A 96 Bitcoin ransom payment ends up on Bitfinex
jpkoning.blogspot.com
jpkoning.blogspot.com
Consider these two scenarios: A stolen bike vs a stolen sack of coffee.
In the case of the bike, if you can find it you can take it back from someone else who bought it. You can identify it distinctly as your bike, even if it had been bought and sold multiple times.
Now imagine a stolen sack of coffee that the thief sells to a vendor at a market. The vendor dumps it into a big bin full of more coffee. Other people buy bags of it, some containing the stolen beans, some not, some a mix. Now you can't identify your distinct stolen coffee anymore. It's not practical to go after the coffee vendor or its customers.
Bitcoin works like the coffee example not the bike. Balances move around like so many kilos of coffee. If you were to make the coffee vendors or their customers liable for stolen beans they happen to touch then you can't have a functioning coffee market at all.
Of course that isn't to say the coffee vendor can't do anything. If the stolen coffee or money is still in the hands of the coffee vendor then they should turn it over to the police when informed. If it's already gone they can tell the police which way the thief went and how much money was paid. Hopefully the police can find the thief and take the proceeds of his crime to make the victim as whole as possible. Also, just because coffee beans can't practically be identified distinctly doesn't mean a coffee vendor that is knowingly trafficking in stolen coffee should get off the hook.
This is how it's done now with cryptocurrency and the biggest practical problem seems to be that law enforcement doesn't move fast enough to contact exchanges confirming that the claim of wrongdoing is bona fide.
That's not true. It just means that reputation, verification and insurance become critical to the coffee market and that friction makes the coffee market way less liquid.
Now, legislatures and courts may choose to provide indemnity to all unknowing parties to reduce that friction, but it is hardly the only course this can go. The coffee vendor could also be held liable for recieving and mixing that stolen property.
With the increasing amounts of money being lost by large insurance companies as a result of this issue and extortion claims, I would not be surprised to see laws in the not too distant future that move that liability off of the insurance companies and onto exchanges and indivuals. Large insurance companies haveich better lobbyists than cryptocurrency exchanges and the government doesn't seem to benefit from making sure cryptocurrency markets have minimal friction.
That is true, but generally everyone wants commodities markets to be low friction and liquid. Your point is well taken that maybe some governments would rather cryptocurrency markets be higher friction.
Also keep in mind that governments put regulations at points that tend to attract problems. Pawn shops in many places are required to keep records that other private buyers and sellers are not required to keep for the very same items.
> Now, legislatures and courts may choose to
Yes, and how this currently works now depends on what choices they have already made regarding stolen property.
In a lot of places the distinction is whether the property is absolutely identifiable as the stolen property. So in the case of a car, iPad, piece of jewelry or similar it is clear. If Malory steals the iPad belonging to Alice and then sells it to Bob then Alice can legally take the iPad from Bob if she can find it. Getting the money back from Malory is Bob's problem now. On the other hand if Malory steals and sandwich from Alice, sell it to Bob, and Bob eats it, then Alice cannot legally force Bob to compensate her. If Bob sold the iPad to Charlie Alice has to take it up with him, she can't make Bob hand over the money Charlie paid.
> I would not be surprised to see laws in the not too distant future
That may happen or may not, but right now the status quo is that once things have been disposed of by an innocent party the innocent party isn't forced to make restitution. Again, I am not going to claim this is how it works in every country on earth, but it is in the places I am familiar with.
If someone steals a 50lb bag of beans and sells them to me, I am now in possession of 50lbs of stolen property. If I sell 25lbs of the beans before the police catch me, they will confiscate the remaining 25lbs of beans and those beans become evidence. Then I will go to jail for receiving stolen property. Then the victim will sue me in civil court for reimbursement of 50lbs of beans.
Just because you can flip something that's stolen doesn't mean it's gone forever. The victim in either case doesn't care which beans or coins they get. They just want the value of n coins. You could probably skip giving him any coins at all and just reimburse him a dollar amount for the value of his property.
Please remember that for the purpose of this discussion the receiver of the stolen goods and the person they are sold onward to are 100% innocent and nobody suspects them of being dishonest. If the receiver was in on it then this does not apply.
