[HN Gopher] North Korean hackers stole a record $1.7B of crypto ...
___________________________________________________________________
North Korean hackers stole a record $1.7B of crypto last year
Author : helsinkiandrew
Score : 254 points
Date : 2023-02-24 07:08 UTC (15 hours ago)
(HTM) web link (www.economist.com)
(TXT) w3m dump (www.economist.com)
| bogomipz wrote:
| There's a really good 12 episode BBC podcast called "The Lazarus
| Heist" that details the extent of this state enterprise.
|
| https://www.bbc.co.uk/sounds/brand/w13xtvg9
| drexlspivey wrote:
| There is also the Darknet Diaries "Bangladesh Bank Heist"
| episode https://darknetdiaries.com/transcript/72/
| NelsonMinar wrote:
| "mixers--large digital pools where crypto owners can deposit
| funds to obscure their origins."
|
| I have a quibble with articles about cryptocurrency fraud. They
| always get around to mixers and then they define it as if it were
| some relatively legitimate thing, like an odd bank. "large
| digital pools", "deposit funds". You have to get to the last
| phrase ("obscure their origins") to understand what mixers really
| are.
|
| A proposed alternate definition: "mixers - international money
| laundering services where illegally obtained cryptocurrency can
| be mixed with other fraud proceeds making it harder for the legal
| system to trace".
|
| (The definition I really would like: "mixers - services that look
| to hide your funds but are actually operated by intelligence
| agencies to track illegal activity". I imagine at least one mixer
| is a honeypot of sorts.)
| barnabee wrote:
| Ideally we would have a world where privacy is the default and
| everyone has it.
|
| Because we don't, and there is considerable friction required
| to have financial privacy, most people don't bother unless they
| really need it or are unusually privacy conscious. Really
| needing it may often mean they are doing something nefarious.
|
| That doesn't mean the technology to enable privacy is "bad", it
| means it's too hard to use and that as a society we have done
| poorly at guaranteeing people's right to privacy.
|
| Not so long ago you might have ben able to say the same thing
| about people communicating with end-to-end encryption, but
| thanks to a concerted effort to improve the UX of this tech.
| and it's adoption by some very widely used services, it's now
| commonplace. End to end encryption could no longer be argued to
| be mostly used by criminals.
|
| Hopefully we will get there with financial privacy too.
|
| NB: in neither case am I suggesting that the government should
| be unable to require you to provide information in some
| situations (or face the consequences of withholding it against,
| say, a court order), only that dragnet surveillance of everyone
| by default is never acceptable.
| judge2020 wrote:
| I thought the ultimate goal was using legitimate exchanges as
| your mixer, since if a mixer only handles illegal crypto,
| chances are the funds can be traced to every destination
| address and the exchanges are tasked with reporting anything
| that comes from those addresses to federal law enforcement. The
| only real anonymity is in tornado cash.
| woah wrote:
| Why don't you post your credit card statement below if you have
| nothing to hide since you're not a criminal?
| acidtakes1 wrote:
| I don't understand why technology that provides a modicum of
| privacy must be demonized. It must be for money laundering and
| criminals. It can't have a legitimate use case. Is it used for
| nefarious activities? Of course, but not exclusively so.
| babypuncher wrote:
| I agree in principal, however if the vast majority of a given
| service's users are using it for criminal activity then maybe
| there's room for some added scrutiny.
| ifyoubuildit wrote:
| Ok, so all you have to do is prove that the vast majority
| of a given service's users are using it for criminal
| activity, right?
| [deleted]
| zht wrote:
| Can I use an RPG-7 to kill animals like bears that threaten
| my life on my property?
|
| Yes.
|
| It's definitely usable for non nefarious activities.
|
| Should I be demonized for having one in my house?
|
| Probably
| eterps wrote:
| And when it's less obvious? Should I be demonized for using
| TOR? Monero? Signal? GPG?
| butterfi wrote:
| Can you provide a legitimate use case for mixers? (I'm not
| trolling, I'm genuinely curious)
| DennisP wrote:
| Providing some basic financial privacy, not from the
| government but from the general public. Everything on chain
| is public. When you buy something or transfer money to a
| friend, you don't necessarily want the recipient to know
| how much money is in your account, or what other addresses
| you've sent money to.
| davidguetta wrote:
| sending money to ukraine when you are russian (like vitalik
| buterin did)
| joyfylbanana wrote:
| If you are transacting in a business environment, I think
| it is an added benefit if the counterparty in the
| transaction can't deduce information out of your
| transaction. Such as how much assets you have, to what
| other services have you been sending funds and so on. As
| Bitcoin does have public ledger, and if you just use single
| address and don't do any privacy enchancing practices, lots
| of information could be deductible using blockchain
| analysis.
|
| I would also suspect that using data collected by
| governments is used for business advantage. Of course it is
| hard to prove quite often. Personally I think that in
| principle it just doesn't make sense to spread your data
| around, as the benefits are tiny and the potential
| downsides can be big.
| nibbleshifter wrote:
| Using Tornado was pretty common among well known/higher
| profile people in the space to avoid causing inadvertent
| market effects or leak info about upcoming projects.
|
| Basically if you were high profile enough, people would
| watch your wallets to see what you were investing
| in/transacting with, and use that as market intelligence.
|
| As far back as 2016 or so I recall someone specifically
| offering their blockchain analysis platform as a way to do
| this.
|
| So you would use tornado to make the money you planned to
| invest/use appear "somewhere else" disconnected, to
| maintain privacy/security of a project.
