TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Hamilton teen embroiled in FBI probe, fingered in $46M cryptocurrency theft

126 pointsby x1ph0zover 3 years ago

20 comments

ashconnorover 3 years ago
<a href="https:&#x2F;&#x2F;archive.md&#x2F;5oAva" rel="nofollow">https:&#x2F;&#x2F;archive.md&#x2F;5oAva</a>
walrus01over 3 years ago
This is a fine example why nobody should rely on SMS &quot;2FA&quot; for anything.<p>SMS &quot;2FA&quot; is not actual 2FA<p>SS7&#x2F;PSTN are horribly broken. People need to stop using them entirely, whenever possible, and stick to that as a firm principle. For the same reason why scam calls and fake caller ID are epidemic. Just disregard the <i>existence</i> of the PSTN, even if your phone has a DID, never give it to anyone or use it for anything. I say this as someone who&#x27;s worked in telecom for 20 years.<p>Social engineering mobile phone operator customer service departments to execute a SIM swap attack is trivially easy if you already possess some basic personal info about the target.<p>You should never rely on having something important that&#x27;s only protected behind a SMS-based password reset&#x2F;login authentication module.
评论 #29335666 未加载
评论 #29335542 未加载
评论 #29338384 未加载
评论 #29337532 未加载
评论 #29339156 未加载
ziddoapover 3 years ago
For those without subscriptions. <a href="https:&#x2F;&#x2F;outline.com&#x2F;3CRjpe" rel="nofollow">https:&#x2F;&#x2F;outline.com&#x2F;3CRjpe</a><p>&gt;<i>That post has since been taken down, but many comments included criticism for leaving such a large amount of Bitcoin accessible on a phone.</i><p>Not to victim blame, but it really is odd to me that someone would leave any amount of BTC on their phone, let alone millions of dollars worth.<p>&gt;<i>The Hamilton teen faces charges of theft over $5,000 and possession of property or proceeds of property obtained by crime</i><p>I&#x27;ve always wondered why the line is drawn at $5,000. It&#x27;s mildly interesting that stealing $46M and stealing $5,000 result in equivalent charges.
评论 #29335055 未加载
评论 #29331212 未加载
评论 #29333873 未加载
评论 #29334872 未加载
评论 #29335551 未加载
评论 #29332074 未加载
评论 #29331166 未加载
glofishover 3 years ago
When random teen can easily steal $46M from a &quot;Bitcoin pioneer&quot; what hope is that for regular folks could make safe use of said value store?
评论 #29331491 未加载
评论 #29331348 未加载
评论 #29338967 未加载
评论 #29331952 未加载
评论 #29334863 未加载
评论 #29331331 未加载
jaywalkover 3 years ago
If you&#x27;re going to steal a large amount of Bitcoin, you should probably have a plan on what you&#x27;re going to do with it that doesn&#x27;t include buying a gaming username that can be trivially traced back to you once you use it.
评论 #29338986 未加载
ChrisArchitectover 3 years ago
Is this Hamilton, Ontario, Canada?! Unclear<p>Also, Josh Jones, the founder of DreamHost? wow. heh<p><i>Edit</i>: Sorry, because I read it on outline&#x2F;archive I didn&#x27;t see the glaring Hamilton Spectator logo at top and related Canada nav. Thanks
评论 #29335815 未加载
评论 #29334730 未加载
amatechaover 3 years ago
&quot;leaving such a large amount of Bitcoin accessible on a phone&quot;<p>&quot;A SIM swap attack [...] gives the hacker access to the victim’s phone&quot;<p>Is it just me or this article massively misrepresenting what a SIM swap attack actually does? Unless there&#x27;s more to the story, no one got access to Jones&#x27; phone. They intercepted 2FA SMSes so they could get access to a wallet service or whatever.
323over 3 years ago
It&#x27;s easy to steal bitcoin (for some definition of easy).<p>The hard part is cashing it out. As Breaking Bad used to say, what criminals want is to pay taxes on their criminal proceeds.
评论 #29331378 未加载
评论 #29337395 未加载
bhoustonover 3 years ago
He should have run just a failed ICO and pocketed the funds as fees to related parties. I understand this is how Metakoven, the NFT king, got his start? <a href="https:&#x2F;&#x2F;www.reuters.com&#x2F;investigates&#x2F;special-report&#x2F;finance-crypto-sundaresan&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.reuters.com&#x2F;investigates&#x2F;special-report&#x2F;finance-...</a><p>Better to claim incompetence than it is to actually steal.
Jerrrryover 3 years ago
another bitcoin bandit bites the dust.<p>I bet he bought an xbox gamertag from the most recent exploit.<p>These kids really do think the 3 letter agencies arent watching, no matter how many of their close friends get v&amp;.<p>The blockchain is forever, and the statue of limitations no longer applies.<p>That verizon&#x2F;att employee from 2018 will get caught, he will give up an alias, and the feds are interested, now that the coins have value.<p>and assuming the feds arent dirty (they are), you have 5 years to run. If the fed assigned to your case decides he wants the coin personally, you have 5 monthes.
评论 #29331926 未加载
评论 #29332044 未加载
评论 #29337477 未加载
jrootabegaover 3 years ago
If you own a lot of crypto and it&#x27;s still protected by SMS auth, you need to disable that (edit: in favor of OTP). If you can&#x27;t, you need to buy a dozen prepaid sim cards and use them randomly. Or pay someone to do it for you. Very cheap in comparison to a theft.
评论 #29331580 未加载
评论 #29331662 未加载
评论 #29331585 未加载
misiti3780over 3 years ago
Honest question:<p>We are all the bitcoin multi-millionaires storing their coins? It seems like in an ideal world, you would use <a href="https:&#x2F;&#x2F;trezor.io" rel="nofollow">https:&#x2F;&#x2F;trezor.io</a> and put that in a safety deposit box, or maybe use Coinbase Vault, but I am generally curious what is the current consensus on the safest ways to store these piles of digital money.
评论 #29335778 未加载
评论 #29334847 未加载
评论 #29334902 未加载
评论 #29332729 未加载
vmooreover 3 years ago
So some exchanges use TOTP 2FA (which is more secure than SMS). And some people like to copy their 2FA &#x27;seed&#x27; which is usually a QR code that they store somewhere securely. Amazing how a simple QR code (or even a recovery code) can be worth so much.
DeathArrowover 3 years ago
&gt;U.S. investigators discovered that some of the stolen cryptocurrency was used to buy a unique online gaming name.<p>Can bitcoins be tracked?
评论 #29338944 未加载
hsnewmanover 3 years ago
This, along with the energy requirements of crypto is why I don&#x27;t&#x2F;won&#x27;t put any money in it.
评论 #29335701 未加载
WFHRenaissanceover 3 years ago
Does his name happen to be Freddy?
thefounderover 3 years ago
Just use webauthn...why is so hard to get that sms and otp is flawed?
hazza_n_dazzaover 3 years ago
its funny to think that if bitcoin crashed tomorrow all this could be for $2.84c
DeathArrowover 3 years ago
I hope Elon Musk keeps his bitcoins safe. :D
NicoJuicyover 3 years ago
&gt; &quot;Just the fact that everyone on earth thinks that Bitcoin is crazy, and no one is telling me why, doesn’t matter,”<p>Says the biggest known victim of a crypto heist in a private person.<p>Ain&#x27;t this ironic.<p>I guess I should spell out that centralization is a feature?