If someone stole 2 iPhones from you and sells them to a used phone dealer, who then sells those very 2 iPhones - your iPhones - to someone else, does the law require the used phone dealer to give you 2 other iPhones of the same model that he happens to have?
I believe, and perhaps I am wrong here, that it does not. As the victim you may well be happy to made whole with 2 other identical iPhones but that is not what will happen. Furthermore, the used phone dealer will not be required to pay you any of the money he received from the buyer of your phones or reimburse you for the cost of your phones.
If the dealer had sold only 1 of the phones then you would get that back and not have to compensate the dealer for his loss resulting in paying the thief.
If the items were such that you cannot prove you own it, such as with coffee beans, then you get absolutely nothing. You do not get some fair volume of them to compensate you.
That is how I understand the way stolen property is handled in general currently. I am not attempting to pass a moral judgement about it, merely describe how it is. (may not be so in all jurisdictions, but in CA/US/UK/AU/at least some parts of SE Asia)
If he sells down the line. Police will follow the chain and if the property is found it will be taken and it will be used in trial and recovered back to you.
The people who bought the used phones may lose them. If they do they can sue the store. If the store hasn't sold them they will lose them and can sue the orginal thief.
But you can identify distinct stolen/tainted Bitcoin. Just like you can identify distinct stolen banknotes.
The difference (according to the article) is that banknotes have special legal status meaning that they're effectively fungible after being spent.
* Bitcoin proponents desire that bitcoin work like the earlier currency example, where an innocent actor who receives stolen currency at part of some transaction for a good or service is protected from having to return those bitcoin.
* Whether an innocent actor in that position is in fact liable or protected in that scenario is fundamentally up to the state(s) involved and their legislative choices.
This (as with the centralization of mining, and exchange prominence) seems to be another example where Bitcoin is -in practice- far more subject to the powers of states than its proponents respresent.
I postulate that few if any states will see any advantage in granting that kind of protection to bitcoin transactions, as states have incentives to ensure their own currencies can be transacted without rigorous detective work, and do not have these same incentives with bitcoin.
>I postulate that few if any states will see any advantage in granting that kind of protection to bitcoin transactions, as states have incentives to ensure their own currencies can be transacted without rigorous detective work, and do not have these same incentives with bitcoin.
Usually these principles apply to all currency, not just the states "own" currency. Why would states need to grant such protection to bitcoin transactions, as opposed to taking away such protection?
Bitcoins are not quite like the a banknote. If I have a $1 and $20 bill that's 2 things each with a serial number. I can give them to you, and you can give them back to me. Bitcoins on the other hand don't work that way. The movement of them changes them, even though you can trace the flow of the value represented.
Let's say someone steals your 1 bitcoins, sending 0.999998 bitcoins to himself, leaving 0.000002 bitcoins for the miner who confirms the transaction. Then the thief sends 0.999996 bitcoins to someone totally innocent in exchange for a car, leaving another 200 satoshi for that miner.
You find the person who sold that car for those bitcoins and he still controls that balance. Are you entitled to get those bitcoins back?
Well, say the car seller had no other bitcoin. One argument would be that he still has 0.999996 of your bitcoins, so he's obligated to give your property back and he needs to figure out how to collect for the car, tough luck for him. The fact that he doesn't have it all is no different than if his car was stolen and he found just missing a couple of hubcaps.
Another argument could be that no, your bitcoins were the UTXO that you could solve the unlock script for, which you still can, so it's like the car seller had received an item that your bitcoins were exchanged for (new script). I don't think most people would have much sympathy for this argument.
But what if your coins were only 1 input into the transaction sent to the car seller, and then the car seller spent half of on his rent, receiving back the balance to his change address?
Now we've arrived at coffee beans. Even though you can know the balances, you cannot say whether your bitcoins are in the possession of the car seller or his landlord. It makes no sense to say that each of them has half, nor does it make any sense to claim that one or the other has your stolen property.
So assuming bitcoins do not have the special money status and stolen bitcoins are going to be treated like other stolen property is then they are like the coffee beans in that they become unidentifiable without anyone trying to be dishonest.
