A 'Blockchain Bandit' Is Guessing Private Keys and Scoring Millions
wired.com
wired.com
> "Don't you feel bad for him?" Bednarek asks with a laugh. "You have a thief here that amassed this fortune and then lost it all when the market crashed."
Well, 15% of $54M is still $8M.
The same reasons it’s run in the past...essentially the same reason for boom and bust cycles in normal markets.
S&P 500 E-mini futures have a notional value of roughly $147,000 right now, and on average, 1-2 million contracts change hands daily.
On average, about 35 billion dollars of SPY, a single S&P 500 ETF is traded daily.
It's hard to find accurate BTC average daily volume numbers, but probably somewhere between 1 and 10 billion dollars daily.
So yes, bitcoin is an extremely thin market compared to the market depth of 2 extremely liquid assets, both of which pale in comparison to the 550 billion USD daily volume of the treasuries market.
BTC does have the tightest bid/ask spread of pretty much any asset that is traded, as a percentage of the asset's value. It's typically a penny to a few cents on the major exchanges, which is a few thousandths of a percent.
Very little blockchain activity happens “on chain”, and absolutely none of the buying/selling to and from other currencies (including USD) does, because thats not possible. Instead most activity happens on exchanges, which hold onto coins for the user and track account balance in a SQL database just like a traditional exchange. Only if a user moves between exchanges or takes possession of their own coins (a rare occurrence) does an on chain transaction happen, otherwise the rest happens in a SQL database somewhere.
These exchanges are absolutely full of straight up fraud, with some analysts claiming up to 95% faked trade volume. Most exchanges trade on their own account, sometimes badly, and the seediest didn’t even require that you create 2 accounts to wash trade. In this case the on chain transactions aren’t rigged, but the price sure is.
Note: these are the exchanges that also famously get robbed (or “robbed”) and go bankrupt with their clients money. Examples famously include Quadrigacx, Mt. Gox, and others.
that sounds a bit FUD-dy. 51% allows you to make a double-spend, not "absolutely rig" the blockchain. even with 100% hashrate you won't be able to spend bitcoins without having a private key.
So not the same reason for boom/bust cycles at all.
Well the mortgage data was available, but no one looked into it until they did, and even then the smart money bet against the market...yet everything remained AAA rated for years despite the known toxicity, turns out the ratings were rigged also.
It’s pump and dump schemes all the way down, public markets/crypto markets it make no difference. There isn’t an economist alive who doesn’t say the stock market is significantly overvalued at this time and yet...historic highs remain, until they don’t.
As someone who started a 401k fresh out of college in 1988, this fear will be in the back of my mind until convert my entire portfolio into bonds. Probably in a few more years it'll begin.
Obviously the market value is based on speculation which tries to predict the future development, and is also strongly affected by the current mood of the markets. That's why there has been a constant increase in value and in addition cyclical 'bubbles'. Currently it seems that the market is starting an another 'bubble cycle'.
There isn't enough users and security for all blockchains to be valuable.
Laundering it appropriately that wouldn't raise questions might be a bigger issue. By no means impossible but a challenge that all by itself could get you in trouble.
Tumbling the coins would help with this, right?
Tumblers/mixers are the most likely place to pick these up.
Ultimately, big-scale heists will always need money laundering.
Given how "easy" the attack actually is, I see no reason to suspect a state actor. This is a genuine question: why don't people start by suspecting some kind of criminal organizations like the mafia instead?
While he was at the NSA, Edward Snowden complained that it stores more information on Americans than on Russians. He complained that that's illegal, but there's another remarkable facet to it: How good is the NSA at collecting information from Russia, then? I can hardly believe that the NSA tries to collect more data on Americans than on its actual mission, so how good is the NSA at its mission?
There are many other examples, like the German service that's supposed to monitor the nazis and missed the a group that made and sold a DVD about its killings.
It seems so strange to assume higher-than-average competence in organisations like that.
Not convinced that guessing private keys of anonymous randoms for a few million in assets of limited fungibility falls into that category. I'm not sure it's a question of competence in this case so much as why would a state be the ones tackling these accounts, when a lone criminal with relevant knowledge of cryptography would have the ability and a lot more motivation to do it?
Oh and their mission changed but it's still self contradictory.
https://withoutbullshit.com/blog/nsa-adopts-new-watchwords-m...
Collecting data, and further, processing that collected data, is fundamentally different than executing a difficult, targeted attack.
State level actors have massive amounts of resources, which makes them uniquely situated to perform difficult tasks like cracking encryption keys or developing insanely complex exploits.
So - the particular competence people give state actors generally has to do with that level of resources, while the same state actors are accurately attributed the incompetence that comes with large bureaucracies.
Same logic as you've just used: it's so easy you don't need to be the mob. What would their edge be anyway? All you need is enough money to rent some cloud servers.
It was "stolen" literally minutes after first depositing the coins at the address; we assumed by someone running a monitoring daemon looking for a large rainbow table of bitcoin addresses, and testing out there efforts on the testnet. I wonder how many bitcoins they managed to extract once they put their system into production.
