Key Bitcoin Developer Calls on FBI To Recover $3.6M in Digital Coin (arstechnica.com) 119
One of the prominent developers behind the bitcoin blockchain said he has asked the FBI to assist him in recovering $3.6 million worth of the digital coin that was stolen from his storage wallets on New Year's Eve. From a report: Luke Dashjr is a developer of the Bitcoin Core, an app that runs 97 percent of the nodes making up the bitcoin blockchain. Bitcoin Core derives from the software developed by the anonymous bitcoin inventor who uses the pseudonym Satoshi Nakamoto. That software was called simply Bitcoin but was later changed to Bitcoin Core to distinguish it from the coin. Dashjr has been contributing to the Bitcoin Core since 2011 and has long championed the concept of decentralization that the cryptocurrency was founded on.
On New Year's Day, Dashjr took to Twitter to report that his entire bitcoin holdings -- worth roughly $3.6 million -- were "basically all gone." He said the hack stemmed from the compromise of a PGP (Pretty Good Privacy) key that he used to ensure that his downloads of Bitcoin Core and a smaller app known as Bitcoin Knots weren't laced with malware. He said all his computers were compromised and urged people to hold off downloading new versions for the time being. "So to be clear: DO NOT DOWNLOAD BITCOIN KNOTS AND TRUST IT UNTIL THIS IS RESOLVED," he wrote. "If you already did in the last few months, consider shutting that system down for now." In the same thread, the developer said he had contacted the FBI and police but hadn't received a response. "What the heck @FBI @ic3. Why can't I reach anyone???" he wrote. "I paid those taxes and the police don't care. What a scam."
On New Year's Day, Dashjr took to Twitter to report that his entire bitcoin holdings -- worth roughly $3.6 million -- were "basically all gone." He said the hack stemmed from the compromise of a PGP (Pretty Good Privacy) key that he used to ensure that his downloads of Bitcoin Core and a smaller app known as Bitcoin Knots weren't laced with malware. He said all his computers were compromised and urged people to hold off downloading new versions for the time being. "So to be clear: DO NOT DOWNLOAD BITCOIN KNOTS AND TRUST IT UNTIL THIS IS RESOLVED," he wrote. "If you already did in the last few months, consider shutting that system down for now." In the same thread, the developer said he had contacted the FBI and police but hadn't received a response. "What the heck @FBI @ic3. Why can't I reach anyone???" he wrote. "I paid those taxes and the police don't care. What a scam."
Wow (Score:5, Insightful)
Re: (Score:3)
Re:Wow (Score:4, Informative)
There are plenty that understand and can track down those folks. But they're not the ones you deal with upfront. It's no different than calling the general IT Helpdesk with a super complex issue. The guy answering the phone isn't going to be able to solve or understand it, but that doesn't mean there aren't people within the organization that do.
Re: Wow (Score:4, Insightful)
Every single time I see anyone who is/was a "champion of decentralization" losing their shit because their stuff was stolen my sides hurt from laughing.
Weird how having no governing body was the bees knees when it was to your advantage, but the nanosecond you have to pay an actual cost for that? "Help! Help! AUTHORITIES that I rejected I need you now, I've been wronged!!"
Please. Go fix the problem you created on your own, isn't that what this whole bullshit was about in the first place? Gtfoh, you didn't want any "centralized" anything with your currency, so deal with the consequences of that decision like an adult as opposed to a toddler who just had their candy taken by a bully.
Re: Wow (Score:5, Insightful)
I can't speak for this particular developer... but it's absolutely possible to support the concept that a nation should uphold people's basic rights and freedoms while still believing there are real benefits to a decentralized currency.
If I'm paying taxes as a U.S. citizen? I *do* expect that covers law enforcement actually investigating crimes committed against me -- even if what's stolen isn't central currency!
The core problem needing fixing sounds like it may be something related to PGP, if it had a flaw in it allowing his private key to be compromised? But not sure what the details are there?