Said value thus does not have to be decided in court to be returned - the question is, do you have to return it in cash of choice or Bitcoin?
The big question is how you find the responsible ransomer if they used a mixer, and whether mixer is culpable for not following KYC for big transaction amounts.
Not at all. You can merge stolen bitcoin with "clean" bitcoin. You can not do that with banknotes.
If you give someone two $10 bills those don't magically turn into a $20. That does happen with Bitcoin though.
Isn't this fundamentally _not_ how it works in the traditional financial world? If you are paid in ill-gotten money it can certainly be clawed back no matter how innocent you are.
This rather prominently came into play during the 2008 financial crisis when it turned out banks were forging wet copies of the original mortgage paperwork on foreclosed properties. When banks realized that it was a problem, title insurance started specifically excluding this, so the original owner could take their property back and you would end up with a mortgage on nothing.
Bitcoin literally has chain of hashes that mark a chain of custody and provably verifies transfers between addresses. Just because actors along the route are mixing it into a big wallet and distributing it out only means they are facilitating money laundering and could be easily be proven to have done so, and every transaction that touches that transaction is complicit.
I'm thinking that there is a need/opportunity to be able to register bitcoins as stolen and if vendors used that database, the whole raft of bitcoins used for nefarious activities and more so stolen ones, can be curtailed. Counterpoint to that thinking would be that it would not curtail the criminal activities such as ransom payments, only shift them into other forms.
Also interesting that the incident response team do not track or follow up tracing and tracking the bitcoins used and that a separate company and process was avenued. This shows that incident response is still a learning process, though encouraging that such situations are within their remit of response and as a service for companies - an important one.
Another take away from this is that law enforcement need to up there game, had this been hard cash, they would be driving this and not the insurance company. That shows how they are behind the times and most likely, budget/skill shortages playing out. But a million dollars is a million dollars in any currency, including crypto currency and again, had this been hard currency, you know that they would of been more resource involved. Though please don't take that as an indictment upon the police services, more an indictment of their resource limitations and one that needs addressing and raised up the flagpole.
Forcing an innocent to hand over bitcoins they had no clue they were tainted will make everyone lose trust in bitcoin and cryptocurrencies in general. What's the point of anonymity when trading when you're culpable for wherever that currency came from.
I would think that a ransom situation would likely qualify as some type of duress. Deciding whether the criminal act is "theft" (ie. stolen) or "fraud" or something else is probably missing the point.
And certainly, some aspect in the exchange (pay money for this encryption key) did not involve permission: the encryption of the files!
But, how to restore things after a wrong has occurred? I agree with your point that there is a risk of committing a greater wrong against an innocent party. Hence the special protections of currency as a unique type of property in the article. Does bitcoin fit this model? An interesting discussion!
If they're innocent, they will generally be able to identify the counterparty to whom they sold the goods or services valued at close to $1M, and the goods&services may then lead to the culprit; because (here's the thing) if they "just" did a fully anonymous $1M cash or cash-equivalent transaction, then they're not really innocent in many jurisdictions, because for large amounts money laundering laws generally (nuances depend on country) require you to identify the other party or not do it. Selling something anonymously for $10 in cash is innocent, but selling something intentionally anonymously for $1M in cash (or BTC) generally is a crime of money laundering by itself, no matter where the money came from.
The original article assumes (with no grounding, but just as an example) that the 'innocent recipient' might be some over-the-counter broker. That broker is legally required to 'know your customer'. And if they don't know their customers, well, then they're not innocent and deserve to lose their money.
The same applies to Bitfinex itself - they're required to know from whom they got these 96 BTC. If they don't, well, it's their problem, why not fine them the equivalent of 96 BTC or more for that.
The only reasonable solution is to track down the actual ransomers and make them pay for the damage they caused. Dragging other parties into this can only make things worse.
You can argue that we should suffer the extortionists for other benefits we get out of Bitcoin. I'm not convinced at this point.
If you're willing to harm innocents for the sake of your cause—even if the goal is to make things harder for extortionists—then you're no better than those you're fighting.
