or by "in possession of the private key" they mean "Coinbase generated the private key earlier and just gave it to the FBI"
the amateur hour doesn't stop there though
Especially together with 'FBI Director Compares Ransomware to 9/11' articles like https://www.foxbusiness.com/technology/fbi-chris-wray-ransom...
You might find it interesting to know that, irl, I never talk about anything remotely conspiratorial. I live life like a normal person, and talk like this on forums as a hedge.
And yeah... if the crackers sent the funds to an exchange they were comically dumb.
https://www.elliptic.co/hs-fs/hubfs/Screenshot%202021-06-07%...
for which the FBI has the “private key,” or the rough equivalent of a password needed to access assets accessible from the specific Bitcoin address.
It seem more likely that the FBI/NSA had and gained some access to the gang's infrastructure and seized the money.
Transmitting ransom money to an exchange without any type of tumbler or atomic swapping, that it's not a realistic scenario.
Maybe they tried to use an ineffective tumbler?
Use your head man, this means they literally went to a Federal Judge and said "hey we have probable cause that this address is on Coinbase" and the Judge was like "wow that is pretty probable" and then they took the warrant to Coinbase who was like "oh damn that's legit ..... can we squirm out of dealing with this .... no ... oh wow that is our address too, okay here is the private key" and then the FBI transferred it
Not neccessarily.
https://www.justice.gov/opa/press-release/file/1402056/downl...
The FBI in Northern California simply needed permission to use the Private Key they already had to access the bitcoin address.
The court that has jurisdiction over these types of crimes is in Northern California.
No, its not.
Its for a particular Bitcoin address for which the FBI had the primary key. The FBI can’t legally seize coins just because it has a private key any more than it can seize physical property because it has a key to a house. It needs a warrant to use the key, which will only be issued with probable cause that the material is subject to seizure.
> Use your head man, this means they literally went to a Federal Judge and said "hey we have probable cause that this address is on Coinbase"
They literally did not; the warrant and supporting affidavit are public (with some redactions), and that is not, even remotely, what they say.
Why would you assume an attacker uses all of the best cloaking tactics?
This doesn't seem like a complex attack at all: monitor common 0 day vuln feeds, attack, install off the shelf ransomware sold by 5$.
It might as well have been a script kiddie.
Maybe not nowadays, but some time ago, after the possibility of tracing transactions was already well known, criminals were still a) first sending all the ransoms they collected directly from the initial ransom address to one address, linking them b) then sending them to their exchange account. No tumbling or obfuscation whatsoever.
https://www.blockchain.com/btc/address/bc1qq2euq8pw950klpjca...
Theres so many other lower hanging fruit posibilities...
1: they served the server provider with a warrant they provided physical access. 2: their server infra was running vulnerable code for another service. 3. weak passwords / weak security in general 4. they cut a deal with the upstream ransomware providers and were provided with the private key used.
A very odd conclusion because that's not the crypto you need to break to steal some coins.