8 ms·
DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside
- ProjectArcturis 5y agoHow? Looks like Darkside transferred the money to an exchange (Coinbase?), didn't hide it well enough, and the FBI just grabbed it?
- paulpauper 5y agoi dont think coinbase addresses have bc1 prefix
- cirowrc 5y agowhere's that sweet sweet transaction graph?
- blancNoir 5y agoNot exhaustive, but you might find this interesting: https://blog.wolfram.com/2021/05/25/sleuthing-darkside-crypto-ransom-payments-with-the-wolfram-language/ https://blog.wolfram.com/2021/05/25/sleuthing-darkside-crypt...
- yamrzou 5y agoThere are more technical details in the linked affidavit (page 6 and 7): https://www.justice.gov/opa/press-release/file/1402056/download https://www.justice.gov/opa/press-release/file/1402056/downl... They kept following transactions on the blockchain, but it's not clear how the private key became in the posession of the FBI.
- qeternity 5y agoThe wetware is always the weakest link.
- ianhawes 5y agoNetsec Twitter's theory is that the attacker(s) had a VPS operating in the US that the FBI was able to access and which contained the key to the wallet where the final payment ended up.
- TaupeRanger 5y agoReally? That seems like something fairly obvious to attempt to prevent from an attacker's viewpoint.
- hammock 5y agoHow? A keylogger? Cache somewhere?
- walrus01 5y agoI am by far no ransomware expert, but it really seems like amateur hour if they were running a Linux based Bitcoin full node using the mainline CLI daemon and client, with a wallet, on some hosting company geographically within the United States. Why would it need to be in the US?
- partyboy 5y agoDon't underestimate the stupidity/incompetence of these ransomware devs. Many cybercriminals have been caught for unbelievably dumb reasons.
- staticassertion 5y agoI only know a few criminal hackers, but within that sample their skillset is really niche. They know what they know well, but otherwise they're just trying to solve problems like any engineer. Kinda like data scientists - they can be masters with a couple of libraries and concepts, but if you have a data science team you also are more or less guaranteed to have a jupyter notebook open to the world, or something along those lines.
- gruez 5y agoSo many questions. Why are they running a bitcoin node on a vps? do they need to make automated payments or something? it's very easy to run a bitcoin node locally, or even airgap the signing keys.
- remarkEon 5y ago>Based on ... I have probable cause to believe that the aforementioned property may be seized... Forgive me if this is a dumb question; I have not used a blockchain explorer for anything consequential. Isn't that wallet just the last place it ended up? So, you have chain of custody but does that prove that the owner of that wallet is the "target"?
- koheripbal 5y agoNope, but the recipient is welcome to come to the US, show up at the FBI and ask for it back.
- ytpete 5y agoI think generally speaking, someone in possession of stolen property isn't entitled to keep that property even if they had nothing to do with the theft and had no reason to believe it was stolen. That prevents them from being guilty of a crime - but authorities can still come seize the property without compensating them at all for their loss. In a way it's similar to getting stuck with counterfeit money. You didn't do anything wrong, but no one is going to just hand you the replacement real money you "deserve" - you just got unlucky.
- koheripbal 5y agoThis is why all these gangs will now switch to Monero the moment they get BTC paid.
- hellbannedguy 5y agoThe Laywer did a great job explaining Bitcoin. Can anyone here (hn) add anything? It seems like steps in the investigation, or process to identifying the bad guys were left out.
- encryptluks2 5y agoLOL... I simply don't believe any of these press releases. For all we know, the government negotiated a deal with the cyber-attackers to create this press release as a way to try to thwart future attacks. Seriously wouldn't put it past them one bit.
- bellyfullofbac 5y agoWell, evidence-less speculation is also useless, here's another one: maybe they have a quantum computer that spat out the private key? Or they asked Google to hack the hackers' Android phones!
- nkrisc 5y agoDo you have a specific reason to not believe it?
- encryptluks2 5y agoYes, the countless lawsuits and evidence that the government lies on a consistent basis, especially involving acts of national security. We can pretend the Iraq War never happened based on fake evidence.
- spfzero 5y agoOr, maybe something like the FBI knows who's behind it through other means (friendly foreign government, etc.). They contact them and let them know they are going to prosecute to the full extent of the law, long prison sentences. The hackers offer to give the money back in exchange for not being prosecuted, FBI agrees, private key is supplied by hackers. It's possible they underestimated how serious things would get and got cold feet.
- walrus01 5y agoThe most interesting and unknown question is how the DOJ/FBI came to be in possession of the private key.
