[HN Gopher] A Botnet Accidentally Destroyed I2P
___________________________________________________________________
A Botnet Accidentally Destroyed I2P
Author : Cider9986
Score : 136 points
Date : 2026-02-22 01:08 UTC (14 hours ago)
(HTM) web link (www.sambent.com)
(TXT) w3m dump (www.sambent.com)
| gnabgib wrote:
| This seems to lack the full story, despite the headline.. Krebs'
| coverage is more in-depth (39 points)
| https://news.ycombinator.com/item?id=46976825
| kace91 wrote:
| Man, I feel so out of depth with cybersecurity news.
|
| Why does i2p (per the article) expect state sponsored attacks
| every February? Where are those forming from, what does the
| regularity achieve?
|
| How come the operators of giant (I'm assuming illegal) botnets
| are available to voice their train of thought in discord?
| OgsyedIE wrote:
| Many state bodies involved in adversarial action have dedicated
| budgets for offensive cyber-warfare, credential thefts, supply
| chain compromises and disinformation. If they haven't used all
| of their budget by the end of the budget period, they'll be
| allocated a smaller budget for the next budget period.
| kace91 wrote:
| Oh ffs. Whenever I think my opinion on the state of the world
| can't get any lower, things somehow manage to get dumber.
| bryanrasmussen wrote:
| I mean this is a common pattern in many large
| organizations, governmental and non, if you didn't use your
| budget it means we can save money, yayyyy! I hadn't really
| considered it would apply to state-backed hacking but makes
| sense.
| flipped wrote:
| State sponsored cyber attacks are news to you? It's been a
| thing since more than 2 decades now.
| nigger238 wrote:
| doing a cyber attack to use up your budget is news
| kace91 wrote:
| Not the attacks themselves, I would expect that kind or
| sabotage that actively provokes negative outcomes in
| people's lives to have a more respectful/competent
| reasoning behind than "meh there's a few leftovers and we
| had to do something"
| rollulus wrote:
| Cool theory but that should result in other attacks that peak
| in February too, can you give examples?
| WaitWaitWha wrote:
| > Why does i2p (per the article) expect state sponsored attacks
| every February?
|
| Because The Invisible Internet Project (I2P) allows government
| dissidents to communicate without the government oversight.
| Censorship-resistant, peer-to-peer communication
|
| > Where are those forming from, what does the regularity
| achieve?
|
| At least PR China, Iran, Oman, Qatar, and Kuwait. censor
| communication between dissidents.
|
| > How come the operators of giant (I'm assuming illegal)
| botnets are available to voice their train of thought in
| discord?
|
| How would you identify someone as 'operators of giant botnets'
| before they identified themselves as 'operators of giant
| botnets'?
|
| please read https://en.wikipedia.org/wiki/I2P
| Zambyte wrote:
| This answer is missing the key "regularity" part of their
| questions, which I would love to know more about.
| braingravy wrote:
| That's a great question... Currently we're in the main
| Chinese holiday period with the Lunar New Year/Spring
| Festival/Chinese New Year, so perhaps people traveling back
| home from foreign lands might use the service more during
| this time?
| margalabargala wrote:
| Sure, but why February and not the other 11 months?
| n2d4 wrote:
| Likely it's just a coincidence -- there were other Sybil
| attacks that are not in February too, so the chance that
| you'd get 3 in Feb isn't all that low.
| jjmarr wrote:
| From the main article, I2P has 55,000 computers, the botnet tried
| to add 700,000 infected routers to I2P to use it as a backup
| command-and-control system.
|
| https://news.ycombinator.com/item?id=46976825
|
| This, predictably, broke I2P.
| infogulch wrote:
| That's an interesting stress test for I2P. They should try to
| fix that, the protocol should be resilient to such an event.
| Even if there are 10x more bad nodes than good nodes (assuming
| they were noncompliant I2P actors based on that thread) the
| good nodes should still be able to find each other and continue
| working. To be fair spam will always be a thorny problem in
| completely decentralized protocols.
| sandworm101 wrote:
| No. They should not try to survive such attacks. The best
| defense to a temporary attack is often to pull the plug.
| Better than than potentially expose users. When there are 10x
| as many bad nodes as good, the base protection of any
| anonymity network is likely compromised. Shut down, survive,
| and return once the attacker has moved on.
| martin-t wrote:
| Why would an attacker move on if it can maintain a
| successful DoS attack forever?
| xmcp123 wrote:
| Because botnets are mostly there to make money nowadays.
| Or owned by state actors.
|
| Either way, it's opportunity cost.
| flipped wrote:
| The mentioned botnet didn't intentionally take down I2P.
| It's run by bunch of kids who don't know what they're
| doing.
| conradev wrote:
| This is why Tor is centralized, so that they can take
| action like cutting out malicious nodes if needed. It's
| decentralized in the sense that anyone can participate by
| default.
| notpushkin wrote:
| > so that they can take action like cutting out malicious
| nodes if needed
|
| How does that work?