|
| Tornado and mixers and such become necessary specifically
| because all transactions are public - unlike in tradfi
| where transactions are opaque except to parties and
| intermediaries.
|
| Similarly to how investors in tradfi tend to keep their
| investment strategies secret where possible.
| benmanns wrote:
| Also, if you want to be able to create legitimate
| projects that are not tied to your real-world identity,
| you need a break between bank -> exchange -> address ->
| ??? -> contract deployment address.
| ynniv wrote:
| The Bitcoin Lightning Network uses indirection for privacy
| and liquidity in a way that could be described as mixing.
| https://en.wikipedia.org/wiki/Lightning_Network
| humanizersequel wrote:
| Lots of good examples already mostly geared around
| minimizing bits leaked for the sake of alpha, but there are
| also instances where it is desirable to be "locally
| clandestine" even if you're a full throated supporter of
| the powers that be on the whole. Persecution does not just
| come by way of financial penalties or the legal system,
| these tools are useful for avoiding social consequences as
| well. A hypothetical I'd expect to play well here: paying
| for an abortion in a large state where it is legal, but in
| a small town where the local church wields an immense
| amount of influence.
| exo762 wrote:
| Scenario one. Individual (while working in a startup) is
| receiving some tokens as a compensation. Time passes. Their
| remuneration being on-chain and visible is a problem when
| negotiating salary in the next job.
|
| Scenario two. I want to have on-chain identity (e.g.
| exo762.eth domain name). To register it I need to have some
| ETH (gas, registration fee). If I sent this ETH directly
| from my "money" account, I will forever link my public
| identity to my money, which is like walking around with "my
| net worth is at least XYZ USD" banner.
| Phlarp wrote:
| How are these scenarios "use cases" for a mixer and not
| critical flaws in the underlying system?
|
| We're in a thread about a rogue state using the tech to
| steal money to fund their operations (Chemical attacks in
| airports, nuclear warheads, intercontinental ballistic
| missiles, etc.) How many nuclear detonations would you
| consider acceptable in exchange for the cryptobros to
| have their toys?
| DennisP wrote:
| How many would you consider acceptable to have an
| international banking system? North Korea hackers stole
| $81 million from the Bangladesh central bank, and it was
| only a fluke that they didn't get away with over a
| billion from that one hack.
|
| https://www.bbc.com/news/stories-57520169
|
| More prosaic wire fraud is common in real estate and B2B
| transactions, and if not noticed immediately the funds
| are often lost after being transferred internationally
| and cashed out. It wouldn't be surprising if NK is behind
| some of that, given what they managed against Bangladesh.
| nanidin wrote:
| Side note, I find it interesting that "bros" is now a
| pejorative - cryptobros, techbros. Are there other
| instances?
|
| We've come a long way from Mario Bros!
| flangola7 wrote:
| I think it originates from "frat bros" which has been a
| negative phrase since before the internet.
| peyton wrote:
| You'd rather they sell meth? They're gonna find the money
| one way or another.
| exo762 wrote:
| How "Operation Choke Point" is not a critical flow of the
| underlying system? I care about civil rights way more
| than I care about NK.
| snthd wrote:
| GNU Taler[0] provides a "modicum of privacy" and isn't
| demonized.
|
| [0] https://taler.net
| ETH_start wrote:
| GNU Taler lets the government surveil people's
| transactions.
| meltedcapacitor wrote:
| It may get demonized if it ever gets some users. Quite a
| Hurd(le)!
| axlee wrote:
| If 99% of BTC mixers' volume is helping laundering
| international drug trade money, arms or human trafficking,
| it's not exactly hard to demonize mixing itself. I have no
| data to base this on, but I assume that privacy absolutists
| are a tiny, tiny drop in the pool of blood and crime.
| bsamuels wrote:
| do you feel the same way about Tor?
|
| If 99% of Tor's volume is helping laundering international
| drug trade money, distributing CSAM, etc, should it be
| demonized as well?
| Closi wrote:
| Intentional consealment of illegal internet traffic isn't
| a crime (the crime is just the crime).
|
| Intentional consealment of illegal financial transactions
| _is_ a crime in-and-of itself (the crime is money
| laundering, which is a seperate offence to the original
| criminal activity that the money came from).
| eterps wrote:
| The point was whether using a mixer is a crime in itself.
| Closi wrote:
| Well it is a crime to use it for obscuring illegal money,
| while it is not illegal to use Tor for obscuring illegal
| internet traffic
| dwighttk wrote:
| conspiracy to commit a crime is often an additional
| charge (IANAL)
| warner25 wrote:
| I think most people _do_ feel that way about Tor, both in
| terms of assuming that 99% of its users are criminals and
| that it should be demonized. It 's interesting to me
| because I think most of those people don't feel the same
| way about encryption in general, which of course enables
| Tor and all sorts of criminal activity in other contexts.
| Everyone has something to hide from someone and wants to
| see the green lock symbol in their browser's address bar
| along with other assurances of some degree of privacy. I
| don't know how most people decide where to draw a line.
| wpietri wrote:
| > If 99% of Tor's volume is helping laundering
| international drug trade money, distributing CSAM, etc,
| should it be demonized as well?
|
| Easy answer: Yes! Although I think it would be hard to
| call it demonizing when something is already 99% demons.
| eterps wrote:
| Should any tech that conceals IP addresses be demonized?
| Or just Tor?
| [deleted]
| ivalm wrote:
| Depends if it is being overwhelmingly used for criminal
| activity.
