The rise of crypto laundries: how criminals cash out of Bitcoin
ft.com
ft.com
Its kind of hilarious that an article in mid-2021 treats this as novel, or that it is novel to many people reading it now.
To me this is like reading about bearer bonds from a 1950s heist.
Chain-hopping is as old as crypto exchanges. It has some folly, because even if a chain analysis firm or armchair blockchain sleuths aren't inspired enough to consider or look on another chain, the records are still permanent.
Hopping over to XMR or privacy chains has been available since 2014. Even with older versions leaking some rings, the best practices from back then still mitigate that, and rotating anytime since 2017 ensures mitigation through now.
The article lacks anything coherent, providing maybe a tiny spark of inspiration for investigators and people enamored by the crypto phenomenon, but wasting everybody's time because there are other techniques fairly unique to the crypto space that are more accessible and efficient and not secret at all.
It goes from Hydra market duffle-bags of cash hiders (lolwut), to chain-hopping and scant mention of privacy coins. It randomly talks about Wasabi wallet same-chain bitcoin mixers, and then talks about Bitcoin Fog's operator being arrested which is much much older technology. It doesn't acknowledge or provide awareness about people actually wanting the privacy coins to begin with or staying within the mixing system (or trading claims to assets in the mixing system), and just assumes people are trying to obfuscate briefly with the end goal of holding non-private coins or fiat.
I don't get the impression that they were avoiding describing useful techniques for criminals, I get the impression that they have no idea.
I suspect this is the case; I used to really enjoy the FT but think the spark has gone since the Nikkei acquisition.
I wonder, recalling the Panama Papers incident, if this has effectively happened already!
They typically launder money via "foundations" or "charities". They acquire power by purchasing media companies. They use the media companies to control public narratives to shift the Overton window of public policies. They also use it to manipulate the truth as it suits them[1]. Their target population for controlling thought narratives are yuppies and the lower classes.
[1] https://mobile.twitter.com/DrewHolden360/status/139733532441...
Someone saying "the privacy of someone moving $100M is bad" sounds reasonable to my public ears.
It is not just the proceeds from criminal activities, but also tax evasion (from the rich or companies) and terrorism financing.
Nit: only if you use zcash shielded wallets(very rare & resource hungry) are your assets private. Most wallets use transparent addresses, which is kind of similar to normal ones.
Given current landscape, only monero is defacto private.
ever heard of CRS (Common Reporting Standard)?
I am fairly certain that many citizens would be tempted to become creative in their transparency (or activities) if they knew they would never get caught. Such is human nature.
It relies on reporting and the right to audit, so they may end up with all of the information anyway; it's more that you are making them ask for it rather than providing it proactively.
E.G. I trust my medical data to my doctor with some reasonable confidence they are using it responsibly.
Same thing here, I can trust my financial institutions with my data, but I want it to be open to authorities to look for criminal activity. I would ideally like that data to be placed under some legislation a la the GDPR to ensure it's used responsibly.
To be clear, I would much rather my data be sold to some advertisers than for corruption/criminal activity to exist.
I get that's not what you want, but it is what OP wants and I can see why.
All part of the eternal struggle between individual freedom and societal good.
One of my other comments might be useful for you in articulating this in the future:
I honestly get why some countries have capital controls; rapid shifts in capital can be truly devastating to a small economy. And criminals are some of the people most eager to move large sums of money to other legal jurisdictions. But there are definitely cases where money laundering isn't linked to what most people would consider crime.
We didn't. This is something that has changed in the UK in my lifetime. Unless you were the subject of an investigation you didn't have to provide much detail to the tax authorities, and what you did provide was kept strictly separate from other areas of government.
There was an attempt to strike a balance with the emphasis on privacy. Nowadays the government thinks it is entitled to all the data all the time.
I've lived in London for 3 years and don't think I've ever used cash for anything in that time. Trains, buses, taxis, bills (don't even need snail mail for those), restaurants, shops.
Outside of London it's a little different, but it's only a matter of a a few more years.
It was very easy. The American public was hoodwinked into accepting the 16th Amendment (levying an income tax) as a tax the rich scheme. And like all tax the rich schemes it was a cover to tax everyone, especially the middle class. You can't have an income tax without the government prying into everyone's finances.