To say this is the moral equivalence of extortion is a long shot.
You don't have a right to trade anonymously; sorry, but that's called money laundering.
* A Mixer
* gamble on one of many online casinos
* buy physical darknet goods with them
* Hack someones account on an exchange and use it.
* The above, but use the coins to 'pump-n-dump' a tiny altcoin. Be one of many 'investors' making money out of the change in altcoin price.
* Go margin trading with them, but make sure to loose them all in a margin call. Do it on a small altcoin so you can be on the other side of that margin call.
Apart from that, every option you suggested just hands the problem off to the next person. Eventually people won't want to transact at all because they don't want to receive tainted bitcoins.
Let's suppose we see some nontrivial amount (so, not $100 but $100k) of BTC being cashed out to dollars or by buying some legal goods, and we see that this BTC recently passed through a mixer. KYC means that the exchange or merchant will identify "oh, that's Bob". And we can ask Bob - well, where did that money came from? And either he can provide some evidence that he got that money in a legitimate transaction from Charlie (who can then be processed in the same manner), or he can be convicted either of (a) using a mixer if he did so himself; (b) violating money laundering laws by doing large anonymous transactions if he did get money from some 'Charlie' that can't be identified; or (c) violating money laundering laws by refusing to disclose the source of these large cash-like payments.
It's not as simple and some particular nuances of the existing laws would need to be adjusted to make this process work, but that's something governments could and would do.
Not for small amounts that can obviously be laundered easily and nobody cares about that, but it would be quite plausible to ensure that no legit organization would touch a million dollars worth of BTC without ensuring a proper paper trail of how it got there; and anybody intentionally passing 100 BTC through a mixer would just make it difficult for themselves to spend those 100 BTC - because every recipient of large amounts will ask for a proper source for your funds, and a mixer is not one.
https://www.wired.com/story/bitcoin-blockchain-fifo-dirty-co...
"Given bitcoin traceability and the ease of getting an injunction, one can imagine that it might make sense for insurers, bitcoin exchanges, and over-the-counter traders to build some sort of private "ransom registry". The moment that an insurer pays a ransom to a hacker, that insurer simultaneously announces the offending address to the registry. A verified OTC trading desk can now protect itself from potential bankruptcy by always checking the registry to make sure that any bitcoins offered to it are "good" bitcoins. Exchanges too would likewise cross-check incoming bitcoin deposits against the registry."
e.g. 1. I pay you 1 BTC 2. Wait until I receive whatever I paid for 2. Now I tell you to send me 0.5BTC or else I'll report the entire 1BTC as ransom payment.
The blacklist is just a new and very powerful tool for additional fraud!
You could check the registry yourself before accepting change, but what if those bills weren't in the registry when you checked?
Such a system could be implemented for bitcoin but there are crypto currencies with stronger privacy guarantees for which this would be practically impossible (those guarantees could maybe be cracked in the future, people are working hard on both sides).
"When we receive our 96 BTC, we'll release your data."
Becomes:
"When we receive our 96 BTC without it being reported to the fraud registry, we'll release your data."
Take the 96 bitcoin, split it into 96 different addresses with 1 bitcoin, then mix those 96 individual addresses to multiple new addresses and then reassemble them elsewhere. This is a horrible explanation, but explains the general idea. You could also mix from Bitcoin to Monero or another currency and back again through various pairs.
There are lots of things out there to attempt to trace the bitcoins back to the source since every transaction is always logged, however if people keep rearranging coins on various addresses it does make it harder.
Having a blacklist registry of all bad/stolen coins would be great if implemented, however I don't know how feasible it would be.
A car with a stolen part does not, itself, become a stolen car, because there’s a clear division between the part and the car itself. The only thing the police would want to seize as stolen property from you is the stolen part—they’d get you to take it out of your car, and be on their way.
Cryptocurrency is less like car parts, and more like gold: putting the crypto through a mixer is like melting some (unknowingly) stolen gold jewellery into a batch of non-stolen gold, forming new gold bars, and then selling those. Is the whole batch of gold now “tainted” by the stolen gold? Does it all need to be seized as stolen property? If not, then what does need to be seized? An equal shaving of gold from each buyer’s new bar?
