[HN Gopher] North Korean hackers stole a record $1.7B of crypto ...
       ___________________________________________________________________
        
       North Korean hackers stole a record $1.7B of crypto last year
        
       Author : helsinkiandrew
       Score  : 254 points
       Date   : 2023-02-24 07:08 UTC (15 hours ago)
        
 (HTM) web link (www.economist.com)
 (TXT) w3m dump (www.economist.com)
        
       | bogomipz wrote:
       | There's a really good 12 episode BBC podcast called "The Lazarus
       | Heist" that details the extent of this state enterprise.
       | 
       | https://www.bbc.co.uk/sounds/brand/w13xtvg9
        
         | drexlspivey wrote:
         | There is also the Darknet Diaries "Bangladesh Bank Heist"
         | episode https://darknetdiaries.com/transcript/72/
        
       | NelsonMinar wrote:
       | "mixers--large digital pools where crypto owners can deposit
       | funds to obscure their origins."
       | 
       | I have a quibble with articles about cryptocurrency fraud. They
       | always get around to mixers and then they define it as if it were
       | some relatively legitimate thing, like an odd bank. "large
       | digital pools", "deposit funds". You have to get to the last
       | phrase ("obscure their origins") to understand what mixers really
       | are.
       | 
       | A proposed alternate definition: "mixers - international money
       | laundering services where illegally obtained cryptocurrency can
       | be mixed with other fraud proceeds making it harder for the legal
       | system to trace".
       | 
       | (The definition I really would like: "mixers - services that look
       | to hide your funds but are actually operated by intelligence
       | agencies to track illegal activity". I imagine at least one mixer
       | is a honeypot of sorts.)
        
         | barnabee wrote:
         | Ideally we would have a world where privacy is the default and
         | everyone has it.
         | 
         | Because we don't, and there is considerable friction required
         | to have financial privacy, most people don't bother unless they
         | really need it or are unusually privacy conscious. Really
         | needing it may often mean they are doing something nefarious.
         | 
         | That doesn't mean the technology to enable privacy is "bad", it
         | means it's too hard to use and that as a society we have done
         | poorly at guaranteeing people's right to privacy.
         | 
         | Not so long ago you might have ben able to say the same thing
         | about people communicating with end-to-end encryption, but
         | thanks to a concerted effort to improve the UX of this tech.
         | and it's adoption by some very widely used services, it's now
         | commonplace. End to end encryption could no longer be argued to
         | be mostly used by criminals.
         | 
         | Hopefully we will get there with financial privacy too.
         | 
         | NB: in neither case am I suggesting that the government should
         | be unable to require you to provide information in some
         | situations (or face the consequences of withholding it against,
         | say, a court order), only that dragnet surveillance of everyone
         | by default is never acceptable.
        
         | judge2020 wrote:
         | I thought the ultimate goal was using legitimate exchanges as
         | your mixer, since if a mixer only handles illegal crypto,
         | chances are the funds can be traced to every destination
         | address and the exchanges are tasked with reporting anything
         | that comes from those addresses to federal law enforcement. The
         | only real anonymity is in tornado cash.
        
         | woah wrote:
         | Why don't you post your credit card statement below if you have
         | nothing to hide since you're not a criminal?
        
         | acidtakes1 wrote:
         | I don't understand why technology that provides a modicum of
         | privacy must be demonized. It must be for money laundering and
         | criminals. It can't have a legitimate use case. Is it used for
         | nefarious activities? Of course, but not exclusively so.
        
           | babypuncher wrote:
           | I agree in principal, however if the vast majority of a given
           | service's users are using it for criminal activity then maybe
           | there's room for some added scrutiny.
        
             | ifyoubuildit wrote:
             | Ok, so all you have to do is prove that the vast majority
             | of a given service's users are using it for criminal
             | activity, right?
        
               | [deleted]
        
           | zht wrote:
           | Can I use an RPG-7 to kill animals like bears that threaten
           | my life on my property?
           | 
           | Yes.
           | 
           | It's definitely usable for non nefarious activities.
           | 
           | Should I be demonized for having one in my house?
           | 
           | Probably
        
             | eterps wrote:
             | And when it's less obvious? Should I be demonized for using
             | TOR? Monero? Signal? GPG?
        
           | butterfi wrote:
           | Can you provide a legitimate use case for mixers? (I'm not
           | trolling, I'm genuinely curious)
        
             | DennisP wrote:
             | Providing some basic financial privacy, not from the
             | government but from the general public. Everything on chain
             | is public. When you buy something or transfer money to a
             | friend, you don't necessarily want the recipient to know
             | how much money is in your account, or what other addresses
             | you've sent money to.
        
             | davidguetta wrote:
             | sending money to ukraine when you are russian (like vitalik
             | buterin did)
        
             | joyfylbanana wrote:
             | If you are transacting in a business environment, I think
             | it is an added benefit if the counterparty in the
             | transaction can't deduce information out of your
             | transaction. Such as how much assets you have, to what
             | other services have you been sending funds and so on. As
             | Bitcoin does have public ledger, and if you just use single
             | address and don't do any privacy enchancing practices, lots
             | of information could be deductible using blockchain
             | analysis.
             | 
             | I would also suspect that using data collected by
             | governments is used for business advantage. Of course it is
             | hard to prove quite often. Personally I think that in
             | principle it just doesn't make sense to spread your data
             | around, as the benefits are tiny and the potential
             | downsides can be big.
        
             | nibbleshifter wrote:
             | Using Tornado was pretty common among well known/higher
             | profile people in the space to avoid causing inadvertent
             | market effects or leak info about upcoming projects.
             | 
             | Basically if you were high profile enough, people would
             | watch your wallets to see what you were investing
             | in/transacting with, and use that as market intelligence.
             | 
             | As far back as 2016 or so I recall someone specifically
             | offering their blockchain analysis platform as a way to do
             | this.
             | 
             | So you would use tornado to make the money you planned to
             | invest/use appear "somewhere else" disconnected, to
             | maintain privacy/security of a project.
             | 
             | Tornado and mixers and such become necessary specifically
             | because all transactions are public - unlike in tradfi
             | where transactions are opaque except to parties and
             | intermediaries.
             | 
             | Similarly to how investors in tradfi tend to keep their
             | investment strategies secret where possible.
        
