TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside

359 pointsby nthitzalmost 4 years ago

28 comments

blhackalmost 4 years ago
I think that the people here speculating about the FBI and private keys are <i>greatly</i> overestimating the competency of these hackers.<p>While it&#x27;s possible this it he FBI flexing some muscle that they have a backdoor into bitcoin&#x27;s hashing algorithm, what seems much more likely (to me) is:<p>There <i>is</i> a more sophisticated hacking group which created this particular ransomware package. They sell this ransomware package to less sophisticated criminals.<p>(<a href="https:&#x2F;&#x2F;www.theverge.com&#x2F;2021&#x2F;5&#x2F;10&#x2F;22428996&#x2F;colonial-pipeline-ransomware-attack-apology-investigation" rel="nofollow">https:&#x2F;&#x2F;www.theverge.com&#x2F;2021&#x2F;5&#x2F;10&#x2F;22428996&#x2F;colonial-pipelin...</a>)<p>Is it so hard to imagine a scenario where the more advanced creators of this ransomware kit gave instructions to their purchasers on things like private keys, and the end user simply ignored them?<p>Somebody ignoring a warning when installing a software, and that allowing the FBI to subpeona access to the server where it was running, and grab this private key, seems <i>FAR</i> more likely to me than the FBI having a backdoor into BTC, or this all being a cover spy novel plot, or anything like that.
评论 #27429893 未加载
评论 #27429910 未加载
评论 #27430728 未加载
评论 #27430989 未加载
评论 #27432471 未加载
评论 #27431819 未加载
shiadoalmost 4 years ago
This story makes absolutely no sense at all. The errors present by these hackers are so comical it&#x27;s simply unbelievable. I&#x27;m supposed to believe some elite Russian hacking group keeps their crypto wallets running on a US host where the FBI just logs right in and snatches the private key? I&#x27;m starting to entertain the conspiracies that the future of commodities price manipulation is fake ransomware attacks. There needs to be a serious audit of CME derivatives trading. There will come a day when some oil futures trader pays a ransomware group or an employee at a pipeline company and makes billions.
评论 #27428899 未加载
评论 #27428872 未加载
评论 #27428452 未加载
评论 #27429534 未加载
评论 #27431617 未加载
评论 #27428435 未加载
评论 #27428266 未加载
评论 #27428312 未加载
评论 #27428553 未加载
评论 #27429228 未加载
评论 #27429926 未加载
评论 #27429647 未加载
评论 #27432409 未加载
评论 #27428300 未加载
评论 #27431841 未加载
评论 #27428426 未加载
评论 #27429437 未加载
评论 #27434444 未加载
评论 #27428845 未加载
评论 #27428805 未加载
评论 #27432098 未加载
评论 #27428926 未加载
评论 #27430467 未加载
评论 #27428556 未加载
评论 #27429138 未加载
shiadoalmost 4 years ago
Here is the FBI controlled address, presumably a Coinbase deposit address<p><a href="https:&#x2F;&#x2F;www.blockchain.com&#x2F;btc&#x2F;address&#x2F;bc1qq2euq8pw950klpjcawuy4uj39ym43hs6cfsegq" rel="nofollow">https:&#x2F;&#x2F;www.blockchain.com&#x2F;btc&#x2F;address&#x2F;bc1qq2euq8pw950klpjca...</a><p>Which got funds from<p><a href="https:&#x2F;&#x2F;www.blockchain.com&#x2F;btc&#x2F;address&#x2F;3EYkxQSUv2KcuRTnHQA8tNuG7S2pKcdNxB" rel="nofollow">https:&#x2F;&#x2F;www.blockchain.com&#x2F;btc&#x2F;address&#x2F;3EYkxQSUv2KcuRTnHQA8t...</a><p>This is the wallet explorer used for clustering the wallet<p><a href="https:&#x2F;&#x2F;www.walletexplorer.com&#x2F;wallet&#x2F;123085fff68ee703&#x2F;addresses" rel="nofollow">https:&#x2F;&#x2F;www.walletexplorer.com&#x2F;wallet&#x2F;123085fff68ee703&#x2F;addre...</a><p>I have no idea why they censored out parts of the bitcoin addresses as googling the uncensored part and transaction quantities lets you find them on countless sites.