Before this financial privacy was the norm.
The first American income tax was also introduced in a war - the Civil War.
There are occasions where society's interest in preventing crime outweighs personal privacy, and one way to look at that is that when something (like, say, ransomware) has an effect on other people, it can no longer be reasonably called private. When that happens, as long as there are reasonable checks and balances, I'm fine with banks giving out information, especially when it's organizations that generally respect the privacy of the people involved.
>> but how have we always just accepted the lack of personal privacy when it comes to finance?
>We didn't. This is something that has changed in the UK in my lifetime. Unless you were the subject of an investigation you didn't have to provide much detail to the tax authorities, and what you did provide was kept strictly separate from other areas of government.
>There was an attempt to strike a balance with the emphasis on privacy. Nowadays the government thinks it is entitled to all the data all the time.
I agree it's valid not to use a bank; one could try to conduct all one's business in cash. But in practice, people doing that are often doing something criminal, so people using cryptocurrency should not be surprised that they end up being treated with the same level of scrutiny as people running around with briefcases of cash. That is to say, their attempts at secrecy may result in a practical loss of privacy.
A reasonable check and balance would be the requirement for the state to get a warrant, issued by a court when probable cause is found, not 'every transaction over $10,000 is reported to the state for its warrantless mass-surveillance system'.
The $10,000 threshold was set in 1970, when factoring in inflation, it was $70,000 of today's money, and when average income was lower, making its application more seldom still.
The dragnet steadily catches more and more transactions from the twin trends of rising real incomes and inflation reducing the real value of the threshold.
We should oppose warrantless mass-surveillance of private financial transactions for the same reasons we oppose mass-surveillance of every one's private communications. The desire to live free from crime does not justify engaging in either.
I think most would agree, and that AML laws are only instituted due to:
1. the complexity of the subject matter obfuscating what these laws do
2. the euphemization of AML laws by the AML industry, like calling them anti-money laundering laws rather than the more descriptive 'financial surveillance laws', and
3. the stigmatization of money, as a result of the public relations efforts of the many who stand to gain from laws restricting people's ability to transact with it.
[1] https://www.reddit.com/r/MakerDAO/comments/de0sys/kyc_is_abs...
[2] https://www.coindesk.com/money-reimagined-ugly-side-kyc-aml-...
[3] https://twitter.com/SpencerKSchiff/status/125276128577685913...
What you are describing as a right: the ability to subject others to warrantless mass-surveillance, violates the core liberal principle of Western culture, namely the rights to privacy and the presumption of innocence.
And for good reason. There is no evidence at all that abrogating these core rights makes people safer, either from threats in general, or specifically from crime.
You would not benefit from it you would loose money
I'm all for privacy, anonymity, etc - which is one of the reasons I'm very excited about crypto - but you always have to look at things from multiple angles.
If you send your coins from wallet A to wallet B with CoinJoin, it's not possible for a third party to identify this transaction, but you can disclose the seed of wallet A and sign a transaction from wallet B thus proving ownership of both.
Its not. Well, by definition it is but it is paradoxical. Money obfuscation is not illegal, but when the source of the money is illicit then money obfuscation is money laundering, but successful money laundering means nobody can ever distinguish between a licit or illicit source, and it is up the accuser to prove the source was illicit, which should be impossible. (Whether there are records or not, there should be no probable cause to receive or act on those records at the standard needed for a criminal investigation)
So, only unsuccessful money laundering is linked to criminal activity, and deterrence relies on stigmatizing all money obfuscation.
Unfortunately this is exactly their position, which they have made quite clear - and it isn't limited to financial transactions. Its the same line of "reasoning" they use to decry the use of encryption. They want to eliminate the concept of privacy all together and be privy to all of your transactions, communications and behavior to ensure nobody is "breaking the law". This was the whole idea behind the Orwellian "Total Information Awareness" program that was so obviously antithetical to freedom that the government was forced to change the name (while continuing to develop the program). In my opinion its far better to live in a free society where we are legally entitled to privacy and a few bad actors get away with crimes than the alternative.
The thing that fascinates me is ... we could do (very similar) analysis on "normal" bank accounts - on a much larger scale but still.
I wonder how much criminal activity would be revealed?
