How Chainalysis made their way into popular Monero wallets
digilol.net
digilol.net
Your own node is connected to other nodes to get latest blocks and publish transactions to the network. These peers are selected randomly among the pool of available nodes. If the attacker has enough nodes, there is a good probability that your node's peers are partly controlled by the attacker. When you publish a new transaction and broadcast it to your peers, the attacker can detect that it is indeed a new transaction (since it is the first time it's seen by the attacker nodes) and that the IP address of your node is the IP address of the transaction sender. It's not going to work 100% of the time (except if _all_ your node's peers are controlled by the attacker) but with a few transactions it's eventually going to lead the attacker to your IP address.
It's the same kind of attacks that are used to deanonymize people on TOR.
If you want to protect yourself from that, you need to add a few layers of trusted no-logs VPN in front of your node, so that the attacker is lead to a dead end.
You're assuming that peers will relay new transactions to all their peers, but that is not the case with the Dandelion protocol that Monero adopted [1].
I suppose even if they controlled all but 2 nodes - the extreme case - even then they couldn't know with certainty which of the 2 nodes sent the transaction, so it could be argued that there is always plausible deniability.
I don’t know which threshold makes the attack practical though. I guess there is probably no threshold: the bigger the share of the network you own, the bigger your percentage of successful IP tagging is.
I agree with what you say about the threshold.
You could craft your transaction and then submit it using a browser on Tor.
And I wonder what an estimate is of % of transactions (by volume and value) that are sent from a full node vs public remote node and public web vs tor/i2p.
Obviously won’t be able to get an accurate answer, but one of the remote nodes in that pool might be able to provide some absolute numbers and a rough estimate of their share of connections in that pool.
Should be easy for them to differentiate clearnet vs tor exit node (and dunno how detectable i2p is).
Even the geo-dns mentioned in the article would be interesting data to see geo-source of transactions.
See: https://x.com/tuxpizza/status/1833251940429377639
The leaked video is here: https://x.com/tuxpizza/status/1832073169978487057
So it gives them an IP that might be associated with a transaction …
Monero is still by far the best we’ve got for privacy
Btw, I wish Satoshi thought more of the concept of nodes' reputation so you can somewhat know how efficient and legitimate the node is.
I agree with that but is there a site which analyses efficiency of the mining nodes from the economic point of view e.g. how fast the nodes confirms transactions, how much fee does it charge/take on average etc. etc. The good old statistics which are sexy to see and observe over time.
P.S. I have this one in my bookmarks directory: https://mempool.space/ are there any others? I didn't follow the crypto scene for the last 5 years so idk.
All miners confirm transactions essentially the same way: highest fee has priority because that's the most profitable way to mine (specifically, feerate: fees/byte). There's no such thing as confirming transactions "faster" or "slower": blocks are found on average every 10 minutes, and all miners have (essentially) the same set of candidate unconfirmed transactions because the P2P network reliably propagates all candidate transactions paying sufficient fees to all miners (there is a dynamically adjusted minimum feerate limit, below which transactions don't propagate, which prevents spam).
Reward stats (Last 144 blocks):
Avg Tx Fee, 1.01k sats/tx, $0.58
Avg Block Fees, 0.0449 BTC/block, $2,592
Miners Reward, 456.46 BTC, $26,352,619
National Bureau of Investigation traced the hacker trough Monero transaction. First they sent 0.1 Bitcoin to the blackmailer's address and used that for statistical analysis tracing the money into and out of Monero.
ps.
The police unecrypted 64-character password was used to protect sensitive data on his hard drive. It was not random enough.
They 'took fingerprint' from a digital imange and used it for identification. The criminal on the run took a photo showing only his hand holding a glass. It was enough to see a fingerprint.
Inside binance the attacker converted the money to monero and from there the trail was lost but they already had enough personal info from binance to inspect his personal bank accounts.
In summary, Monero remains untraceable. Even more now that the goverments forced binance to remove monero support. Now attackers will use centralized exchange sites where no western authorities can ask for help or simply use decentralized P2P exchanges.
Monero remains technically untraceable, not in practice. Money must go in and out to be useful and it can be traced.
They payment was made into bitcoin address, then transferred into Monero, then it was sent into another Monero wallet. After that they used statistical analysis to determine the most likely receiver.
All sections of the additional investigation report where KRP discloses its methods have been retracted. Details about the analysis of Monero traffic are not revealed.
How the attacker would actually use that money is a separate discussion. I've never looked into it but I'd guess there are illegal/grey services that would provide this service for a fee.
>and maybe cycle it through a few wallets,
Your argument: Monero + extra protocol is safe.
The general pattern of these arguments:
Argument: Technology X is not necessarily 100% safe.
Counterargument: there exist way to use technology safely so it is.
In monero there is privacy on each transaction. Of course it isn't complicated to match public transactions if you transfer 100k EUR from binance to monero and then magically 99k EUR are credited into your personal bank account within 1~2 days. Finland is a small country, deposits from bank accounts related to crypto exchanges are easy to find.
Not even monero could save a person with such awful practices.
Anyways, you can pay toilet paper with monero quite OK. Just convert some value into a government-approved currency like bitcoin or BNB and buy stuff with a mastercard at grocery stores.
There are details about the Monero analysis, it is written on the report they lost track of the money when it got sent to a monero wallet.
How it was guessed: "KRP claims that by employing heuristic analysis involving educated guesses based on patterns and probabilities, they could infer the most likely path of the funds.
The small amount, together with other funds, possibly from victim payments, was sent to a second Bitcoin address linked to the same email address, which was later found to be linked to an email server managed by Kivimäki."
There isn't much magic here. In a small country is fairly easy to spot anomalies across bank accounts. That's it.
No, it wasn't, and please admit that.
You claimed law enforcement traced the attacker through Monero. They didn't. They couldn't. They traced him through Binance.
See also: Tracing the WannaCry 2.0 Monero Transactions — https://medium.com/@nbax/tracing-the-wannacry-2-0-monero-tra..., https://twitter.com/bax1337/status/1442846034460282886
https://old.reddit.com/r/Monero/comments/19emsfe/finlands_na...
Any source of this? Was this some bitlocker or another FDE?
https://krebsonsecurity.com/2022/11/hacker-charged-with-exto...
He was caught because he uploaded all of the stolen data but accidently included a directory of all his passwords and personal information.