North Korean hackers stole a record $1.7B of crypto last year
economist.com
economist.com
1. They hack computers not code. Their normal plan is to steal keys by compromising users and computers. This is in contrast to the normal "hack" that works by finding and exploiting bugs in code.
2. They immediately exfiltrate the stolen money back to the real world via bazillions of mule accounts that are already standing by. In contrast to the "normal" hacker who attempts to obfuscate and hide funds on-chain, and slip away with some at a far future date.
Here's a writeup from a company after the big 600 million dollar NK hack.
https://roninblockchain.substack.com/p/back-to-building-roni...
That's the primary way hacks are conducted by most hackers. Hackers are primarily social engineers, not technical. Technical hackers are extremely rare regardless of nationality.
If you leave an unsecured mail server accessible to the internet, it'll start sending spam emails within 30 minutes.
On the other hand, phishing emails are also automated, and that's essentially asking for the password.
But we can broadly categorize security incidents into two bins: first are opportunistic attackers which broadly attempt a method that sometimes works. Two common examples are minimally-targeted phishing emails (think Best Buy invoice) and automated scanning for old versions of WordPress with known vulnerabilities. Second are targeted attacks, where the attacker chooses a target and then attempts different methods to reach success. Overall targeted attacks are far less common than opporunitistic ones, but because they involve a higher level of effort they're only attempted when there's a high level of motivation. Targeted attacks tend to result in greater financial losses than opportunistic attacks, for example, because compromising machines to add them to a botnet usually isn't worth the effort of a targeted attack, but getting banking credentials or crypto wallets usually is.
All of information security is fairly bimodal in this way. It often seems like even technical professionals like software engineers struggle to understand basic security practices, but I think this is one of the biggest causes: most people tend to think about one case and ignore the other. Unfortunately one of the things that makes security very difficult is that both cases are real and the two require fairly different practices to deter, prevent, and detect.
Social methods are far more common with targeted attacks because "true" social engineering involves a higher level of effort, like time on the phone. That said, phishing falls into an in-between where some consider it to be a social method but it is amenable to widespread automation. There's also a wide spectrum of effort in phishing. Many are tempted to try to categorize phishing activity into a binary of "phishing" and "spear-phishing" (I hate these terms), but that doesn't really reflect reality very well. In a large corporation you can usually find examples of phishing that are targeted to varying degrees of specificity: at anyone, at corporate employees broadly, at people in the industry, at employees of a company, a department in that company, and even carefully tailored to a specific employee. The frequency of course tails off as you get more specific, but then it's not that unusual for some organized crime group to run a sustained campaign of fairly closely-targeted phishing as happened recently with Twilio.
Opportunistic attacks are certainly greater in volume to the extent that some call them "internet background noise," but most think that targeted attacks probably produce greater total financial damage. Security is very faddish though, not only on the defense side but also on the offense side, so it probably varies from year to year. For example, the emergence of ransomware was a major trend that required a strategic shift in defense in many organizations since ransomware attacks were fairly low effort but also very high damage in many cases.
When I checked out they gave me a receipt and I went to throw it away and saw a handful of wifi passwords in the trash bin.
Lesson learned.
You still did well writing the brute force. How did you know the composition though?
I'm just a 'regular security guy' but in that link you posted they detail that after the initial phishing compromise "The attacker managed to leverage that access to penetrate Sky Mavis IT infrastructure and gain access to the validator nodes." They don't detail the bugs that got them access to the nodes but this didn't give them control of the network so "the attacker found a backdoor through our gas-free RPC node, which they abused to get the signature for the Axie DAO validator. ...Sky Mavis requested help from the Axie DAO to distribute free transactions ... Axie DAO allowlisted Sky Mavis to sign various transactions on its behalf. This was discontinued in December 2021, but the allowlist access was not revoked."
Sounds like a pretty classic hack to me. They got into the network, got access to some important servers (how? they should be totally segregated from the corporate network). Then found a depreciated endpoint that allowed them blindly sign transactions. This is bread and butter for any pentesting work, makes me wonder if any of these web3 orgs are hiring security firms to test their systems and not just smart-contracts.
Instead, the Axie bridge was a multisig, and as of that wasn’t bad enough, most of the signatories were controlled by the same organization on the same infrastructure. Really demonstrated that concerns about decentralization are not just pedantic or academic.
They’re called Advanced Persistent Threats for a reason.
No snark intended.
It’s been a big problem that needs fixing across the industry.
https://venturebeat.com/security/report-average-time-to-dete...
Their keys their coins.
I'm almost convinced that this is how they recruit those mule burners, since signing up for employment requires a lot of personal information that can be leveraged into opening bank accounts or other financial vehicles in that person's name.
I have a quibble with articles about cryptocurrency fraud. They always get around to mixers and then they define it as if it were some relatively legitimate thing, like an odd bank. "large digital pools", "deposit funds". You have to get to the last phrase ("obscure their origins") to understand what mixers really are.