Congratulations, you tracked the transaction to a shell company and have no jurisdiction to unwind who the cash withdrawal went to? Ignoring the coin washing services referenced in the story.
There is enough bad guys that are not sophisticated enough and are thinking that bitcoin will do all hard work of hiding it for them.
Obviously they are wrong.
Would this be (more or less) forensic accounting applied proactively to all accounts? I know techniques similar to 'chain analysis' are applied in criminal investigations, but it's usually reactive (due to the labor involved and the need for warrants in many jurisdictions).
I don't think so really, the fact that the ledger is public is really the thing that makes this is a credible model.
In the absolutely general sense of "if all banks around the world opened all their books and banking secrecy laws didn't exist, and if we somehow had the ability to trace through cash transactions" then sure, theoretically (and again not accounting for the absolutely vast difference in scale between the volume of transactions in the real world vs the blockchain), but none of that is even remotely probable.
it's not likely, but it's possible. Laws can be used, if the political will is there. It's not like encryption where you can't actually force it!
The thing is, this data can contain sensitive information, which existing gov't may want to keep hiding (like CIA slush funds etc).
OK, sure, in about the same sense that world government is possible: hardly anyone is asking for it and there is a tremendous level of investment in the status quo by all the people with political power.
Sure, banking secrecy laws could be a problem for large-scale frauds totaling millions, but smaller-scale operations typically stay within the same country where the law most likely already allows this kind of tracing, but it's so unefficient that by the time it's tracked down the money is already gone for good.
Anonymity never was a design goal (even though it helped) and transactions are now too slow and expensive to make it a viable payment network. You can still buy drugs in Bitcoin, but it is not why people invest so much into it.
Let's say, you have a lot of Bitcoins and your buddy is a bitcoin miner. You craft your transaction such a way that you put all your coins as transaction fee. You send your transaction only to your buddy. Your buddy picks it up and solves the puzzle afterwards. Fees will be converted to brand new coins.
it's possible to spot such transactions if they violate transaction forwarding rules (aka standardness rules) but not consensus rules. for example, a transaction greater than 100kB is not standard but still valid.
Little tiny 'gotchas' aren't going to save you from a determined investigator. They are trying to follow a trail of evidence so they can produce more evidence. What you need is a clean break, so that the investigator hits a dead end and has no productive leads they can follow.
Just pretend you sent that transaction a millisecond before it was mined.
- 144 blocks per day are mined on average
- the current network hashrate is 145M TH/s
- a 100 TH/s rig is about $10k.
The investment to be able to have full control of mining one block on average, without electricity, internet and storage :
- per week: you'd need 143k TH/s (145M / (144 * 7)), so about $14M of investment in just the mining rig (provided you can buy it all)
- per month: you'd need 33k TH/s, so $3M of mining rig investment.
- per year: you'd need 2.7k TH/s, so about $270k in mining rig equipment.
Of course, there are a lot of variables here (e.g hashrate is highly variable), but this gives a general idea.
All this for a "washing" method that heavily implicates the miner: the address of the new coins is still known, it's not really "clean", just an unusual transaction.
Might go unnoticed if the original coins weren't suspicious, but if an investigator is already looking at the original transaction because they suspect it was involved in crime, this type of jump is unlikely to throw them off the trail.
Worst idea to launder ever.
People frantically contact all the mining pools to see who mined it and if they will return the funds to the sending address.
This has happened many times and they usually do return it, because people have nearly universal consensus that it was a mistake.
Kind of not a great way because it is too conspicuous.
There was one time this happened that was interesting and intended to be conspicuous:
Some hackers got access to an exchange, but the exchange had some pretty good security and would not let them withdraw large amounts, but the hackers could set the transaction fee. So they started burning all the exchange's money by distributing them to miners with this high transaction fee, to let the exchange know they were serious and needed their demands met.
Could they have coordinated with a miner and nobody would be the wiser? Sure.
I believe that this happened at some point during the 70s right around the time congress declared "war on drugs"?
edit: aha, I refer to 91st USA congress: https://en.wikipedia.org/wiki/Bank_Secrecy_Act https://en.wikipedia.org/wiki/Comprehensive_Drug_Abuse_Preve...
The state has never had a right to understanding the financial flows or private property, it found a convenience with the electronic financial system and deputized all financial intermediaries to data mine and snitch for it.
