{"id":21860,"date":"2022-02-12T18:38:28","date_gmt":"2022-02-12T18:38:28","guid":{"rendered":"https:\/\/davidgerard.co.uk\/blockchain\/?p=21860"},"modified":"2022-06-18T12:58:47","modified_gmt":"2022-06-18T12:58:47","slug":"could-morgan-and-lichtenstein-have-done-the-2016-bitfinex-hack-im-not-ruling-it-out","status":"publish","type":"post","link":"https:\/\/davidgerard.co.uk\/blockchain\/2022\/02\/12\/could-morgan-and-lichtenstein-have-done-the-2016-bitfinex-hack-im-not-ruling-it-out\/","title":{"rendered":"Could Morgan and Lichtenstein have done the 2016 Bitfinex hack? I\u2019m not ruling it out"},"content":{"rendered":"<p>New York crypto scenesters Ilya &#8220;Dutch&#8221; Lichtenstein and his wife Heather Morgan have been arrested for money laundering. They&#8217;re alleged to have tried to cash out the proceeds of the 2016 hack of the Bitfinex crypto exchange. [<a href=\"https:\/\/www.justice.gov\/opa\/pr\/two-arrested-alleged-conspiracy-launder-45-billion-stolen-cryptocurrency\"><i>Department of Justice<\/i><\/a>]<\/p>\n<p>This hack hit crypto like a bombshell. 120,000 BTC was stolen from customer addresses. Bitfinex gave <i>all<\/i> its customers \u2014 hacked or not \u2014 a 36% \u201chaircut.\u201d The exchange eventually made up the \u201chaircut\u201d with Bitfinex&#8217;s stablecoin Tether in mid-2017.<\/p>\n<p>This is also when the issuance of Tether started going through the roof \u2014 even as they had no banking. This launched the 2017 crypto bubble. I detail the process in <a href=\"https:\/\/davidgerard.co.uk\/blockchain\/book\/\"><i>Attack of the 50 Foot Blockchain<\/i>,<\/a> chapter 8.<\/p>\n<p>Lichtenstein and Morgan were charged with money laundering \u2014 but not with doing the hack itself.<\/p>\n<p>(I\u2019m not sure the US would even have jurisdiction for the hack itself. But the US most certainly has jurisdiction for the money laundering.)<\/p>\n<p>Lichtenstein and Morgan are absolutely standard crypto bros who think they\u2019re startup geniuses. They\u2019re loud, brash and nowhere near as smart as they think they are.<\/p>\n<p>But the Bitfinex hack reeks of social engineering for insider information, not sophisticated computer science brilliance. This is cryptocurrency \u2014 standards are low.<\/p>\n<p>Could Morgan have been that social engineer? I&#8217;m not ruling it out.<\/p>\n<h3>How the hack was done<\/h3>\n<p>In 2016, Bitfinex kept customers&#8217; bitcoins segregated \u2014 each customer&#8217;s holding was in its own separate multi-signature blockchain address.<\/p>\n<p>You needed two of the three keys to the address to move bitcoins out of it. One key was held by Bitfinex, one by BitGo, and one by the customer.<\/p>\n<p>BitGo had built an API for Bitfinex to use. This was not a public interface \u2014 only the two companies knew about it.<\/p>\n<p>Bitfinex would pass transactions to BitGo via the private API. BitGo checked the transaction against their policy for that address, and signed if it was OK.<\/p>\n<p>The API allowed policy changes \u2014 but a bug in the API meant you could set <i>global<\/i> limits, that applied to\u00a0<em>all<\/em> customer addresses, without it being flagged for human review.<\/p>\n<p>The hacker somehow got into Bitfinex\u2019s systems, got access to an account that could change global limits, set the limit very high &#8230; and drained 2000 customer addresses into a single address.<\/p>\n<p>This was how the hack was described to me by Phil Potter of Bitfinex\/Tether, when I spoke to him for <i>Attack.<\/i> Tether principals have been caught in many, many lies \u2014 see the <a href=\"https:\/\/davidgerard.co.uk\/blockchain\/2021\/02\/23\/new-york-settles-with-tether-a-wrist-slap-with-a-strong-leash\/\">New York<\/a> and <a href=\"https:\/\/davidgerard.co.uk\/blockchain\/2021\/10\/29\/the-cftc-settlement-with-tether-and-bitfinex-42-5-million-dollars-in-fines\/\">CFTC<\/a> settlements \u2014 so you may or may not want to take this with a grain of salt. However, Potter&#8217;s description largely matches the version I&#8217;d heard from others before this. [<a href=\"https:\/\/www.reddit.com\/r\/Buttcoin\/comments\/6gn4ej\/draft_explanation_of_the_bitfinex_hack_needs\/\"><em>Reddit<\/em><\/a>]<\/p>\n<p>The hacker had information you&#8217;d need to be a Bitfinex or BitGo insider to know:<\/p>\n<ul>\n<li aria-level=\"1\">that the API existed;<\/li>\n<li aria-level=\"1\">code for the API, to see the bug in it;<\/li>\n<li aria-level=\"1\">access to Bitfinex systems to send valid requests to BitGo.