No, you couldn't have made more money than the Twitter hacker
fortenf.org
fortenf.org
> The big issue with all of these is that it’s very difficult to participate in the stock market anonymously. The SEC has all sorts of monitoring in place to catch more common forms of insider trading and fraud and you can guarantee that they would conduct a long, thorough investigation into a hypothetical hack-based market fraud. Unlike Bitcoin transactions, wire transfers and stock purchases can be reversed after the fact, and the exposure and risk go way up when you’re actually working with US dollars.
But this is divorced from reality. In reality you'd be one of thousands of people holding HTZ calls or TSLA puts in your Robinhood account. You could make a huge payday and be indistinguishable from the crowd. With the crypto scam, one person will eventually have to turn this BTC into fiat. With market manipulation, you've made thousands of retail investors indistinguishable from yourself rich. Which one sounds like a better idea?
Former options market maker. We regularly got incredibly detailed data requests from regulators following corporate actions. Everyone who made money got scrutiny. Anyone who made money who wasn't similarly profitable before is almost automatically punted to their broker's compliance department, who will put in several hours of investigative work by default.
One of the most consistent knowledge gaps between professional and amateur traders, I've found, is the underestimation of how advanced and pervasive insider trading / market manipulation surveillance is.
> Anyone who made money who wasn't similarly profitable before
WSB is one offs and gets investigate. Other market players have historical data showing they are not one hit wonders. Like someone who hits 5/17 is different than one who hits 1/21
It's something you know intellectually, but MAN it's wild to see it in action.
The price of Tesla would plummet by 75% for at least 30 mins while the mess was sorted. If it dropped to 500, you could make 500k easily without very much risk of being detected. Then switch directions and buy calls. Easy money. Or get 5 friends to but 1 put each. Not that hard and pretty undetectable.
Can you please explain to us how all-knowing and how all-powerful the SEC / gov is?
Given the SEC only has a staff of 4600 employees?
How advanced and how pervasive are their technologies?
Any examples?
And 4,600 is just the number of employees at the SEC — there are legions of employees at the relevant institutions who work on data compliance.
Someone who buys a few million in puts just before hacking twitter is indistinguishable from some random robinhood user who decides it's time to go all in on puts because of a wsb post.
Lots of people have had the idea that the SEC/FBI/etc. can never catch them. Right up until they go to prison.
Of course, insider trading among well connected hedge fund managers and our unaccountable financial elite is indeed pervasive and goes by without being prosecuted all the time, but it's fair to assume yesterday's hackers aren't in this protected class.
And a lot of those non-prosecutions involve either (a) civil fines, (b) the compliance department censuring or firing the relevant employee, or (c) the Feds backing down from a fight with a big white shoe defense firm. None of that applies to these Twitter hackers.
Any stats/evidence to backup your claim?
Because anyone could just buy a crap load of $0.10 options marked a week out, wait a few days, then tank the stock. It would look like you got stupidly lucky, I have no clue how anyone could connect that to the twitter event directly. Especially since it’s not like you’ll be the only one that “won the lottery”.
(Tesla isn’t a great stock for doing this though because their IV is so high that the premiums are crazy expensive)
The more standard deviations you go into profitability, especially over one trade, the more likely you'll be to get the stink-eye.
From that point, if someone raises a flag, it's just a matter of seeing whether they've been implicated in anything else. It's why departments that seemingly have no reason to have intel access are hooked into classified networks - precisely for this kind of data sharing.
Precisely why you would be caught.
So you would investigate this poster for insider trading? There are thousands of posts like this each week.
For these people buying $10,000 out of the money contracts on a random ticker is completely normal and still legal. So tipping somebody like that off would certainly hard to correlate.
Is your position outsized relative to other punters in the OTM weeklies market? Most people don't bet the farm on one big lottery trade because the risk of ruin is too great.
Will there really be that many people who time things as well as you do and haul in a bonanza payout as though they had perfect foresight? A lot won't even be watching the market for the 5 or 10 minutes your rumor moves the stock, and of those who are, a lot of them will hang on for moar gainz.
Basically you can use not that much money to buy unlikely to be profitable options and make an actual crapload of money - and it would look identical to just being lucky.
The thing is 90% of people don't trade options themselves, and 99% of people don't do random fd plays. If you tipped off someone from WSB then they'd likely get away with it - that's what they do. Tip off a family member who has never traded options before, well....
Time is also a factor here. It's possible the hackers here were afraid their insider would chicken out. If they were afraid of that, they don't have time to setup a realistic looking brokerage account, transfer money and do some trading to make it all look good. That type of setup would take weeks or even months. If you sign up and the first thing you do is go all in on TSLA puts shortly before this happened you're gonna be on a list of suspects.