This has subsequently become conflated with a right of the state to have all of this information, as the people running it now are unfamiliar with not having these conveniences.
The market, on the other hand, is simply reverting to a mean. It has developed and chosen an electronic financial system that doesnt require financial intermediaries.
So the state is going to lose its power to criminalize transactions. If there are any actual criminal behaviors with distinctive victims, then it has to do an actual investigation and find the individual and prosecute them. It really isnt that absurd of a concept.
https://www.google.com/amp/s/www.vogue.co.uk/fashion/article...
Anybody that claims they know is just trying to scam a government for a lucrative blockchain analysis contract. Just another crypto entrepreneur aiming to leak fiat out of the system, even while pretending to act like an adversary to crypto users.
The reality is that:
A) the UBO either isn't trying to hide because they can acquire the goods and services they want without laundering (other tokens, governance control of a crypto network, passive income, digital art, using the dirty funds to pump other tokens that they already own with clean money allowing them to derive entrepreneurial or trading genius benefits)
B) the UBO know they can launder whenever they feel like it or get around to it
C) the funds have already changed UBOs to people that were not involved and shouldn't be tracked, because A) and B) already happened onchain or offchain
What I was describing here wasn't that, I am referring to onchain transfers in trade for goods and services. (Part C could also be hand to hand trusted transfer of a wallet/private key)
Chain analysis still assumes that its the same owner or related guilty beneficiary all the way to a centralized exchange.
a) I give you my wallet, and you immediately send the coins to a new address to protect against my (potential) copy of the wallet, or
b) I just send the coins to your new address myself.
Either way, the blockchain records a transfer from my address to your new address.
So you're the blockchain analysis firm for the Department of Justice, and you're like "omg omg look the coins are moving! omg omg look its going to a centralized exchange account lets go subpoena the records and find out who has the KYC and identifying information behind that account."
DOJ busts down the door "aha! got you!"
If it was the person that actually hacked or did drug trafficking, then they found that person and charge them with that, wire fraud, money laundering etc.
If it was just the recipient then the investigation is still ongoing and much lesser charges are possible. The DOJ would at best case try to find out who the "kingpin" is by overcharging the second person, but the primary observation is that the DOJ has not stopped any particular activity. Either way, its still not quite what happens:
The reality is that it is many hops between unrelated people before it hits a centralized exchange that is subpoena-able at all. People.don't.need.or.want.fiat. Especially not a lot of it at any given time. Even hedge funds take in-kind investments of crypto to create a new limited partner. People don't need to cash out first and then invest that cash.
the reality offchain can be very different, I was trying to make clear just in case you or others that didn't catch that. but I think we're agreeing on everything.
I would say the lack of major prosecutions on this is because criminals still launder the money first and don't want to frame people (or have the exchange account frozen so soon), and DA/prosecutors use their discretion to tell when its unlikely the person in question was the actual person they are looking for, for now. Some people likely are getting framed, judging from televised arbitration shows like Judge Judy where the entertainer keeps cutting off the defendant who calmly says their bank account was compromised, and awards everything to the plaintiff.
This isn't crypto specific and is for bank and brokerage accounts too. Most darknet money-isolating tutorials talk about trading stocks in a brokerage account with stolen/recreated credentials as well.
Unless an account in your name wire transferred money directly for a shipping container full of cocaine, you would never find out that someone has opened a bank/brokerage/crypto account in your name and was operating it like a normal person accumulating money and occasionally trading.
Think of it like being a victim of identity fraud but the fraudster improves your credit score by acting normally and responsibly for you. That's literally whats happening pretty often.
Not everyone wants fiat. Not now, not eventually. They are able to obtain goods and services in crypto. They are able to pay developers, buy games, invest in other crypto/projects ensuring the success or perception of success of people they like, control crypto networks with voting power, create exchanges and other infrastructure. There is no "eventually buy a multimillion dollar house how do I do that inconspicuously or maybe I can buy it with crypto in the future". It's just recognizing that it is possible whenever you want, but also not a priority or a necessary addition to what people value in this world.
It's fungible enough for all the purposes that many individuals with dirty crypto or organizations with dirty crypto care about.
Without that, your trading partner ends up holding a "dirty" wallet — just as if you gave them a suitcase full of marked bills.