<\/li>\n<\/ul>\n<p>Could you get that information and access \u2014 or get to somewhere you could get that information \u2014 by talking your way past someone? <i>Possibly.<\/i><\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"https:\/\/davidgerard.co.uk\/blockchain\/2022\/02\/12\/could-morgan-and-lichtenstein-have-done-the-2016-bitfinex-hack-im-not-ruling-it-out\/morgan-razzlekhan\/\" rel=\"attachment wp-att-21861\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-21861\" src=\"https:\/\/davidgerard.co.uk\/blockchain\/wp-content\/uploads\/2022\/02\/morgan-razzlekhan.jpg\" alt=\"\" width=\"510\" height=\"315\" srcset=\"https:\/\/davidgerard.co.uk\/blockchain\/wp-content\/uploads\/2022\/02\/morgan-razzlekhan.jpg 680w, https:\/\/davidgerard.co.uk\/blockchain\/wp-content\/uploads\/2022\/02\/morgan-razzlekhan-300x185.jpg 300w, https:\/\/davidgerard.co.uk\/blockchain\/wp-content\/uploads\/2022\/02\/morgan-razzlekhan-348x215.jpg 348w\" sizes=\"auto, (max-width: 510px) 100vw, 510px\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<h3>But then, Morgan and Lichtenstein<\/h3>\n<p>Morgan and Lichtenstein are alleged to have tried to launder the BTC directly from the Bitcoin address the stolen coins were sent to \u2014 they weren\u2019t sent to another address first. In fact, a lot of the stolen BTC is still in that address.<\/p>\n<p>If the government&#8217;s allegations are true, Morgan and Lichtenstein were clearly goddamn dumbasses: [<a href=\"https:\/\/www.justice.gov\/opa\/press-release\/file\/1470186\/download\"><i>Statement of Facts<\/i><\/a><i>, PDF; <\/i><a href=\"https:\/\/s3.documentcloud.org\/documents\/21202276\/memo-with-photos-ddc-stayed-release-in-36b-crypto-launder-case-of-lichtenstein-and-morgan-now-photos-story-here-httpwwwinnercitypresscomcrypto4lichtensteinmorganicp021022html.pdf\"><i>Government\u2019s reply in support of review of Detention Order<\/i><\/a><i>, PDF<\/i>]<\/p>\n<ul>\n<li aria-level=\"1\">IRS investigators first spotted the couple trying to launder bitcoins out via darknet market AlphaBay \u2014 when AlphaBay had just been taken over by international authorities. This was the key to cracking the case and busting Morgan and Lichtenstein.<\/li>\n<li aria-level=\"1\">A WalMart gift card was bought with some of the stolen coins \u2014 and used for purchases in Morgan\u2019s name, sent to her address.<\/li>\n<li aria-level=\"1\">A text file on cloud storage, listing all of the Bitcoin addresses and keys, was registered in Lichtenstein\u2019s name.<\/li>\n<li aria-level=\"1\">A plastic bag was found in their apartment labeled \u201cBURNER PHONE.\u201d<\/li>\n<\/ul>\n<p>\u201cBeing smart in no way stops you from being stupid,\u201d as I said to the Financial Times. [<a href=\"https:\/\/www.ft.com\/content\/ec447c39-2c6b-440a-a620-6de65f6fe491\"><i>FT<\/i><\/a><i>, paywalled<\/i>]<\/p>\n<p>And then there\u2019s Morgan\u2019s Bitcoin rap career as \u201cRazzlekhan.\u201d [<a href=\"https:\/\/www.vice.com\/en\/article\/88gve4\/woman-who-allegedly-laundered-dollar1b-in-bitcoin-was-cringe-youtube-rapper\"><i>Vice<\/i><\/a>]<\/p>\n<p>But look around you. Crypto finance systems are made of cardboard and gaffer tape. Coinbase, the most popular consumer crypto exchange, can barely stay online. Hacks and dumb errors happen <em>all the time.<\/em> &#8220;Bozo&#8221; is standard in this space.<\/p>\n<p>Morgan has bragged at length about her social engineering skills. [<a href=\"https:\/\/www.youtube.com\/watch?v=JmahJCWJ8iM&amp;t=1s\"><i>YouTube<\/i><\/a>] How good she is, that\u2019s questionable. But you don\u2019t need to be very good at all to be better than crypto average.