(This is assuming that the hackers did not have control of the time window in which they had elevated access.)
Yes, but of those people, a lot of them probably have a history of buying TSLA puts because they are generally bearish on the stock. Or a history of buying calls on HTZ. And they've lost a lot of money in the past over this, because TSLA keeps going up and HTZ keeps going down.
In other words, I can look at all buyers of HTZ and TSLA stocks and most likely eliminate those with histories of buying puts or calls on these stocks.
So now I have a smaller pool of people who suddenly bought HTZ or TSLA puts/calls. Of those, I can probably eliminate anyone with small positions. This isn't worth risking for a profit of a few thousand dollars. Sure I can get a few friends together to invest from their accounts, but the more people i involve, the more i risk. Plus, i can't just do family members or friends who live nearby (unless i'm in a major city), because it'll look strange if a group of people who are related or live close to each other are running the same trades at the same time.
So now they have whittled it down quite a bit. So i bring in the FBI and I start investigating my much smaller list and I target it towards people with computer savviness. It's can probably eliminate accountants and many others who most likely don't have skills to hack twitter. So it's a smaller group of people and the chances of getting caught are no longer so small (not to say it's impossible to get away with it though).
It's not comparable to something like the Hertz thing which drags on for weeks or the TSLA run-up which has been going on for months. Imagine filtering for trades that happen within a specific 120-second window. Then filter by people who have atypically large volume during that window. It's not a long list.
Also, you could filter for new traders and traders overly invested in TSLA. Giving the rather mediocre execution (i.e. single Bitcoin address), I doubt the attacker had a lot of time and capital upfront to hide in these masses.
Lastly, stock market transactions can be paused and are reversible - there's a good chance of a circuit breaker hitting or a reversal happening with that blatant market manipulation.
Keep in mind that a lot of the SEC's enforcement breadth comes from brokers' compliance departments. Any time anyone makes an unusual profit around corporate actions, the SEC basically requires a thorough investigation by the broker's compliance staff.
> I highly doubt that the SEC wouldn't put the required resources into this
I doubt they would not -> I think they would
The SEC would be extremely motivated to find these people to make an example of them so others think twice in the future.
Not sure I agree they'd have investigated thousands of people.
Because prosecuting Elon Musk requires going up against top tier defense lawyers and proving things like "Musk tweeted this with the intention of impacting his stock's value" or something.
With hackers, you can use the financial stuff to target the hackers, and then either (a) prove the computer crimes or (b) use the computer crimes and the surrounding stock sales to prove intent. You also don't have to go up against a legal defense better funded than some militaries.
You and I and yesterday's Twitter hacker are not in this class.
Given that he said "buy the stock" and "short the stock", options leverage may be the missing puzzle piece for the author.
When communications are hacked, the market typical figures it out in a matter of minutes. Anyone wishing to capitalize on a Twitter hack would have to have perfect timing to exit their trade.
If someone was trading options of a similar volume all day every day before and after the hack, they might be able to blend in. However, once you filter down on the number of people who caught windfalls in the narrow window of time between the hack and when the market reversed and then filter further for people who invested atypically large amounts on that particular trade, it's not as short of a list as you suggest.
As of today, Hertz trading volume is around 5 million, while Tesla volume is around 13 million.
I still think the OP is underestimating the risk of getting caught though.
- Any head of state is communicating directly with the press at all times through their comms department and/or they themselves commanding the focus of the press.
- Any specific company targeted, as soon as the movement in their valuation occurred, would be able to blast out the truth via PR Newswire that the specific claims were untrue and the result of a hack.
I think in this case since the correction would occur so quickly the number of trades executed made by retail would be pretty easy to sift through, and you’d undergo heavy scrutiny, even if you had an established trading history that explained your position taking.
A retail investor would be very easy to catch, basically. On something like this, I’d imagine enforcement would be a federal priority. The data available to law enforcement on matters like this is voluminous and it would only be a matter of time. Lack of enforcement is usually just a resource constraint or low prioritization. You’d have to have a much more complex plan than just taking and exiting a market position.
The only conceptual framework I can fit the idea of getting away with hacking twitter accounts to move the market and successfully exiting would be an institution with billions of positions moving fluidly in a predetermined way to align with the information seeded by the twitter posts for a short period of time. But why would anyone do that right now when all the investment banks have close to record revenue? Just 5 months ago, investment banks were in a rough spot. Now they are raking in this market recovery with little effort. I don’t know why you’d expose yourself to prison for a one time gain that would be limited because the institution needs to it make it obvious this occurred so you cannot extract maximum return.
