Crypto 'mixer' convicted of money laundering on Bitcoin Fog
bloomberg.com
bloomberg.com
For anyone else curious, it's described in this affidavit, page 8: https://storage.courtlistener.com/recap/gov.uscourts.dcd.230...
Mt. Gox didn't help. Liberty reserve didn't help. Bitcoin shuffling didn't help.
If it looks like a money laundering tool with a paper trail, it's eventually just a prosecution tool.
One day, Monero books will be cracked wide open and we won't even know until later.
Edit: sorry, missed the evidence about using same IP for both the mtgox and LR account. Weird using the chain of transactions and then doing that kind of rookie mistake.
Ocamm’s Razor doesn’t point me to malice. It’s just as easily a kid trading gift cards $20/time until he has the funds. This looks like an idea that starts small, and frankly when it was invented it wasn’t illegal at the moment of creation.
It’s the story laid out in the court case and the changing of regulations and laws that created the crime. Inception of an idea alone doesn’t lead me to believe the intent was malice; privacy, obfuscation, the lack of funds maybe.
Obfuscation can be as simple as protecting privacy.
As an example I can say the first day I stepped foot in a cryptocurrency community was on IRC about 13 years ago. I didn’t realize Freenode showed your hostmask by default and random people had IPwhois’d my netmask, asking about where I work, pulling up the address on street view…
I’ve exclusively used rented servers bouncers cloaks etc ever since. That’s the community I realized I was dealing with.
What ISPs provide this level of detail to people other than law enforcement? (And I'm pretty sure law enforcement need to follow an actual process too) Is it a US thing? Looking up my IP tells you... A different city, where presumably my ISP owns some infrastructure or office space
This is how many illegal services get decloaked. They have a clearnet domain, but ironically a darknet .onion too which is what they should just have, not a clearnet domain (if what you're doing is illegal or operates in a legal grey area). I am aware it's possible to get a clearnet domain anonymously with services like NJALLA[0], but you have to take extra special care, pay with crypto, do everything over Tor, use XMPP w/OTR etc
[0] https://njal.la/
KYC on the other hand wasn't set in stone until recently whether it was $10,000 or $600 and the Bank Secrecy Act is a bit of joke at this point if they really want us to KYC/AML every person we transact with in excess of $600 AND report that. Report it to who?
We're all criminals it would seem, but that email where they told him all the money was illegal will basically be the nail in the coffin.
Fincen, obviously.
Their purpose for existing is to be the giant mother-of-all surveillance warehouses. Collect it all.
Relevant text: Re: United States v. Sterlingov, Case No. 21-cr-399 (RDM)
Dear Judge Moss:
As you know, we represent Ciphertrace, a wholly owned subsidiary of Mastercard International Incorporated (“Mastercard”). Defense counsel engaged Ciphertrace as an expert in the matter of U.S. vs. Sterlingov, 21-cr-399 (RDM). Ciphertrace prepared an expert report (the “Ciphertrace Report”), and a Ciphertrace employee, Ms. Jonelle Still, testified at a Daubert hearing before the Court in August 2023.
It recently came to Mastercard’s attention that, contrary to the wording of the Ciphertrace Report, some of the data relied upon may be unverifiable and unauditable. This issue was unknown to Ms. Still at the time of the Report and appears to be due to data collection practices originating prior to Mastercard’s acquisition of Ciphertrace. It also appears that at least some of the data relied upon in the Ciphertrace Report may have come from other companies, including Chainalysis. Mastercard has advised defense counsel of this matter and writes to bring it directly to the Court’s attention.
As soon as Mastercard counsel learned about the potential data issues, Mastercard launched an expedited, privileged investigation involving internal and outside counsel and an outside forensics team. This investigation is ongoing, but we have learned enough to conclude that parts of the Ciphertrace Report are unreliable.