               | benmanns wrote:
               | Also, if you want to be able to create legitimate
               | projects that are not tied to your real-world identity,
               | you need a break between bank -> exchange -> address ->
               | ??? -> contract deployment address.
        
             | ynniv wrote:
             | The Bitcoin Lightning Network uses indirection for privacy
             | and liquidity in a way that could be described as mixing.
             | https://en.wikipedia.org/wiki/Lightning_Network
        
             | humanizersequel wrote:
             | Lots of good examples already mostly geared around
             | minimizing bits leaked for the sake of alpha, but there are
             | also instances where it is desirable to be "locally
             | clandestine" even if you're a full throated supporter of
             | the powers that be on the whole. Persecution does not just
             | come by way of financial penalties or the legal system,
             | these tools are useful for avoiding social consequences as
             | well. A hypothetical I'd expect to play well here: paying
             | for an abortion in a large state where it is legal, but in
             | a small town where the local church wields an immense
             | amount of influence.
        
             | exo762 wrote:
             | Scenario one. Individual (while working in a startup) is
             | receiving some tokens as a compensation. Time passes. Their
             | remuneration being on-chain and visible is a problem when
             | negotiating salary in the next job.
             | 
             | Scenario two. I want to have on-chain identity (e.g.
             | exo762.eth domain name). To register it I need to have some
             | ETH (gas, registration fee). If I sent this ETH directly
             | from my "money" account, I will forever link my public
             | identity to my money, which is like walking around with "my
             | net worth is at least XYZ USD" banner.
        
               | Phlarp wrote:
               | How are these scenarios "use cases" for a mixer and not
               | critical flaws in the underlying system?
               | 
               | We're in a thread about a rogue state using the tech to
               | steal money to fund their operations (Chemical attacks in
               | airports, nuclear warheads, intercontinental ballistic
               | missiles, etc.) How many nuclear detonations would you
               | consider acceptable in exchange for the cryptobros to
               | have their toys?
        
               | DennisP wrote:
               | How many would you consider acceptable to have an
               | international banking system? North Korea hackers stole
               | $81 million from the Bangladesh central bank, and it was
               | only a fluke that they didn't get away with over a
               | billion from that one hack.
               | 
               | https://www.bbc.com/news/stories-57520169
               | 
               | More prosaic wire fraud is common in real estate and B2B
               | transactions, and if not noticed immediately the funds
               | are often lost after being transferred internationally
               | and cashed out. It wouldn't be surprising if NK is behind
               | some of that, given what they managed against Bangladesh.
        
               | nanidin wrote:
               | Side note, I find it interesting that "bros" is now a
               | pejorative - cryptobros, techbros. Are there other
               | instances?
               | 
               | We've come a long way from Mario Bros!
        
               | flangola7 wrote:
               | I think it originates from "frat bros" which has been a
               | negative phrase since before the internet.
        
               | peyton wrote:
               | You'd rather they sell meth? They're gonna find the money
               | one way or another.
        
               | exo762 wrote:
               | How "Operation Choke Point" is not a critical flow of the
               | underlying system? I care about civil rights way more
               | than I care about NK.
        
           | snthd wrote:
           | GNU Taler[0] provides a "modicum of privacy" and isn't
           | demonized.
           | 
           | [0] https://taler.net
        
             | ETH_start wrote:
             | GNU Taler lets the government surveil people's
             | transactions.
        
             | meltedcapacitor wrote:
             | It may get demonized if it ever gets some users. Quite a
             | Hurd(le)!
        
           | axlee wrote:
           | If 99% of BTC mixers' volume is helping laundering
           | international drug trade money, arms or human trafficking,
           | it's not exactly hard to demonize mixing itself. I have no
           | data to base this on, but I assume that privacy absolutists
           | are a tiny, tiny drop in the pool of blood and crime.
        
             | bsamuels wrote:
             | do you feel the same way about Tor?
             | 
             | If 99% of Tor's volume is helping laundering international
             | drug trade money, distributing CSAM, etc, should it be
             | demonized as well?
        
               | Closi wrote:
               | Intentional consealment of illegal internet traffic isn't
               | a crime (the crime is just the crime).
               | 
               | Intentional consealment of illegal financial transactions
               | _is_ a crime in-and-of itself (the crime is money
               | laundering, which is a seperate offence to the original
               | criminal activity that the money came from).
        
               | eterps wrote:
               | The point was whether using a mixer is a crime in itself.
        
               | Closi wrote:
               | Well it is a crime to use it for obscuring illegal money,
               | while it is not illegal to use Tor for obscuring illegal
               | internet traffic
        
               | dwighttk wrote:
               | conspiracy to commit a crime is often an additional
               | charge (IANAL)
        
               | warner25 wrote:
               | I think most people _do_ feel that way about Tor, both in
               | terms of assuming that 99% of its users are criminals and
               | that it should be demonized. It 's interesting to me
               | because I think most of those people don't feel the same
               | way about encryption in general, which of course enables
               | Tor and all sorts of criminal activity in other contexts.
               | Everyone has something to hide from someone and wants to
               | see the green lock symbol in their browser's address bar
               | along with other assurances of some degree of privacy. I
               | don't know how most people decide where to draw a line.
        
               | wpietri wrote:
               | > If 99% of Tor's volume is helping laundering
               | international drug trade money, distributing CSAM, etc,
               | should it be demonized as well?
               | 
               | Easy answer: Yes! Although I think it would be hard to
               | call it demonizing when something is already 99% demons.
        
               | eterps wrote:
               | Should any tech that conceals IP addresses be demonized?
               | Or just Tor?
        