1. The attacker has enough capital to load up on HTZ calls or TSLA puts.
2. The attacker has been planning this for a while.
3. The attacker is a US citizen
If any of those is not true, it changes the risk/reward considerably.The money one is easy. Even if you get a bunch of call options for free, and if you manage to temporarily push TSLA down 10% (unlikely), then you still need $900,000 in working capital in order to exercise enough of those options to be able to dump them later for a $100,000 gain.
#2 and #3 adjust the actual risk of the operation. #2 because shoving the money around quickly gives a clearer signal for the SEC to pick up on, and #3 because triggering a whole bunch of extra KYC red tape risks getting even more hounds on your trail.
BTC does have to be turned into fiat. But I can only assume, based on how rarely people who conduct ransomware scams and the like seem to get caught, that bitcoin laundering is a solved problem.
Furthermore, professional black hats tend to have business expenses that can be paid in bitcoin so they don't even need to convert all of it.
Not true, you can sell to close back into the market without exercising. This is what most options traders do.
Also you can easily get them for "free" in a manner of speaking, if you use something like a bull put spread. You sell a naked leg of the position that pays for the purchase of the other leg.
Doing this anonymously would be much harder, but that's not what you were suggesting.
It's likely you could continue to narrow things down via KYC data; location, past trading history, etc.
Sell a call spread, buy a put spread, do a diagonal calendar...
The more relevant question is "does the SEC employ people aware of the various techniques available", to which the answer is "of course".
There are certainly some strong employees as well, but they have only so much time.
An objection that, while true, doesn't impact "will they go after Bitcoin scammers" much. If anything, it's precisely the sort of thing they'd prefer to do over fighting with industry.
If you don't leave evidence for a targeted inspection against you, it wouldn't help them to be able to narrow it down to "you probably did it" if they couldn't clear the "reasonable doubt" hurdle.
Regulators already surveil and request records in respect of trading activity following corporate actions. No warrant needed.
There's nothing to hide after the fact. Dump the burner computer you used for the hack when you're done and never log in to the accounts, VPNs and VPSs you used again.
That you have the money is an open and legal fact, so you don't have to conceal anything really.
That's what efficiency looks like. Each transaction took a small amount of time, the clerks processed each one efficiently and had little downtime between them. Each clerk was maximally utilized, and the DMV was fully utilized all day.
A DMV where you could walk into at any time and a clerk was available to help you immediately would be incredibly inefficient: it would have too many clerks who were being paid to stand there not working. Convenient, yes, efficient, no.
Yes, one can find examples of incompetence and inefficiency if one looks, but one can find the opposite as well. I think a blanket attitude of government == inefficient incompetence is an unhelpful one, and a major part of how you get DMVs that deserve the purgatory comparison.
You might be the only trader taking investment advice from Taylor Swift, but plausible deniability is all you need
One of the advantages of using BTC for this attack is that as a stateless currency, fewer states are willing to dedicate resources to pursue people getting their BTC defrauded out from under them.
Like what? Any proof?
How many crimes out of 100 do you think are actually caught and prosecuted by the FBI?
https://www.nbcphiladelphia.com/news/national-international/...
In this case, someone trying a major stock market manipulation would have drawn a lot of org resources. And given that even without those resources, it appears the dragnet may be closing in on them (https://krebsonsecurity.com/2020/07/whos-behind-wednesdays-e...), it would have likely been a bad call to try actual stock manipulation with their hack.
Any efforts to defer that (using a patsy with an established trading history, buying longer-term options, buying them earlier) cuts into your margins, and may well not work (since again, you've got to be the first one out since you know it's a momentary dip).
[1] - Remember, you know this is a momentary dip because you know the hack is going to get discovered soon, but the other investors don't know where the bottom is.
Also, I suspect that if the hack had occurred during market hours, Twitter execs would have aggressively shut down the entire site. I imagine the hacks were intentionally timed to start after the markets closed to maximize the window for bitcoin payments. Twitter stayed up, so if that was the strategy, it seemed to work.
Synchronize intent in one online bubble. Make it look like banal, random, distributed behavior via Robinhood transactions.
Mom, dad, grandma, and grandpa sat on the couch shouting impotently at Dan Rather.
The kids are shouting about all that behind their backs and figuring out how to leverage information technology from age 5 at a different scale than 30 years ago, to coordinate
Feds would first filter the list of traders who have clean backgrounds and narrow it down to anyone who haven't been trading the stock for a while and they will review anyone who have withdrawn their cash quickly.
Unless you have been doing years of planning, planting clean evidences, you would stand out from the crowd.
This is utterly clueless.
