Man robbed of 16 bitcoin hunts down suspects, sues their parents – Ars Technica

Posted: August 30, 2021 at 2:30 am

Andrew Schober was almost all-in on cryptocurrency. In 2018, 95 percent of his net wealth was invested in the digital tokens, which he hoped he could sell later to buy a home and support his family.

But then disaster struck. Schober had downloaded an app called Electrum Atom after clicking a link on Reddit, mistakenly thinking it was a bitcoin wallet. Instead, it was malware that allowed hackers to steal 16.4552 bitcoin when he tried moving some of his tokens. At the time, they were worth nearly $200,000. Today, they would be worth over $750,000.

The lawsuit alleges that two men in the UKboth minors at the time, now attending university for computer scienceused the supposed wallet app to deliver malware that inserted itself into a computers Java libraries. The malware then proceeded to monitor Schobers activity, waiting for him to copy a bitcoin address. When Schober went to paste it, the malware swapped the copied address for another that was stored in the code. Schober was intending to transfer bitcoin from one of his addresses to another, but instead the malware sent the cryptocurrency to the hackers own addressa classic man-in-the-middle attack.

The clever twist is that when Schober went to paste an address, the malware would swap it out for one that looked similarthere were 195,000 addresses embedded in its code.

In the wake of the hack, Schober hired experts to trace the flow of cryptocurrency from his addresses to accounts controlled by the hackers.

The blockchain analysis presented in the lawsuit suggests that the hackers tried to launder the bitcoin into Monero, a privacy-focused cryptocurrency. But to do that, they needed the private key that went along with the public key for the address used by the malware. Around the time of the theft, one of the young men, using an account apparently under his name, posted a question to GitHub about how to obtain said private key. That account also contained GitHub repositories for the malware along with code for a program that allowed for algorithmic trading at the Bitfinex exchange, where two deposits involving Schobers bitcoin were traced to. Together, it led Schober to the alleged thieves.

At the time of the theft, the alleged perpetrators were both minors, so as Schober learned their identities, he sent their parents notes informing them of what he knew. It seems your son has been using malware to steal money from people online, he wrote. Schober appealed to the parents, asking them to make this right, without involving law enforcement. He said he would drop the matter if the stolen bitcoin was returned in full, and he listed an address and gave them a deadline. He sent one note in 2018 and another in 2019. He never heard back from either of the young men's parents.

That silence led him earlier this year to file a lawsuit against the young men and their parents, claiming that the adults knew or should have known that their children were engaged in illegal computer abuse(s) and/or cryptocurrency theft(s).

One of the defendants, Hazel D. Wells, mother of one of the young men, filed a motion to dismiss the case, saying that the statute of limitations on three of the four claims had expired (conversion, trespass to chattel, and a violation of the Computer Fraud and Abuse Act). Defendants did not reply to the fourth, civil conspiracy. Schobers attorney replied that the clock didnt begin when the bitcoin was stolen, but rather when he learned of the identities of the alleged hackers.

At issue in this case is the fact that cryptocurrency transactions are hard to trace and are irreversible, unlike those that happen within the traditional banking system. Tracking down thieves requires investing significant sums of money, as Schober did, and even then, getting back the stolen tokens is a long shot.

Cryptocurrency theft is big business. Last year alone, nearly $2 billion in cryptocurrencies was involved in theft, hacks, or fraud. That number seems to be down this year, but only because theft of decentralized finance investments is on the rise.

Though significant, those cases are small potatoes compared with the Poly Network breach that happened earlier this month. The hacker managed to exploit a vulnerability in the way the company handled smart contracts to steal $600 million for fun before returning the stolen coins and netting a $500,000 bug bounty.

Read more here:
Man robbed of 16 bitcoin hunts down suspects, sues their parents - Ars Technica

Related Posts