The World Is Watching: Can WannaCry’s Creators Cash Out Their Bitcoin Ransom?

Nah, they are not unskilled.
They are just trying to promote bitcoin.
They have succeeded now that the whole world notice!
Now that these bitcoins are stuck there is less in circulation.
No wonder the bitcoin price shoots up close to breaking the $2000 barrier!
Hahaha…

The World Is Watching: Can WannaCry’s Creators Cash Out Their Bitcoin Ransom?

The hackers behind the infamous WannaCry ransomware have had a lucrative week. So far, they have racked up almost $80,000 in bitcoins. But their next step may be more difficult – they still have to figure out how to move that money, without giving themselves away to authorities.

The well-publicized cyber-attack, which began in Asia, has locked up hundreds of thousands of computers in more than 150 countries. Once a computer gets infected, a tab pops up demanding a $300 payment in bitcoin to unfreeze the data.

Shockingly, despite no clear evidence that anyone who pays the ransom actually receives the promised decryption keys to unlock their encrypted files, some people have been putting up the funds, sending their bitcoin off to one of the hacker’s three bitcoin wallet addresses.

But now, with the world’s cybercrime teams watching those bitcoin addresses, the question is: Will the hackers be able to launder that money and spend it? Or, is the money tainted, traceable, and therefore worthless to the thieves?

Follow the coins

Originally bitcoin was touted as an anonymous payment vehicle. But over the years it has become clear that bitcoin is pseudonymous rather than truly anonymous.

Bitcoin addresses, payments and transactions are all visible on the blockchain. And by analyzing transaction patterns, it is possible to trace money and find the actual parties behind the public keys – strings of numbers bitcoin uses to identify its participants.

As WannaCry is the most widespread bitcoin ransomware attack in history, the criminals behind it have garnered a lot of attention. So, if they want to actually spend their funds, they will have to find a clever way to remove all links from the original bitcoin addresses.

As of right now, though, the bitcoins are still sitting untouched, and the trail is cold.

Hiding their tracks

So what are the options for the bad actor(s) behind the ransomware attack?

Laundering bitcoin is a little different from laundering fiat money, but is just a matter of applying the right tools, according to Emin Gün Sirer, a professor at Cornell University. According to him, technologies already exist for shedding so called ‘tainted’ bitcoins – they just require a little technical know-how.

One of the simplest processes is ‘chain hopping’, where bitcoins are converted into other digital currencies, usually at offshore exchanges. “Following the trail gets quite difficult as the coins cross jurisdictions and change shape,” Sirer told CoinDesk.

Another technique known as ‘tumbling’ would allow the hackers to pool their ill-begotten bitcoins with other people’s coins.

In a bitcoin tumbling service, coins from different sources are mixed together and then re-disbursed. Conceivably, the hackers could repeatedly mix their coins until the coins were diluted enough to throw law officials off their path.

But Ethan Heilman, the Boston University researcher behind TumbleBit, a proposed bitcoin tumbler, indicated that mixing bitcoin is risky business, especially when dealing with larger sums of money. As he pointed out, one of the problems the hackers may run into is finding a large enough number of bitcoins to adequately mix with.

“Even if they mix the coins such that they will be hard to follow, if the WannaCry hackers make a mistake and join the coins back together, those coins could become vulnerable to clustering and other blockchain analysis techniques,” he said.

Further, it is unclear how effective most mixers actually are, Heilman added.

Newbie mistakes?

Notably, the fact that the hackers used only three bitcoin addresses to collect their money suggests they don’t know much about bitcoin privacy. Had they used a unique bitcoin address for each computer WannaCry infected, the money would have been a lot more difficult to trace.

In a LinkedIn post, Neil Walsh, the UN’s head of global cybercrime, pointed to that and other shortcomings in the ransomware to suggest the hackers are likely in over their heads.

He wrote:

“We estimate that the attackers are relatively unskilled, and are probably unprepared for the impact their malware turned out to have. It is quite possible that they are unsure how to launder the bitcoin funds safely.”

However, as Sirer pointed out, hacking is a rich, stratified ecosystem, and the people who put together the exploit may now be looking for an expert at laundering coins. Or, they may simply be biding their time before attempting to retrieve the funds.

He concluded:

“The authorities are revved up right now, and time will help dilute their focus. The hackers can probably afford to wait, potentially for a long time.”

Read More : Coindesk.com, By Amy Castor, The World Is Watching: Can WannaCry’s Creators Cash Out Their Bitcoin Ransom?

Share this article

Leave a comment

Related Posts

卖光家产投资比特币 一家人环游大马等四十国

比特币大使一家在2014年就開始用比特幣環遊世界了,只是沒有被報導出來而已。 浏览:𝕐𝕠𝕦𝕋𝕦𝕓𝕖: 𝔹𝕚𝕥𝕔𝕠𝕚𝕟 𝕎𝕠𝕣𝕝𝕕 𝕋𝕠𝕦𝕣𝕨𝕨𝕨.𝔹𝕚𝕥𝕔𝕠𝕚𝕟𝕎𝕠𝕣𝕝𝕕𝕋𝕠𝕦𝕣.𝕠𝕣𝕘#𝔹𝕚𝕥𝕔𝕠𝕚𝕟𝕎𝕠𝕣𝕝𝕕𝕋𝕠𝕦𝕣 卖光家产投资比特币 一家人环游大马等四十国 虚拟货币盛行,荷兰就有一个五口家庭,在2017年时几乎变卖所有家产,包括房产、汽车、退休帐户等,把钱全部投入在比特币上,他们也因此被称为「比特币家族(Bitcoin Family)」。如今随着比特币水涨船高,一家人已经环游世界40个国家。 综合外电报导,泰胡图(Didi Taihuttu)和妻子育有3个小孩,他2017年时将自己的家产套现,包括房产、汽车、退休帐户、衣服、玩具等,并将所有金钱押注在波动性极大的比特币上,当时比特币的价格是900美元(约3636令吉)。 4年期间一家人仅靠比特币,便游历了40个国家及地区。他们表示,不会与不使用比特币的人交易。不过有时为了过日子,他们要通过以物易物、讨价还价,比特币扣帐卡进行交易,甚至要说服卖家接受加密货币等。 泰胡图一家发现,地球上有2个地方可以用比特币交易几乎所有东西,一个是斯洛文尼亚首都卢布尔雅那(Ljubljana)和一个义大利小村庄罗韦雷托(Rovereto)。在卢布尔雅那,他们用比特币支付汽车维修费用和电影戏票;在罗韦雷托,则购买摩托车、缴税和理发。 比特币在2017年时曾一度暴涨逼近2万美元,但2018年暴跌至3100美元,不过在比特币暴跌之际,泰胡图反而大手笔买进。本月上旬比特币价格再度逼近2万美元历史高位,泰胡图指自己仍然不断买入比特币,投资额已比当年再多增一倍,「如果比特币在2022年能达到20万美元,我也不觉得惊讶。」 实际上,有分析师表示,比特币确实还有很大的上涨空间。投资公司Galaxy Digital行政总裁麦克(Mike Novogratz)认为,「这次比特币的反弹才刚开始,并预计到明年将升至6万美元。」 摘自: http://news.seehua.com/?p=640313&fbclid=IwAR0LqkVZWGUJ_dj6wtJG6O14FPqNEMTPJDITjBwztY7WspdqA5e7Uacr5qY

20 Dec 2020