But crypto worth millions that's hacked and stolen from you should be taken seriously as a crime ... yes.
Re: (Score:2)
The core problem needing fixing sounds like it may be something related to PGP, if it had a flaw in it allowing his private key to be compromised?
It seems pretty clear that his computer was compromised and not PGP itself. In a sense that's a flaw with default PGP - it should be using dedicated hardware and not just a general computer - but that's pretty much the design, the reason that people use PGP in the first place and the reason some people use hardware protection with PGP. If someone is monitoring your computer when you use PGP then they get the chance to see your keystrokes and can decrypt your key just as well as you can.
The cold wallet is in
Re: (Score:2)
Re: (Score:1)
The keyword is gain. Mining bitcoin is only taxable when you convert it to another crypto/currency.
Re: (Score:1)
The keyword is gain. Mining bitcoin is only taxable when you convert it to another crypto/currency.
So he didn't convert it, so it was of no real value, so what's he whining about again?
Re: (Score:2)
Re: Wow (Score:2)
Re: (Score:2)
This is not a case of a hobo, who's shoes were stolen by another hobo. I, for one, would expect the FBI to react to a case like "theft of assets worth 3 million or more".
Can they recover my stolen cocaine too? (Score:1)
I can't speak for this particular developer... but it's absolutely possible to support the concept that a nation should uphold people's basic rights and freedoms while still believing there are real benefits to a decentralized currency.
If I'm paying taxes as a U.S. citizen? I *do* expect that covers law enforcement actually investigating crimes committed against me -- even if what's stolen isn't central currency!
The core problem needing fixing sounds like it may be something related to PGP, if it had a flaw in it allowing his private key to be compromised? But not sure what the details are there?
But crypto worth millions that's hacked and stolen from you should be taken seriously as a crime ... yes.
If he paid proper taxes on EVERY CENT of money he earned, then yes, I'd agree with you, but I am not aware of a single usecase for cryptocurrency beyond circumventing laws. It has enabled cybercriminals, ransomware, pig butchering scams, drug transactions, spam and botfarms, money-laundering, and tax evasion....and it has provided no benefit in exchange, TMK. Even if this individual didn't engage in crimes, his career is focused on enabling criminal activity. I suppose, in theory, a crime is a crime, but
Re: (Score:2)
You know, I guess that depends on one's viewpoint?
I'd say that while no, I wouldn't expect govt. to pursue theft of a drug like cocaine they've declared "illegal"? It should absolutely investigate marijuana theft if we wind up decriminalizing it at the Federal level in the U.S.
Since Bitcoin and other crypto-currencies aren't illegal to possess, they're not equivalent to cocaine at all!
Who really pays "proper taxes on EVERY CENT" they earn? Ever have a garage sale? Did you report all of those earnings? Ever
Bitcoin is the crack pipe (Score:3)
Since Bitcoin and other crypto-currencies aren't illegal to possess, they're not equivalent to cocaine at all!
Fair point, they're more like drug paraphernalia than the illegal drugs. So his collection of crack pipes was stolen? Theft is theft, but this guy's main purpose in life is to build technology that has provided benefit to criminals and few others...unless you could people profiting off hype bubbles. He is entitled to some support, but given that law enforcement has limited resources...perhaps focus on people more deserving?
No ... as far as I'm concerned, government is far too expansive as it is, and spends MOST of what it demands from me in taxes just to cover its own interest of the deficit it's run up trying to do more than it can afford to do! Next is probably expenditures on perpetual wars.
No shit. Want to know why?...because not enough people pay taxes. They tax every
"perhaps focus on people more deserving?" (Score:2)
Do we really want to start descending into that particular rabbit hole? Triaging investigative priorities on the basis of your evaluation of the victims and their contributions to society?
What if the police decide not to investigate the theft of your SUV because they think you're fucking up the environment with it?
Re: (Score:2)
Do we really want to start descending into that particular rabbit hole? Triaging investigative priorities on the basis of your evaluation of the victims and their contributions to society?
