Live BTC transactions in Twitter hack
blockchain.com
blockchain.com
Please discuss the general aspects there and the BTC aspects here.
What I like most about decentralization is that anyone in the world can create a new crypto business on the blockchain rails, integrate with everyone else, and attract users. Of course there are real-world repercussions if your physical entity is in a locale with laws that you violate, but it is orders of magnitude easier to start a crypto exchange than a traditional bank.
Also, I've read that silver is hot now, given the likely surge in the silver/gold ratio.
Most people can open a credit card or bank account in 30 minutes or less. Waiting a week for a blockchain to download is a non-starter for most.
Regardless of that, I recently synced Monero from scratch in 3 hours, over a 802.11n network that never seems to do better than ~75Mbps. We can extrapolate that Bitcoin would be done in something like 9.5 hours. So I don't know where you got a week from.
If you still don't like that, you can always use a remote node, in which case you can begin using a new account literally immediately, even better than your 30 minutes at a bank.
IMHO that is a perfectly fine tradeoff for a new user who doesn't want to commit to syncing the blockchain. Nevertheless, when I deal with new, non-technical users in the Monero community, I find that they almost always prefer to run their own fully synced node, even though they understand the tradeoff (i.e., that using a remote node is probably fine). I even had a guy that has no computer, phone only, looking for help on setting up a full node on his phone.
Anecdotal perhaps, but it certainly makes me skeptical of the claim that blockchain size is a big hurdle for many people at all.
Oh yeah, and just for completeness: you can prune the blockchain with both Bitcoin and Monero if storage space is a concern, reducing it by something like 70%.
Also I'd test your speed report, but ultimately I don't want waste 300GB or 85GB of my monthly download cap on that experiment. In the past download was slow and CPU usage was high while syncing. I don't see people running to devote a large portion of their internal storage or download cap for crypto, unless they are crypto enthusiasts.
No, it doesn't. Why would you make such an absurd statement? Using a remote node is nothing like using a centralized payment processor. For one thing, they can't gain access to your funds. For another, there are thousands that you can use interchangeably.
If you're relying on a completely hosted webwallet, then you really don't know that they don't have access to your funds. If you use something like Electrum then there is less risk, but you're still relying on a third-party to relay accurate information to you about the blockchain, which could possibly open yourself up for attacks(albeit complex and likely limited in scope). Every new tool/service adds more layers, and means more trust of third parties is required.
It's laughable to compare this to using a third party which can hold your funds indefinitely and censor your transactions with no recourse for you. That's very simple, and unlimited in scope.
Sure, running a local node is even better, but using a remote one doesn't "remove the benefit." That's nonsense. It removes maybe the bottom 1% of the benefit while leaving the other 99% intact.
I didn't say it removed all benefit, but removed the benefit of "not relying on a third party", because you are. It sounds like you're saying "you can most likely trust those third parties", which is not the point of being independent.
It's simply not comparable to trusting a third party that can block your transaction without recourse and/or hold your funds indefinitely.
If you are worried about other wallets not accepting "my" wallet, as is the typical problem with hosting your own email, you don't need to worry. Money is money, if I receive it I receive it. It's just completely different from receiving a text-based message like the wide-open and free SMTP is.
- It is decentralized, but some exchanges process big percentages of conversions. Transferring the coins to other BTC wallets is decentralized. Moving it out of the BTC blockchain is often done through exchanges though, but there's a lot of them, and you can avoid the exchanges as well.
- No, everybody controls it; it's a consensus-based system, so if enough people agree on taking things in one or another direction it will. Look up "hard fork" in the context of BTC.
obv the hackers will likely use multiple addresses
Once you’ve got the infra in place, you can have AML and other compliance staff triage and action from a dashboard (blocking suspect transfers until further review has been performed, and releasing transfers of a review shows nothing suspect).
(Have done some AML/KYC work in the fiat finance space)
Only because I've seen first-hand how advanced their taint analysis is, so I'm already over that surprise.
I'm betting Gemini also blacklisted that BTC address, especially considering that they were in the first wave of fake tweets.
Really wondering now just how much BTC the attacker effectively left on the table by reusing a single wallet address, especially considering that lots of people who deal in crypto use just a handful of exchanges to send it. Would be pretty difficult to quantify, though.