               | [deleted]
        
               | ivalm wrote:
               | Depends if it is being overwhelmingly used for criminal
               | activity.
        
               | acdha wrote:
               | Mostly, yes. I sympathize with the goals in theory since
               | I grew up on 90s internet dreams too but as a practical
               | matter if you run a large website you'll see mostly
               | attacks from Tor, it shows up a lot in news about crime,
               | and it's noticeably helping people in actual repressive
               | regimes because it's still too easy to identify the
               | network traffic when the stakes are high.
        
             | throwaway290 wrote:
             | Privacy absolutists are free to deal in cash. Whatever
             | amounts they send and receive, criminals and dictators do
             | orders of magnitude more and people suffer as a result.
             | 
             | If it wasn't so sad it would be funny that the countries
             | with highest levels of freedom and least corruption tend to
             | be the ones with most vocal privacy absolutists...
        
               | ETH_start wrote:
               | The most powerful states don't need to launder any money,
               | since they can just pass a law legitimizing any action
               | they do, with no need to hide the funds generated from
               | any one else.
        
               | stirfish wrote:
               | >the countries with highest levels of freedom and least
               | corruption tend to be the ones with most vocal privacy
               | absolutists...
               | 
               | Correlation or causation?
        
               | throwaway290 wrote:
               | Only irony. No one is taking cash away from those guys.
        
             | csomar wrote:
             | Funny thing is, you can barely launder any tangible amount
             | of money with Bitcoin let alone crypto.
        
               | chollida1 wrote:
               | > Funny thing is, you can barely launder any tangible
               | amount of money with Bitcoin let alone crypto.
               | 
               | https://www.cnbc.com/2022/08/10/crypto-criminals-
               | laundered-5...
               | 
               | Is $540M considered a tangible amount? I'll let you
               | quibble over that but I'd think most criminals would be
               | more than happy to be able to launder $540M.
        
               | [deleted]
        
             | lovich wrote:
             | Would privacy absolutists even use BTC? I was under the
             | impression that every transaction was out in the open and
             | permanent.
        
               | thefounder wrote:
               | The answe is no but they can make a trade off using
               | something like monero. BTC's only read advantage is the
               | network effects. As far as the tech is concerned it is
               | mediocre compared with other ledgers.
        
           | adr1an wrote:
           | Please give an example
        
             | T0Bi wrote:
             | If you don't want to link your 'public' wallet with your
             | cold wallets. General privacy on a chain where everyone can
             | see everything.
        
             | acidtakes1 wrote:
             | Signal: https://www.nytimes.com/2022/12/28/opinion/jack-
             | dorseys-twit...
        
               | graeme wrote:
               | Signal is not a crypto mixer. The argument here is about
               | the frequency a certain service is used for crime.
               | 
               | For example, library records generally have a fair amount
               | of privacy. Criminals sometimes consult libraries. Crime
               | is not the dominant use of libraries.
               | 
               | Mixers have a fair amount of privacy. Mixers are used by
               | criminal, and crime is overwhelmingly the dominant use of
               | mixers.
               | 
               | To rebut this you'd need to show large and innocent use
               | cases which use mixers. Not an unrelated app.
        
               | acidtakes1 wrote:
               | I'm only arguing the definition shouldn't be changed to
               | something that is explicitly negative, even if the vast
               | majority of the time it's used for nefarious reasons.
        
         | earnesti wrote:
         | Basically almost all custodial crypto exchanges and services
         | function as mixers, as they don't separate customer funds.
         | Using Blockchain analysis you can see that certain transaction
         | likely belongs to certain service, but to get the details you
         | have to file a data request, and hope that the service has done
         | the KYC properly.
        
         | ETH_start wrote:
         | Smart contract based mixers like Tornado Cash are just code for
         | encrypting transactions. The only reason that a large
         | proportion of Tornado Cash transactions were criminal in origin
         | is that the legitimate parties were largely scared off from
         | using it, because of the legal uncertainty around it, with
         | people fearing what exactly ended up happening - with OFAC
         | sanctioning the actual code - happening.
         | 
         | This left only the bravest parties, and criminals to use it,
         | leading to a high proportion of users being criminals.
         | 
         | If it weren't for that uncertainty about the legal treatment TC
         | would receive from government (say if Congress passed
         | legislation explicitly providing a right to use financial
         | privacy technology), a huge proportion of the whole crypto
         | economy would have been using Tornado Cash, as they should be,
         | because privacy is an absolute bare minimum for a functioning
         | financial system.
         | 
         | The conceptual treatment you're giving transaction encryption
         | is to treat privacy as criminal. This is an ideological outlook
         | that promotes putting total trust and faith in a small elite in
         | government and finance to engage in warrantless dragnet
         | surveillance of every one's financial transactions.
        
       | bparsons wrote:
       | At last. Someone has found a real world use case for crypto.
        
         | input_sh wrote:
         | Hey that's not fair!
         | 
         | It's actually the third real world use case, behind getting
         | better drugs than from your local dealer and the entirety of
         | the ransomware industry.
        
         | Oxidation wrote:
         | I thought getting money to places governments didn't want to
         | get money to was one of the explicit aims of cryptocurrency.
        
       | pwthornton wrote:
       | How can you steal $1.7B of nothing?
        
       | shp0ngle wrote:
       | That's... not that much?
       | 
       | I mean it's about what Meta spends in one and a half months on
       | metaverse
        
       | magwa101 wrote:
       | [dead]
        
       | shayanbahal wrote:
       | That is peanuts comparing to how much was lost in FTX, 3AC,
       | Celcius, etc.
        
         | rr888 wrote:
         | Not really FTX customer assets were about $8 bil and they have
         | $5 bil?
        
       | spaceman_2020 wrote:
       | And they said crypto has no use cases /s
        
       | helsinkiandrew wrote:
       | https://archive.ph/SUYp1
        
       | exo762 wrote:
       | With our current state of cybersecurity (total shambles), we
       | worry about NK stealing rather modest amounts of money. While
       | relying exclusively on cybersecurity to prevent SkyNet scenario.
       | 
       | Fun times.
        