| cyphar wrote:
| While anyone can run a Tor node and register it as
| available, the tags that Tor relays get assigned and the
| list of relays is controlled by 9 consensus servers[1]
| that are run by different members the Tor project (in
| different countries). They can thus easily block nodes.
|
| [1]: https://consensus-health.torproject.org/
| flipped wrote:
| It's 10, not 9. And there are severe problems with having
| a total of 10 DA be the essential source of truth for
| whole network. It would be trivial to DDoS the DAs and
| bring down the Tor network or at the very least, disrupt
| it: https://arxiv.org/abs/2509.10755.
|
| It's the only complaint I have of the current state of
| Tor. Anyone should be able to run directory authority,
| regardless if you trust the operator or not (same as
| normal relays).
| nigger238 wrote:
| Anyone can. The DA code is open source and is used
| whenever you run a testnet. You can also run a DA on the
| mainnet - how do you think the 10 primary DAs exist?
| They're not 10 computers owned by a single organization -
| they're 10 mutually trusting individuals. However, most
| of the network won't trust you.
| 01HNNWZ0MV43FF wrote:
| Finding good nodes is a thorny problem for human friendship,
| too!
| kkfx wrote:
| That's why the Web of Trust, or classic GNUPG key signing
| parties are a forgotten/ignored must have. Anyone can
| change and go rouge of course, but it's statistically less
| likely.
| kbrkbr wrote:
| If I understand gp correctly, the web of trust comes
| after finding these human nodes, and will not help you in
| the process.
| kkfx wrote:
| It doesn't work for I2P due to its design, but for things
| like Nostr, it works well. Essentially, the goal is to
| build up a list of "known" reliable relays over time,
| while simultaneously blacklisting anyone who joins and
| proves to be unreliable relying on the statistic that
| collaborative individuals outnumber hostile ones in any
| sufficiently large cohort.
|
| Of course, it's far from being 100% effective, but it
| mitigates the issue significantly.
| nigger238 wrote:
| Hostile entities generally have a lot of money they can
| use to perform a Sybil attack.
| kkfx wrote:
| Sure, but can't break the trusted part of the network who
| can remain operational in that case, even if not really
| anonymous anymore.
| seertaak wrote:
| Funny and excellent comment!
| embedding-shape wrote:
| > Even if there are 10x more bad nodes than good nodes [...]
| the good nodes should still be able to find each other
|
| What network, distributed or decentralized, can survive such
| an event? Most of the protocols break down once you hit some
| N% threshold of the network being bad nodes, asking it to
| survive 1000%+ bad nodes when others usually is something
| like "When at least half the nodes are good". Are there
| existing decentralized/distributed protocols that would
| survive a 1000% attack of bad nodes?
| Dylan16807 wrote:
| I guess "predictably" is valid but what actually went wrong?
| After going through multiple sources I can't tell if the botnet
| nodes were breaking the protocol on purpose, breaking the
| protocol on accident, or correct implementations that
| nevertheless overwhelmed something.
| illusive4080 wrote:
| Why does Discord allow a server for a botnet owner?
| fragmede wrote:
| botnet owners dying typically come forwards and say they are
| trying to run a botnet, so there may be some difficulty there.
| fragmede wrote:
| botnet owners don't typically come forwards and say they are
| trying to run a botnet, so there may be some difficulty in
| detecting them there.
| ddtaylor wrote:
| Discord has a lot of terrible servers. This is one of the
| reasons they were not trusted when they came out and wanted to
| do identity verification. They already have a lot of
| information yet fail to do meaningful enforcement at scale.
| Aurornis wrote:
| Only a couple years ago the outrage was that Discord was too
| eagerly banning servers and users.
|
| I know several people whose Discord accounts were banned
| because they participated in a server that later had some
| talk of illegal activities in one of the channels. There are
| similar stories all over Reddit.
| zamadatix wrote:
| If a Walmart has ~100 people in it and wants to get rid of
| 4 shoplifters but really sucks at selecting them well then
| the likely result is 4 normal people are very upset while
| all of the shoplifters are still there.
|
| In the same scenario, even if Walmart is right about who
| they ejected 75% of the time then they still have ~1
| shoplifter remaining and ~1 very upset person.
|
| Even in an ideal world where Walmart is right about
| ejection 100% of the time it doesn't mean they start
| receiving 0 new shoplifters either, it just means the
| number of people wrongly made upset is 0.
|
| Discord's problem (on both ends) lies in lack of depth in
| investigating bans. It takes resources to review when
| someone shouldn't be banned and it takes resources to make
| sure you ban everybody. Putting too low of resources into
| banning just means that both sides of the scale manage to
| get tipped in the wring direction at the same time.
| nigger238 wrote:
| Two things can be true at once. They can ban normal things
| too much and ban bad things too little.
| chmod775 wrote:
| There's servers where they just hang out, but which themselves
| are legitimate. Cybersecurity related ones etc. You can ban
| them and they'll just switch to another account within a
| minute. Occasionally discord or a server owner does, but
| everyone knows its pointless. There's probably other servers
| that are mostly used by cybercriminals, maybe command-and-
| control backups, and security researchers may stumble upon
| these when taking some malware apart, join them, and end up
| getting in contact with the owner.