[1] https://testnet-faucet.mempool.co/
I don't remember the address we used, though. Here's [1] a similar one, for "correct horse battery staple" -- the funds were moved (in the same block) from the address to a single-use address where they sat.
[1] https://live.blockcypher.com/btc-testnet/tx/835509e51ab9054e...
Bitcoin does not support embedding messages in addresses (and embedding messages in transactions is controversial as it will be stored in blockchain forever, so many block explorers do not render such messages to discourage it).
This isn’t surprising. “Brain wallets” have been been discouraged for a long time now. Unless you really know what you’re doing it’s easy to accidentally pick an insecure phrase. Even a paragraph of text from, say, an obscure book will probably eventually be found, if that book ever ends up digitized on the Internet.
The safest way is to generate a truly random key, then map that to a wordlist like BIP39 does.
I had no idea about:config worked in the Android app as well.
I always thought about all the opportunities to do it on other blockchains, but the challenge of picking which blockchain would be so taxing
Now that this season there are several high values one like Ethereum you can easily choose
The concepts are the same for all of the chains
Also lol at state actor. Guessing a private key of “1”? Come on. People were doing this with entire phrases from obscure songs and poems 6 years ago. No brainwallet is safe. Deflecting is a great way to get away with hacking
[1] https://godoc.org/github.com/ethereum/go-ethereum/crypto#ToE...
Secret key recovery via nonce reuse(linked SO post) is a different than simply trying a range of integers which is mostly what these researchers did.
- Debian OpenSSL was a Debian dev trying to prevent use of uninitialised memory (because Valgrind complained), without realising that uninitialised memory is used for randomness.
- Years ago a bunch of PHP stuff (I forget what) was seeded with the string value of a randomness function, rather than it's output.
What happened here?
It was more subtle than that: there were two identical calls, one of which added uninitialized memory, while the other added real entropy. The developer mistakenly removed both, thinking both were equally useless, instead of only removing the one with undefined behavior. To make things worse, another call added the current PID, so the results weren't identical every time. See more detail at https://research.swtch.com/openssl
It seems like there is an arms race of Blockchain Bandits leading to HFC-like systems aiming to try out as many generic private keys as possible as quickly as possible.
I got to a stage where I wanted to test my code all the way to the BTC blockchain. I figured I'd stick in the randomizing seed later, and just make sure I could talk to the blockchain. To my surprise, every time I made a transaction I'd see another one on the explorer sites, emptying my new address. I did it a couple of times thinking I'd coded something wrong or something like that.
You'd think they'd put a minimum in there before grabbing the coins.
It doesn't. Bitcoin is architecturally limited to ~7 transactions per second, and typical rates are about half that.
Ethereum is the world currency. Everyone is using it. Criminals and script kiddies are running scripts that guess completely random private keys. Occasionally they make hits and steal people's wealth.
What's the next step in securing your wallet? Making sure your wealth is stored across a million wallets?
If you were really concerned, you could make a multisig wallet.
https://github.com/ethereum/EIPs/blob/master/EIPS/eip-999.md
Unfortunately crypto’s greatest strength (that it’s akin to cash) is also it’s greatest weakness. There’s no way to set up 2FA like I can with my bank and there’s no fraud protection, etc.
Edit: doesn’t mean he’s not a thief, btw.
That's not true. Bank transactions are reversible. The legal system has your back.
https://www.consumerfinance.gov/ask-cfpb/how-do-i-get-my-mon...
2FA should be enabled for any centralized accounts, like exchanges, but there’s no authority who could require a second factor for a real Bitcoin wallet.
Edit: multi-sig has been available for a while, so I suppose that could almost be considered 2FA
I guess what I’m really asking is: does Coinbase do this? Because honestly, if Joe User doesn’t know to do this and it’s not made available through the most popular consumer interface... it doesn’t matter.
In the end, you still have to obey the laws of the land. No mater how decentralized some tech is, it's still attached to some country, and thus its laws.
Which seems like just the kind of dependency many crypto-enthusiasts are trying to avoid; and it's unclear to what extent states are interested in taking on that responsibility.
Without that, it really is a wild west out there, where anyone who can guess my key is free to claim my wealth. That model may appeal to some people, but I doubt the general public will care for it.
We don’t know if the person “guessing” Ethereum keys is also the one generating them, but from the article it seems there are multiple people scanning for known keys, so at least some of them aren’t intentionally duping users.
Cryptocoin theft also seems have the same advantage as a buried bag of cash in that criminal prosecution doesn't prevent you from still owning the goods.
I suppose there's restitution, depending on venue.
IMO it's a little different on if it's morally wrong/theft.
But you still have a good point: Ethereum -- which the article is about -- specifically endorses the philosophy of "code is law", that you can actually replace all of law enforcement and courts with smart contracts on the blockchain, that there's no need for an external power to override its results.
Dumb contract spec? Give out the private keys? Tough. "Code is law."