       | pelagicAustral wrote:
       | I wonder how many ICBM can that get you... probably like 3 or
       | something...
       | 
       | - Found my answer: https://www.brookings.edu/what-nuclear-
       | weapons-delivery-syst...
       | 
       | Not a lot...
        
         | brucethemoose2 wrote:
         | The US mass produced warheads and icbms like they were candy
         | canes. The unit costs for NK are probably higher, though maybe
         | not dramatically so with newer tech to help.
        
           | HPsquared wrote:
           | Probably more hours of work to produce each one, but at a
           | _substantially_ lower hourly rate.
        
         | agloe_dreams wrote:
         | ..I mean...one of those in Seoul is WWIII and MAD of all of
         | Asia...so like...isn't that enough?
        
           | drewmol wrote:
           | I'd like to think that if it was from NK, it would likely be
           | MAD of NK, but not all of Asia. If China was attacked for
           | instance, they have the capabilities to ensure MAD of any
           | other nation or all of them, via a network of nuclear armed
           | submarines - from undetectable locations - even after the
           | nuclear destruction of their mainland. This makes it pretty
           | unlikely for another nation to fire nuclear weapons into
           | China.
        
         | credit_guy wrote:
         | Maybe a few dozen.
         | 
         | Take the US Trident 2 [1]. Wikipedia lists a cost of $31 MM, in
         | 2019 dollars, which would be about $37 MM today. With $1.3 BN
         | you could buy 35 of those.
         | 
         | But the North Koreans are not buying their missiles from
         | Lokheed-Martin. They are building them in house, so you'd
         | expect them to pay much less for labor and materials.
         | 
         | [1] https://en.wikipedia.org/wiki/UGM-133_Trident_II
        
           | H8crilA wrote:
           | Arms procurement costs are very hard to pin down due to the
           | cost of R&D and the cost of logistical packages. The same
           | system can "cost" X but also 3X, 4X or sometimes even more if
           | all of the real costs are properly included.
           | 
           | Also, US strategic rocket weapons (ICBMs) are actually not
           | the best in their class, as a result of post-soviet partial
           | denuclearization. Many aren't even MIRV. This doesn't apply
           | to submarines and bombers, those are top notch. Especially
           | bombers, many decades ahead.
        
             | dwighttk wrote:
             | (NB: Trident is an SLBM)
        
               | H8crilA wrote:
               | You're right! I don't know why but I was thinking about
               | the Minuteman all the time.
        
       | hnthrowaway0315 wrote:
       | How do they use the $$? I guess it's not easy to convert to USD
       | so the only option is on black market? Some vendors say chip
       | vendors or weapon vendors may be willing to take crypto?
        
         | eunos wrote:
         | They launder it up in Macau supposedly
        
         | paulpauper wrote:
         | Also, as prices falls, presumably these figures will need to be
         | downgraded? I don't think they are cashing out this crypto, but
         | probably most of it stays dormant in wallets. Crypto falls so
         | fast, likely this figure will be downgraded by a magnitude of 5
         | or more by next year . Putting an exact figure is hard.
        
       | sandworm101 wrote:
       | I care less about how much they stole than about how much they
       | _sold_. Crypto is all well and good, but how they sell it for
       | cash or products to avoid sanctions should be the lead story.
       | Stealing crypto hurts crypto _investors_. Avoidance of
       | international sanctions hurts innocent _people_ , mostly poor
       | people living under an oppressively regime who have no connection
       | to crypto.
        
         | MarcellusDrum wrote:
         | _International sanctions_ hurts innocent people. Who do you
         | think is suffering more from the sanctions, Assad or the poor
         | Syrians?
        
       | aaron695 wrote:
       | [dead]
        
       | rishishah20 wrote:
       | Never ever use your savings to invest in Crypto, if you want to
       | invest only invest 2 to 10 percent what you make is still risky.
        
         | trpv wrote:
         | How is your personal opinion on investing in crypto relevant
         | here?
        
       | dwighttk wrote:
       | I'm guessing numbers are real hard to get for North Korea's GDP,
       | but a couple places I looked[1] showed it on the order of tens of
       | billion USD!
       | 
       | [1]CIA world fact book and world bank (both a few years old)
        
       | ianpurton wrote:
       | I didn't get passed the pay wall but my question is how do we
       | know this?
       | 
       | What's the trail of evidence that leads to this conclusion.
        
         | ascotan wrote:
         | https://blog.chainalysis.com/reports/2022-biggest-year-ever-...
         | 
         | Seems like most of this theft is happening when people port
         | currency between exchanges and the bridge is vulnerable.
        
         | DethNinja wrote:
         | They mostly correlate this by the methods used by APTs.
         | 
         | Each APT usually utilises a specific set of techniques to
         | commit these heists: https://attack.mitre.org/groups/
         | 
         | Obviously perfect correlation is not possible but set of
         | utilised techniques are usually enough to pinpoint the specific
         | APT.
        
         | fumblebee wrote:
         | When you see an economist.com submission on HN, typically the
         | top comment is a morally dubious but ever so helpful archive
         | link to get around the paywall.
         | 
         | In this case: https://archive.ph/SUYp1
        
           | [deleted]
        
           | bell-cot wrote:
           | Having javascript disabled by default in your browser works
           | fine on most HN-linked sites. Without waiting for someone to
           | post an archive link.
        
             | loeg wrote:
             | You can just browse to archive.is yourself -- no need to
             | wait.
        
       | mattmcknight wrote:
       | I suppose one question is whether they sold it or they are now
       | HODL-ing $170M of crypto.
        
       | [deleted]
        
       | onewheeltom wrote:
       | [flagged]
        
       | baby wrote:
       | I'm wondering how much money trafficking and theft happens in the
       | traditional finance world. It's great that we can analyze so much
       | of what's happening in cryptocurrencies as most are open for the
       | world to see.
        