The question isn't whether we should investigate the tax returns of the wealthy because they are good or bad or make good contributions or bad contributions to society. The question is why the wealthy for the most part are not held to account, while the less wealthy are held to account, REGARDLESS of their respective contributions to society.
The answer is because the wealthy can afford to pay specialists to either arrange their affairs to be opaque to the tax authorities, or they can afford to pay other sp
Re: (Score:2)
The law and law enforcement are concerned with what's legal. Bitcoin is legal, and according to the IRS, property. Therefore, regardless of the questionable uses (or lack thereof) of Bitcoin, or who is or isn't paying taxes, it is appropriate to investigate it
To continue with analogies, if somebody breaks into your house, should my first act as enforcement be to check to make sure your property taxes are paid in full?
Re: "perhaps focus on people more deserving?" (Score:1)
no rabbit hole, uninsured gambling tokens were lost. sucks to be that loser. FBI has thefts of money to look into
Re: (Score:2)
According to the IRS, property was stolen.
https://www.irs.gov/businesses... [irs.gov].
Re: (Score:2)
Re: (Score:2)
If I'm paying taxes as a U.S. citizen? I *do* expect that covers law enforcement actually investigating crimes committed against me -- even if what's stolen isn't central currency!
No issues with this, but the real question is whether you get to set priorities for law enforcement just because you pay taxes....
He reported it less than a week ago. That report is going to be in a queue now. Why does he think he deserves an instant response?
Re: (Score:1)
I can't speak for this particular developer... but it's absolutely possible to support the concept that a nation should uphold people's basic rights and freedoms while still believing there are real benefits to a decentralized currency.
You said that exactly right: "believing". As opposed to "knowing". People are willing to believe all sorts of crap. Many even believe their beliefs are knowledge. Actually knowing is much harder.
Re: (Score:2)
Bitcoin is not a "decentralized currency." It is not a currency. End of story.
Nothing of real value was lost.
Re: (Score:2)
One of the major attractions of crypto is that you don't pay tax on it. I wonder how much of his income from bitcoin he reported to the IRS.
Re: Wow (Score:5, Insightful)
Decentralization is not a problem, it's a compromise which mitigates some risks while replacing them with new ones.
With a centralized system you can lose everything at the whim of whoever is in control of the system, or in the event of a failure of the system.
With a decentralized system you can lose everything irretrievably if you screw up and lose possession of your keys.
Decentralized systems have existed longer than centralized systems. It's always been possible to hoard gold and keep it hidden in the back of your cave, and it's always been possible for a hostile party to turn up, hit you over the head with a club and steal your gold.
Both systems have known risks, both systems have ways in which you can be vigilant to reduce the chances of these catastrophes happening.
Which is worse? that's going to depend on your personal circumstances and preferences, but neither is inherently bad.
Re: (Score:1)
Decentralization is not a problem
It's a solution looking for a problem.
Re: (Score:2)
Re: (Score:3)
No, seriously: what are the problems of centralized trust, compared against decentralized trust.
With centralized trust, your trust is in ONE entity, and that entity can certainly fuck you over on a whim (after all, you TRUST them), but they also can FIX problems after they happen, because they are trusted to do so. They have the authority to make corrections...like returning 3.6 mil in stolen moneys.
Centralized trust allows for massive efficiencies in processing compared to decentralized.
With decentralized
Re: (Score:2)
The key point is that you have to trust the central entity, there are only a limited number of such entities and it's very hard to set up a new one yourself. You have no insight into how the organisation works, so it's largely unknown.
A good example of this is Swift which recently kicked out Russia.
With a decentralized system yes you do have to trust the system, but the inner workings of the system are well known so you can make an informed decision on the level of risk. When it comes to individual members
Re: Wow (Score:1)
wrong. you only pay if you have a buyer when you sell. Holding cryptocooin, buying and creating are tax free.
Uninsured gambling tokens get no respect when lost.