- ulzeraj 5y agoA private key is not needed if the funds are on an exchange. Apparently there is a warrant to seize property on Northern California so I guess it might be Coinbase. And yeah... if the crackers sent the funds to an exchange they were comically dumb.
- vesinisa 5y agoThe press release specifically mentions that the cryptocurrency was seized through FBI having posession of the private key.
- lhorie 5y agoIt's not an either/or thing though, right? IMHO, it seems plausible for the FBI to get a private key from a cooperating exchange?
- ulzeraj 5y agoDid the crackers surrendered the private keys? And if so why was a warrant issued? https://www.elliptic.co/hs-fs/hubfs/Screenshot%202021-06-07%20at%2022.13.19.png?width=1188&height=620&name=Screenshot%202021-06-07%20at%2022.13.19.png https://www.elliptic.co/hs-fs/hubfs/Screenshot%202021-06-07%...
- SavantIdiot 5y agoTo the previous poster's point: it didn't say which private key. There can be multiple with cloud storage.
- sneak 5y agoAs someone who has been on the receiving end of federal seizure orders for cryptocurrency private keys, they were in my case satisfied by publishing a transfer (signature) to a USG address, not actual disclosure of private key material, despite that being explicitly stated in the order.
- deleted 5y ago[deleted]
- shiado 5y agoThis story makes absolutely no sense at all. The errors present by these hackers are so comical it's simply unbelievable. I'm supposed to believe some elite Russian hacking group keeps their crypto wallets running on a US host where the FBI just logs right in and snatches the private key? I'm starting to entertain the conspiracies that the future of commodities price manipulation is fake ransomware attacks. There needs to be a serious audit of CME derivatives trading. There will come a day when some oil futures trader pays a ransomware group or an employee at a pipeline company and makes billions.
- floatingatoll 5y agoNo, they’re not elite, they’re just script kiddies with a payout mechanism.
- SavantIdiot 5y ago"Script kiddies" got their name because 20 years ago any kid could download some code and create a DDoS attack by running a pre-written script. Ransomware hacks seem a bit more sophisticated, even with today's highly modular malware. I think it is an interesting proposal: a fake attack as shown by the disparity in savvy between the attack and the payment, or a really dumb screw up. EDIT: as "koheripbal" says below, maybe their tumbler is a boob (paraphrased).
- AJ007 5y agoHow much sophistication does it take to attack a computer system running software that hasn’t been patched in years?
- rhodozelia 5y ago./nestea.o
- icedchai 5y agoMany so called "professionals" are still running operations with 5+ year old distributions that haven't been patched in almost as many years, and servers that people are afraid to reboot. I was once contracted by a company that was literally afraid to have any employees reboot a server because they had no idea how it worked, if it would come back up, and what to do if something didn't restart. They wanted an outside guy to take the blame.
- alex_young 5y agoColonial paid $4.4M in BTC around May 6th. Coindesk shows BTC/USD around $58K on May 6th. FBI recovers $2.3M in BTC today. Current BTC/USD around $34K today. 34 / 58 = .58 4.4 * .58 = 2.552 Looks like they recovered more or less all of it? [1] https://www.coindesk.com/price/bitcoin https://www.coindesk.com/price/bitcoin
- ls612 5y agoWSJ reported they recovered 64 Bitcoin out of 75 paid in ransom by the company, so it was most of it.
- koheripbal 5y agoColonial paid 75 BTC, and they recovered 63.7 BTC.
- rejectedandsad 5y agoI'm guessing the rest was fees/etc coming out of the crypto tumblers they used?
- blhack 5y agoThey didn't use any tumblers, that's how they got caught. edit: it says so in the article: As alleged in the supporting affidavit, by reviewing the Bitcoin public ledger, law enforcement was able to track multiple transfers of bitcoin and identify that approximately 63.7 bitcoins, representing the proceeds of the victim’s ransom payment, had been transferred to a specific address
- rejectedandsad 5y agoI think tumblers can be traced if they are backfired or monitored. Though perhaps that requires more assumptions than the fact that they were incompetent and didn’t use any.
- 5y ago
- vmception 5y agoSHUM - Should have used Monero SHUTC - Should have used Tornado.cash SHURENVM+TC - Should have used RenVM and Tornado.cash
- deleted 5y ago[deleted]
- h3cate 5y agoRather than the us just "having" the key, could it not be a possibility that they in fact managed to somehow crack it? If any power could surely it's the us right?