| acdha wrote:
| Mostly, yes. I sympathize with the goals in theory since
| I grew up on 90s internet dreams too but as a practical
| matter if you run a large website you'll see mostly
| attacks from Tor, it shows up a lot in news about crime,
| and it's noticeably helping people in actual repressive
| regimes because it's still too easy to identify the
| network traffic when the stakes are high.
| throwaway290 wrote:
| Privacy absolutists are free to deal in cash. Whatever
| amounts they send and receive, criminals and dictators do
| orders of magnitude more and people suffer as a result.
|
| If it wasn't so sad it would be funny that the countries
| with highest levels of freedom and least corruption tend to
| be the ones with most vocal privacy absolutists...
| ETH_start wrote:
| The most powerful states don't need to launder any money,
| since they can just pass a law legitimizing any action
| they do, with no need to hide the funds generated from
| any one else.
| stirfish wrote:
| >the countries with highest levels of freedom and least
| corruption tend to be the ones with most vocal privacy
| absolutists...
|
| Correlation or causation?
| throwaway290 wrote:
| Only irony. No one is taking cash away from those guys.
| csomar wrote:
| Funny thing is, you can barely launder any tangible amount
| of money with Bitcoin let alone crypto.
| chollida1 wrote:
| > Funny thing is, you can barely launder any tangible
| amount of money with Bitcoin let alone crypto.
|
| https://www.cnbc.com/2022/08/10/crypto-criminals-
| laundered-5...
|
| Is $540M considered a tangible amount? I'll let you
| quibble over that but I'd think most criminals would be
| more than happy to be able to launder $540M.
| [deleted]
| lovich wrote:
| Would privacy absolutists even use BTC? I was under the
| impression that every transaction was out in the open and
| permanent.
| thefounder wrote:
| The answe is no but they can make a trade off using
| something like monero. BTC's only read advantage is the
| network effects. As far as the tech is concerned it is
| mediocre compared with other ledgers.
| adr1an wrote:
| Please give an example
| T0Bi wrote:
| If you don't want to link your 'public' wallet with your
| cold wallets. General privacy on a chain where everyone can
| see everything.
| acidtakes1 wrote:
| Signal: https://www.nytimes.com/2022/12/28/opinion/jack-
| dorseys-twit...
| graeme wrote:
| Signal is not a crypto mixer. The argument here is about
| the frequency a certain service is used for crime.
|
| For example, library records generally have a fair amount
| of privacy. Criminals sometimes consult libraries. Crime
| is not the dominant use of libraries.
|
| Mixers have a fair amount of privacy. Mixers are used by
| criminal, and crime is overwhelmingly the dominant use of
| mixers.
|
| To rebut this you'd need to show large and innocent use
| cases which use mixers. Not an unrelated app.
| acidtakes1 wrote:
| I'm only arguing the definition shouldn't be changed to
| something that is explicitly negative, even if the vast
| majority of the time it's used for nefarious reasons.
| earnesti wrote:
| Basically almost all custodial crypto exchanges and services
| function as mixers, as they don't separate customer funds.
| Using Blockchain analysis you can see that certain transaction
| likely belongs to certain service, but to get the details you
| have to file a data request, and hope that the service has done
| the KYC properly.
| ETH_start wrote:
| Smart contract based mixers like Tornado Cash are just code for
| encrypting transactions. The only reason that a large
| proportion of Tornado Cash transactions were criminal in origin
| is that the legitimate parties were largely scared off from
| using it, because of the legal uncertainty around it, with
| people fearing what exactly ended up happening - with OFAC
| sanctioning the actual code - happening.
|
| This left only the bravest parties, and criminals to use it,
| leading to a high proportion of users being criminals.
|
| If it weren't for that uncertainty about the legal treatment TC
| would receive from government (say if Congress passed
| legislation explicitly providing a right to use financial
| privacy technology), a huge proportion of the whole crypto
| economy would have been using Tornado Cash, as they should be,
| because privacy is an absolute bare minimum for a functioning
| financial system.
|
| The conceptual treatment you're giving transaction encryption
| is to treat privacy as criminal. This is an ideological outlook
| that promotes putting total trust and faith in a small elite in
| government and finance to engage in warrantless dragnet
| surveillance of every one's financial transactions.
| bparsons wrote:
| At last. Someone has found a real world use case for crypto.
| input_sh wrote:
| Hey that's not fair!
|
| It's actually the third real world use case, behind getting
| better drugs than from your local dealer and the entirety of
| the ransomware industry.
| Oxidation wrote:
| I thought getting money to places governments didn't want to
| get money to was one of the explicit aims of cryptocurrency.
| pwthornton wrote:
| How can you steal $1.7B of nothing?
| shp0ngle wrote:
| That's... not that much?
|
| I mean it's about what Meta spends in one and a half months on
| metaverse
| magwa101 wrote:
| [dead]
| shayanbahal wrote:
| That is peanuts comparing to how much was lost in FTX, 3AC,
| Celcius, etc.
| rr888 wrote:
| Not really FTX customer assets were about $8 bil and they have
| $5 bil?
| spaceman_2020 wrote:
| And they said crypto has no use cases /s
| helsinkiandrew wrote:
| https://archive.ph/SUYp1
| exo762 wrote:
| With our current state of cybersecurity (total shambles), we
| worry about NK stealing rather modest amounts of money. While
| relying exclusively on cybersecurity to prevent SkyNet scenario.
|
| Fun times.