|
| In general I don't think law enforcement _wants_ discord to
| take these down or ban them. These guys would have no problem
| to just make some IRC servers or whatever to hang out on
| instead, which would be much harder to surveil for law
| enforcement - compared to discord just forwarding them
| everything said by those accounts and on those servers.
| xmcp123 wrote:
| Ever tried to ban a botnet owner from a service they want to
| use?
|
| It's basically impossible. They have money, IPs, identities,
| anything you could possibly want to evade.
| Cider9986 wrote:
| They are rich in regard to the tools needed to abuse services
| haha.
| charcircuit wrote:
| If you just look at the messages in those kinds of discords.
| It's blatant. They aren't even trying to hide it.
| bee_rider wrote:
| It would be pretty funny if the age verification stuff
| blocked some of these folks.
| Aurornis wrote:
| Discord age verification is only for content filters,
| adult-themed servers, and a few other features.
|
| They aren't requiring age verification for everyone to join
| servers and chat. The headlines and panic really got away
| from the actual story.
| bawolff wrote:
| I imagine because banning these things is both whack-a-mole and
| like finding a needle in a hay stack.
| samus wrote:
| Why wouldn't they? There are Discord servers about anything you
| can imagine and also what you can't or don't want to image. As
| long as they don't start disrupting their infra Discord
| couldn't care less.
|
| Also, how would you even go about classifying them as botnet
| operators?
| Ekaros wrote:
| A MAU is a MAU... They likely use relatively little computing
| capability while making numbers look really good...
| richardfey wrote:
| I wonder how cjdns would have handled this
| hoppp wrote:
| Isn't I2P java? The botnet uses java? I thought python or C is
| preferred for that kinda stuff
| mhitza wrote:
| The official router implementation is Java. i2pd is an
| alternative written in C++.
|
| Once established communication can transparently be processed
| through a socks proxy, or integration with SAM or similar
| https://i2p.net/en/docs/api/samv3/
| monero-xmr wrote:
| Computers are so fast it doesn't matter
| flipped wrote:
| "Since the abstraction layers have quadrupled, let's not just
| care about the actual performance anymore!"
| fuzzfactor wrote:
| Not my downvote, but which computers would that be?
|
| More people than just myself might want one.
| rippeltippel wrote:
| Communication between bots use network protocols, it doesn't
| matter in which language those protocols are implemented.
| Cider9986 wrote:
| The video seems to be a bit more in-depth.
| cookiengineer wrote:
| This was one of the worst writeups I ever read. Even a LinkedIn
| Premium post would have had more technical details, lol
| pmontra wrote:
| This seems to be a better post about what happened, from the same
| site https://www.sambent.com/i2p-2-11-0-ships-post-quantum-
| crypto...
| nneonneo wrote:
| Those are some weird-ass visualizations. I can only assume they
| were AI-generated.
| KennyBlanken wrote:
| I'll save everyone else a click: AI slop text coupled with the
| strangest, most pointless visualizations I've ever seen.
| SV_BubbleTime wrote:
| Speak for yourself!
|
| I didn't really understand the link between Alice and Bob
| until I saw a green floaty dot go through a pile of spaghetti
| with the word compromise beneath it.
| charcircuit wrote:
| >hostile nodes
|
| >they accidentally disrupted I2P while attempting to use the
| network as backup command-and-control infrastructure
|
| So were they hostile or were they using it normally?
| shevy-java wrote:
| > The I2P development team responded by shipping version 2.11.0
| just six days after the attack began.
|
| Not wanting to be overly critical, but any net-infrastructure
| project kind of has to keep bot-attacks in mind and other attack
| vectors, in the initial design stage already. Any state-actor
| (and other actors, though I would assume it is often a state
| financing the bot network behind-the-scene) can become
| potentially hostile.
| rollulus wrote:
| This article (with high slop vibes) and another article on their
| site (linked in the comments) seem to suggest that post quantum
| encryption mitigated the Sybil attack, without explanation. I
| fail to understand how the two are even related.
| Roark66 wrote:
| Is there a shittier summary anywhere, please? Or did the author
| reached the peak of enshittification?
|
| Honestly, did the bot implementation have bugs or was it a proper
| implementation that crashed the network due to sheer numbers?
|
| Also, how does changing the encryption standard affect anything
| if the bots tried to integrate correctly with the network?
|
| Is the problem "fixed" or is it not? Elsewhere I found large
| number if botnet devs got pissed off with this botnet operator
| and 600k nodes went offline. Might this have much more to do with
| the situation getting better than simply changing encryption?
|
| Also, was there any suggestion a quantum breaking attack was
| attempted? No. So why put the emphasis on "post quantum" in this
| article?
|
| Bad. Very bad.
| nigger238 wrote:
| Sam Bent has turned full influencer
___________________________________________________________________
(page generated 2026-02-22 16:01 UTC)