Finally, people (apparently even the "informed" crowd here) greatly overestimate the difficulty of identifying individuals or actions in massive systems that are effectively recorded and completely surveilled, and they underestimate the resources of the feds. It's usually not that hard to whittle down to a handful of actions, and even if there are hundreds it only takes a tiny bit of taxpayer money to comb through it by hand.
It just requires having capital already and trading the indices.
Not if the perpetrator already participates in a cryptocurrency economy.
And even if the individual wants to convert to government currency, do you think that's a big hurdle in post Soviet states, or for state-sponsored attackers?
If they didn't mean the BTC address to be an authenticity stamp after the fact it seems silly to not have varied it to get around blocks.
edit: They can also use it for blackmail even if there's no incriminating DMs. By making up fake DMs and then using the authenticity stamp to "prove" they were authentic. Could cause quiet a bit of chaos if released in the right way and be worth something to someone.
Elon Musk might have some suspect DMs, but honestly I think his crazy Twitter behavior is priced into TSLA already.
The hackers may have saved the DMs from lots of accounts and only publicly used big accounts which don't have any DMs to publicize the hacks
In that case, it's irrelevant what the public thinks of them, all that matters is what the blackmailed individual's ability to pay and what they thinks about the public seeing them.
Put another way, maybe Musk's DMs being leaked doesn't actually change anything, but maybe Musk feels like it changes a lot for him, either personally or professionally. That's worth money to someone with the DMs.
If you're Musk with his money and resources, what's $10k or $20k to keep knowledge out of the public that you slept with your friend's or some random famous person's wife, or cheated on your girlfriend? The amount of money something like that is worth is relative to available money to the person and what the personal cost is to spend it. How much does it hurt Musk to spend $100k? Would he spend that much to try to keep knowledge of someone woman pregnant with his child getting an abortion? I think probably, if he thought he could keep the fact he paid secret if it came out later, since that would only make any story worse (regardless of how he feels about abortion, paying a lot to keep it secret is just fuel for any criticism while also being worthwhile for anyone that wants privacy).
It's a win/win situation, they can't lose. They've invested nothing in their scam to begin with.
If that value is still small, then there is no incentive to raise the price of the bounty.
It's tough to know for sure if it would've made more, though. Given the limited time window, I think I slightly lean towards exploiting greed vs. exploiting altruism. If they could somehow keep he tweets up for over 24 hours, I think your idea would likely win, but given they may have thought they might have about an hour, I think the scam route might've been more reliable.
But the general sloppiness of the stratagem points towards not having the time / resources to do that.
As for which one would win, I don't know. I can see the argument of immediacy with the scam. The charity scam I think would draw in a lot more smaller donors but I can't see them feeling the need to immediately send.
Personally I would have gone with the bounty, then shamed Twitter for the (probably) low payout in an effort to promote my brand.
The problem is that the attack requires active social engineering to pull off, so it probably wouldn't have been eligible for a bounty. "I could trick your employees and gain access to user accounts" isn't really covered.
The hackers knew their tweets would be pulled down in a few minutes or so, so they had to put out tweets saying "in the next 30 mins" for people to send money immediately.
This works well in what they tried, but asking people to donate in the next 30 mins would certainly have made it look suspicious.
Even media could have fall.
Than they can come with Jeff Bezos yes I'm donating too. It would have more real.
It's human nature to play games like this. The whole idea of startup "IPO exit" is really just a ponzi play (if you think the company is good - why the heck would you sell it just as soon as the "dumb money" moves in?).
You could set up a plausible history ahead of time by doing innocent TSLA trades. Maybe establish a pattern of regularly scheduled trades. And then it just so happens that the fake tweet comes out right around when your scheduled trade was going to execute.
Not to mention that this requires a lot of upfront time and capital and depends on no circuit breaker being pulled, which would be quite likely giving the high amount of damage and blatant market manipulation.
"Signs of progress toward a coronavirus vaccine by Moderna propelled most corners of the stock market higher. … Most of the gains followed the release of a new study suggesting Moderna had reached a breakthrough with its coronavirus vaccine, setting the stage for a larger trial at the end of this month. Cruise-ship operators, airliners and other stocks sensitive to the coronavirus crisis led the stock market higher. Shares of Moderna rose $5.18, or 6.9%, to $80.22.
Royal Caribbean Cruises Ltd. was up 21.2%. Norwegian Cruise Line Holdings Ltd. was up 20.7%. Carnival Corp. was up 16.2%. American Airlines Group Inc. was also up 16.2%. United Airlines Holdings was up 14.6%. The biggest gainers were the vaccine-sensitive industries, not Moderna itself."