In the traditional banking and commerce system, if you get scammed on, say, ebay, they will refund you. If someone hacks into your online banking, the warranties set by your bank will refund you (to a point). If your bank goes tits up, the national bank will compensate you.
Yes you pay a fee, but it's insurance.
Anyway, your statement + the actual scam in question just reminds me of eve online, where the money doubling scam is old as balls. The funny thing is that the operators of the game allow it - nobody stole money from you, you gave it away. Some scams there are long hauls, people slowly working their way up in the ranks of a corporation before liquidating the assets and taking the money. Again, the company behind the game will do nothing because their systems have not been compromised - YOU gave the person access to the company wallet. It's funny.
Bitcoin is the same, you're responsible for your own actions, you don't pay an insurance fee, you bear all the risk yourself. If you give your BTC to an exchange and they get hacked, that's on you because you moved your money out of your own wallet. They may compensate you (or print their own money to do so), but they may not have to.
CCP's policy on allowing this type of grift is fair, if greed overtakes rational thinking then the 'victim' has no one to blame. Granted in this case they used trusted twitter users to trojan their scam, not sure that has happened on eve.
This makes all the chain analysis companies and the armchair blockchain sleuths simply follow transactions on the bitcoin blockchain forever, thinking they are doing something productive with their lives, while you have hopped over to another chain that they can't track assuming they even noticed that you swapped.
That was a viable last decade solution and is unfortunately centralized, this decade in 2020 you can also use the decentralized renBTC to permissionlessly lock up and mint your bitcoin as an erc20 token on the Ethereum blockchain. So now you are really liquid and have access to the entire decentralized finance economy.
But again, if you really want to get government bucks and an unlinked trail, you need to sell the renBTC token for Ether and move that Ether into either Tornado.cash for a little while, or go back to the centralized solution like Morphtoken and swap the Ether for XMR as XMR has an inherently stronger anonymity set than anything else.
Peace.
In any case as your lawyer might tell you: if the origin is illicit it is money laundering. If the origin is not illicit then its not money laundering.
The irony being that it is the onus of the accuser to determine the origin, and if you do it right that is not possible to know in any scenario. Typically money laundering then is a tacked on charge, after other clear evidence is already known, to help ensure a conviction.
But really at this point, its probably better if your public resources weren't spent on flagging transactions in the first place, and if the private sector was not burdened with doing this work for the state.
It is if done for purposes of e.g. avoiding taxes or purchasing illicit goods.
That said, obfuscation per se is not illegal in most jurisdictions.
yes, people need to be aware of the universe of illicit origins. When I was working for the US government most of the people indicted under these laws (structuring, avoiding reporting thresholds, and then obfuscation so money laundering) were not terrorists or drug dealers. They were people like landlords freaking out because a tenant was suing them and they wanted to move their money without triggering a real or imagined $10,000 threshold. Whoops structuring is illegal straight to jail and we’ll take the money too! Tenant lawsuit still pending lol.
All while HSBC completely undermined the ‘purity’ of the licit financial system in the tune of billions over many years on behalf of the LITERAL CARTEL. Guys, 9/11 wasn’t that expensive to pull off, and today’s compliance measures wouldnt have flagged those wire transfers, so who is this for?
Stigmatizing the whole concept of having money and moving money has been an expensive and unnecessary and fruitless exercise. While increasing the costs of offering a financial service.
Non-political checks on the power of the state, like cash and its electronic corollary, private digital currencies, are needed in case of the failure of the political system to prevent the state from becoming oppressive.
An institution like physical cash can be powerful/deeply-embedded enough to survive totalitarian governments.
No. The obfuscation of licitly-acquired funds used for illicit purposes is still money laundering.
And it can't be, as long as fiat money exists. There's no tracing involved in passing notes around. The only times fiat transactions become suspicious is if you try and cross a border with a lot of cash or valuables on hand, which is where crypto comes in because it knows no borders. This makes law enforcement nervous.
I'm sure that besides crypto there's many ways to move large amounts of money or valuables across borders though. The rich do it, they just set up shell companies and pay licenses for intellectual property, paying a token amount of corporate taxes.