We regret the unavoidable impact of this issue on the Defense, the Government, and, of course, Case 1:21-cr-00399-RDM Document 239-1 Filed 02/04/24 Page 3 of 3
February 1, 2024 Page 2
this Court – especially with the fast approaching trial date. We stand ready to answer the Court’s questions.
Respectfully,
A. Joseph Jay III for SHEPPARD, MULLIN, RICHTER & HAMPTON LLP
https://www.cbsnews.com/news/crypto-scam-risk-bbb-report/
There's a nice website, I've seen on HN before, that has a complete list of crypto scams and their total value. I wonder what the overall percentage of crypto transactions are for scams? 50%? more?
The only reason crypto is allowed is because it literally sucks money out of the real economy thus tamping down inflation.
Less than 5% according to the companies like Chainalysis who have a vested interest in making crypto seem dangerous so they can hock their product (analysis tools) to law enforcement.
So not “50% or more” lol
*Exceptions:
-Broken stablecoin smart contacts or stablecoin wallets with lost private keys.
-Many bonds, for example: I-Bonds.
Also, acts as a mixer even if you end up storing your coins locally.
Good thing that there's no such people :)
I mean, if you love living within the hidden taxation called inflation of the fiat world, feel free.
I don't think I've heard anyone pretending this in the last 10 years.
Anything that happened to BTC was "good" for BTC.
For the uninformed, all transactions post to a separate address, so you'd have to correlate which addresses seem to be used together in various other transactions to tie transactions back to a single "wallet". (Ackchyually that's not entirely true; there are some low level details regarding UTXOs and HD wallets, but in practice you can assume it works like that).
And I don't think anyone (who is worth listening to) is advocating BTC for trivial transactions; it has already solidly cemented its role as a "wire" service for larger transfers.
LTC apparently seems "a better BTC" for trivial transaction. Also Monero which supposedly doesn't even need mixing.
Why do people even care using BTC which needs mixing when there are Monero and ZCash?
If you read early Bitcoin literature, you'll discover a number of very clear and vocal warnings against "address re-use".
The protocol was designed so that addies should not ever be used more than once or it would introduce vulnerabilities.
It's indeed kind of like giving everyone permanent read-only access to your bank account.
Except that, if Bitcoin was used as intended, there would only ever be one transaction per account and there would be a new account created for each new transaction, so who cares about the reveal.
It's too bad Satoshi didn't enforce the "one new addie for every new transaction rule) that at the code level (I guess the computational burden might have been an additional problem to solve).
"The criticisms are just a failure of the imagination," said Tyler Winklevoss. <--- Not a Nobel Prize winner
1) Conspiring to money launder
2) Money laundering (so I guess the conspiracy succeeded?)
3 & 4) Failing to register a money transfer service
So the important steps are
a) demonstrating the defendant (Sterlingov) is the person running (and I guess profiting?) from the mixer. That's not a crime, just that it's a thing that they have to do, and I guess we're able to successfully show (sounds like some dumb "opsec" mistakes).
b) show that the defendant intended money launderers to use it, and that they did (charges 1&2)
c) show that the defendant did not register the service (charges 3&4)
So I'm going to leave (b) to the end, it's more complicated and IANAL, so let's look at (a) & (c).
Charges 3&4, and C is very simple - it does not matter that it's online, it does not matter that it's crypto, and it does not matter whether or not you care about privacy or laundering. The law requires all money transfer services to be registered, and this service was demonstrably not registered, so it's a very clear cut that whoever operated the mixer was breaking the law. That the prosecutors had to prove Sterlingov was running the service further demonstrates that it was not registered, and given they apparently were able to prove he was running the service I hope we can all see that he is guilty of this crime, even if you may not like the law requiring you to register your service (if you think a law is illegal you would use the courts to prove it is illegal and invalidate the law).
To me it seems plainly obvious, that given they apparently had sufficient evidence to show that Sterlingov was running the service, that he's guilty of not registering it, even if he had actively prevented any laundering using it.