- yamrzou 5y agoI wondered the same thing, so I went looking for answers and found this excellent video by 3Blue1Brown: How secure is 256 bit security? : https://www.youtube.com/watch?v=S9JGmA5_unY https://www.youtube.com/watch?v=S9JGmA5_unY
- h3cate 5y agoReally informative video but this is talking about hashing functions. Private keys are created differently using (some) shared information between the private and public keys. If there was one area I could see the us investing their time and effort since RSA came out it's here. Don't get me wrong, it would be out there if they could crack even one key but like I said, if anyone can it's them.
- TZubiri 5y agoNo. If anyone had the ability to crack bitcoin addresses, they would not spend that technology on something as inconsequential as this. It would be saved for national defense issues
- h3cate 5y agoCompletely agree but it could be perceived as a show of strength.
- anonporridge 5y agoStill stupid. As soon as some entity reveals they have the power to crack one of these algorithms, everyone scrambles to migrate to something orders of magnitude harder. It's a weapon you'd only be able to use for maybe a few weeks or months before all the worthwhile targets immunize themselves against you. We already have quantum safe asymmetric cryptography, just no incentive to move fast to deploy it.
- xwdv 5y agoMaybe this is the way to deal with ransomware, just seize stolen crypto.
- labrador 5y agoDon't they mean Putin in an agreement with the Biden administration made Darkside give some money back as a way of easing American public tensions and political fallout ahead of the summit?
- rejectedandsad 5y agoIf that is what they did, that's a fantastic diplomatic success story
- Scoundreller 5y agoNot completely unusual. I doubt Russia is too crazy about the idea of pipelines=targets. Especially one that doesn't even compete with them. 2x especially the billing! 64% of Russian exports are gas and oil. https://commons.wikimedia.org/wiki/File:Russia_Export_Treemap.png https://commons.wikimedia.org/wiki/File:Russia_Export_Treema...
- TZubiri 5y agoThat's some schizo shit right there
- paulpauper 5y agoI am guessing that the key pair generation process was faulty. The FBI found an exploit in a wallet used by the hackers allowing the private key to be predicted. The prefix is bc1,which is uncommon. A few weeks ago there was such a vulnerability with Cake Wallet. Or they installed malware on the hacker's computers and were able to log the private key as it was generated. Or the hackers foolishly stored the key pairs on a server Bitcoin is falling and this news does not help because it shows that some aspect is less secure than previously thought.
- mnouquet 5y agoSummary of your post: you have no idea what you are talking about.
- bpodgursky 5y agoI'm wondering if the attackers sent their coins through a mixer, and now some chump with money on coinbase just got his coins jacked b/c he deposited after using a shady mixer.
- deleted 5y ago[deleted]
- lvs 5y agoAlmost certainly what's not secure is the endpoint, wherever the keys were stored. That shouldn't really be news. The endpoints are always the weakest links in an encrypted channel.
- gge 5y agobc1 isn't an uncommon prefix, its a bech32 native segwit address that's been in use for years now (IIRC 1 and 3 are the other prefixes, 1 being the first and most popular and 3 being a backwards compatible segwit address, i.e. non native). Stats: https://txstats.com/dashboard/db/bech32-statistics?orgId=1 https://txstats.com/dashboard/db/bech32-statistics?orgId=1 faulty key pairs being generated is a well known issue with poorly developed wallets, not with Bitcoin itself. None of the popular wallets have this issue so it doesn't undermine Bitcoin.
- 5y ago
- paxys 5y ago> The Special Prosecutions Section and Asset Forfeiture Unit of the U.S. Attorney’s Office for the Northern District of California is handling the seizure Hah, of course the DoJ office doing bitcoin investigations is in San Francisco. Also interesting that they were able to recover only $2.3M out of the $4.4M paid. I wonder if Colonial Pipeline will ever see this money.
- koheripbal 5y agoThey recovered 63.7 out of 75 BTC. The USD price just changed in the interim.
- ac29 5y agoPlausible theory on how they did this here: https://twitter.com/brucedkleinman/status/1402044745916973057 https://twitter.com/brucedkleinman/status/140204474591697305... tl;dr: The hackers used the same full node wallet more than once, and the FBI was able to narrow in on an IP address because the first relay of the transactions was the same across multiple transactions. This server was in California, which allowed the FBI to seize it.
- nojito 5y agoThe warrant isn't proof that the server was in California. That's simply where the FBI field office that is going to access the bitcoin address is based out of.
- Black101 5y agoThey probably should have asked for Moneros ... and in a self hosted wallet.