<\/p>\n<p>Slight cleverness and persistence at doorknob rattling is how a huge amount of actual hacking is done. Per the Statement of Facts, the two had allegedly been rattling doorknobs at a whole pile of exchanges already.<\/p>\n<h3>But did they do it?<\/h3>\n<p>Of course, the other reason I won&#8217;t say &#8220;they did it\u201d is that if you were looking for patsies, Morgan and Lichtenstein fit that bill perfectly. Or the hacker was looking for a <a href=\"https:\/\/davidgerard.co.uk\/blockchain\/2019\/05\/02\/crypto-capital-and-bitfinexs-missing-millions-and-reggie-fowler\/\">Reggie Fowler<\/a> to turn the bitcoins into money in bank accounts.<\/p>\n<p>If the Department of Justice won&#8217;t say Morgan and Lichtenstein are the hackers, I&#8217;m not going to declare they are. But I will say that they have the minimal skills needed to even try this. And definitely the bull-headed persistence.<\/p>\n<p>And really \u2014 how much social engineering skill do you need to fox crypto people? I mean, they already bought cryptos.<\/p>\n<p>&nbsp;<\/p>\n<blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">thinking of just dming every account I see with a laser eyes profile or a bitcoin symbol and explaining that I&#39;m the bitcoin wallet inspector. <a href=\"https:\/\/t.co\/Nw131y68Ww\">https:\/\/t.co\/Nw131y68Ww<\/a><\/p>\n<p>&mdash; James Palmer (@BeijingPalmer) <a href=\"https:\/\/twitter.com\/BeijingPalmer\/status\/1491536630519418883?ref_src=twsrc%5Etfw\">February 9, 2022<\/a><\/p><\/blockquote>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<p>&nbsp;<\/p>\n<br><br><div align=\"center\"><p><a href=\"https:\/\/www.patreon.com\/bePatron?u=8420236\"><img src=\"https:\/\/davidgerard.co.uk\/blockchain\/wp-content\/uploads\/2021\/10\/become_a_patron_button.svg\" alt=\"Become a Patron!\" title=\"Become a Patron!\" width=217 height=51><\/a><br><p style=\"align:center;\" class=\"patreon-badge\"><i>Your subscriptions keep this site going. <a href=\"https:\/\/www.patreon.com\/bePatron?u=8420236\">Sign up today!<\/a><\/i><\/p><\/div>","protected":false},"excerpt":{"rendered":"<p>The hack reeks of social engineering for insider information, not sophisticated computer science brilliance.<\/p>\n","protected":false},"author":1,"featured_media":21861,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[176,38,2450,2732,2733,675],"class_list":["post-21860","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorised","tag-alphabay","tag-bitfinex","tag-bitgo","tag-heather-morgan","tag-ilya-lichtenstein","tag-phil-potter"],"jetpack_featured_media_url":"https:\/\/davidgerard.co.uk\/blockchain\/wp-content\/uploads\/2022\/02\/morgan-razzlekhan.jpg","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/davidgerard.co.uk\/blockchain\/wp-json\/wp\/v2\/posts\/21860","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/davidgerard.co.uk\/blockchain\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/davidgerard.co.uk\/blockchain\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/davidgerard.co.uk\/blockchain\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/davidgerard.co.uk\/blockchain\/wp-json\/wp\/v2\/comments?post=21860"}],"version-history":[{"count":33,"href":"https:\/\/davidgerard.co.uk\/blockchain\/wp-json\/wp\/v2\/posts\/21860\/revisions"}],"predecessor-version":[{"id":23141,"href":"https:\/\/davidgerard.co.uk\/blockchain\/wp-json\/wp\/v2\/posts\/21860\/revisions\/23141"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/davidgerard.co.uk\/blockchain\/wp-json\/wp\/v2\/media\/21861"}],"wp:attachment":[{"href":"https:\/\/davidgerard.co.uk\/blockchain\/wp-json\/wp\/v2\/media?parent=21860"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/davidgerard.co.uk\/blockchain\/wp-json\/wp\/v2\/categories?post=21860"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/davidgerard.co.uk\/blockchain\/wp-json\/wp\/v2\/tags?post=21860"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}