That wallet still holds value — all dirty money does — but it's a lot less value than cleaned money.
Databases of stolen credit card numbers sell for not-much money. It's not just because you need stuff set up to drain the cards; it's because the money you drain from the cards is dirty. The dirty money is worth only about as much as the database itself. It's when you clean it that it attains "face value."
Banks need to report any transactions greater than $10K (or a series of smaller transactions that make up $10K). The consequences of a bank not reporting far exceed any profit they would make from it.
This is one of the reasons that common fronts for crime are companies that would be expected to handle a lot of cash :)
Also the major advantage of cryptocurencies in crime is their international nature. It means I can sit in a country that has no extradition treaty with the places I'm doing crime, safe in the knowledge that I won't be touched, as long as I'm careful who I target.
Or a large amount of smaller companies for which 5K in revenue a month won't look suspicious (I'm thinking of stuff like these small phone (repair) shops, and there was a massage parlor down the road that was open frequently but never saw any customers. Still managed to stay open for years. Maybe that grey Mercedes that parked out in front of it once a month had something to do with it?)
Create customer records of as many high dollar value appointments as you want!
Just today my superior shared WSJ opinion piece saying it should be banned altogether. I genuinely chuckled. It was ignored for so long, but only now when it may be genuinely hard to just put down, because real players joined the fray, did the offensive PR started.
It's not that banning it will bring salvation, it's just that it's one less evil to worry about, with no clear downsides as crypto really isn't used for anything good.
We are fast approaching the "fight you" stage.
Its easy to ignore a bad but unpopular thing. As the bad thing gets popular, more will be written about it. Pretty straight forward process.
Some drug markets are already dealing in Monero only. It's just a matter of time before more people catch on.
Zcash from a theoretical perspective is a lot stronger, but I believe from a practical perspective (due to things like weaknesses in the mempool privacy) is also not very private.
That's contrary to what I've read, care to expand? As far as I know the IRS is still offering a bounty to crack Monero
"Monero is the best-in-class anonymous cryptocurrency in production today."
What the hell is it trying to say then?
From what I've been able to gather from this gist, its argument that Monero is "unsafe" hinges on the extra sentence: "under the formal threat model proposed and analyzed in this paper". Curiously, section 8, "Analysis Under Full Threat Model", is completely blank. And it also curiously never properly defines the "full threat model"
From what I gather however, its main argument is that 10 decoys (in RingCT) is too few and there could be probabilistic attacks and the some of the decoys could be malicious actors. The Monero developers already know this however, and are working on Triptych and Arcturus [1] to fix this. Note that this doesn't mean that Monero is 0% safe (as the gist likes to pretend by writing stuff like "Monero has been broken"), but it rather means that Monero is 80-90% safe rather than 100% safe. And if you're that worried, the Monero wallet offers the option for churning [2]
Lastly, the gist is more than 3 years old now, without a single update to it. Does the author not know that in 3 years there could be lots of upgrades and fixes to Monero? The fact that the largest Dark Net Market is now using Monero only surely should be an indication that Monero is doing something right?
[1]: https://www.monerooutreach.org/stories/monero-triptych.html
[2]: https://monero.stackexchange.com/questions/4565/what-is-chur...
It's trying to say everything else is broken too. I think Zcash is now best is class though.
> Note that this doesn't mean that Monero is 0% safe (as the gist likes to pretend by writing stuff like "Monero has been broken"), but it rather means that Monero is 80-90% safe rather than 100% safe.
No, the main point of the gist is that the analytic attacks are able to entirely break any user whose wallet functions as a stream wallet, which in practice is nearly everyone. To fall outside of the "stream wallet" definition provided in the gist, you have to run a custom wallet (not the main Monero code), and the implementation of that wallet has to be highly user hostile.
The attack doesn't target weaknesses in the monero implementation, it targets weaknesses in the monero architecture. Any decoy system has the exact same issues. If Monero is still on a 10 decoy system (even if it were on a 100,000 decoy system), all the attacks in the gist apply.
> I think Zcash is now best is class though.