- joemazerino 5y agoI'm not reading how the private key for the wallet was obtained. Anyone?
- not2b 5y agoThey aren't going to tell us that, so they can keep using the same tricks.
- shiado 5y agoHere is the FBI controlled address, presumably a Coinbase deposit address https://www.blockchain.com/btc/address/bc1qq2euq8pw950klpjcawuy4uj39ym43hs6cfsegq https://www.blockchain.com/btc/address/bc1qq2euq8pw950klpjca... Which got funds from https://www.blockchain.com/btc/address/3EYkxQSUv2KcuRTnHQA8tNuG7S2pKcdNxB https://www.blockchain.com/btc/address/3EYkxQSUv2KcuRTnHQA8t... This is the wallet explorer used for clustering the wallet https://www.walletexplorer.com/wallet/123085fff68ee703/addresses https://www.walletexplorer.com/wallet/123085fff68ee703/addre... I have no idea why they censored out parts of the bitcoin addresses as googling the uncensored part and transaction quantities lets you find them on countless sites.
- kart23 5y agoI'm confused. That account had a little over *69 btc this morning, yet the FBI affidavit said it only has 63.7 btc. What's up with the disparity? https://www.justice.gov/opa/press-release/file/1402056/download https://www.justice.gov/opa/press-release/file/1402056/downl... *edited
- shiado 5y agoThey only seized 69.6 as that's what was transferred to an exchange. It's interesting they split the resulting funds into two addresses. One to presumably return to who paid the ransom and the rest which would be held until whoever is indicted can prove they are not proceeds of crime (lol good luck).
- kart23 5y agooops, you're right, I misinterpreted the 'total received' line
- Scoundreller 5y agoYou can see the split here: https://www.blockchain.com/btc/address/bc1qu57hnxf0c65fsdd5kewcsfeag6sljgfhz99zwt https://www.blockchain.com/btc/address/bc1qu57hnxf0c65fsdd5k...
- 5y ago
- blhack 5y agoI think that the people here speculating about the FBI and private keys are greatly overestimating the competency of these hackers. While it's possible this it he FBI flexing some muscle that they have a backdoor into bitcoin's hashing algorithm, what seems much more likely (to me) is: There is a more sophisticated hacking group which created this particular ransomware package. They sell this ransomware package to less sophisticated criminals. (https://www.theverge.com/2021/5/10/22428996/colonial-pipeline-ransomware-attack-apology-investigation https://www.theverge.com/2021/5/10/22428996/colonial-pipelin...) Is it so hard to imagine a scenario where the more advanced creators of this ransomware kit gave instructions to their purchasers on things like private keys, and the end user simply ignored them? Somebody ignoring a warning when installing a software, and that allowing the FBI to subpeona access to the server where it was running, and grab this private key, seems FAR more likely to me than the FBI having a backdoor into BTC, or this all being a cover spy novel plot, or anything like that.
- wyager 5y agoIf the FBI has broke any of Secp256k1, SHA256, or RIPE160, (they have not) they’re not going to blow that on a $3M haul.
- onetimemanytime 5y agoThey might be saving for bigger things, however this is a lot more than $3million. It's about holding the US economy hostage, as these will increase in frequency.
- stingraycharles 5y agoHow is this holding the US economy hostage?
- kick_in_the_doo 5y agoRandomware attacks on energy (oil and potentially electric grid) and hospitals. And that's only what we've seen so far.
- Geee 5y agoHackers make transactions on clearnet revealing their IP address -> FBI seizes the server.
- alksjdalkj 5y agoMore info: https://krebsonsecurity.com/2021/06/justice-dept-claws-back-2-3m-paid-by-colonial-pipeline-to-ransomware-gang/ https://krebsonsecurity.com/2021/06/justice-dept-claws-back-...
- doggosphere 5y agoLooks like the criminals used CoinBase: https://twitter.com/thisisbullish/status/1402056137340604418?s=21 https://twitter.com/thisisbullish/status/1402056137340604418... How amateur is that…
- dragonwriter 5y agoThe only thing anywhere in the “supporting” documents or diagrams concerning coinbase is that it is shown as the destination of a 0.001 BTC transfer from the address the funds went to. This is one of several pieces I’ve seen claiming things about Coinbase and embedding documents or other evidence that doesn’t seem to come close to supporting the conclusion. I’m not saying Coinbase wasn’t used and that that didn't have something to do with the seizure, but its being repeatedly claimed with the same kind of evidence presentation that tends to accompany conspiracy theories.