| pelagicAustral wrote:
| I wonder how many ICBM can that get you... probably like 3 or
| something...
|
| - Found my answer: https://www.brookings.edu/what-nuclear-
| weapons-delivery-syst...
|
| Not a lot...
| brucethemoose2 wrote:
| The US mass produced warheads and icbms like they were candy
| canes. The unit costs for NK are probably higher, though maybe
| not dramatically so with newer tech to help.
| HPsquared wrote:
| Probably more hours of work to produce each one, but at a
| _substantially_ lower hourly rate.
| agloe_dreams wrote:
| ..I mean...one of those in Seoul is WWIII and MAD of all of
| Asia...so like...isn't that enough?
| drewmol wrote:
| I'd like to think that if it was from NK, it would likely be
| MAD of NK, but not all of Asia. If China was attacked for
| instance, they have the capabilities to ensure MAD of any
| other nation or all of them, via a network of nuclear armed
| submarines - from undetectable locations - even after the
| nuclear destruction of their mainland. This makes it pretty
| unlikely for another nation to fire nuclear weapons into
| China.
| credit_guy wrote:
| Maybe a few dozen.
|
| Take the US Trident 2 [1]. Wikipedia lists a cost of $31 MM, in
| 2019 dollars, which would be about $37 MM today. With $1.3 BN
| you could buy 35 of those.
|
| But the North Koreans are not buying their missiles from
| Lokheed-Martin. They are building them in house, so you'd
| expect them to pay much less for labor and materials.
|
| [1] https://en.wikipedia.org/wiki/UGM-133_Trident_II
| H8crilA wrote:
| Arms procurement costs are very hard to pin down due to the
| cost of R&D and the cost of logistical packages. The same
| system can "cost" X but also 3X, 4X or sometimes even more if
| all of the real costs are properly included.
|
| Also, US strategic rocket weapons (ICBMs) are actually not
| the best in their class, as a result of post-soviet partial
| denuclearization. Many aren't even MIRV. This doesn't apply
| to submarines and bombers, those are top notch. Especially
| bombers, many decades ahead.
| dwighttk wrote:
| (NB: Trident is an SLBM)
| H8crilA wrote:
| You're right! I don't know why but I was thinking about
| the Minuteman all the time.
| hnthrowaway0315 wrote:
| How do they use the $$? I guess it's not easy to convert to USD
| so the only option is on black market? Some vendors say chip
| vendors or weapon vendors may be willing to take crypto?
| eunos wrote:
| They launder it up in Macau supposedly
| paulpauper wrote:
| Also, as prices falls, presumably these figures will need to be
| downgraded? I don't think they are cashing out this crypto, but
| probably most of it stays dormant in wallets. Crypto falls so
| fast, likely this figure will be downgraded by a magnitude of 5
| or more by next year . Putting an exact figure is hard.
| sandworm101 wrote:
| I care less about how much they stole than about how much they
| _sold_. Crypto is all well and good, but how they sell it for
| cash or products to avoid sanctions should be the lead story.
| Stealing crypto hurts crypto _investors_. Avoidance of
| international sanctions hurts innocent _people_ , mostly poor
| people living under an oppressively regime who have no connection
| to crypto.
| MarcellusDrum wrote:
| _International sanctions_ hurts innocent people. Who do you
| think is suffering more from the sanctions, Assad or the poor
| Syrians?
| aaron695 wrote:
| [dead]
| rishishah20 wrote:
| Never ever use your savings to invest in Crypto, if you want to
| invest only invest 2 to 10 percent what you make is still risky.
| trpv wrote:
| How is your personal opinion on investing in crypto relevant
| here?
| dwighttk wrote:
| I'm guessing numbers are real hard to get for North Korea's GDP,
| but a couple places I looked[1] showed it on the order of tens of
| billion USD!
|
| [1]CIA world fact book and world bank (both a few years old)
| ianpurton wrote:
| I didn't get passed the pay wall but my question is how do we
| know this?
|
| What's the trail of evidence that leads to this conclusion.
| ascotan wrote:
| https://blog.chainalysis.com/reports/2022-biggest-year-ever-...
|
| Seems like most of this theft is happening when people port
| currency between exchanges and the bridge is vulnerable.
| DethNinja wrote:
| They mostly correlate this by the methods used by APTs.
|
| Each APT usually utilises a specific set of techniques to
| commit these heists: https://attack.mitre.org/groups/
|
| Obviously perfect correlation is not possible but set of
| utilised techniques are usually enough to pinpoint the specific
| APT.
| fumblebee wrote:
| When you see an economist.com submission on HN, typically the
| top comment is a morally dubious but ever so helpful archive
| link to get around the paywall.
|
| In this case: https://archive.ph/SUYp1
| [deleted]
| bell-cot wrote:
| Having javascript disabled by default in your browser works
| fine on most HN-linked sites. Without waiting for someone to
| post an archive link.
| loeg wrote:
| You can just browse to archive.is yourself -- no need to
| wait.
| mattmcknight wrote:
| I suppose one question is whether they sold it or they are now
| HODL-ing $170M of crypto.
| [deleted]
| onewheeltom wrote:
| [flagged]
| baby wrote:
| I'm wondering how much money trafficking and theft happens in the
| traditional finance world. It's great that we can analyze so much
| of what's happening in cryptocurrencies as most are open for the
| world to see.
| ourmandave wrote:
| Like Binance audits? =D
| 55555 wrote:
| I wonder how much their hackers stole using bank wires? Surely
| they are doing both.