         | ourmandave wrote:
         | Like Binance audits? =D
        
       | 55555 wrote:
       | I wonder how much their hackers stole using bank wires? Surely
       | they are doing both.
        
         | H8crilA wrote:
         | Not only that but they're even printing their own US dollar
         | bills (see superdollar or kattalio).
        
           | ttyprintk wrote:
           | Thank you, I couldn't remember the name of it.
        
       | supernova87a wrote:
       | I wonder how big the pressure/temptation is for a North Korean,
       | hacking for the state (presumably), to escape with a couple
       | hundred coins and defect?
       | 
       | I'm sure the repercussions / penalties must be huge, but then so
       | are the amounts they must be seeing day by day, compared to
       | average standard of living in N. Korea.
       | 
       | Or maybe this is a cadre of military / public conscripted workers
       | who regard this hacking as a patriotic service even?
        
         | appleiigs wrote:
         | Probably not worth the multi-generational punishment.
        
       | moremetadata wrote:
       | Not bad for a supposedly backwards repressed regime, unless thats
       | the least stolen compared to 1st world countries?
       | 
       | It also exposes a wider problem the crypto community are not
       | addressing.
        
         | rahen wrote:
         | > Not bad for a supposedly backwards repressed regime
         | 
         | What do you mean by supposedly?
         | 
         | > It also exposes a wider problem the crypto community are not
         | addressing.
         | 
         | What wider problem? That money (in any form) can be stolen by a
         | malevolent state?
        
           | smcl wrote:
           | > What do you mean by supposedly?
           | 
           | The DPRK is often portrayed as incompetent, helpless state
           | purely able to eke out an existence by the grace of China (to
           | whom it is useful only as a sort of attack dog cum buffer
           | state). So the fact that they've managed to run an operation
           | that can steal this much crypto may come as a surprise to
           | many. I don't imagine their intelligence agencies are quite
           | on the same level of electronic warfare capabilities as USA,
           | UK, Israel and friends, though.
           | 
           | > That money (in any form) can be stolen by a malevolent
           | state?
           | 
           | Right but as we repeatedly saw in the last couple of years, a
           | North Korean hacker could swindle some dope out of their $10k
           | ape jpeg from across the globe at relatively little cost.
           | They'll have a bit of a tougher job stealing that same $10k
           | from someone's bank, from a safe deposit box, or hell even
           | from a box under their bed. It requires another level of
           | sophistication entirely and the costs and risks would be
           | prohibitively high. I am sure if the North Korean state took
           | issue with me personally and wanted to empty my bank account,
           | they could probably make some headway ... but they'd likely
           | get caught and they'd spend more time and effort doing so
           | than they'd actually be able to retrieve.
        
             | acdha wrote:
             | I'm not sure it's out of line with the normal news media
             | portrayal: for decades, it's been understood that there's
             | an elite which has access to many things which the average
             | citizen is prevented from doing, and this seems more in
             | keeping with that since ransomware doesn't require unusual
             | levels of skill as much as legal immunity. This seems in
             | line with the level of resources and skill they'd need to
             | do things like the kidnappings and assassinations: a modest
             | number of people and resources, but not remotely near the
             | level they'd need to field a modern army or high-tech
             | economy, and nothing like the ability to hit a hard target.
             | 
             | What limited that before were the protections built in to
             | the real banking system. Stealing a billion dollars and
             | actually getting away with it was hard until
             | cryptocurrencies were introduced with far fewer safeguards.
        
             | Salgat wrote:
             | It's not really surprising. NK is able to outsource their
             | education to Chinese universities, and with a division that
             | can yield $1.7B in revenue, it's not surprising they invest
             | in this skillset, even if the country at large is destitute
             | and backwards.
        
               | smcl wrote:
               | It _is_ a surprise for those who take the common
               | portrayal of the country at face value. We know it 's not
               | quite the "hermit kingdom" it's often described as, but
               | most do not.
        
               | drewmol wrote:
               | Any good sources on what it's actually like?
        
               | smcl wrote:
               | There are no good sources for what your average North
               | Korean's life is currently like. There are a handful of
               | famous accounts from a few of those who escaped the
               | country and they're obviously pretty grim (particularly
               | those describing prison camp life) but the stereotype of
               | this primitive country, which is backwards both
               | ideologically and technologically. I'm not an idiot, I
               | don't believe there's a little hidden Wakanda going on
               | there. But we can at least observe that if they're able
               | to hack that quantity of crypto there is _some_ kind of
               | tech operation going on there, however small it might be.
               | So they 're not _entirely_ shut off and they 're able to
               | penetrate at least a bunch of western crypto-startups.
               | 
               | If you're motivated, don't mind a very on-rails,
               | restricted and relatively pricey tour, you can actually
               | visit yourself: https://koryogroup.com - I've wanted to
               | for a while, but I've spent less money to travel in other
               | interesting places with fewer restrictions for longer, so
               | it's hard to justify the expense.
               | 
               | An interesting read you might like is by a couple of
               | Austrian guys who decided to hop on a train there,
               | confusing and irritating border officials who didn't
               | expect an invasion from the northern direction :)
               | http://vienna-pyongyang.blogspot.com
               | 
               | Probably the most accessible and interesting thing
               | though, is a podcast series called "Blowback" (it's
               | Season 3, the previous two were on the Cuban revolution
               | and the Iraq war). Now obviously this isn't the _current_
               | day but it presents a slightly more balanced view of the
               | events leading up to and throughout the Korean War than
               | your average American or Brit might have picked up
               | through osmosis. It 's fascinating, well-produced, well-
               | sourced and has a very good soundtrack. Here's ep 1: http
               | s://www.stitcher.com/show/blowback/episode/s3-episode-1-.
               | ..
               | 
               | As I said, there will be no good way to get any kind of
               | verifiable account of how awful or how ok-ish is it is
               | there. And I'm deliberately putting "ok-ish" as the upper
               | limit because while I'm sure that all the ~20 million
               | inhabitants aren't all living the prison camp lifestyle,
               | I don't imagine your average North Korean has a
               | particularly pleasant life.
               | 
               | Sorry, maybe not the answer you were hoping for but I
               | hope you enjoy any or all of the things I suggested :)
        
           | moremetadata wrote:
           | North Korea's internet access is through a fibre optic
           | connection from China, you know that place with the supposed
           | great firewall of china, whilst the likes of the UK hides the
           | fact and 5eyes hides the fact its got total oversight of the
           | internet including Tor!
           | 
           | https://en.wikipedia.org/wiki/Telecommunications_in_North_Ko.
           | ..
        
