I love money laundering as much as the next guy (#1560586) — we talked about this a lot in the spring after I'd read Oliver Bullough's book, nay, infantile crusade against money laundering (#1453638).
Also after the first skirmishes of the token wars (= coldcard heist), I noted that for Bitcoin to truly truly win — and be a permissionless, unstoppable outside money for the world — these hackers have to be able to turn their bitcoin spoils into real goods and services without detection or getting caught #1540824, #1540813
"For bitcoin to win, truly, you kind of want these attackers to succeed. Money that can’t be stopped and can’t be traced, can’t be in any way clawed back or thwarted. (I refer you to the 'Unstoppable' entry in your closest dictionary.)"
but because if permissionless freedom money can’t be turned into real goods and services, somewhere and at some point, it isn’t truly global freedom money. It’s just another system of permissioned and surveilled control.
Yet another round of hacks/heists (#1564335) prompted the natural question:
How much bitcoin can be safely laundered?
Are we too small/the offramps and swap tricks too low liquidity to actually and meaningfully avoid detection and realize the ultimate test of a bearer-asset money?
(Juan: "ah yes ecash. big bad volume")
What say the stackers?
True, bearer-asset freedom money or surveilled control?
No.
So many ppl in BTC get this wrong, if BTC was untraceable like Monero it could never become a world reserve currency. Money laundering is one of the best ways governments catch criminals, and society will not accept a world without that power.
Even if 'the people' were able to entirely circumvent the government into making an untraceable currency like Monero the world reserve currency, I think that would make crime too easy and would not be a stable equilibrium. The right answer is always a balance, and you want some AML capacity built into money.
The difference between BTC and fiat or CBDCs is that the latter are way too easy to scale surveillance for, it can easily become mass surveillance of everyone. With BTC you have to put in a lot of targeted effort, so it's not scalable to the masses, and is only practical for targeted cases, which is exactly the balance you want.
In a world where BTC is widely accepted as payment, another key difference is that the government would have to go through the court of law to freeze money, unlike the fiat system where they can just command banks to do it extralegally.
Also there would be no single jurisdictional monopoly on which UTXOs can be spent bc you say there are some sanctioned addresses in the US, you could just go abroad and spend.
Finally, if there is some government mass oppression event the public can resist by organizing massive coinjoins to the point where it doesn't make sense to sanction the entire coinjoined group, and traceability is severely damaged.
What's stopping him from opening a bunch of lightning channels?
Complexity, counterparty risk, dragnet inevitability.
I meant the question as more of a hypothetical: i.e. Can he open a bunch of lightning channels and would that make spending easier?
Is that how you meant your answer?
I take the aggregation point: total Lightning capacity is what, 4,000 BTC... kind of hard to just double that
What's the rush?
What I'm wondering is just whether this is a viable way to use or move the loot.
patience is a crazy important virtue for a scammer like this. UTXOs strictly watched right now; everyone will have forgotten about it/moved on in 10 years.
Sit on it, single-sig, don't fucking touch for a decade etc. Wait for the world to catch up (such that 600 or 4000 BTC while a great sum, wouldn't be unheard of -- large funds transacting, Middle Eastern sov funds making txs etc)
huh? It's literally 1 row in a database over at chainalysis. No one will forget. Wait 10 years get caught in 10 years.
...and then someone deletes the spreadsheet; Chainalysis gets bought up by Google, archives get lost in a restructuring; new hacks turn everyone's attention that way; Congress passes some law and they scrap monitoring of old addresses now presumed lost; some new Bitcoin tech obfuscation technique rises to the top (e.g., like Samourai/Whirlpool a few years back).
Ten years is loooong in Bitcoin times. Lots can happen
I gave supratic a one-liner this morning to see if it moves
Thus, on your raspi with core you can do
bitcoin-cli scantxoutset start '["addr(bc1ql4mfu6aundtkksxklfajs2h3t9nzcd6gyqjlte)"]' \ | jq '.total_amount | floor' \ | xargs echo "0 == 598 - " \ | bcand then evaluate that; if it returns
1it means it didn't move and if it is0it means it moved.Now you put that into a crontab, bake an
if [[ $outcome -eq 0 ]]; then send_me_email.sh; fiaround it and you too are now a $50 cost-basis superspy worth gazillions, just like chainalysis.Yes. Its too small to do it quickly and with each new channel open/close the loop will tighten
What loop is tightening?
As in if you're a thief and I'm the popo, with every move you make I will learn more about you and eventually I will catch you. And you're going to have to make a lot of moves if you're going to exit through LN. Thousands.
please elaborate. Also, what's "dragnet inevitability..."?
The fact that you need an addressable node so eventually you'll be traced by LE.
no problem, sir... we can just reach out to MRBOND_1. He seems trustworthy
lol
That's what I thought you meant, but a node can be anywhere, including places without LE that would care about this.
There are no places without LE. Name one.
I didn't say there were
You didn't, but if there is LE, they can be made to care. With a 4k BTC target on your back, anyone can be made to care. There is no reason anyone in LE wouldn't care about you.
Your IP address is traceable. Your tor key is mappable to your IP address by multiple agencies worldwide (that's the dragnet.) It literally takes a phone call and a credit promise. "We'll do a joint press release".