| H8crilA wrote:
| Not only that but they're even printing their own US dollar
| bills (see superdollar or kattalio).
| ttyprintk wrote:
| Thank you, I couldn't remember the name of it.
| supernova87a wrote:
| I wonder how big the pressure/temptation is for a North Korean,
| hacking for the state (presumably), to escape with a couple
| hundred coins and defect?
|
| I'm sure the repercussions / penalties must be huge, but then so
| are the amounts they must be seeing day by day, compared to
| average standard of living in N. Korea.
|
| Or maybe this is a cadre of military / public conscripted workers
| who regard this hacking as a patriotic service even?
| appleiigs wrote:
| Probably not worth the multi-generational punishment.
| moremetadata wrote:
| Not bad for a supposedly backwards repressed regime, unless thats
| the least stolen compared to 1st world countries?
|
| It also exposes a wider problem the crypto community are not
| addressing.
| rahen wrote:
| > Not bad for a supposedly backwards repressed regime
|
| What do you mean by supposedly?
|
| > It also exposes a wider problem the crypto community are not
| addressing.
|
| What wider problem? That money (in any form) can be stolen by a
| malevolent state?
| smcl wrote:
| > What do you mean by supposedly?
|
| The DPRK is often portrayed as incompetent, helpless state
| purely able to eke out an existence by the grace of China (to
| whom it is useful only as a sort of attack dog cum buffer
| state). So the fact that they've managed to run an operation
| that can steal this much crypto may come as a surprise to
| many. I don't imagine their intelligence agencies are quite
| on the same level of electronic warfare capabilities as USA,
| UK, Israel and friends, though.
|
| > That money (in any form) can be stolen by a malevolent
| state?
|
| Right but as we repeatedly saw in the last couple of years, a
| North Korean hacker could swindle some dope out of their $10k
| ape jpeg from across the globe at relatively little cost.
| They'll have a bit of a tougher job stealing that same $10k
| from someone's bank, from a safe deposit box, or hell even
| from a box under their bed. It requires another level of
| sophistication entirely and the costs and risks would be
| prohibitively high. I am sure if the North Korean state took
| issue with me personally and wanted to empty my bank account,
| they could probably make some headway ... but they'd likely
| get caught and they'd spend more time and effort doing so
| than they'd actually be able to retrieve.
| acdha wrote:
| I'm not sure it's out of line with the normal news media
| portrayal: for decades, it's been understood that there's
| an elite which has access to many things which the average
| citizen is prevented from doing, and this seems more in
| keeping with that since ransomware doesn't require unusual
| levels of skill as much as legal immunity. This seems in
| line with the level of resources and skill they'd need to
| do things like the kidnappings and assassinations: a modest
| number of people and resources, but not remotely near the
| level they'd need to field a modern army or high-tech
| economy, and nothing like the ability to hit a hard target.
|
| What limited that before were the protections built in to
| the real banking system. Stealing a billion dollars and
| actually getting away with it was hard until
| cryptocurrencies were introduced with far fewer safeguards.
| Salgat wrote:
| It's not really surprising. NK is able to outsource their
| education to Chinese universities, and with a division that
| can yield $1.7B in revenue, it's not surprising they invest
| in this skillset, even if the country at large is destitute
| and backwards.
| smcl wrote:
| It _is_ a surprise for those who take the common
| portrayal of the country at face value. We know it 's not
| quite the "hermit kingdom" it's often described as, but
| most do not.
| drewmol wrote:
| Any good sources on what it's actually like?
| smcl wrote:
| There are no good sources for what your average North
| Korean's life is currently like. There are a handful of
| famous accounts from a few of those who escaped the
| country and they're obviously pretty grim (particularly
| those describing prison camp life) but the stereotype of
| this primitive country, which is backwards both
| ideologically and technologically. I'm not an idiot, I
| don't believe there's a little hidden Wakanda going on
| there. But we can at least observe that if they're able
| to hack that quantity of crypto there is _some_ kind of
| tech operation going on there, however small it might be.
| So they 're not _entirely_ shut off and they 're able to
| penetrate at least a bunch of western crypto-startups.
|
| If you're motivated, don't mind a very on-rails,
| restricted and relatively pricey tour, you can actually
| visit yourself: https://koryogroup.com - I've wanted to
| for a while, but I've spent less money to travel in other
| interesting places with fewer restrictions for longer, so
| it's hard to justify the expense.
|
| An interesting read you might like is by a couple of
| Austrian guys who decided to hop on a train there,
| confusing and irritating border officials who didn't
| expect an invasion from the northern direction :)
| http://vienna-pyongyang.blogspot.com
|
| Probably the most accessible and interesting thing
| though, is a podcast series called "Blowback" (it's
| Season 3, the previous two were on the Cuban revolution
| and the Iraq war). Now obviously this isn't the _current_
| day but it presents a slightly more balanced view of the
| events leading up to and throughout the Korean War than
| your average American or Brit might have picked up
| through osmosis. It 's fascinating, well-produced, well-
| sourced and has a very good soundtrack. Here's ep 1: http
| s://www.stitcher.com/show/blowback/episode/s3-episode-1-.
| ..
|
| As I said, there will be no good way to get any kind of
| verifiable account of how awful or how ok-ish is it is
| there. And I'm deliberately putting "ok-ish" as the upper
| limit because while I'm sure that all the ~20 million
| inhabitants aren't all living the prison camp lifestyle,
| I don't imagine your average North Korean has a
| particularly pleasant life.