If it were possible to figure out which mixer recipient was the original jewellery thief, you could just seize their mixed assets, since those assets should be equal in value to the stolen input assets. But the whole point of a mixer is to destroy that linkage, such that you have no idea who any of the recipients are.
One, mixer output could be, by default, added to the registry as laundering proceeds. Or two, the subunits could be traced through the mixer, thus retaining their black marks.
You know how they say that every US dollar bill has a little cocaine on it? Using your suggestion, every dollar bill would be marked tainted as drug proceeds.
Let me put it this way: what would you do with your float if you run a convenience store in a bad part of town, and know that there are marked bills floating around in the local economy, and that the police might pop in at random one day and take them out of your till? Well, you'd probably deposit your float in your local bank at the end of each day, and then get new, guaranteed-unmarked bills from the bank. That's mixing! It's not money laundering, just mixing. You're removing the potential liability of being blamed for what your customers' employers' customers' employers did.
If someone buys a coffee with tainted coins, is the cafeteria now responsible for querying the registry to reject the transaction? Or it risks to have whole daily turnover, if spent together, end up tainted?
Ex: If half of the bitcoins used to buy a car were fraudulent, would you need to return half the car?
So a laundering service could specialize in buying tainted coins and to sell them off to other unsuspecting people, pocketing the difference. In return they could provide clean coins for their customers.
This risk would have to be managed by contracts, insurance, and/or quick exchange for safer assets.
Some decades ago (unfortunately, so long ago that I can't easily find any references to it - it was probably in the 1980s), there was a robbery of a large number of bank notes in my country. For a while after that, all cashiers at markets had a booklet with the serial numbers of the stolen bank notes, so they would be rejected and/or reported to the police. That was possible because the bank notes were newly issued (so they had blocks of consecutive serial numbers), and had never actually entered circulation (IIRC, they were stolen before arriving at the bank).
While the situation is not identical, there are some similarities: an innocent person (who did not take care of checking the serial number when receiving a bank note) could have their money rejected when trying to buy at a market (and would probably also be questioned by the police).
(I don't recall whether the one(s) who stole the bank notes was/were actually caught; are there other Brazilians here who remember about this case? I think it's not the 2005 robbery, which stole only notes which had already entered circulation.)
Is this typically the case? As far as I understand, fraud losses for example are often treated quite differently than stolen goods. Are ransom payments really considered stolen?
This doesn't necessarily seem like the kind of a situation where the nemo dat rule would be directly applicable, especially given that it doesn't typically extend to money anyway.
No, the relevant law doesn't apply to stolen goods. It only applies to goods that were obtained by the seller with the consent of the original owner.
"Where a person having bought or agreed to buy goods obtains with the consent of the seller possession of the goods or the documents of title to the goods, the delivery or transfer by that person or by a mercantile agent acting for him of the goods or documents of title under any sale pledge or other disposition thereof to any person receiving the same in good faith and without notice of any lien or other right of the original seller in respect of the goods shall have the same effect as if the person making the delivery or transfer were a mercantile agent intrusted by the owner with the goods or documents of title."
The only cryptocurrency that comes close to solving this is Monero, which isn't traceable.
If the attackers were smart, this is what they would've done: Send them to Bitfinex, which is an unregulated and shady exchange, sell them for Monero and withdraw them immediately. Congratulations, now you have a bunch of untraceable cryptocurrency.
[1]https://news.bitcoin.com/how-to-obscure-bitcoin-cash-transac... [2]https://medium.com/@tornado.cash/introducing-private-transac...
with cashfusion not even the server owners know which transactions belong to who, which isnt the case with normal mixers[1].
[1]https://medium.com/@james.waugh28/is-cashfusion-really-anony...
Traceability doesn't need to be a problem.
Steal enough banknotes and the bank will go to great lengths to find you. The Northern Bank robbery stole a significant fraction of all NB notes in circulation, so the bank re-issued them, relying on the impossibility of the criminals laundering them before the swap deadline.
https://www.belfasttelegraph.co.uk/news/northern-ireland/the...