Thus anything that needs to be addressable will per definition get caught if there's any pattern. And since the list of nodes with proper outbound liquidity is not infinite at all, you're going to run into issues avoiding patterns.
Better just call one of the known scammers in our midsts if they'd like to have 4k BTC at 95% discount. You'll be rid of your burden in no time. And still never have to work again. All thanks to kimi.
the nature of the timechain makes it always traceable once you try to convert sats into goods/services.
it's only "untraceable" if there is no point in tracing it (amount too small) or if the cost of tracing it is too large/time-consuming.
but privacy and untraceability are not the key point of bitcoin. the entire point of bitcoin is to have an asset that is absolutely scarce and auditable to prevent fractional reserve banking, and to give people peer to peer electronic cash to transact on the internet. the pseudonymity helps give regular users a little bit of privacy, but it cannot give thieves the absolute untraceability they want.
don't you think that's at least a little contradictory? If thieves can't get untraceability, we regular users aren't getting enough privacy/security either.
Yes but there is a difference between the value. 4K bitcoins is a lot of value so it’s worth spending significant money/resources on tracing it while tracking a regular user with say 0.5bitcoin is not worth doing.
yep but tbh 0.5 btc is still a lot of money lol
privacy and security are two very different things. you may know those coins belong to me but you can't get it from me without my permission. bitcoin may be traceable but is also unconfiscateable.
and even if i happen to be a coldcard user, you might steal it from me but also know that i will be able to track where you are moving those coins and eventually i will find you.
so i can argue that traceability is actually a security feature.
This post was downzapped 6883 sats as of now.
That's cute. Who's boosting it back up??
It would be so complex to launder 4000 bitcoin, people will be tracking this with a microscope!
Wouldn’t it be possible to do this by exchanging that money for other cryptocurrencies and covering one’s tracks? Monero, perhaps? Or wouldn’t it be possible to cover one’s tracks by using CoinJoin as well??
No that's the worst plan. Is how the bitfinex hack dude and his gf got caught.
in #879654, it sounded like a good idea
I think your biggest enemy against any observer, passive or active, is still the
"Shapeshift heuristic". And if you're a true criminal, I think that active subpoenaing and raiding of insecure services that cannot be coerced into cooperation, will truly make this difficult.Not to mention complexity but that could in theory be overcome with really good software.
I'm always surprised thieves dont go partial robinhood.
The resulting chaos of suspicion, false leads, twitter drama etc hopefully creates enough smoke for you to hide in.
When they give away 10% from the 80,000 addresses, they indicate that those 80,000 addresses are theirs because they behave the same and differently from the others.
this sounds like insane amounts of fun. (and FUD!)
I wanna see it
It seems that one of the CC hackers thinks they can launder 97 BTC using coinjoins and swapping to thorchain and eth.
#1564480
we shall see.
We'll know if/when they get caught. But it'll just be crickets if they're successful, no?
perhaps the first hurdle is whether the internet sleuths can track it. if they all lose track of it, we still won't know about how close LE is getting until/if they do catch the person.
LE likes getting tips on this. So all you need is 1 sleuth, 1 X post, 1 reproduction of the proof, and 1 email. And that ball rolls.
Anyone willing to take a 50% paycut on the stack will be able to find someone to launder it.
that's usually the point with fiat money laundering, too. Very easy to offload if you're willing to share the spoils
Looking through the comments 6 hours after you posted this, there seems to be a feeling that no, the holder of these stolen won't bitcoin won't be able to avoid detection.
Rather than implying that there is no such means, I suspect the people who actually have a good plan for how to avoid detection are not going to explicitly lay it out here.
But as far as a small-time, not-particularly-savvy person goes, it is going to be very, very difficult to move these coins.
Or maybe the jury really is out on whether you can move that much stolen bitcoin.
It will certainly be interesting to watch the Coldcard and Liquid coins.
indeed
I found the chainanalysis video I replied to in #879654 quite interesting. You can see where they hit roadblocks vs where they find leads.
I don't think the chain betrays the would-be launderers as much as their behavior. They're probably going to act like thugs once they get the cash and then the investigators come in and break em down like any other criminal. Maybe if they have a good story and discipline it can work. Like they were scuba diving and the most amazing thing floated down from the surface. 😁
Interesting thought experiment and indeed in order for Bitcoin be the permissionless asset that we desire, unscrupulous scammers should be able to get away with doing the wrong thing. But I feel approving such equality of treatment will lead us down the slippery slope. I mean, I wouldn’t want us to go back to the dark old days where Bitcoin was used for illicit and illegal items on the Silk Road
This was a degen
OP_RETURNin a tx to the attacker addressamazing...
V4V directly onchain.
The don't-spam-my-chain Knotzies must be KICKING THEMSELVES
https://twiiit.com/JuanSGalt/status/2097067341859184749
Bitcoin is the nuclear arms inspection treaty of money. As you approach state or institutional scale movement, its meant to be tracked.
The coldcard hacker probably has the most watched coin other than Satoshis, doubt that's ever getting out at scale. Attacker are for ed to live like a pleb and drip small amounts over a very long time.