Re: (Score:3)
good luck finding somebody in law enforcement who even understands what actually happened and how specifically to track down the perpetrators.
You'd probably need a log of the entire Internet to find them anyway.
Besides, a "champion of decentralization" calling on the centrals to help him when his money got stolen is just too hilarious...
I wonder if the IRS is aware of those millions? He's liable for tax even if it was stolen from him. :-)
Re: (Score:2)
Theft is counted as a loss for tax purposes assuming it's properly accounted for (ie you report the theft to the police), if it was all stolen then your loss would cancel out your gain and no tax would be due.
Re: (Score:2)
Re: (Score:2)
Me? I find it hard to believe a champion of decentralization was faithfully reporting all his holdings and earnings to the IRS.
Re: (Score:2)
You really should read the second paragraph. This is like saying that wealthy people can’t be robbed.
Re: Wow (Score:1)
wealthy people have assets, not gambling tokens that only have value if sold for money
Re: (Score:2)
Re: (Score:3)
Different skillsets?
We can assume this guy understands cryptography, crypto currency and programming in whatever language bitcoin core is written in.
But does he have a strong handle on configuring and hardening the platforms he uses? Does he have good security awareness around phishing and other social engineering attacks? Even if he does have a strong understanding of such areas, is he vigilant or has he become lazy/complacent over time?
These are completely different skillsets, it's quite possible to be go
Re: (Score:2)
Re: (Score:2)
Re: (Score:2)
Re: (Score:2, Informative)
That said there's something fishy about the whole thing. He claims to have had cold wallets compromised and that shouldn't be possible. Cold means not connected to the internet.
It's possible this is some bizarre scheme like insurance fraud or something. But if it is that's not any better because it means someone who's a key developer for Bitcoin commits casual fraud. Also that he's stupid enough to think he
Re: (Score:2)
Wrong, it shows how strong it is.
Even Bitcoin's own devs can't just edit a server to force money to move.
Most important thing is to not keep all your eggs in one basket. my modest crypto is split between 3 different types of wallet, so no one failure can fuck me over.
Re: (Score:2)
Most important thing is to not keep all your eggs in one basket. my modest crypto is split between 3 different types of wallet, so no one failure can fuck me over.
So you can (probably) only be robbed of a third of your eggs at once? Most would still say they got "fucked over" if a third of their bank account balance disappeared with absolutely no way to get it back.
Re: (Score:1)
So if a key developer of crypto can be hacked what does that say about all the people who have no idea what is under the hood?
Exactly this. Also, if the key people are incompetent, what does that say about their product? This whole cypto-"currency" thing is an unmitigated train-wreck of arrogance, stupidity, incompetence and greed.
Re: Wow (Score:2)
So his stuff was on some cloud server. How hard would it be for an sysadmin at the hosting service to do, well whatever he wanted. Or a compromised sysadmin account
Re: Wow (Score:2)
To be fair, that's almost certainly what made him a target. It doesn't like the typical type of hack many fall for. It sounds targeted.
Re: (Score:2)
Re: (Score:2)
Don't confuse "crypto" [cryptocurrency] with "security", or even "encryption". The guy could be actually clueless but suffer from an acute case of Dunning-Kruger because he's a "crypto genius".
That dude is crazy (Score:5, Informative)
This "bitcoin dev" is a real nutjob. Among other things, he's a hardcore religious nut that thinks slavery was "employment" and abortion should be a crime punishable by execution. He has a sordid history of crazy tweets.
https://reddit.com/r/Buttcoin/... [reddit.com]
Re: (Score:2)
Re:That dude is crazy (Score:5, Funny)
It's called Google. You go to www.google.com and you will see a place to type with two buttons under it. Type in the person's first and last name then click the button on the left, it's labelled "Google Search".
Re:That dude is crazy (Score:5, Funny)
Re: (Score:2)
Re: (Score:2)
Because no two people can be named the same thing. And people can't take on persona's to vilify someone or appear different online than they are in person.