[1] https://www.bloomberg.com/opinion/articles/2020-07-16/a-vacc...
People with enough money to be investing regularly also probably don't need to orchestrate elaborate smash-and-grab cybercons to make money. People in such a position would already be doing fine and would have the added bonus of never fearing going to jail. I suspect whoever did this likely doesn't have much fiat money, or if they do, it's probably mostly dirty money which wouldn't be feasible to invest with.
Here, there's no risk/reward trade-off like there would be from shorting. It's a much more scalable attack: every additional hijacking results in additional expected value, but no additional risk. With some form of stock betting, the more you scale it up (in terms of reward potential), the more the activity would stand out.
I think the attackers made the smartest possible decision, given what they had/could do, if their goal was purely total profit (plus not getting caught). If their primary goal wasn't money, then it's certainly a squandered opportunity, but most criminals are just in it for the money.
I mean, yeah, there might be a ten or hundred people who match this criteria, but market manipulation is a very serious crime and when people lost many millions, the SEC is going to pour a lot of resources into checking everyone.
EDIT: This is also assuming the hacker is American. I bet you a lot that this matches very few people in, for example, India.
I have heard of drug busts that began with detectives going to a university in a town where the drugs (think synthesized drugs) seem to be originating from. Cross-reference all students on financial aid with all students that had taken Organic Chemistry 300. You could count the number on one hand.
Each were watched, one was seen making the handoff....
Will they go to those same lengths to find people who profit a few hundred grand or a mil on the stock market, when the consequences of what we're talking about could result in tens or hundreds of millions of dollars of profit/loss?
These arguments all seem to be operating on the assumption that there would be a large number of day/swing traders who would exit their positions with perfect timing, but this is unlikely because they wouldn't have the knowledge that the price move was ephemeral and driven by a false rumor. The number of people who made a half million off it would be a lot smaller than you think.
There aren’t that many individual investors with short positions that large.
Watch stock go up, sell before the whole thing is clarified.
Here's a scenario demonstrating the idea:
Let's say I spend $92,300 to buy 61 shares of TSLA at its current price of $1,512.18. Then I post my Tweet causing TSLA to jump to $1600.00 on the same day and sell my 61 for $97,600. My total profit is only $5,300.
But what if instead I buy $92,300 of 7/17 TSLA call options at $1600? They cost only $9.23 per contract for 10,000 contracts. Now the same price movement to $1,600.00 today causes the value of my options to increase to $39.16 per contact. I can sell them for $391,600 netting me a total of $299,300 for the same starting capital. If you have access to margin then you're talking millions in profit with even a small price movement (though at that point you probably have to start worrying about the SEC).
In general though I agree with you - I think a person absolutely could make more than $100k on the market with not a lot of capital and get away with it.
Of course, "not a lot of capital" is still more than no capital.
The only time where the SEC has a really easy chance of catching you is with very out of the money puts purchased only days before the attack. The volume is much lower there and that's a much more common way to make money on this stuff (since with put options you don't need to short massive amounts of the stock).
Not quite, I believe most major exchanges banning the address probably did a lot more to control the situation. Twitter took way way too long to react and their best course of action was just blocking all tweets from verified users...
Many people, hundreds if not thousands, have long positions on Hertz. They may be able to find something suspicious, but not anything that could differentiate you from "I read on wallstreetbets that buying these Hertz calls was a good idea." Especially if you seed your account with a few similar bets first.
And then you're still in hell, because instead of having a total damage amount of 120k$ plus some vague twitter downtime you now have cost investors millions of dollars and are in the highly illegal territory of stock market manipulation, instead of a rather simple scam with modest damage.
Also, saying "I've read that on WSB" is nice, but the FBI is still going to take your equipment for a nice inspection. No fun, I can tell you that.
Yes, the FBI can do much more with having all your personal and financial information handed directly to them then they can with the IP address of a VPN exit node in a server log. There is no comparison.
What if the US Federal Reserve had tweeted out a link to fake economic data suggesting an enormous fall in the USD was around the corner? Algorithmic trading could shift the USD by $0.01, which when multiplied 100x could have a pretty large impact on your USD/EUR play.
Any foreign actor could get a brokerage account with relative ease compared to hacking a major social network. For the SEC to investigate, they would have to go through multiple companies to find the account. First would be the exchanges to search for suspicious trades. Next the clearing brokerage firms which online fintechs use to do the trades and then lastly the the fintech that stolen account was created on. Much longer to investigate than it takes for the money to settle from the trade and to get money out of the account.
Also there is a good change that you wouldn't trip any of the online FI's monitoring. If the money went out to the same account it came in on, that isn't that suspicious and happens all the time. The cash transfers would generate SAR(suspicious activity report) but still that would take a while for government to process and investigate.