As such, traceability will remain a risk for anyone receiving cryptocurrency payments. If a chain analysis reveals an illegal transaction as a precursor, it's going to be considered stolen goods, not money, as the article states.
That's fine, but if the governments don't take action it'll be up for the courts to decide that.
>it's going to be considered stolen goods, not money, as the article states.
This is not at all obvious. It's not even clear that the nemo dat rule would apply to any kind of ransom payment.
The governments don't need to do this, the courts do. There's an existing principle they could very cleanly apply here.
Yes it's a little different from the problem described in the post, but it's another facet of the fungibility issue.
The same way they could decide to ban Monero... seems like what you describe with z-cash is more complex to support in an exchange than simply removing a whole cryptocurrency, thus is less likely to happen.
Don't forget, that this pool should be part of criminal organizacion because I don't think any businessman will invest hundreds of millions of dollars and risk his mining operations shut down.
Surely any pool that adopted such a policy would lose most of their members pretty quick. Same for any pool that leaves money on the table by deliberately excluding valid, profitable transactions.
Small miners will not be able to include, because of orphaning. I agree, that it's not easy process and its expensive.
However, I still see this as a good thing; if the hackers did sell 96 Bitcoin to one single buyer, then we can now start a paper trail (or physical evidence) on what the single buyer gave them in return (paper money transfer?)
If one were to sell a sports car in exchange for a pile of marked bills taken from a bank robbery, one would rapidly find oneself in hot water. Receiving stolen goods is a crime.
Edit: after reading TFA, this is the crucial point (in English law, I guess): "Banknotes, coins, and other highly-liquid paper instruments have a very special legal status. ... was granted to banknotes centuries ago in order to ensure that ... money remained highly liquid. If every merchant had to verify...". Interesting case.
In practice, the law is not trying to 'get' people who innocently receive stolen money or goods. In the example you gave, it would be up to prosecutorial discretion what to do; trying to claw back one salary's worth of already-spent money is probably not worthwhile.
But if someone shows up and tries to deposit a couple grand worth of marked bills, they can expect to be taken into a police station for questioning, and should fully cooperate: this makes it unlikely that the penalty will extend further than confiscation of the stolen cash.
The important thing to realize is: if any of this goes to trial, the prosecution only needs to prove that the money is stolen. It doesn't need to prove the receiver knew it was stolen; that's not what the crime is here, that knowledge makes it a worse crime, accessory to robbery.
https://en.wikipedia.org/wiki/Possession_of_stolen_goods
The state-level standard appears to vary, the most common case is 'should have known', rather than 'knew for a fact'.
With Bitcoin, where all transactions are a matter of public record, I'd hazard that 'should have known' is baked-in. It will be interesting to see what case law is established in this arena.
That said, my statement above is clearly stronger than reality, except in some states where knowledge doesn't need to be proven.
Who should have known what? After receiving any bitcoin (can't be before!) everyone is obliged to figure out if the coin came from a ransomware attack? How? And what do they do if some of the coin was so tainted?
This is different than recieving other types of stolen goods that haven't been given this special legal status, which ensures that money is fungible and can be accepted with relatively little concern by honest people.
As for your example I'm not sure. Said repairman would unlikely be in legal trouble, but I don't know if the money would be seized or not.
> Banknotes, coins, and other highly-liquid paper instruments have a very special legal status. If you unknowingly accept some banknotes from someone who just obtained them illegally (say via ransom or theft), the law can't compel you to give those banknotes back to the original victim. Money, as the great British jurist Lord Mansfield once declared, isn't like regular property: it "can not be recovered after it has passed into currency."
So the key questions are if cryptocurrency qualifies legally as currency and if not, what the legal standards are for who ends up the owner of that property when it gets mixed via various means.
> The penalty for larceny and the crime of receiving and concealing stolen property in Michigan depends upon the value of the substantiated property or money involved.
https://www.cyabdolaw.com/larceny-and-receiving-stolen-prope...
It says nothing about the need to return stolen money recieved as part of a legitimate seeming transaction.
https://github.com/bitcoin/bips/blob/master/bip-0341.mediawi...