So that's not his Twitter account that we're all getting this news from?
Re: (Score:2, Insightful)
There is no hate like christian love. He’s an example of a typical MAGA voter.
Re: (Score:3)
Re: (Score:3)
There is real evil in this world and these fuckups are part of it. Of course anybody that takes anything meaningful literally cannot be very smart. These are not evil masterminds, they are more like Satan's little helpers. Funny how they have become what they fear most and did not even notice.
Re: (Score:2)
Re: (Score:2)
Do you have some reading dysfunctionality? I was _very_ _obviosuly_ answering to the post right above mine.
Re: (Score:1)
That's rich (Score:2)
he had contacted the FBI and police but hadn't received a response. "What the heck @FBI @ic3. Why can't I reach anyone???" he wrote. "I paid those taxes and the police don't care. What a scam."
"What a scam" eh...
The fuzz probably it was just as important to help the Bitcoin dude as it was helping little Timmy recover his stolen Monopoly money - because that's what Bitcoin really is. Either that or they thought he was yet another crypto scammer himself and they decided to let him stew in his own sauce.
Re:That's rich (Score:5, Insightful)
"The government sucks! I'm so done with their bullshit!"
> Create a new "currency" specifically to do an end-run around government control and taxes
> Things go predictably wrong
"Why won't the government help me?!"
=Smidge=
This crypto thing is going great! (Score:5, Funny)
I feel for him (Score:3, Insightful)
Re: (Score:2)
Cryptocurrency is just like invisible Beenie Babies.
Fool's Errand (Score:1)
So, I can create something in code (which has no real value basis) intended to undermine the US tax system, expose it to the internet, fail to adequately protect it, and then complain that the police/Feds won't help me when it's stolen? Nah, I don't think so.
Another idiot (Score:2)
Re: (Score:2)
Indeed. And that regulation for financial service providers was only established after everything else failed to work.
Plot twist! (Score:1, Funny)
FBI stole it.
I hope he gets a visit from the IRS. (Score:1)
Re: (Score:2)
You pretty much have to pay taxes unless you deposit money in the monthly $9000 Tony Soprano style. If your bank sees a large enough deposit they alert the IRS.
Re: I hope he gets a visit from the IRS. (Score:2)
Re: (Score:2)
Indeed. Before computers, keeping deposits below that threshold could have worked. At this time, banks have special rules that automatically detect multiple deposits somewhat under the threshold and report them with a higher priority.
Re: (Score:2)
The silver lining in this cloud is that now he doesn't have to pay any tax on that 3.6 million anymore!
Ie, if it was bitcoin and left in bitcoin then there was $0 realized income. Now if he sold all that bitcoin and got dollars, then spent all those dollars to buy the same bitcoin back, then he'd owe some taxes; possibly he could spend then next 53 years with loss carryovers...
Re: (Score:1)
All of his coins were mined from the early days. None of it was money he transferred in.
So his actual loss was... the power bill for the mining?
Whodunnit? (Score:1)
Hardware Wallet? (Score:2)
You'd think by now experienced or advanced crypto folks would only be using a hardware wallet. Virtual wallets are primed for picking...
Irony (Score:5, Insightful)
Bitcoin folks: Decentralize finance! Get the government taxation out of my wallet!!
Also Bitcoin folks: Ahhh! Someone scammed our decentralized system! Quick! Call the centralized law enforcement agency funded by centralized taxation and tell them to get my coins back!
This guy's just trying to "bleed the beast"-- standard anti-government stuff.
1. Demand every possible form of government service and funding
2. Refuse to fund the government
3. Show that the government is crap and should be eliminated
Re: (Score:2)
> Bitcoin folks: Decentralize finance!
Core has been pushing recentralization of Bitcoin since at least 2015. Luke loves small blocks so much he suggested reducing the block size.
Force everybody off-chain and into routing nodes that would hold their money custodially and be subject to regulation.