This is a philosophy not universally held by blockchain advocates, but definitely held by Ethereum advocates (if inconsistently -- see DAO hack). So it's a fair response in this case.
An inconsistently adopted/implemented belief doesn’t sound like a belief at all.
Crypto is putting something in a magic box with a sign on it that says "contents property of the first person to utter the magic words". "Your" cryptocurrency is not yours. It's "owned by" the magic words, not you. You can assign new magic words, but you can never insert yourself between the crypto and magic words, until you cash out the crypto to some other form of currency.
https://en.wikipedia.org/wiki/Export_of_cryptography_from_th...
There's always some other hacker in some other country ready to take your unsecured coins.
I'm not a lawyer, but I'm pretty sure that using a guessed key to transfer funds is as illegal as using a guessed password would be to transfer funds from one bank account to another or using a "guessed" house key to enter a house and walk away with the TV.
That's not to say that you have a lot of options to get your ether back, but that's not fundamentally different from regular theft either.
That puts him squarely in the jurisdiction of whatever country the victim lives in, with all the complications that entails (for the thief, that is.)
This is basically theft where there is no risk for the thief.
Sure, my point is just that the difference isn't in legality or possibility for recourse, but in the probability of successful enforcement of the law. The problem isn't so much that the thief is in another country, even if he lives next door to you, it's impractically hard to track him down unless he makes a mistake.
Regular theft certainly occurs and is illegal, however this scenario is entirely different from the most common types of regular theft.
A criminal operating in a foreign nation is going to steal: physical items from my house, my wallet, my car, items in my car, my bike, the watch on my arm, the tv in my living room, valuables in my home safe, valuables in my safety deposit box (that one is very difficult in general)? Nope.
The most common types of regular theft involve physical items that are physically lifted. Even most bank account scams are performed domestically, not internationally.
There is an extraordinarily tiny set of potential criminals likely to, or capable of targeting me when it comes to the most common forms of regular theft. It is not open to a global-scale competition as in this 'blockchain bandit' case.
A friend recently had their vehicle broken into. A thousand dollars worth of physical items were stolen. Half of it was recovered quickly by checking local pawn shops. Good luck doing anything like that with Ethereum and a foreign bandit.
That's true, at least for recognizable things. If the thief steals currency, e.g. a stack of dollar bills, you'll have about the same potential to get those bills (or others) back unless you locate the thief. The jurisdiction adds a layer of confusion, but that's not the relevant part imho. If I break into your mail account and illegally transfer your domains to my hoster, you'll have high chances to get them back, even if I'm in another country or continent, because there's a central authority that has the power to make it happen if you can provide sufficient proof. There's no such authority for ether (well ... they could fork, but realistically, they won't) or cash, and that's what makes it hard.
Nothing could stop you from opening a business that would offer insurance in case of key theft. Most banks offer around $100k (depends on the country) in case they go bankrupt or robbed which is very little if you have life time savings in them that are way more than $100k. Big banks have an advantage though in that if they ever go bankrupt they tend to be bailed out by the government which is hard to replicate as a business (you still end up paying for it through inflation so you don't technically get your money back when your bank goes bankrupt as the total value of your money goes down).
I don't think insurance models work for this. How can the insurance company verify that the key wasn't stupid simple? It seems very hard to determine prices and premiums if can't assess the 'risk' - knowing that all 'risk' comes from the potential of user-error and nothing else
Also, there's the issue that in our financial system its very difficult for the common person to transfer all of their money to another account they own and call it theft. If I'm not mistaken that is a possibility with every single cryptocurrency, right?
There is no way to prove a key was stolen and no way to prove the theft was not a fraud. Insurance is backed up with jail time for insurance fraud and is STILL rife with fraud (especially automotive insurance).
Blockchain theft insurance is not a business that would survive long.
Of course the anonymity factor would make it all difficult, but on the other hand you can't ever truly abscond with the cash. If they could trace the movement through the ledger to a legitimate business entity that respects the same country's laws, they might be partially recoverable.
At a small scale it would be a waste of time, but on a large enough scale it might work.
Why not? If they only garanty $100k and everytime you lose your key you get to pay more like car insurance. Making it more expensive to fraud with time. Not to mention all the fraud detection mechanisms that could be put in place and jail time could still apply if you're caught frauding.
Just like cash.
From a privacy standpoint classic dematerialized money (credit cards and such) are a major regression.
A good cryptomoney offers all dematerialization benefits, and enforces privacy even better than cash.
I don't think that's true. If you could go to the cops with dead-to-rights evidence that someone stole your coins, pretty sure the cops could still charge them with larceny because the law still views cryptocurrency as a form of property. Plenty of people have been charged with crimes for stealing cryptocurrency -- the ex-secret service agent who stole from the custody of the Silk Road investigation comes to mind.
It's just that catching and prosecuting cybercriminals across jurisdictions is a _very_ hard problem that it might as well be that you have "no recourse" in 99.99% of cases.