A proposed alternate definition: "mixers - international money laundering services where illegally obtained cryptocurrency can be mixed with other fraud proceeds making it harder for the legal system to trace".
(The definition I really would like: "mixers - services that look to hide your funds but are actually operated by intelligence agencies to track illegal activity". I imagine at least one mixer is a honeypot of sorts.)
Yes.
It’s definitely usable for non nefarious activities.
Should I be demonized for having one in my house?
Probably
If it wasn't so sad it would be funny that the countries with highest levels of freedom and least corruption tend to be the ones with most vocal privacy absolutists...
Correlation or causation?
My point is that the most powerful countries don't need to clean their dirty money to spend their money abroad, because they are the center of the world economy, and everything is available to them to buy. Russia is economically on the periphery and thus does need to clean it.
If 99% of Tor's volume is helping laundering international drug trade money, distributing CSAM, etc, should it be demonized as well?
You can apply basically the same argument to money. If I have $20m in Bitcoin I don’t want my name to be tied to my wallet address (because a KYC exchange saw where the money went to) because it makes me a target, for example. And in the case of censorship or something I want to be able to do with the money what I please.
Privacy is a fundamental human right, in my opinion. We have to use cumbersome technology to get any modicum of true digital privacy. Just because people use it for illegal things doesn’t mean that the desire for privacy or the technology itself is bad. One day things we find morally just may be illegal too
Intentional consealment of illegal financial transactions is a crime in-and-of itself (the crime is money laundering, which is a seperate offence to the original criminal activity that the money came from).
Easy answer: Yes! Although I think it would be hard to call it demonizing when something is already 99% demons.
All I'm saying is that if there's something where "99% of [...] volume is helping laundering international drug trade money, distributing CSAM" that that is obviously terrible for the world and we should be asking some strong questions about who's supporting it and why. Is somebody gaining something that's more important than the lives forever ruined?
https://www.cnbc.com/2022/08/10/crypto-criminals-laundered-5...
Is $540M considered a tangible amount? I'll let you quibble over that but I'd think most criminals would be more than happy to be able to launder $540M.
If you made it this far, then you start the laundering process.
You can't launder money with Bitcoin because Bitcoin is not well integrated with any country financial devices in any meaningful manner.
For example, library records generally have a fair amount of privacy. Criminals sometimes consult libraries. Crime is not the dominant use of libraries.
Mixers have a fair amount of privacy. Mixers are used by criminal, and crime is overwhelmingly the dominant use of mixers.
To rebut this you’d need to show large and innocent use cases which use mixers. Not an unrelated app.
Scenario two. I want to have on-chain identity (e.g. exo762.eth domain name). To register it I need to have some ETH (gas, registration fee). If I sent this ETH directly from my "money" account, I will forever link my public identity to my money, which is like walking around with "my net worth is at least XYZ USD" banner.
We're in a thread about a rogue state using the tech to steal money to fund their operations (Chemical attacks in airports, nuclear warheads, intercontinental ballistic missiles, etc.) How many nuclear detonations would you consider acceptable in exchange for the cryptobros to have their toys?
We've come a long way from Mario Bros!
https://www.bbc.com/news/stories-57520169
More prosaic wire fraud is common in real estate and B2B transactions, and if not noticed immediately the funds are often lost after being transferred internationally and cashed out. It wouldn't be surprising if NK is behind some of that, given what they managed against Bangladesh.
I would also suspect that using data collected by governments is used for business advantage. Of course it is hard to prove quite often. Personally I think that in principle it just doesn't make sense to spread your data around, as the benefits are tiny and the potential downsides can be big.
Basically if you were high profile enough, people would watch your wallets to see what you were investing in/transacting with, and use that as market intelligence.
As far back as 2016 or so I recall someone specifically offering their blockchain analysis platform as a way to do this.
So you would use tornado to make the money you planned to invest/use appear "somewhere else" disconnected, to maintain privacy/security of a project.
Tornado and mixers and such become necessary specifically because all transactions are public - unlike in tradfi where transactions are opaque except to parties and intermediaries.
Similarly to how investors in tradfi tend to keep their investment strategies secret where possible.
Because we don’t, and there is considerable friction required to have financial privacy, most people don’t bother unless they really need it or are unusually privacy conscious. Really needing it may often mean they are doing something nefarious.
That doesn’t mean the technology to enable privacy is “bad”, it means it’s too hard to use and that as a society we have done poorly at guaranteeing people’s right to privacy.
Not so long ago you might have ben able to say the same thing about people communicating with end-to-end encryption, but thanks to a concerted effort to improve the UX of this tech. and it’s adoption by some very widely used services, it’s now commonplace. End to end encryption could no longer be argued to be mostly used by criminals.