Authentication of a person is broken in the US and needs to be fixed. We can't rely on credit report data and SSN.
Also use different addresses per account. Should be really easy.
This Twitter hack could have changed history, could have made some group of insiders fabulously wealthy, could have started a war, etc. Yet they "waste" it on an obvious scam.
My competing hypotheses:
- The hacker got way in over his head and panicked (the wasted opportunity branch)
- The hacker siphoned the DMs from the hacked accounts (and others that did not tweet out the scam), and this is just the beginning
- There are larger forces at work, and this was a demo for a larger client and is part of a longer play
The name of 2600 magazine is inspired by the story of people who---having discovered the worldwide telecommunications grid could be manipulated by properly-sequenced audio tones---used that knowledge and power to make free long-distance phone calls.
seems unlikely, considering that the nature of the hack (compromised insider account) would most likely be cut off after detection. That's exactly what happened in this case.
- The hacker intentional choose a rather low-crime way with modest damage amount so that Twitter catches most the heat and he doesn't have all three letter agencies hunting for his head.
- He knows that OP-SEC is hard and choose a way that was simple enough to avoid traps.
So yes, there's definitely going to be a search, but he could've gotten far more heat.
How do you start a war on Twitter? Let's say the hacker impersonates Trump and tweet "Missiles heading your way Kim!!", then what? First of all, every develop nation in the world has ways to detect missile launches. Second, there would just be a phone call between embassy asking "Whut??" and the situation would be solved in 15 minutes.
People need to stop pretending that Twitter is the real world.
With Trump though, it gets more complicated. He has antagonized and name-called the leader of NK on Twitter. He has announced policies on Twitter that even his cabinet weren't aware of beforehand. If he posted the above tweet (sub out "Kim" for "Little Rocket man") and you were Kim Jong-un, what would you do?
Sure, he's never announced a military attack on Twitter before (I think... although I'm not 100% sure) but given the other things he's done and his general nature, could you be 100% sure it's fake? And if it's not fake, then the rational thing would be to counterattack with whatever capability you have without waiting for confirmation from someone else.
And then, if you're one of the US Joint Chiefs: You see the tweet, you know that it's false, but you consider it from Kim's perspective (see the last paragraph) and have to game out the chance that Kim will see this as a credible attack and launch his rockets, in which case you'd want to launch ours immediately.
It's totally possible that they could get Kim on some sort of "Red Phone Line" and convince him that it's fake before he launches, and that might even be the most likely outcome. But if the hacker timed this right (to some time where the president was asleep or harder than usual to contact) I feel like there is a nontrivial chance it could result in at least one nuclear warhead getting launched.
The tweets would have to be subtle and not something you wouldn’t say or now can back down from easily without damaging your reputation .
Social engineering is not a hammer , it needs find grained understanding of psychology , pressure points and what resonates with the crowds , these are skills which blue checks also need to be well blue checks that’s probably why they are more scared .
manipulating public opinion is their day job after all .
Deep fakes and hacks like this are scary for them coz these attack at the core of their strength - the trust the people have in them and their ability to manipulate it .
One of his central interests is how these decisions are made. Where is the conference room? Where are the decision-makers? What does it take to get them assembled? What are their moods and information diets, and how might that influence them in a moment of crisis? What are plausible sequences of "accidental" escalation events that might align the stars for a nuclear launch? And how might Trump's Twitter interact with all of this?
It's fiction, obviously, but if you're interested in the guy's bona fides, this is some really fascinating open source intelligence work [0].
You absolutely could make money in the stock market instead and it has happened before buy trading the indices. The "problems" with individual companies don't exist when trading indices like the SPX or VIX.
This has already happened before, Associated Press' hacked twitter account sent out something alarming sending the indices in a brief frenzy. Like long enough for trading to react before correcting.
On paper, the stock strategy could make more money. In practice, I think it's extremely unlikely it would be the optimal strategy here, or even a decent strategy. The maximum potential reward would be higher, but the expected value would be lower. (Perhaps it'd be negative, even, depending on the probability assigned to imprisonment and asset seizure.)
I think the attackers chose pretty much the best possible strategy if their sole goal was maximizing profit and minimizing risk of getting caught. Someone else suggested maybe setting up a fake call for charity donations, which might have worked even better, but overall I think they picked the smartest plan.
Taking it as hard cash sounds risky or laborious. Taking it to a bank account will trigger red flags. A story will have to be told that makes sense and holds up.
Converting it slowly over years is an option, but I'd put that in the 'hard' category especially if you keep doing this and sending the balance up.