I'd like to have some anonymous money just in case the future gets really dark, but I'm not sure if it's wise to flag myself as a BTC purchaser that changes to XMR.
stop using surveillance coins to begin with and just use Monero natively instead of as a conduit
In the mean time pollute the pool by doing more lawful transactions in monero, monero is half as old as bitcoin and has only been used on darknet markets for half of that due to its older user experience challenges
Just swap to the more fungible asset. Its a flight to liquidity the market always chooses that.
The state just figured out how to use transparent blockchains as a tool a decade late and the market has already moved on
The ROI won’t be great but you’ll have virgin coins to do what you want with.
even in hot climates where power isn't cheap enough, buying digital asset mining computers to breakeven or even take a 5-8% loss is the best way to convert any amount of money from that local economy into the global digital economy.
Of course, if the future is dark enough for a list of everyone who has ever bought XMR to be compiled, then your name would be on it, along with mine.
If you're worried about that, I suppose you could distribute the XMR to a bunch of different addresses over some length of time. (All addresses you control, unbeknownst to the authorities.) Then if they do hunt you down you have a plausible story that you spent it all.
For real money, hire someone who knows what they're doing.
Not really, you need to be able to justify to the tax authority how you got in possession of any amount of assets you have and prove you pay taxes on it.
So if a large amount of money eventually show up in your bank account (or you buy a house or any other "visible" asset) and it is not compatible with your previous tax returns it is likely the tax authority will notice it and at that point you are fried
Reread that paragraph and dont skip it this time.
You run a very successful fly-by-night VPS service paid for only in crypto. There is a decent sized market for that by the way. Too bad most of your customers are fake, anyway be diligent and actually mimic your customer behavior over TOR.
Run a subscription service.
Figure it out. Some to all of your customers will be fake because it will just be you making more accounts and paying yourself.
Report taxes on your wildly successful SaaS cloud business.
Assuming you even want govbucks, you deposit the clean crypto into your business and personal bank accounts.
No different than cash based services except its online/digital native and not constrained by local market liquidity and brick and mortar overhead.
Usually they do that when they stumble upon them during tax/laundering investigations, but they'll prosecute anything.
And isn't it easier to simply cash out XMR you've allegedly mined back in 2014? Long-term held. cost basis zero, capital gains rate 20% max in the US. That's even better than the 21% corporate income tax.
Privacy and tax evasion are not identical..
the licit private transactions are indistinguishable from illicit
Edited to add: I’ve heard of drug dealers doing it. Whether it’s true or not I can’t say.
That’s the point of criminalizing all options
Or just avoiding an easy conviction under tax evasion laws?
But they also were trying to bust him for evasion because he declared zero income and lived a visibly lavish lifestyle. The government was gathering evidence on his spending to estimate his income and how much he evaded.
You can't sustainably solve that problem by simply paying lots of tax on magic illegal money, especially not in today's interconnected world. Laundering is core to the solution.
not paying taxes on illicit activities = tax evasion and likely discovery of illicit activity in criminal investigation = FAIL
money laundering = illegal if the government has determined the source is illicit = FAIL
those are the options and deterrents.
if you money launder with proper obfuscation, you wind up with money that you do pay taxes on and will never trigger an investigation.
BTW when you declare your crypto gains, the IRS not only does not care about the source, there's not even a place on the forms to list the source.
That might change in the future though.
You want to unlink the transactions
Maybe eternal September wouldn’t have happened...
The success rate of those simulated attacks dropped drastically after the first few tries. Maybe if more companies did this it would also help fewer people to fall for it outside of work.
New address: bc1qwr30ddc04zqp878c0evdrqfx564mmf0dy2w39l
Tweet: https://mobile.twitter.com/CashApp/status/128352200769559757...
Edit: I was only making a joke, relax. Most likely it’s not a single person’s mistake. It’s just something you say when shit hits the fan.
1) A single person is responsible for the flaw.
2) A single person is either already under performance review or committed gross neglect of duties.
3) The above single person will be terminated rather than retrained.
If this is how you would speak about your own employees during a security incident, your business deserves to fail.
If this is how you expect to be treated by your employer during a security incident, you should seek employment elsewhere.
Would you joke about firing someone for a mistake during an interview? I would consider that a dealbreaker if I were interviewing someone, as in "this interview is over, go home".