Hopefully we will get there with financial privacy too.
NB: in neither case am I suggesting that the government should be unable to require you to provide information in some situations (or face the consequences of withholding it against, say, a court order), only that dragnet surveillance of everyone by default is never acceptable.
Unfortunately I'm a normal person with my primary/only income being my salary.
I benefit from this 100 times more than not.
I can't and won't do tax evasion. The rich and bad do.
This left only the bravest parties, and criminals to use it, leading to a high proportion of users being criminals.
If it weren't for that uncertainty about the legal treatment TC would receive from government (say if Congress passed legislation explicitly providing a right to use financial privacy technology), a huge proportion of the whole crypto economy would have been using Tornado Cash, as they should be, because privacy is an absolute bare minimum for a functioning financial system.
The conceptual treatment you're giving transaction encryption is to treat privacy as criminal. This is an ideological outlook that promotes putting total trust and faith in a small elite in government and finance to engage in warrantless dragnet surveillance of every one's financial transactions.
One of the more recent difficulties with a lot of privacy technology is that the main user might not be the abused and those wanting to avoid being abused, but instead... really awful criminals.
And with anything cryptocurrency or blockchain in the last decade, it's not only the users who are criminals, but much of the technology itself is built by scamming atop scamming.
I'd quibble with any article today that mentions cryptocurrency/blockchain at all without acknowledging how sketchy the entire space is.
Pre-Web cynical cyberpunk writers were better at predicting much of the modern world, than were the optimistic techies who mostly saw tremendous opportunity for goodness.
[1]CIA world fact book and world bank (both a few years old)
I'm sure the repercussions / penalties must be huge, but then so are the amounts they must be seeing day by day, compared to average standard of living in N. Korea.
Or maybe this is a cadre of military / public conscripted workers who regard this hacking as a patriotic service even?
What's the trail of evidence that leads to this conclusion.
In this case: https://archive.ph/SUYp1
Each APT usually utilises a specific set of techniques to commit these heists: https://attack.mitre.org/groups/
Obviously perfect correlation is not possible but set of utilised techniques are usually enough to pinpoint the specific APT.
Seems like most of this theft is happening when people port currency between exchanges and the bridge is vulnerable.
- Found my answer: https://www.brookings.edu/what-nuclear-weapons-delivery-syst...
Not a lot...
Take the US Trident 2 [1]. Wikipedia lists a cost of $31 MM, in 2019 dollars, which would be about $37 MM today. With $1.3 BN you could buy 35 of those.
But the North Koreans are not buying their missiles from Lokheed-Martin. They are building them in house, so you'd expect them to pay much less for labor and materials.
Also, US strategic rocket weapons (ICBMs) are actually not the best in their class, as a result of post-soviet partial denuclearization. Many aren't even MIRV. This doesn't apply to submarines and bombers, those are top notch. Especially bombers, many decades ahead.
Fun times.
I mean it’s about what Meta spends in one and a half months on metaverse
It's actually the third real world use case, behind getting better drugs than from your local dealer and the entirety of the ransomware industry.
It also exposes a wider problem the crypto community are not addressing.
What do you mean by supposedly?
> It also exposes a wider problem the crypto community are not addressing.
What wider problem? That money (in any form) can be stolen by a malevolent state?
The DPRK is often portrayed as incompetent, helpless state purely able to eke out an existence by the grace of China (to whom it is useful only as a sort of attack dog cum buffer state). So the fact that they've managed to run an operation that can steal this much crypto may come as a surprise to many. I don't imagine their intelligence agencies are quite on the same level of electronic warfare capabilities as USA, UK, Israel and friends, though.
> That money (in any form) can be stolen by a malevolent state?
Right but as we repeatedly saw in the last couple of years, a North Korean hacker could swindle some dope out of their $10k ape jpeg from across the globe at relatively little cost. They'll have a bit of a tougher job stealing that same $10k from someone's bank, from a safe deposit box, or hell even from a box under their bed. It requires another level of sophistication entirely and the costs and risks would be prohibitively high. I am sure if the North Korean state took issue with me personally and wanted to empty my bank account, they could probably make some headway ... but they'd likely get caught and they'd spend more time and effort doing so than they'd actually be able to retrieve.
If you're motivated, don't mind a very on-rails, restricted and relatively pricey tour, you can actually visit yourself: https://koryogroup.com - I've wanted to for a while, but I've spent less money to travel in other interesting places with fewer restrictions for longer, so it's hard to justify the expense.
An interesting read you might like is by a couple of Austrian guys who decided to hop on a train there, confusing and irritating border officials who didn't expect an invasion from the northern direction :) http://vienna-pyongyang.blogspot.com
Probably the most accessible and interesting thing though, is a podcast series called "Blowback" (it's Season 3, the previous two were on the Cuban revolution and the Iraq war). Now obviously this isn't the current day but it presents a slightly more balanced view of the events leading up to and throughout the Korean War than your average American or Brit might have picked up through osmosis. It's fascinating, well-produced, well-sourced and has a very good soundtrack. Here's ep 1: https://www.stitcher.com/show/blowback/episode/s3-episode-1-...