That being said... There is technology out there the FBI is hopping in bed with that is used to track this exact thing.
I think if they tumbled it an insane amount, they might get away with about 90% of the principal.
They most certainly could have gotten away with some form of manipulation using Elon's (or someone else's) account and gotten away with it.
The idea isn't to be anonymous per se, it is to blend in with the crowd. You join a few communities, you can easily, easily pull the Casino Royale short position/puts.
Say that production is halted, that you discovered faulty accounting, immediate recall, etc. Tesla would've plummeted.
And that's if you want to blend in with the crowd of volume and people holding puts, which, are not that expensive, especially if you push out a few weeks.
--
With bitcoin, it is not anonymous. You will have a pain to cashout 100k+ of bitcoin. The address is now literally blacklisted, the coins will be forever tracked, exchanges blocked and whenever there's movement, ironically, twitter threads will appear similar, if not akin to bitmex margin calls.
Any localbitcoin dealer worth their salt, would flag it because even if it's in escrow, it is most likely that small amount would blacklist their own account, especially since most traders are cheap and will send from exchange>localbitcoin escrow.
- If you never trade in options or short sell, but the first trade you do is a massive windfall, that will stand out.
- To earn a decent amount, you need a lot of exposure to the particular stock. If you're not exposed somewhere else, and only to tesla to maximize this particular great trade, again that stands out.
- The above may narrow the scope, so when investigators look at you particularly, does your personal background include technical capabilities that others in the narrowed group would not have.
I suspect your correct in the sense, that if you had lots of assets, regularly trade in markets, and can be prepared ahead of the hack that you might be able to pull off market manipulating. But if you stumble into this huge hack as the author sort of points out, and were trying to pull this off before someone else discovers the bug or exploit and are unprepared, for many it doesn't seem likely they'd be able to manipulate the markets without standing out.
- You could use a tumbler.
- You could use an exchange without KYC. Not all exchanges are US based.
- You could use websites such as morphtoken (preferably over a VPN, TOR, or i2p proxy) convert to any blockchain (perhaps Dash to create anonymized transactions) then convert back to BTC.
And a few more...
Playing the stock market is a huge risk as the SEC can probably filter down most participants who would've benefitted. It's far riskier.
And if you want to blend in with trades made by some insider community, then any posts you make there to trigger that crowd (and the timing of these posts) will be useful evidence to separate you from the crowd. I mean, it's just as with the investigation of pump-and-dump schemes with the added benefit that after warrants to sieze and review computers you can also get some evidence of the hack.
This significantly underestimates effectiveness of market surveillance tools.
First of all, market surveillance is going to score trades based on profitability and on the expected value of outcomes. If the actor in question does not have a habit of trading options in certain patterns, he will be sticking out of the sea of other bets, significantly reducing the number of actors he can hide in. This will flag money movement. This will flag strange account funding. This will flag strange volume. This will flag strange time the order was placed in compared to the usual trades of this individual.
> If you do a good job, you've just convinced 100 people to be your patsies (and made them a handsome sum in the meantime)
This will probably not increase but decrease randomness.
The trick of avoiding being picked up on a market surveillance is not to hide among others who do what one does rather it is to hide a specific action one performs among a pattern of one's typical actions. That is why a hacker who does not normally trade options will most likely get nailed should he win based on a hack.
Regardless, you compare things to their alternatives. Here the alternatives are: make much more money, make less money, don't commit crime. The first and last alternative each have logical reasons to recommend them, the middle one doesn't.
But, in fairness, they haven’t actually made it yet though: it’s not cashed out and everyone’s watching the address like a hawk.
The Securities and Exchange Commission is drawing Republican criticism following reports that senior agency staff used government-issued computers to surf pornographic websites, according to the Associated Press.
An internal memo obtained by the AP said the SEC's inspector general has investigated 33 employees for looking at porn in the past five years, and 31 of those probes occurred since the financial turmoil began. This conduct violates governmentwide ethics rules, the memo stated.
It would have made total sense if the hijacked accounts suggested doubling others' donations to certain charities, as we have seen played out in the beginning of June. In fact, the first time I saw those tweets, with their "giving back" theme, I misread them as meaning exactly that, doubling donations to charities. But instead they were proposing to immediately send the money back, doubled. Asking people for money first is hardly a believable "giving back" offer; it should have raised so many eyebrows and red flags. Especially coming from Biden's account — I might almost believe it coming from Elon, but for Biden that would be completely out of character; he wouldn't have the imagination.
Also, I wonder if more of the value of the blackmail could captured with an auction mechanic; as in donate to X for public release or donate to Y to keep it private at a certain time the account with the most money wins. This mechanic could be manipulated behind the scenes for even more money.