|
| Sorry, maybe not the answer you were hoping for but I
| hope you enjoy any or all of the things I suggested :)
| moremetadata wrote:
| North Korea's internet access is through a fibre optic
| connection from China, you know that place with the supposed
| great firewall of china, whilst the likes of the UK hides the
| fact and 5eyes hides the fact its got total oversight of the
| internet including Tor!
|
| https://en.wikipedia.org/wiki/Telecommunications_in_North_Ko.
| ..
| mountainriver wrote:
| I think crypto has made it easier for them to steal money. I
| would be curious to see how much money oppressive regimes
| were able to steal and use before crypto to after
| smcl wrote:
| Yeah that's the part of the equation I'm curious about, so
| they stole "$1.7B" of crypto but were they able to actually
| get anything they can use out of it or does Kim Jong Un
| just really want to take part in the pay-to-play bored ape
| sewer game or whatever.
| ttyprintk wrote:
| Years ago, I heard that the top industrial export from
| North Korea was counterfeit $100 bills. When traveling in
| the surrounding countries, people treat that denomination
| with more skepticism as you get closer to North Korea.
| Special paper-protecting and flaw-spotting techniques that
| I have never seen inside the USA.
| monero-xmr wrote:
| The crypto currency world is hyper focused on stopping this,
| considering it is one of the main avenues that statists attack
| crypto with now that the environmental nag is gone since the
| switch to Proof of Stake.
|
| I would say, conservatively, the traditional banking and real
| estate markets are 10,000x worse than crypto markets, but are
| un-policed because it's hidden, unlike the public blockchain
| networks. The few scams that are exposed, like the HSBC money
| laundering scandal, dwarf all of the crime every committed via
| crypto. But we didn't even put HSBC out of business or put a
| single employee in jail!
|
| Here is the Danish money laundering fraud that just concluded
| with $2 billion in fines on $160 billion in laundered money
| https://www.justice.gov/opa/pr/danske-bank-pleads-guilty-fra...
| oneoff786 wrote:
| I like the use of "statists" to negatively refer to people
| who use facts to support their arguments.
| wpietri wrote:
| Those wild and crazy people in favor of any form of
| government!
| EamonnMR wrote:
| Did Bitcoin switch to proof of stake while I wasn't looking?
| nibbleshifter wrote:
| Eth did.
|
| Bitcoin is slowly losing dominance - its legacy technology,
| and bitcoin maxis/satoshi purists refuse to recognise that
| tech must evolve over time.
|
| Its fucking insane to me how "The White paper" has become a
| holy text among Bitcoiners. Its made it almost fucking
| impossible to make any improvements to the protocol - hence
| forks, altcoins, etc.
| arp242 wrote:
| Money laundering is a crime, but not a scam. Besides, there's
| some nuance here: HSBC were fined for not doing enough to
| prevent it as required by law. You know, the kind of laws
| that don't even apply to crypto. "They are breaking rules but
| we are not!" is an easy claim to make if you have no rules
| but the others do.
| boringg wrote:
| That 10,000x worth sounds like its using specific numbers as
| opposed to hand wavy arguments for which crypto is predicated
| on. Glad you brought real numbers to the table.
| crazygringo wrote:
| > _The crypto currency world is hyper focused on stopping
| this_
|
| Can you explain how?
|
| I'm super curious because the whole point of crypto is you
| can't reverse transactions, and therefore crypto is only ever
| as secure as computer security generally, and there's nothing
| crypto can do about computer security generally.
|
| Or are people coming up with some new paradigm here that
| fixes this somehow?
| anonymousDan wrote:
| Why 'generally'? Why can't crypto systems be designed to be
| more secure than other software given what is at stake
| (e.g. by making the effort to formally verify
| systems/applications). Not saying it will happen but don't
| see why it is impossible.
| crazygringo wrote:
| Because ultimately it all comes down to the security of
| your keys. Which are just information.
|
| Keeping keys secure is no different from keeping anything
| else secure. That's why 'generally'.
|
| And crypto doesn't do anything about key security. That's
| up to each person/org to figure out for themselves.
|
| (North Korea didn't hack the blockchain. They hacked
| however people/orgs kept their keys.)
| dbmikus wrote:
| There's a fair amount of work on key security, such as
| via multi-party computation, Shamir's secret sharing,
| etc. These let multiple parties combine to give access to
| a key. Some cool stuff here are companies like
| https://web3auth.io/ and https://magic.link/.
|
| This stuff is useful outside of blockchain as well.
|
| The state of user protection in crypto right now is
| definitely bad, but there is a lot of work and research
| being done to improve it.
|
| EDIT: I think I'm actually making the same point you
| made, but anyways here's a couple cool links and things
| to google for secret security :)
| recuter wrote:
| > Can you explain how?
|
| By posting long tirades on Internet forums that surmise:
| "We have top men working on it right now. Top... men.."
| bdcravens wrote:
| The biggest risk with North Korea is seeing the state of the
| country, and underestimating the regime itself.
| JumpCrisscross wrote:
| Spot on. I once heard the Kims described as multimillionaires
| with one of the largest armies in the world [1] and nukes.
|
| [1] https://en.m.wikipedia.org/wiki/List_of_countries_by_numb
| er_...
| arp242 wrote:
| Size isn't everything when it comes to armies. See: Russia
| and Ukraine, USSR and the US in Afghanistan, Afghan army
| and Taliban, Boudica and the Romans, etc.