Do you consider HN an appropriate forum for pithy one-liner jokes that do not contribute to the discussion? Reconsider.
I saw this happen before. A newish IT guy accidentally deployed a script to a few hundred machines that took down the whole worldwide intranet for a multi-billion dollar juggernaut for an hour or so. He was supposedly forgiven, but ended up on a "performance improvement plan" where he had a bunch of impossible tasks, and every shortcoming was documented to use against him until he was fired.
I wish things worked the way you think they do, or if not that way, I wish they'd at least just shitcan the dude on the spot (with a few months' severance) and be done with it.
These tactics are hard to prove if someone goes to court over it (probably) but are just as hard to recover emotionally from and can stunt a person all the way to their next job or many.
You might even get a free laptop out of it..
(This comment is only considering employment in the UK)
Would have made them more difficult to track and shut down as well. More hallmarks that this wasn't probably something they lucked into, rather than some sophisticated attack.
Several high-profile Twitter users, including Elon Musk, Bill Gates, and the official Uber account appear to have been hacked, and all promoted that address, saying any funds sent to it will be doubled.
speculation time: How did those accounts get hacked? Did they all get spearphished? Did twitter get compromised?
The curtain has been pulled back for some. Their favorite tweeters aren’t actually tweeting themselves
Edit: I also wonder if it’s an elaborate money laundering scheme. Mix coins with deniability. Combine with the Epstein drama, maybe there’s more to what meets the eye. Either way it’s popcorn time
If what you are saying was true, there would be some sort of evidence. Plus musicians/pop stars are very different from Official corporate twitter.
Special protected accounts (e.g., Trump's) seem unaffected, whereas hundreds (thousands?) of "regular" accounts, high profile and small, are compromised.
Bill gates and Bezos not showing up on twitter search. Twitter ghosting some of the affected accounts
Weirdly enough, sold a half a Bitcoin, made a bad investment, put the rest into Bitcoin, still 0.5BTC.
How it works is that the scammer announces in an area (usually the trade hub system Jita) that they're quitting and giving away all their money. They link to a webpage that (they claim)_shows all of their bank transactions, using Eve's API.
You send them 100K just to try it out, they send you back 200K, both transactions show up in the webpage. "Ha it works!", you say, sending them 1M, they send you 2M back.
Until at any point, they stop sending you money back. Their outgoing transaction shows up in the webpage, but ingame you never received anything. When you message them they go "must be a bug, I sent the money because look at my transaction log. Contact support, not my problem, the money left my account"
You'd think it just doesn't work, why would anyone fall for that, but plenty fall from it. Plenty of people try and outsmart them as well, making use of it to earn some money. But as another commenter pointed out, it can be like a game of roulette.
1TransactionoutputsAsTexta13AtQyk 0.00000667 BTC
1YouTakeRiskWhenUseBitcoin11cGozM 0.00000668 BTC
1forYourTwitterGame111111112XNLpa 0.00000669 BTC
1BitcoinisTraceabLe1111111ZvyqNWW 0.00000670 BTC
1WhyNotMonero777777777777a14A99D8 0.00000671 BTC
bc1qxy2kgdygjrsqtzq2n0yrf2493p83kkfjhx0wlh 0.00001337 BTC
Can anyone explain what happened in this block of transactions to me?
I guess the choice of BTC but the scammer(s) was based on its much bigger popularity relative to Monero (many people have a few satoshis somewhere, but not many have some monero lying around)
How did you find that so quick?
https://tokyo2018.scalingbitcoin.org/transcript/tokyo2018/ho...
https://arxiv.org/pdf/1704.04299/
Basically, the chaff transactions go to/from wallets actually owned by people. If you analyze enough of the chaff transactions, especially when the XMR that made them up is respent, you can deanonmyize users.
This is why people recommend you do not reuse wallets often but that still does not solve the problem.
Zcash I think is secure, or is per most analyses I've read.
https://tokyo2018.scalingbitcoin.org/transcript/tokyo2018/ho...
https://arxiv.org/pdf/1704.04299/
Basically, the chaff transactions go to/from wallets actually owned by people. If you analyze enough of the chaff transactions, especially when the XMR that made them up is respent, you can deanonmyize users.
This is why people recommend you do not reuse wallets often but that still does not solve the problem.