           | mountainriver wrote:
           | I think crypto has made it easier for them to steal money. I
           | would be curious to see how much money oppressive regimes
           | were able to steal and use before crypto to after
        
             | smcl wrote:
             | Yeah that's the part of the equation I'm curious about, so
             | they stole "$1.7B" of crypto but were they able to actually
             | get anything they can use out of it or does Kim Jong Un
             | just really want to take part in the pay-to-play bored ape
             | sewer game or whatever.
        
             | ttyprintk wrote:
             | Years ago, I heard that the top industrial export from
             | North Korea was counterfeit $100 bills. When traveling in
             | the surrounding countries, people treat that denomination
             | with more skepticism as you get closer to North Korea.
             | Special paper-protecting and flaw-spotting techniques that
             | I have never seen inside the USA.
        
         | monero-xmr wrote:
         | The crypto currency world is hyper focused on stopping this,
         | considering it is one of the main avenues that statists attack
         | crypto with now that the environmental nag is gone since the
         | switch to Proof of Stake.
         | 
         | I would say, conservatively, the traditional banking and real
         | estate markets are 10,000x worse than crypto markets, but are
         | un-policed because it's hidden, unlike the public blockchain
         | networks. The few scams that are exposed, like the HSBC money
         | laundering scandal, dwarf all of the crime every committed via
         | crypto. But we didn't even put HSBC out of business or put a
         | single employee in jail!
         | 
         | Here is the Danish money laundering fraud that just concluded
         | with $2 billion in fines on $160 billion in laundered money
         | https://www.justice.gov/opa/pr/danske-bank-pleads-guilty-fra...
        
           | oneoff786 wrote:
           | I like the use of "statists" to negatively refer to people
           | who use facts to support their arguments.
        
             | wpietri wrote:
             | Those wild and crazy people in favor of any form of
             | government!
        
           | EamonnMR wrote:
           | Did Bitcoin switch to proof of stake while I wasn't looking?
        
             | nibbleshifter wrote:
             | Eth did.
             | 
             | Bitcoin is slowly losing dominance - its legacy technology,
             | and bitcoin maxis/satoshi purists refuse to recognise that
             | tech must evolve over time.
             | 
             | Its fucking insane to me how "The White paper" has become a
             | holy text among Bitcoiners. Its made it almost fucking
             | impossible to make any improvements to the protocol - hence
             | forks, altcoins, etc.
        
           | arp242 wrote:
           | Money laundering is a crime, but not a scam. Besides, there's
           | some nuance here: HSBC were fined for not doing enough to
           | prevent it as required by law. You know, the kind of laws
           | that don't even apply to crypto. "They are breaking rules but
           | we are not!" is an easy claim to make if you have no rules
           | but the others do.
        
           | boringg wrote:
           | That 10,000x worth sounds like its using specific numbers as
           | opposed to hand wavy arguments for which crypto is predicated
           | on. Glad you brought real numbers to the table.
        
           | crazygringo wrote:
           | > _The crypto currency world is hyper focused on stopping
           | this_
           | 
           | Can you explain how?
           | 
           | I'm super curious because the whole point of crypto is you
           | can't reverse transactions, and therefore crypto is only ever
           | as secure as computer security generally, and there's nothing
           | crypto can do about computer security generally.
           | 
           | Or are people coming up with some new paradigm here that
           | fixes this somehow?
        
             | anonymousDan wrote:
             | Why 'generally'? Why can't crypto systems be designed to be
             | more secure than other software given what is at stake
             | (e.g. by making the effort to formally verify
             | systems/applications). Not saying it will happen but don't
             | see why it is impossible.
        
               | crazygringo wrote:
               | Because ultimately it all comes down to the security of
               | your keys. Which are just information.
               | 
               | Keeping keys secure is no different from keeping anything
               | else secure. That's why 'generally'.
               | 
               | And crypto doesn't do anything about key security. That's
               | up to each person/org to figure out for themselves.
               | 
               | (North Korea didn't hack the blockchain. They hacked
               | however people/orgs kept their keys.)
        
               | dbmikus wrote:
               | There's a fair amount of work on key security, such as
               | via multi-party computation, Shamir's secret sharing,
               | etc. These let multiple parties combine to give access to
               | a key. Some cool stuff here are companies like
               | https://web3auth.io/ and https://magic.link/.
               | 
               | This stuff is useful outside of blockchain as well.
               | 
               | The state of user protection in crypto right now is
               | definitely bad, but there is a lot of work and research
               | being done to improve it.
               | 
               | EDIT: I think I'm actually making the same point you
               | made, but anyways here's a couple cool links and things
               | to google for secret security :)
        
             | recuter wrote:
             | > Can you explain how?
             | 
             | By posting long tirades on Internet forums that surmise:
             | "We have top men working on it right now. Top... men.."
        
         | bdcravens wrote:
         | The biggest risk with North Korea is seeing the state of the
         | country, and underestimating the regime itself.
        
           | JumpCrisscross wrote:
           | Spot on. I once heard the Kims described as multimillionaires
           | with one of the largest armies in the world [1] and nukes.
           | 
           | [1] https://en.m.wikipedia.org/wiki/List_of_countries_by_numb
           | er_...
        