As I said, there will be no good way to get any kind of verifiable account of how awful or how ok-ish is it is there. And I'm deliberately putting "ok-ish" as the upper limit because while I'm sure that all the ~20 million inhabitants aren't all living the prison camp lifestyle, I don't imagine your average North Korean has a particularly pleasant life.
Sorry, maybe not the answer you were hoping for but I hope you enjoy any or all of the things I suggested :)
You're quoting articles about poverty in North Korea at me as if I'm in denial about this, which is weird because I start and end my comment talking about how shit life is probably like there. It's a bit like you read a couple of words, got excited that you spotted one of The Reds and decided to call in an airstrike
I don’t know what you’re doing, feels a little bit like you’re trying to beat a statement out of me, or tell me I’m guilty of WrongThink.
He is making a point: it's foolish to assume North Korea is just a bunch of starving people with no heat, living in dilapidated Soviet-style buildings.
They've built nukes. They're pretty successful at hacking. It has capabilities the defy the stereotype.
I once read a blog post or something from someone who claimed to have gone to North Korea to teach Computer Science or something. This article sounds like it covers similar ground: https://www.vice.com/en/article/z4m8qx/how-to-teach-computer....
Also, North Korea also has an elite. IIRC, a significant chunk of North Korean imports are luxury goods and modern consumer products to keep this elite happy.
What limited that before were the protections built in to the real banking system. Stealing a billion dollars and actually getting away with it was hard until cryptocurrencies were introduced with far fewer safeguards.
https://en.wikipedia.org/wiki/Telecommunications_in_North_Ko...
I would say, conservatively, the traditional banking and real estate markets are 10,000x worse than crypto markets, but are un-policed because it's hidden, unlike the public blockchain networks. The few scams that are exposed, like the HSBC money laundering scandal, dwarf all of the crime every committed via crypto. But we didn't even put HSBC out of business or put a single employee in jail!
Here is the Danish money laundering fraud that just concluded with $2 billion in fines on $160 billion in laundered money https://www.justice.gov/opa/pr/danske-bank-pleads-guilty-fra...
Can you explain how?
I'm super curious because the whole point of crypto is you can't reverse transactions, and therefore crypto is only ever as secure as computer security generally, and there's nothing crypto can do about computer security generally.
Or are people coming up with some new paradigm here that fixes this somehow?
Keeping keys secure is no different from keeping anything else secure. That's why 'generally'.
And crypto doesn't do anything about key security. That's up to each person/org to figure out for themselves.
(North Korea didn't hack the blockchain. They hacked however people/orgs kept their keys.)
This stuff is useful outside of blockchain as well.
The state of user protection in crypto right now is definitely bad, but there is a lot of work and research being done to improve it.
EDIT: I think I'm actually making the same point you made, but anyways here's a couple cool links and things to google for secret security :)
By posting long tirades on Internet forums that surmise: "We have top men working on it right now. Top... men.."
Bitcoin is slowly losing dominance - its legacy technology, and bitcoin maxis/satoshi purists refuse to recognise that tech must evolve over time.
Its fucking insane to me how "The White paper" has become a holy text among Bitcoiners. Its made it almost fucking impossible to make any improvements to the protocol - hence forks, altcoins, etc.
[1] https://en.m.wikipedia.org/wiki/List_of_countries_by_number_...
Nuclear weapons and the fortified long-range artillery that can shell Seoul are the main point of concern, which are essentially a small-scale version of cold war era mutually assured destruction. The number of people in the army as such? I'm not so sure that's really something that's all that meaningful.
I don't buy, for a second, this narrative that NK would have elite hackers.
Do you guys realize how retarded that country is?
Everytime the subject comes up I can't but say we're talking about the country where official propaganda pictures trying to make believe they have military hoovercraft (as if it was a cool thing btw) are badly photoshopped.
A country with a total GDP of not even $20 billion and which cannot correctly Photoshop propaganda pictures simply doesn't have great hackers. The heist alone would be 10% of their GDP FFS.
What I do believe is that another nation state used to do very dirty things is putting the blame on NK.
But --and that's not a stab at the economist in particular-- mainstream media were also telling us that SBF was an altruistic genius making billions in arbritrage trades and that he'd make the world a better place by being an effectuive altruist.
In other words: I read between the lines.
And I take the "I cannot photoshop a picture but I can haxx0r 1.7 bn a year" with a gigantic pinch of salt.
And so should you.
P.S: how do we "know" it's NK? "Becuz them IPs are from NK". Yeah. Exactly.