Zcash I think is secure, or is per most analyses I've read.
These transactions were sent from a vanity address(es) [1], and in this case they're used to spam the recipient with implied messages, specifically about their poorly viewed scam--take it as a 'l33t' way of sending a message, hence the amount on the last tx. Another notable one was the EnjoySochi, as in the Olympics, transactions that spammed the network for a while 6 years ago [2].
1: https://en.bitcoin.it/wiki/Vanitygen
2: https://bitcoin.stackexchange.com/questions/22404/why-is-enj...
Creating a couple of wallets and a website can be done mostly anonymously. Sure, the money is a lot less, but so is the risk.
> If you've ever watched Goldfinger, you have to wonder if the real ploy isn't somewhere else, such as auctioning off DMs, blackmail, etc., and the bitcoin thing just proof of concept.
0: https://twitter.com/tylercowen/status/1283518906041278468
Perhaps they felt as though they already had everything they needed and didn't mind ending their access? That would be weird, though, because I imagine long-term, continued access to DMs would likely be more valuable than just cutting out now.
Usually it's in April but this year it was delayed for Covid.
https://twitter.com/search?q=bc1qxy2kgdygjrsqtzq2n0yrf2493p8...
They'll all say "Twitter Web App" as the tweet source.
If you search through all accounts (ie: also the unverified ones), you see plenty that say Twitter for iPhone or Twitter for Android. Those are likely trolls.
Those are here: https://twitter.com/search?q=bc1qxy2kgdygjrsqtzq2n0yrf2493p8...
Replace the old BTC address with this one: bc1qwr30ddc04zqp878c0evdrqfx564mmf0dy2w39l
In general, we (humans) are not great at assessing the potential of negative/positive effects beyond certain scale (black swans and all), and analogies along the lines of “like X, but digital” are just too attractive. Those analogies are dangerous, since the scale makes Y an entirely new thing with effects that cannot be predicted based on its outside similarity to X.
This applies to many concepts including infosec (e.g., likening remotely exploitable vulnerabilities to faulty door locks), cryptocurrency, mass media, though when I was writing the above I mainly was specifically thinking about cryptocurrency. It is misleadingly similar to “cash, but digital and not backend by government”, but its scale makes it something we actually have never had to deal with before, with unknown implications that go both ways.
Considering the potential effects can be unbounded, limiting it in order to bound the downsides ones might be a rational (but both unpopular, boring and ambiguous) thing to do, even if it also limits the upsides.
EDIT: Replies are right. Now I see that the majority of it went to the same address as the source.
[1] https://www.blockchain.com/btc/tx/4df1391d936d3256ce84a867e1...
Total Received: 11.39184745 BTC
edit: OK, either this is strange or I don't understand how it works.
If your coin is 1 and you want to send one person 0.2 and another person 0.3, you can do that as a single transaction to three destinations, one with 0.2, another with 0.3 (to the people you’re sending to) and a final one with 0.5 back to one of your own addresses (aka a change wallet)
Say you have 1 BTC on an address and you want to send 0.1 to someone, you still need to send all of the money. So wallets "split" the 1 BTC into 0.1 and 0.9 outputs, sending the 0.9 to yourself to another address you control. It's called a change address.
Modern wallets do this automatically, but it can be confusing to look at it on a blockchain explorer.
It's time to learn more about Bitcoin. :)
I am not sure how much that is for them but there are claims that the 'regular' version of that scam already nets millions a year.
Twitter after all has a lot higher risk than the 3rd party app, it is in their interest to make sure partners dealing with high profile accounts or partners handling a large volume of accounts are also secure.
12 years after it was founded.
1JustReadALL1111111111111114ptkoK
1TransactionoutputsAsTexta13AtQyk
1YouTakeRiskWhenUseBitcoin11cGozM
1BitcoinisTraceabLe1111111ZvyqNWW
1WhyNotMonero777777777777a14A99D8
1forYourTwitterGame111111112XNLpa
Link: https://www.blockchain.com/btc/tx/67b814526ae6ee78a16059bfcf...
The hackers basically ran an advertisement on the most followed Twitter users in the world, and had 374 conversions (based on the number of transactions as of the time of this post).
Maybe now things will change.
which one of us did that?