So that leaves the money laundering charges. Once you're transferring money US law has a variety anti laundering regulations, and the fact that some, or even most of your users are legitimate isn't a requirement. Afaict they just have to show that you could be reasonably aware you were processing illegal transfers and were not actively trying prevent those transfers. This applies to banks as well as mixers. A bunch of forum posts by the operator specifically talk about how other "legitimate, visible businesses" would be forced to reveal info about your funds to authorities (directly comparing its secrecy to SilkRoad), posted links about needing a mixer to evade taxes, and how you needed to use a tor based mixer (e.g. their's) to avoid law enforcement taking down the mixer. It doesn't take a giant leap to see even from what's in the government's statement of facts here that this was being advertised as a service to hide transactions that would otherwise be required to be reported. The government does not need to point to them explicitly saying "hey, use me for your laundering needs".
Note that it does not matter if you think you should not have to report those transactions, the law says that you do, and that a service that facilitates you hiding those transactions is breaking the law. It does not matter if you think some transactions should not be illegal, the law says they are illegal, and that a service that facilitates those transactions if breaking the law. This case is not "bitcoin fog made illegal sales" or "hid its income from the IRS" (though I'd be curious if they did that), it's that they facilitated others doing so in a manner that was illegal.
If you want to run a mixer, it's very clear you will be running a financial transfer entity and need to register it, or you are committing a crime. Again it does not matter if you think it should not be a crime, the law says that it is. If you don't like it, you need a court to rule it's invalid, or you need to get people who agree with you elected.
If you want to run a mixer, it's similarly clear you are not subject to completely new rules (or lack thereof) vs other financial transfer services so you have to try to prevent illegal uses of your service, not just not promoting it for that purpose, but actively preventing such transactions as much as reasonably possible, including identity verification, just as required by any other financial service.
The people using Bitcoin Fog might be engaged in money laundering if they were using it for something otherwise illegal, but I don't see how you could argue the service itself was unless they somehow knew the purpose behind every transaction occurring on their platform.
Regular banking has piles and piles of AML/KYC regulation that they need to follow in order to not become guilty of money laundering, or aiding money laundering.
Are you saying Bitcoin Fog followed all this regulation, or are you saying Bitcoin Fog can unilaterally can declare itself exempt from AML/KYC laws?
Sorry if this sounds like a confrontational question. I don't mean it to be. Just intend for it to be a clear question.
Those two laws make it illegal for businesses to transmit money without requesting all sorts of private information from their customers, and providing that information to the government under some circumstances.
In other words, under current U.S. law, yes, privacy is indeed a crime.
[1]: https://storage.courtlistener.com/recap/gov.uscourts.dcd.230...
[2]: https://www.law.cornell.edu/uscode/text/18/1960
[3]: https://code.dccouncil.gov/us/dc/council/code/titles/26/chap...
Then consider that most of the transactions processed by the fog came from places like silk road.
The law doesn't require you to know affirmatively that the service is only used for benign purposes. Just about every public service in existence probably gets used to support illegal activity at some point or another. You just can't be knowingly assisting with a crime.
Every crypto"currency" utilizing a transaction fee is a negative sum game and those are scams. That's all there is.
They may have avoided collecting identifying information on specific individual people, but it's absurd to think that they could have reached the scale they did with no knowledge of where and for what purpose their service was being used.
The startup engineer's fantasy is that you can build something useful and users will flock to it through no further involvement of your own, but that's almost never a thing -- and certainly not here.
The affidavit[1] another user linked elsewhere in this thread says:
> BITCOIN FOG was publicly advertised on Internet forums and well-known web pages promoting darknet markets as a tool for anonymizing bitcoin transactions.
But it doesn't really go into detail. "well-known web pages promoting darknet markets" might just mean "Reddit".
And I think you might be underestimating the impact of word-of-mouth advertising. I don't recall Tor or Mullvad having to extensively advertise to criminals in order to get as popular as they are now.