             | arp242 wrote:
             | Size isn't everything when it comes to armies. See: Russia
             | and Ukraine, USSR and the US in Afghanistan, Afghan army
             | and Taliban, Boudica and the Romans, etc.
             | 
             | Nuclear weapons and the fortified long-range artillery that
             | can shell Seoul are the main point of concern, which are
             | essentially a small-scale version of cold war era mutually
             | assured destruction. The number of people in the army as
             | such? I'm not so sure that's really something that's all
             | that meaningful.
        
       | miguelazo wrote:
       | It may be a totalitarian dictatorship, but this is totally
       | expected behavior given the sanctions in place against them.
       | Sanctions that amount to collective punishment, which is
       | supposedly illegal under international law. Perhaps if the
       | sanctions were reduced/removed, they'd feel like this sort of
       | activity was less necessary/justified to get hard currency.
        
       | droptablemain wrote:
       | You know, it's possible they wouldn't have to resort to such
       | things if we weren't intent on sanctioning them to death.
        
         | Salgat wrote:
         | What makes you think they'd behave any differently?
        
           | droptablemain wrote:
           | Are you implying the Korean people are inherently "evil" or
           | something?
        
             | sebzim4500 wrote:
             | What a strange comment. If anything, he was implying that
             | the rulers of NK are evil and he didn't even really say
             | that.
        
       | arp242 wrote:
       | Estimated GDP of North-Korea is around $16B (2019); just for
       | context.
        
         | qwerty1793 wrote:
         | . E12mj sc an Bb.2 ml BBC1
        
         | Willish42 wrote:
         | Looking at other countries on https://en.wikipedia.org/wiki/Lis
         | t_of_countries_by_GDP_(nomi..., North Korea is near the middle
         | of the pack too. Really puts into perspective how enormous an
         | amount of money this is by most countries' standards.
        
         | londons_explore wrote:
         | And stolen crypto is more comparable to the import/export
         | figure... And exports were $142M in 2020.
        
           | v3ss0n wrote:
           | 10 years worth
        
       | TacticalCoder wrote:
       | I call complete total and utter bullshit.
       | 
       | I don't buy, for a second, this narrative that NK would have
       | elite hackers.
       | 
       | Do you guys realize how retarded that country is?
       | 
       | Everytime the subject comes up I can't but say we're talking
       | about the country where official propaganda pictures trying to
       | make believe they have military hoovercraft (as if it was a cool
       | thing btw) are badly photoshopped.
       | 
       | A country with a total GDP of not even $20 billion and which
       | cannot correctly Photoshop propaganda pictures simply doesn't
       | have great hackers. The heist alone would be 10% of their GDP
       | FFS.
       | 
       | What I _do_ believe is that another nation state used to do very
       | dirty things is putting the blame on NK.
       | 
       | But --and that's not a stab at the economist in particular--
       | mainstream media were also telling us that SBF was an altruistic
       | genius making billions in arbritrage trades and that he'd make
       | the world a better place by being an effectuive altruist.
       | 
       | In other words: I read between the lines.
       | 
       | And I take the "I cannot photoshop a picture but I can haxx0r 1.7
       | bn a year" with a _gigantic_ pinch of salt.
       | 
       | And so should you.
       | 
       | P.S: how do we "know" it's NK? _" Becuz them IPs are from NK"_.
       | Yeah. Exactly.
        
         | drexlspivey wrote:
         | https://en.wikipedia.org/wiki/Lazarus_Group
        
       | danielvf wrote:
       | As a blockchain security guy, it's really easy to spot the
       | occasional North Korean heists on Ethereum. The big tells are:
       | 
       | 1. They hack computers not code. Their normal plan is to steal
       | keys by compromising users and computers. This is in contrast to
       | the normal "hack" that works by finding and exploiting bugs in
       | code.
       | 
       | 2. They immediately exfiltrate the stolen money back to the real
       | world via bazillions of mule accounts that are already standing
       | by. In contrast to the "normal" hacker who attempts to obfuscate
       | and hide funds on-chain, and slip away with some at a far future
       | date.
       | 
       | Here's a writeup from a company after the big 600 million dollar
       | NK hack.
       | 
       | https://roninblockchain.substack.com/p/back-to-building-roni...
        
         | jareklupinski wrote:
         | Every once in a while I'll get a pleasantly worded email from a
         | random address asking if I want to do 'low effort remote
         | accounting services' to the tune of $3.5k a month.
         | 
         | I'm almost convinced that this is how they recruit those mule
         | burners, since signing up for employment requires a lot of
         | personal information that can be leveraged into opening bank
         | accounts or other financial vehicles in that person's name.
        
         | blitzar wrote:
         | > steal keys by compromising users and computers
         | 
         | Their keys their coins.
        
         | nhooyr wrote:
         | > Their normal plan is to steal keys by compromising users and
         | computers. This is in contrast to the normal "hack" that works
         | by finding and exploiting bugs in code.
         | 
         | That's the primary way hacks are conducted by most hackers.
         | Hackers are primarily social engineers, not technical.
         | Technical hackers are extremely rare regardless of nationality.
        
           | ourmandave wrote:
           | The NSA called, they want their 0-day exploits back.
        
             | zwkrt wrote:
             | It's not that they don't exist, but the easiest way to gain
             | access to a computer system is always going to be to ask
             | for the password.
             | 
             | https://xkcd.com/538/
        
               | Cpoll wrote:
               | I have no evidence for this, but my feeling was always
               | that the highest-volume exploits were just having a bot
               | run yesterday's Day-0 on every IP listening on a port.
               | You can't get that kind of volume by calling people and
               | asking for their password.
               | 
               | If you leave an unsecured mail server accessible to the
               | internet, it'll start sending spam emails within 30
               | minutes.
               | 
               | On the other hand, phishing emails are also automated,
               | and that's essentially asking for the password.
        
