin is falling and this news does not help because it shows that some aspect is less secure than previously thought.

Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside

#75
post #53

Earlier quoted context omitted.

You find it improbable that geopolitical enemies tend to be the ones that attack us? Feels like saying "I find it weird that people I insult disproportionately punch me in the face".

It's also a very old technique to proxy attacks through countries without extradition treaties.

I don't disagree, obviously. But the question here is if it's reasonable to find that hackers in countries that we consider to be political enemies disproportionately are the ones hacking us.

There are numerous incentives that, to me, make it not only reasonable but extraordinarily likely.

Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside

#76
post #68
post #62

Rather than the us just "having" the key, could it not be a possibility that they in fact managed to somehow crack it? If any power could surely it's the us right?

I wondered the same thing, so I went looking for answers and found this excellent video by 3Blue1Brown: How secure is 256 bit security? : https://www.youtube.com/watch?v=S9JGmA5_unY

Really informative video but this is talking about hashing functions. Private keys are created differently using (some) shared information between the private and public keys. If there was one area I could see the us investing their time and effort since RSA came out it's here. Don't get me wrong, it would be out there if they could crack even one key but like I said, if anyone can it's them.

Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside

#77
post #24

This story makes absolutely no sense at all. The errors present by these hackers are so comical it's simply unbelievable. I'm supposed to believe some elite Russian hacking group keeps their crypto wallets running on a US host where the FBI just logs right in and snatches the private key? I'm starting to entertain the conspiracies that the future of commodities price manipulation is fake ransomware attacks. There nee…

Indeed was just discussing the same thing. Perhaps they simply are tracking if the money goes anywhere or using this as a way to hide their incompetence? Just saying they can do something they really can’t or put a legal hold on that wallet so if any exchange receives it they get fined?

Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside

#78
post #24

This story makes absolutely no sense at all. The errors present by these hackers are so comical it's simply unbelievable. I'm supposed to believe some elite Russian hacking group keeps their crypto wallets running on a US host where the FBI just logs right in and snatches the private key? I'm starting to entertain the conspiracies that the future of commodities price manipulation is fake ransomware attacks. There nee…

Agreed, there is something that is not being told here.

Maybe the US struck a deal with whoever did this to safe face or something.

Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside

#79
> The Special Prosecutions Section and Asset Forfeiture Unit of the U.S. Attorney’s Office for the Northern District of California is handling the seizure

Hah, of course the DoJ office doing bitcoin investigations is in San Francisco.

Also interesting that they were able to recover only $2.3M out of the $4.4M paid. I wonder if Colonial Pipeline will ever see this money.

Post reply on HN