|
| Nuclear weapons and the fortified long-range artillery that
| can shell Seoul are the main point of concern, which are
| essentially a small-scale version of cold war era mutually
| assured destruction. The number of people in the army as
| such? I'm not so sure that's really something that's all
| that meaningful.
| miguelazo wrote:
| It may be a totalitarian dictatorship, but this is totally
| expected behavior given the sanctions in place against them.
| Sanctions that amount to collective punishment, which is
| supposedly illegal under international law. Perhaps if the
| sanctions were reduced/removed, they'd feel like this sort of
| activity was less necessary/justified to get hard currency.
| droptablemain wrote:
| You know, it's possible they wouldn't have to resort to such
| things if we weren't intent on sanctioning them to death.
| Salgat wrote:
| What makes you think they'd behave any differently?
| droptablemain wrote:
| Are you implying the Korean people are inherently "evil" or
| something?
| sebzim4500 wrote:
| What a strange comment. If anything, he was implying that
| the rulers of NK are evil and he didn't even really say
| that.
| arp242 wrote:
| Estimated GDP of North-Korea is around $16B (2019); just for
| context.
| qwerty1793 wrote:
| . E12mj sc an Bb.2 ml BBC1
| Willish42 wrote:
| Looking at other countries on https://en.wikipedia.org/wiki/Lis
| t_of_countries_by_GDP_(nomi..., North Korea is near the middle
| of the pack too. Really puts into perspective how enormous an
| amount of money this is by most countries' standards.
| londons_explore wrote:
| And stolen crypto is more comparable to the import/export
| figure... And exports were $142M in 2020.
| v3ss0n wrote:
| 10 years worth
| TacticalCoder wrote:
| I call complete total and utter bullshit.
|
| I don't buy, for a second, this narrative that NK would have
| elite hackers.
|
| Do you guys realize how retarded that country is?
|
| Everytime the subject comes up I can't but say we're talking
| about the country where official propaganda pictures trying to
| make believe they have military hoovercraft (as if it was a cool
| thing btw) are badly photoshopped.
|
| A country with a total GDP of not even $20 billion and which
| cannot correctly Photoshop propaganda pictures simply doesn't
| have great hackers. The heist alone would be 10% of their GDP
| FFS.
|
| What I _do_ believe is that another nation state used to do very
| dirty things is putting the blame on NK.
|
| But --and that's not a stab at the economist in particular--
| mainstream media were also telling us that SBF was an altruistic
| genius making billions in arbritrage trades and that he'd make
| the world a better place by being an effectuive altruist.
|
| In other words: I read between the lines.
|
| And I take the "I cannot photoshop a picture but I can haxx0r 1.7
| bn a year" with a _gigantic_ pinch of salt.
|
| And so should you.
|
| P.S: how do we "know" it's NK? _" Becuz them IPs are from NK"_.
| Yeah. Exactly.
| drexlspivey wrote:
| https://en.wikipedia.org/wiki/Lazarus_Group
| danielvf wrote:
| As a blockchain security guy, it's really easy to spot the
| occasional North Korean heists on Ethereum. The big tells are:
|
| 1. They hack computers not code. Their normal plan is to steal
| keys by compromising users and computers. This is in contrast to
| the normal "hack" that works by finding and exploiting bugs in
| code.
|
| 2. They immediately exfiltrate the stolen money back to the real
| world via bazillions of mule accounts that are already standing
| by. In contrast to the "normal" hacker who attempts to obfuscate
| and hide funds on-chain, and slip away with some at a far future
| date.
|
| Here's a writeup from a company after the big 600 million dollar
| NK hack.
|
| https://roninblockchain.substack.com/p/back-to-building-roni...
| jareklupinski wrote:
| Every once in a while I'll get a pleasantly worded email from a
| random address asking if I want to do 'low effort remote
| accounting services' to the tune of $3.5k a month.
|
| I'm almost convinced that this is how they recruit those mule
| burners, since signing up for employment requires a lot of
| personal information that can be leveraged into opening bank
| accounts or other financial vehicles in that person's name.
| blitzar wrote:
| > steal keys by compromising users and computers
|
| Their keys their coins.
| nhooyr wrote:
| > Their normal plan is to steal keys by compromising users and
| computers. This is in contrast to the normal "hack" that works
| by finding and exploiting bugs in code.
|
| That's the primary way hacks are conducted by most hackers.
| Hackers are primarily social engineers, not technical.
| Technical hackers are extremely rare regardless of nationality.
| ourmandave wrote:
| The NSA called, they want their 0-day exploits back.
| zwkrt wrote:
| It's not that they don't exist, but the easiest way to gain
| access to a computer system is always going to be to ask
| for the password.
|
| https://xkcd.com/538/
| Cpoll wrote:
| I have no evidence for this, but my feeling was always
| that the highest-volume exploits were just having a bot
| run yesterday's Day-0 on every IP listening on a port.
| You can't get that kind of volume by calling people and
| asking for their password.
|
| If you leave an unsecured mail server accessible to the
| internet, it'll start sending spam emails within 30
| minutes.
|
| On the other hand, phishing emails are also automated,
| and that's essentially asking for the password.
| jcrawfordor wrote:
| It's probably safe to say that phishing is the most
| common method among APTs like state intelligence
| agencies. It's cheap, it's easy, it works. No reason to
| burn zero-days unless simpler methods with less exposure
| don't work, and they usually do.