I fundamentally disagree. Zcash is sponsored and funded by so many government agencies which raises a stupid amount of red flags. It's sponsored by US DARPA, Israeli Digital ministries, Amazon, etc. [1] It's absolutely ridiculous that a coin with so many links to bad institutions could ever be considered trustworthy. Furthermore, its lead developer was caught with his pants down when he went on a ramble about how they could install backdoors for government agencies to track criminal transactions, while also making it secure and anonymous for normal people. The fact that the project didn't completely collapse that moment still blows my mind. [2][3]
> No, the main point of the gist is that the analytic attacks are able to entirely break any user whose wallet functions as a stream wallet, which in practice is nearly everyone.
>The attack doesn't target weaknesses in the monero implementation, it targets weaknesses in the monero architecture. Any decoy system has the exact same issues.
I've read through the gist you linked again, and I think I now understand what the threat model being analysed is. He makes the following assumptions:
* >The anonymous stream wallet model assumes a single adversary that has global visibility of all payment streams on the network.
* >This global adversary is assumed to be performing an ongoing Sybil attack on the network.
* >the global adversary is assumed to have access to unknown side-channels that help to de-anonymize the user. [...] examples could include more exotic techniques known only to the adversary.
First of all, these are incredibly optimistic assumptions. Sybil attack, maybe. But, a government (adversary) having "unknown" side-channel attacks to de-anonymise users? Really? I mean, if I'm able to make such an easy assumption that a government has unknown side-channel attacks without having anything to back up my assumption with, then I could write a paper on pretty much any technology and accuse them of being "insecure" and "broken". But you know as well as I do that such assumptions are bonkers.
The gist then goes on to say:
"Though a global adversary may seem like a strong assumption, techniques such as the flashlight attack, dragnet surveillance, government mandated KYC, and the general nature of corporate information sharing and data selling today suggest that a single party could potentially gain a substantial and surprising amount of knowledge about any particular identity on the internet"
Which doesn't make 100% sense. Sure, such techniques would work if we were talking about Bitcoin where addresses are fixed and the blockchain is completely transparent. But this is Monero. If a government uses KYC to link a real life identity to a Monero address, a user can simply generate a new wallet and send the transaction from the KYC'd address to a blank wallet. The sender wallet is hidden with decoys, and most importantly (!!!), the receiving wallet is 100% hidden thanks to stealth addresses. No need to worry about decoys. So, how on earth would a government use their vast databases to get around this?
If this gist was so well written, why wasn't it submitted for peer review, and why hasn't it received an edit in 3 years?
---
Fundamentally, Monero is objectively safer due to how it's not in bed with so many government agencies, and how the developer team is decentralised and anonymous. Theoretical attacks and GitHub gists from 3 years ago saying how someone could do this or that don't mean anything when the only other alternatives are literally sponsored by Israeli ministries. Furthermore, the IRS $625k bounty for breaking Monero is still open, and the largest dark market curently uses Monero only. I believe that these 2 things speak volumes more than a gist from 3 years ago.
====================
[1]: http://zerocash-project.org/about_us
What weaknesses? Anything besides IP?
Funny because Wasabi requires a lot of manual coin control to preserve anonymity. Samourai Wallet automates most of these and offers obfuscating tools.
And does not have a desktop client. Next to useless.
The exchanges are definitely in on it. From trading bots, to price volatility. Pretty sure there's inside trading being done on most successful exchanges.
Nothing better than knowing the behavior of a bunch of traders and figuring out the best massive bot trading strategies.
Secret Network also has an AMM called SecretSwap for exchange to any other asset
All smart contract execution on the secret network is private, as in the variables and current state is not stored on chain for perusal, all assets are smart contracts
It is more so that the Secret Network is able to basically shard a Monero multi-signature address across the SGX chips that the validators are required to have, and from consensus mint or burn sXMR when XMR is deposited or withdrawn
I mean there's bound to be laundering going on via banks, but it's risky.
Heard about one guy that tried to get his Bitcoin winnings onto his regular account, his bank wouldn't accept it because they couldn't verify its source. Of course, he managed to open up an account at another bank who accepted it without question, and transferring it to his main account from that bank was also done without question, so it's not exactly consistent.
You nailed it here without noticing it: you just use the right bank(s) in the right countries, and then just shuffle and move money around.
I'm pretty sure there are organizations dedicated to set up these operations.
https://www.vice.com/en/article/g5bkyq/drug-cartels-used-aus...