评论 #27429903 未加载
评论 #27430404 未加载
评论 #27429913 未加载
评论 #27429959 未加载
walrus01almost 4 years ago
The most interesting and unknown question is how the DOJ&#x2F;FBI came to be in possession of the private key.
评论 #27428158 未加载
评论 #27428082 未加载
评论 #27433633 未加载
评论 #27429573 未加载
yamrzoualmost 4 years ago
There are more technical details in the linked affidavit (page 6 and 7): <a href="https:&#x2F;&#x2F;www.justice.gov&#x2F;opa&#x2F;press-release&#x2F;file&#x2F;1402056&#x2F;download" rel="nofollow">https:&#x2F;&#x2F;www.justice.gov&#x2F;opa&#x2F;press-release&#x2F;file&#x2F;1402056&#x2F;downl...</a><p>They kept following transactions on the blockchain, but it&#x27;s not clear how the private key became in the posession of the FBI.
评论 #27427927 未加载
评论 #27428417 未加载
评论 #27429265 未加载
评论 #27427926 未加载
评论 #27428941 未加载
paulpauperalmost 4 years ago
I am guessing that the key pair generation process was faulty. The FBI found an exploit in a wallet used by the hackers allowing the private key to be predicted. The prefix is bc1,which is uncommon. A few weeks ago there was such a vulnerability with Cake Wallet.<p>Or they installed malware on the hacker&#x27;s computers and were able to log the private key as it was generated.<p>Or the hackers foolishly stored the key pairs on a server<p>Bitcoin is falling and this news does not help because it shows that some aspect is less secure than previously thought.
评论 #27433001 未加载
评论 #27429667 未加载
评论 #27430324 未加载
评论 #27430397 未加载
评论 #27429133 未加载
评论 #27429209 未加载
galaxyLogicalmost 4 years ago
Can someone explain simply why it is supposed to be so hard to track ransomware bitcoin payments, if all bitcoin transactions are in a shared public ledger?<p>If the victim pays someone we know which account it goes to, right? Then we know that account is criminal.<p>If bitcoins move from that account to other accounts we know that accounts that receive them are essentially &quot;hiding stolen goods&quot;. So they are criminal accounts as well.<p>Then at some point they want to get dollars, and FBI can catch them by following where the dollars were sent. No?
评论 #27432810 未加载
评论 #27431339 未加载
评论 #27431304 未加载
alex_youngalmost 4 years ago
Colonial paid $4.4M in BTC around May 6th. Coindesk shows BTC&#x2F;USD around $58K on May 6th.<p>FBI recovers $2.3M in BTC today. Current BTC&#x2F;USD around $34K today.<p>34 &#x2F; 58 = .58<p>4.4 * .58 = 2.552<p>Looks like they recovered more or less all of it?<p>[1] <a href="https:&#x2F;&#x2F;www.coindesk.com&#x2F;price&#x2F;bitcoin" rel="nofollow">https:&#x2F;&#x2F;www.coindesk.com&#x2F;price&#x2F;bitcoin</a>
评论 #27428634 未加载
评论 #27428637 未加载
dogman144almost 4 years ago
I mean… this was just a software wallet getting owned, almost for sure. Pair that with not clicking the right AWS region and the details are likely.<p>I’m curious what the wallet provider was.
paxysalmost 4 years ago
&gt; The Special Prosecutions Section and Asset Forfeiture Unit of the U.S. Attorney’s Office for the Northern District of California is handling the seizure<p>Hah, of course the DoJ office doing bitcoin investigations is in San Francisco.<p>Also interesting that they were able to recover only $2.3M out of the $4.4M paid. I wonder if Colonial Pipeline will ever see this money.