- openmosix 5y agoNope https://twitter.com/SecurityGuyPhil/status/1402079972060131332 https://twitter.com/SecurityGuyPhil/status/14020799720601313...
- rawtxapp 5y agoThat refers to the concept of coinbase, not coinbase the company. It's a technical term on the blockchain for the coins dispensed to the miner.
- dogman144 5y agoI mean… this was just a software wallet getting owned, almost for sure. Pair that with not clicking the right AWS region and the details are likely. I’m curious what the wallet provider was.
- ipsin 5y agoThe DoJ press release doesn't make this clear: what happens to the money now? Is it returned to the company, or does the DoJ keep it as an asset forfeiture?
- void_mint 5y agoI was told governments can't get involved in crypto, that's what makes it great? Totally anonymous? Untraceable?
- deleted 5y ago[deleted]
- deleted 5y ago[deleted]
- Haemm0r 5y agoMaybe this is just a result of good old police work: https://xkcd.com/538/ https://xkcd.com/538/
- galaxyLogic 5y agoCan someone explain simply why it is supposed to be so hard to track ransomware bitcoin payments, if all bitcoin transactions are in a shared public ledger? If the victim pays someone we know which account it goes to, right? Then we know that account is criminal. If bitcoins move from that account to other accounts we know that accounts that receive them are essentially "hiding stolen goods". So they are criminal accounts as well. Then at some point they want to get dollars, and FBI can catch them by following where the dollars were sent. No?
- lacker 5y agoThe FBI doesn't have access to every Bitcoin exchange. There are exchanges in other countries that let you trade anonymously, either into fiat or other cryptocurrencies.
- yaitsyaboi 5y agoDo those other exchanges have some other type of anonymity mechanism? I guess I could see Monero on Bitcoin as a service, but if it isn't something like that it seems just as pseudoanonymous as regular BTC
- probably_wrong 5y agoLeaving aside services like bitcoin mixers designed to obfuscate the process, I think the usefulness of bitcoin for ransomware is that it allows you to move a big sum of money quickly without verifying your identity and without going through bank checks. I think you are correct about getting dollars out being the risky part, but this way the criminals will at least have a head start in their race against the FBI.
- avhwl 5y ago>Can someone explain simply why it is supposed to be so hard to track ransomware bitcoin payments, if all bitcoin transactions are in a shared public ledger? Clearly, it's not. This is a pervasive misconception. Bitcoin is not, and is not even meant to be, private. Even with obfuscation attempts, nearly every ransomware gang has their bitcoin payments fully tracked, as this one did. There is a robust industry of blockchain analytics that pulls in many many millions each year surveilling the bitcoin blockchain. Virtually all exchanges (fiat on and off ramps) collaborate with those analytics companies and require full KYC/AML of their customers, and can thus apply their KYC label data to blockchain metadata. Bitcoin is not account based: it is based on unspent transaction output sets. UTXOs can be combined with many other UTXOs, combined into one, or split into many. This leaves a large amount of potential for obfuscation strategies such as CoinJoin[^1]. Nearly all of these gangs attempt to use CoinJoin or similar but make small mistakes such as being representative of a large amount of the volume, leaking information through timing, combining their outputs into one, or countless other potential errors, and often a simple "FIFO" strategy can trace flows. Obfuscation is not a robust anonymity strategy, and pseudonymity is not anonymity. To quote Vitalik Buterin, "If your privacy model has a medium anonymity set, it really has a small anonymity set. If your privacy model has a small anonymity set, it has an anonymity set of 1. Only global anonymity sets (eg. as done with ZK-SNARKs) are truly robustly secure."[^2] [^1]: https://en.bitcoin.it/wiki/CoinJoin https://en.bitcoin.it/wiki/CoinJoin [^2]: https://twitter.com/vitalikbuterin/status/1196468111995756544 https://twitter.com/vitalikbuterin/status/119646811199575654...
- Animats 5y agoThis is just an early part of an investigation. Since DOJ got this far, they have leads on who did it. Russian hackers have been captured in Israel, Spain, Belarius... Sometimes, after the FBI identifies them, they just watch and wait.
- trhway 5y ago>As alleged in the supporting affidavit, by reviewing the Bitcoin public ledger, law enforcement was able to track multiple transfers of bitcoin and identify that approximately 63.7 bitcoins, representing the proceeds of the victim’s ransom payment, had been transferred to a specific address does it mean that "tainted" BTC can be seized any time, even if the current holder may have no relation to the original crime?