>Gates: Coronavirus vaccine found. Secure yours by sending 0.01 BTC. Dont forget about your family ...
>nvidia: Limited early run 50 RTX 3080 and 50 RTX 3090 giveaway. Send 0.01 BTC to qualify ...
and so on and on
There was so much more targeting/personalization they could do beyond old tired 'double your ISK scam'.
$TSLA OTM call/put options with the right tweet could easily make someone millions, and the liquidity and open volume is crazy enough on them that it'd be very hard to be found out. If that isn't good enough, you could post rumors and tweets beforehand to cause many others to also buy in, and there would be no way to reasonably separate who was behind it and who just joined in on it.
For example:
1) Tweet as Elon musk "Very good TSLA news coming up"
2) many more people buy calls, including yourself
3) Tweet as Elon musk "TSLA earning are going to beat by so much"
4) sell your calls for puts
5) Tweet very negative/offensive/terrible content
4chan would go wild.
1. Change the order of who they targeted. The hacker started by attacking Elon Musk and a few other high profile celebrities. But, later in the hack, they tweeted from Mr. Beasts profile, a Youtuber who is known for giving away large sums of money. If they had started with Mr Beast, then there would be a lot less skepticism and a lot more confusion, since it would have been a lot more likely to not actually be a scam in users minds.
2. Target poorly regulated markets. Theres a decent amount of Liquidity on the betting market for the US presidential election on betfair. Have Biden tweet something out about him dropping out due to heart problems, have the Reuters/AP tweet a breaking news article confirming it, bada bing bada boom millions of dollars coming your way. Its not like the only liquid markets are well regulated. It looks like a hack thats designed to scare people for political points, but you can make money off it.
Why not?
I'm basing this on the fact that both the Trump and Biden campaign staffers are probably sending a lot of DM's. Releasing the most embarrassing information at the right time could prove pivotal.
This is not insider trading. When an insider tips off an associate, investigators have full information on the pool of insiders. "Who knew about this ahead of time?" is a strong filter. Assuming the attacker had perfect opsec and the attack itself doesn't leave evidence that exposes them, they live in a much larger and murkier pool.
Additionally, the attacker might have known of this vector months ahead of time. This gives them time to lay groundwork, find accomplices, and prepare.
Quick thought experiment:
There is a bar I used to go to pretty often. It was cash only. Aside from cell tower pings, possible Google Maps location history, and N days worth of security footage, there is nothing tying me to that bar. I've known one of the bartenders there for five years now. We grew up in the same town. We're not Facebook friends, we don't talk on the phone, but we've now known each other in this context for quite a while. If you had a perfect "back home" social graph, we're probably ~3-4 degrees of separation. Linking us to one another locally starting from his perspective would involve very invasive investigation (i.e. putting names to faces for everybody on the N days of security footage that bar has archived, a subpeona for bulk subscriber data of people who have been to that bar, etc).
If I try to involve him in my market manipulation scheme, there's the risk he turns me in outright or that he rips me off and keeps the money for himself. Basically, the criminal conspiracy version of counterparty risk. Set that risk aside for a moment. Assume that he's on board with the plan. Also assume that I, as the attacker, leave no digital evidence pointing back to me.
Think about how egregious his trading behavior would have to be to bring enough scrutiny upon himself that the SEC has people reviewing this bar's security footage, building profiles of the randos who have been to that bar, all that. I don't claim that "tipping off the bartender" is the world's most original securities crime, but unearthing that connection is a much more involved process than the cases of "spouse/sibling/college roommate/tennis partner of CEO bought OTM options a week before acquisition was announced."
X people make, say, 1-10 million dollars off of a zany bet on stocks. Imagine how obvious your trade would have to be such that Y years from now, one of those new millionaires moves back to East Bumblef and makes a money-losing real estate transaction with another East Bumblefian (say, moi), and the SEC jumps over a hedge like "ah-HA! We've been watching your accounts this whole time, that other East Bumblefian knows how computers work and lived in an apartment four blocks from your old workplace in 2015, nobody could possibly negotiate this poor of a land deal, checkmate!"
It's an ocean of contracts out there.
My guess is it would trend downward since my evaluation of $tsla is that it is a personality driven bubble; but my evaluation isn't everyone else's.
And if you really want to be pedantic, the hacker has made $0 from it so far, since the Bitcoins haven't been transferred anywhere to cash out. Which is pretty easy to beat :-p
As far as this topic goes: you could prove the argument false by doing a better hack and making a lot more money. Or we could gain confidence in it as years pass and hacks happen but no one makes a lot more money.