|
| But we can broadly categorize security incidents into two
| bins: first are opportunistic attackers which broadly
| attempt a method that sometimes works. Two common
| examples are minimally-targeted phishing emails (think
| Best Buy invoice) and automated scanning for old versions
| of WordPress with known vulnerabilities. Second are
| targeted attacks, where the attacker chooses a target and
| then attempts different methods to reach success. Overall
| targeted attacks are far less common than opporunitistic
| ones, but because they involve a higher level of effort
| they're only attempted when there's a high level of
| motivation. Targeted attacks tend to result in greater
| financial losses than opportunistic attacks, for example,
| because compromising machines to add them to a botnet
| usually isn't worth the effort of a targeted attack, but
| getting banking credentials or crypto wallets usually is.
|
| All of information security is fairly bimodal in this
| way. It often seems like even technical professionals
| like software engineers struggle to understand basic
| security practices, but I think this is one of the
| biggest causes: most people tend to think about one case
| and ignore the other. Unfortunately one of the things
| that makes security very difficult is that both cases are
| real and the two require fairly different practices to
| deter, prevent, and detect.
|
| Social methods are far more common with targeted attacks
| because "true" social engineering involves a higher level
| of effort, like time on the phone. That said, phishing
| falls into an in-between where some consider it to be a
| social method but it is amenable to widespread
| automation. There's also a wide spectrum of effort in
| phishing. Many are tempted to try to categorize phishing
| activity into a binary of "phishing" and "spear-phishing"
| (I hate these terms), but that doesn't really reflect
| reality very well. In a large corporation you can usually
| find examples of phishing that are targeted to varying
| degrees of specificity: at anyone, at corporate employees
| broadly, at people in the industry, at employees of a
| company, a department in that company, and even carefully
| tailored to a specific employee. The frequency of course
| tails off as you get more specific, but then it's not
| that unusual for some organized crime group to run a
| sustained campaign of fairly closely-targeted phishing as
| happened recently with Twilio.
|
| Opportunistic attacks are certainly greater in volume to
| the extent that some call them "internet background
| noise," but most think that targeted attacks probably
| produce greater total financial damage. Security is very
| faddish though, not only on the defense side but also on
| the offense side, so it probably varies from year to
| year. For example, the emergence of ransomware was a
| major trend that required a strategic shift in defense in
| many organizations since ransomware attacks were fairly
| low effort but also very high damage in many cases.
| breck wrote:
| In 2011 I spent hours writing a script to brute force a
| wifi password at a hotel because I didn't want to pay $5
| a day for wifi. It worked. I was pleased with myself.
|
| When I checked out they gave me a receipt and I went to
| throw it away and saw a handful of wifi passwords in the
| trash bin.
|
| Lesson learned.
| big_youth wrote:
| > 1. They hack computers not code. Their normal plan is to
| steal keys by compromising users and computers. This is in
| contrast to the normal "hack" that works by finding and
| exploiting bugs in code.
|
| I'm just a 'regular security guy' but in that link you posted
| they detail that after the initial phishing compromise "The
| attacker managed to leverage that access to penetrate Sky Mavis
| IT infrastructure and gain access to the validator nodes." They
| don't detail the bugs that got them access to the nodes but
| this didn't give them control of the network so "the attacker
| found a backdoor through our gas-free RPC node, which they
| abused to get the signature for the Axie DAO validator. ...Sky
| Mavis requested help from the Axie DAO to distribute free
| transactions ... Axie DAO allowlisted Sky Mavis to sign various
| transactions on its behalf. This was discontinued in December
| 2021, but the allowlist access was not revoked."
|
| Sounds like a pretty classic hack to me. They got into the
| network, got access to some important servers (how? they should
| be totally segregated from the corporate network). Then found a
| depreciated endpoint that allowed them blindly sign
| transactions. This is bread and butter for any pentesting work,
| makes me wonder if any of these web3 orgs are hiring security
| firms to test their systems and not just smart-contracts.
| woah wrote:
| The problem was ultimately in the bridge's design and
| implementation. Even though it was sold as a decentralized
| system it was a multisig with very few signatories. A
| properly designed decentralized bridge would require the
| compromise of many validators, each with a different
| infrastructure setup. This is why you never hear about
| Ethereum itself getting hacked.
|
| Instead, the Axie bridge was a multisig, and as of that
| wasn't bad enough, most of the signatories were controlled by
| the same organization on the same infrastructure. Really
| demonstrated that concerns about decentralization are not
| just pedantic or academic.
| 3np wrote:
| IIRC the 9 nodes where effectively controlled by 3 sets of
| keys so they only had to compromise 2 to take control. And
| they took weeks to discover it happened. The incompetence
| and brazenness astonishes. Team as well as investors.
| anonkogudhyfhhf wrote:
| The companies getting hacked are not the web3 ones like
| Ethereum or Terra. They are normally inside jobs with the
| founders stealing from the "decentralised" network they
| secretly control. It's the exchanges that are run like
| traditional business without the magic blockchain power.
| testTED wrote:
| Ethereum is not a company.
| anonkogudhyfhhf wrote:
| Not officially but in practice nothing that distinguishes
| it from a company
| joejoesvk wrote:
| where do they get such skilled people?
| tunnuz wrote:
| For anyone intrigued by this, and also into listening podcasts,
| and I can totally recommend "The Lazarus Heist".
| thatgerhard wrote:
| How would they turn that into usable currency over there?
| tpmx wrote:
| PRC and its banks tend to be helpful towards NK.
___________________________________________________________________
(page generated 2023-02-24 23:01 UTC)