zlacker

[return to "Feds arrest couple, seize $3.6B in hacked Bitcoin funds"]
1. danso+T4[view] [source] 2022-02-08 17:10:48
>>mikeyo+(OP)
The statement of facts is linked to from the press release, and describes generally how the Feds were able to trace the stolen funds (they found a file listing private keys, after gaining access to the suspect's cloud storage) https://www.justice.gov/opa/press-release/file/1470186/downl...

> The 2017 transfers notwithstanding, the majority of the stolen funds remained in Wallet 1CGA4s from August 2016 until January 31, 2022. On January 31, 2022, law enforcement gained access to Wallet 1CGA4s by decrypting a file saved to LICHTENSTEIN’s cloud storage account, which had been obtained pursuant to a search warrant. The file contained a list of 2,000 virtual currency addresses, along with corresponding private keys.

> ...The connection among the VCE 1 accounts was further confirmed upon reviewing a spreadsheet saved to LICHTENSTEIN’s cloud storage account. The spreadsheet included the log-in information for accounts at various virtual currency exchanges and a notation regarding the status of the accounts

> ...Lichtenstein Email 2 was held at a U.S.-based provider that offered email as well as cloud storage services, among other products. In 2021, agents obtained a copy of the contents of the cloud storage account pursuant to a search warrant. Upon reviewing the contents of the account, agents confirmed that the account was used by LICHTENSTEIN. However, a significant portion of the files were encrypted

◧◩
2. colinm+h5[view] [source] 2022-02-08 17:12:09
>>danso+T4
$4 billion has got to buy an awful lot of compute time, but still, how did they decrypt the file?
◧◩◪
3. tevon+331[view] [source] 2022-02-08 21:16:03
>>colinm+h5
Is it me or should he have literally just gotten a hardware wallet, transferred everything to that account, then burned the old key?

Of course that txn would show up on-chain, but if you don't have possession of the private key for the first account, and no digital device has ever "seen" the hardware account then he would've been fine.

This is assuming the key piece of evidence was his private key, and he wouldn't have been prosecuted without it.

Additionally, putting your key in cloud storage sounds like the dumbest thing ever... Just memorize your seed phrase and write it down. Its 4bn for christ sake.

◧◩◪◨
4. pshc+Mb1[view] [source] 2022-02-08 21:57:33
>>tevon+331
Yeah, a hardware wallet is good, although for a billion dollars, 100 hardware wallets would be better. Could even go so far as to split a private key into seven horcruxes using Shamir's Secret Sharing and bury them in locations around the world.

Memorizing a seed phrase leaves you vulnerable to a $5 wrench attack, I wouldn't recommend it.

◧◩◪◨⬒
5. hnburn+Sh1[view] [source] 2022-02-08 22:27:04
>>pshc+Mb1
The famous Bitcoin family reportedly spread their hardware wallets across the globe.

https://www.cnbc.com/2021/08/11/bitcoin-family-hides-bitcoin...

◧◩◪◨⬒⬓
6. rlt+xk1[view] [source] 2022-02-08 22:43:24
>>hnburn+Sh1
The article suggests each location contains 100% of the key, not using Shamir’s Secret Sharing.

> Taihuttu is trying to put a crypto cold wallet on every continent so it’s easier to access his holdings.

I hope it’s at least encrypted with an additional passphrase, otherwise it’s only as strong as the weakest bank’s security.

[go to top]