               | jcrawfordor wrote:
               | It's probably safe to say that phishing is the most
               | common method among APTs like state intelligence
               | agencies. It's cheap, it's easy, it works. No reason to
               | burn zero-days unless simpler methods with less exposure
               | don't work, and they usually do.
               | 
               | But we can broadly categorize security incidents into two
               | bins: first are opportunistic attackers which broadly
               | attempt a method that sometimes works. Two common
               | examples are minimally-targeted phishing emails (think
               | Best Buy invoice) and automated scanning for old versions
               | of WordPress with known vulnerabilities. Second are
               | targeted attacks, where the attacker chooses a target and
               | then attempts different methods to reach success. Overall
               | targeted attacks are far less common than opporunitistic
               | ones, but because they involve a higher level of effort
               | they're only attempted when there's a high level of
               | motivation. Targeted attacks tend to result in greater
               | financial losses than opportunistic attacks, for example,
               | because compromising machines to add them to a botnet
               | usually isn't worth the effort of a targeted attack, but
               | getting banking credentials or crypto wallets usually is.
               | 
               | All of information security is fairly bimodal in this
               | way. It often seems like even technical professionals
               | like software engineers struggle to understand basic
               | security practices, but I think this is one of the
               | biggest causes: most people tend to think about one case
               | and ignore the other. Unfortunately one of the things
               | that makes security very difficult is that both cases are
               | real and the two require fairly different practices to
               | deter, prevent, and detect.
               | 
               | Social methods are far more common with targeted attacks
               | because "true" social engineering involves a higher level
               | of effort, like time on the phone. That said, phishing
               | falls into an in-between where some consider it to be a
               | social method but it is amenable to widespread
               | automation. There's also a wide spectrum of effort in
               | phishing. Many are tempted to try to categorize phishing
               | activity into a binary of "phishing" and "spear-phishing"
               | (I hate these terms), but that doesn't really reflect
               | reality very well. In a large corporation you can usually
               | find examples of phishing that are targeted to varying
               | degrees of specificity: at anyone, at corporate employees
               | broadly, at people in the industry, at employees of a
               | company, a department in that company, and even carefully
               | tailored to a specific employee. The frequency of course
               | tails off as you get more specific, but then it's not
               | that unusual for some organized crime group to run a
               | sustained campaign of fairly closely-targeted phishing as
               | happened recently with Twilio.
               | 
               | Opportunistic attacks are certainly greater in volume to
               | the extent that some call them "internet background
               | noise," but most think that targeted attacks probably
               | produce greater total financial damage. Security is very
               | faddish though, not only on the defense side but also on
               | the offense side, so it probably varies from year to
               | year. For example, the emergence of ransomware was a
               | major trend that required a strategic shift in defense in
               | many organizations since ransomware attacks were fairly
               | low effort but also very high damage in many cases.
        
               | breck wrote:
               | In 2011 I spent hours writing a script to brute force a
               | wifi password at a hotel because I didn't want to pay $5
               | a day for wifi. It worked. I was pleased with myself.
               | 
               | When I checked out they gave me a receipt and I went to
               | throw it away and saw a handful of wifi passwords in the
               | trash bin.
               | 
               | Lesson learned.
        
         | big_youth wrote:
         | > 1. They hack computers not code. Their normal plan is to
         | steal keys by compromising users and computers. This is in
         | contrast to the normal "hack" that works by finding and
         | exploiting bugs in code.
         | 
         | I'm just a 'regular security guy' but in that link you posted
         | they detail that after the initial phishing compromise "The
         | attacker managed to leverage that access to penetrate Sky Mavis
         | IT infrastructure and gain access to the validator nodes." They
         | don't detail the bugs that got them access to the nodes but
         | this didn't give them control of the network so "the attacker
         | found a backdoor through our gas-free RPC node, which they
         | abused to get the signature for the Axie DAO validator. ...Sky
         | Mavis requested help from the Axie DAO to distribute free
         | transactions ... Axie DAO allowlisted Sky Mavis to sign various
         | transactions on its behalf. This was discontinued in December
         | 2021, but the allowlist access was not revoked."
         | 
         | Sounds like a pretty classic hack to me. They got into the
         | network, got access to some important servers (how? they should
         | be totally segregated from the corporate network). Then found a
         | depreciated endpoint that allowed them blindly sign
         | transactions. This is bread and butter for any pentesting work,
         | makes me wonder if any of these web3 orgs are hiring security
         | firms to test their systems and not just smart-contracts.
        
           | woah wrote:
           | The problem was ultimately in the bridge's design and
           | implementation. Even though it was sold as a decentralized
           | system it was a multisig with very few signatories. A
           | properly designed decentralized bridge would require the
           | compromise of many validators, each with a different
           | infrastructure setup. This is why you never hear about
           | Ethereum itself getting hacked.
           | 
           | Instead, the Axie bridge was a multisig, and as of that
           | wasn't bad enough, most of the signatories were controlled by
           | the same organization on the same infrastructure. Really
           | demonstrated that concerns about decentralization are not
           | just pedantic or academic.
        
             | 3np wrote:
             | IIRC the 9 nodes where effectively controlled by 3 sets of
             | keys so they only had to compromise 2 to take control. And
             | they took weeks to discover it happened. The incompetence
             | and brazenness astonishes. Team as well as investors.
        
           | anonkogudhyfhhf wrote:
           | The companies getting hacked are not the web3 ones like
           | Ethereum or Terra. They are normally inside jobs with the
           | founders stealing from the "decentralised" network they
           | secretly control. It's the exchanges that are run like
           | traditional business without the magic blockchain power.
        
             | testTED wrote:
             | Ethereum is not a company.
        
               | anonkogudhyfhhf wrote:
               | Not officially but in practice nothing that distinguishes
               | it from a company
        
       | joejoesvk wrote:
       | where do they get such skilled people?
        
       | tunnuz wrote:
       | For anyone intrigued by this, and also into listening podcasts,
       | and I can totally recommend "The Lazarus Heist".
        
       | thatgerhard wrote:
       | How would they turn that into usable currency over there?
        
         | tpmx wrote:
         | PRC and its banks tend to be helpful towards NK.
        
       ___________________________________________________________________
       (page generated 2023-02-24 23:01 UTC)