[1]: https://storage.courtlistener.com/recap/gov.uscourts.dcd.230...
Not a lawyer, but as far as I know its only criminal if you know or at least have a strong reason to believe you're participating in a money laundering scheme. That wouldn't apply to a privacy service that has legitimate uses, particularly an automated one where there's no opportunity to use common sense to reason about which customers are legit.
Anyone operating a crypto mixer knows that people will endeavor to use it to illegally launder funds, and to as I understand it if you know that, you have to implement _effective_ methods to prevent that illegal mixing. It does not matter that there are legal transfers, you have a legal duty to not carry the illegal ones, and if you are not actively trying to prevent those illegal transfers you are liable.
A more day-to-day analogy would be that it is illegal to knowingly buy, sell, or accept stolen property. If you do buy stolen property but there's no reason for you to have thought it is stolen you haven't done anything wrong (though the purchase or sale is invalid, so you've lost the money). If however police can show that you knew or could reasonably know the property was stolen it they could chose to charge you with a crime, and your defense would presumably be some variation of why it was reasonable for you to believe the property was not stolen.
The problem is specifically that everyone running a mixer knows that people attempt to launder their funds through mixers, and so therefore should have mechanisms in place to ensure that they are not accepting transfers that can reasonably related to criminal enterprises, just as you would have to when buying/selling property in the real world. Given that most crypto is trivially auditable there are very few arguments that would support not having at minimum automated rejection of transactions involving any known wallet, and moreover constantly updating the list of known bad addresses.
Certainly if I were on a jury, and the person running the mixer could not show their reasonable actions to prevent laundering, that the system was constantly tracking, updating, and expanding the disallowed wallets precisely because that can be done almost entirely automatically, that would count against their claims to not be intentionally supporting laundering.
Again, the issue here is not running the mixer, it's not that occasional illegal transactions go through - that's unavoidable - it's the failure to take reasonable steps to stop plausibly illegal transfers. The way banks handle this is they block suspicious transactions pending receipt of the actual sender and recipient, and documentation of the origins of the funds. Which is what a mixer would need to do.
"knowingly conduct ... financial transactions ... involving property represented to be the proceeds of specified unlawful activity, ..., knowing and intending the the transaction was disguised in whole and in part to conceal and disguise the nature, location, source, ownership, and control of property believed to be the proceeds of specified unlawful activity, and intended to promote the carrying on of the specified unlawful activity."
> I don't see how you could argue the service itself was unless they somehow knew the purpose behind every transaction occurring on their platform.
The indictment states that the US government did an undercover operation in 2019 in which Bitcoin Fog was told that a transaction was from illegal activities and Bitcoin Fog accepted it anyways. If the person sending you Bitcoin says "I did a crime to get this", it is hard to claim you didn't know it was from criminal activity.
If it was just a message sent by an agent, I hope we will not see a conviction.
Or rather, even if the admins were knowingly facilitating crime, from a liability perspective they would be better off reporting/rejecting any users that say they're committing a crime and only do business with criminals smart enough to wink wink nudge nudge.
I can only think of two scenarios where someone would tell a mixer the money is dirty:
1. They are law enforcement
2. They have already been caught by law enforcement and are being used as bait, either knowingly or not
Yes, it potentially makes it harder for the authorities to track your activity, but it's also the only way to stop any random person in the entire world from seeing your transaction. Privacy is not inherently money laundering.
The issue is that if you run a mixer and someone says "please launder my drug money" you reject that person's coins unless you like Federal prison. It is like if you run a gun store and someone comes in and asks for a gun "to rob a bank", that person is a Federal agent and if you sell them a gun an indictment is forthcoming.
People are doing life sentences for giving their friend a ride when their "friend" decided to hold up a liquor store.
I can't imagine anybody reads private messages on such a service or could be expected to, with any significant volume.
From the very same link you posted: only laundering "the proceeds of specified unlawful activity" is illegal.
It is totally 100% legal to launder clean money.