Maybe you're thinking of the Bitcoin Cash chain - the OG's who continued Satoshi's chain-of-keys blockchain. Many of them are anarchists.
Core has been largely funded by Blockstream which was funded by AXA, the C
Re: (Score:1)
All My Apes (Score:2)
Re: (Score:1)
Ah yes... (Score:2)
It do be like that tho... [imgur.com]
WTF? (Score:2)
I used to mine Bitcoin until I decided to "cash out", retire from work, buy myself a Model X and a nice house.
Back then I kept the private keys for my wallet on a separate, airgapped machine. I bought, wiped and reinstalled a cheap netbook for this purpose. It was never connected to any network. When not in use, it was kept in a safe. The passphrase required to decrypt the keys on this machine and allow a transactions to be signed was kept in my head and nowhere else.
How can it be that anybody with a good u
the bigger story than the lack of sympathy (Score:2)
Predictably, a lot of comments show little sympathy for said dev. However...
Funny (Score:2)
Compromised in November? Huh? (Score:2)
Re: (Score:2)
stick a fork in it (Score:3)
Sounds like a good time to stick a fork in it and rewrite the chain starting just before the theft.
"all gone" ? "PGP"? (Score:1)
I suppose people still use PGP these days, tho' I haven't seen much of it (minus one bank that used their commercial product). GPG?
And "all gone"? How about some details? How does ones PGP key "get compromised"? Weak key? Weak passphrase? Keylogger?
Isn't this blockchain thingy supposed to show transfers?
We need some deets.
Please stop reporting bitcoin values in dollar! (Score:2)
I really don't see the point in reporting the value of these bitcoin in $$ when the value fluctuates so much. I mean, I get you want to communicate the general value of the coins to the average reader, but seriously, at this point everyone knows that next week's value will either be $3k or $1.2B.
I've long had a belief that crypto (of any flavor) can't be a "rEaL" currency until prices are natively set in that coin.
Wonder how his PGP key got haxxed... (Score:2)
There was talk about 2048 bit keys being able to be factored using quantum computing, but I wonder how the key got compromised:
* Was it just tossed in ~/.gnupg where anyone who got some access to the machine with his user context could fetch his key from that?
* Was it stored in a HSM, even something like a YubiKey, where it was stolen, decapped, and the key read out?
This is something for people to consider. If their cryptographic certs are valuable, like their gpg key, their wallet, and such... use a HSM
Re: (Score:2)
Not factored. To factor 2048 bits using a QC, you need one with about 6000 effective (!) Qbits that can do a long and complex calculation. The current record is somewhere about 50..100 effective Qbits (IBM with 400 Qbits before error correction, they do not say how many effective Qbits those are though.) and these are unsuitable for long or complex calculations.
This guy probably just did several stupid things.
Re: (Score:2)
Re: (Score:2)
The only way for Joe Sixpack to be able to keep crypto secure is if some mainstream place... not an exchange, as one's holdings can gox [sic] in an instant... but a bank financed R&D for some security device on par with a Trezor Model T... but a lot more resistant to stuff. Even then, there is the issue of recovery, and Joe Sixpack doesn't really care about storing a BIP-39 backup of his keys.
Best way for Joe Sixpack to "win" this game, is not to play at all.
Boating Accident (Score:3)
I've been in Bitcoin for a decade, the bad guys hacked my computers, and they stole my TOTAL worth: $3.6M. Damn then!
It's ALL gone.
OH NO.
ALL of it.
Definitely all of it.
Everytime I see crypto stolen I get suspicious (Score:2)
The dismantling of cryptocurrency myths in real li (Score:2)
I remember the good old days when crypto was super duper guaranteed to be the second coming of deity and any criticism can only come from clueless haters.
A decade of practical real life and human greed later, and turns out it is neither really all that decentralized, nor really fully anonymous and untraceable nor all that secure, it is however a gigantic waste of resources - and I still can not widely pay for a pizza or a beer with it.
In fact, with the insane value rollercoaster in the last few years, I wou