评论 #27428925 未加载
alksjdalkjalmost 4 years ago
More info: <a href="https:&#x2F;&#x2F;krebsonsecurity.com&#x2F;2021&#x2F;06&#x2F;justice-dept-claws-back-2-3m-paid-by-colonial-pipeline-to-ransomware-gang&#x2F;" rel="nofollow">https:&#x2F;&#x2F;krebsonsecurity.com&#x2F;2021&#x2F;06&#x2F;justice-dept-claws-back-...</a>
Geeealmost 4 years ago
Hackers make transactions on clearnet revealing their IP address -&gt; FBI seizes the server.
ac29almost 4 years ago
Plausible theory on how they did this here: <a href="https:&#x2F;&#x2F;twitter.com&#x2F;brucedkleinman&#x2F;status&#x2F;1402044745916973057" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;brucedkleinman&#x2F;status&#x2F;140204474591697305...</a><p>tl;dr: The hackers used the same full node wallet more than once, and the FBI was able to narrow in on an IP address because the first relay of the transactions was the same across multiple transactions. This server was in California, which allowed the FBI to seize it.
评论 #27429356 未加载
h3catealmost 4 years ago
Rather than the us just &quot;having&quot; the key, could it not be a possibility that they in fact managed to somehow crack it? If any power could surely it&#x27;s the us right?
评论 #27428708 未加载
trhwayalmost 4 years ago
&gt;As alleged in the supporting affidavit, by reviewing the Bitcoin public ledger, law enforcement was able to track multiple transfers of bitcoin and identify that approximately 63.7 bitcoins, representing the proceeds of the victim’s ransom payment, had been transferred to a specific address<p>does it mean that &quot;tainted&quot; BTC can be seized any time, even if the current holder may have no relation to the original crime?
cirowrcalmost 4 years ago
where&#x27;s that sweet sweet transaction graph?
评论 #27428277 未加载
Animatsalmost 4 years ago
This is just an early part of an investigation. Since DOJ got this far, they have leads on who did it.<p>Russian hackers have been captured in Israel, Spain, Belarius... Sometimes, after the FBI identifies them, they just watch and wait.
ipsinalmost 4 years ago
The DoJ press release doesn&#x27;t make this clear: what happens to the money now?<p>Is it returned to the company, or does the DoJ keep it as an asset forfeiture?
void_mintalmost 4 years ago
I was told governments can&#x27;t get involved in crypto, that&#x27;s what makes it great? Totally anonymous? Untraceable?
评论 #27431269 未加载
Haemm0ralmost 4 years ago
Maybe this is just a result of good old police work: <a href="https:&#x2F;&#x2F;xkcd.com&#x2F;538&#x2F;" rel="nofollow">https:&#x2F;&#x2F;xkcd.com&#x2F;538&#x2F;</a>
joemazerinoalmost 4 years ago
I&#x27;m not reading how the private key for the wallet was obtained. Anyone?
评论 #27429648 未加载
Black101almost 4 years ago
They probably should have asked for Moneros ... and in a self hosted wallet.
doggospherealmost 4 years ago
Looks like the criminals used CoinBase:<p><a href="https:&#x2F;&#x2F;twitter.com&#x2F;thisisbullish&#x2F;status&#x2F;1402056137340604418?s=21" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;thisisbullish&#x2F;status&#x2F;1402056137340604418...</a><p>How amateur is that…
评论 #27430401 未加载
评论 #27430172 未加载
评论 #27430548 未加载
ProjectArcturisalmost 4 years ago
How? Looks like Darkside transferred the money to an exchange (Coinbase?), didn&#x27;t hide it well enough, and the FBI just grabbed it?
评论 #27428867 未加载
labradoralmost 4 years ago
Don&#x27;t they mean Putin in an agreement with the Biden administration made Darkside give some money back as a way of easing American public tensions and political fallout ahead of the summit?
评论 #27428897 未加载
评论 #27429021 未加载
xwdvalmost 4 years ago
Maybe this is the way to deal with ransomware, just seize stolen crypto.
vmceptionalmost 4 years ago
SHUM - Should have used Monero<p>SHUTC - Should have used Tornado.cash<p>SHURENVM+TC - Should have used RenVM and Tornado.cash
评论 #27428726 未加载
encryptluks2almost 4 years ago
LOL... I simply don&#x27;t believe any of these press releases. For all we know, the government negotiated a deal with the cyber-attackers to create this press release as a way to try to thwart future attacks. Seriously wouldn&#x27;t put it past them one bit.
评论 #27428375 未加载
评论 #27428010 未加载
评论 #27428199 未加载