Showing posts with label bitcoin. Show all posts
Showing posts with label bitcoin. Show all posts

Saturday, September 13, 2025

Attorney Generals go after Bitcoin ATMs for supporting Fraud

On 08SEP2025, the District of Columbia's Attorney General filed a lawsuit against Athena, a "Bitcoin ATM machine" provider with 4100+ BTMs installed. Athena charges as much as a 26% fee when someone deposits cash to buy cryptocurrency. More importantly, the lawsuit claims that 93% of all deposits into Athena “BTMs” in the DC area were made by scam victims.

The main argument made by this lawsuit is that Athena knows that it is facilitating fraud, it is making substantial profit from that fraud (up to 26% per transaction), and that it refuses to refund money to the victims, despite 1/4th of the money still being in Athena's coffers after a transaction!  

https://oag.dc.gov/sites/default/files/2025-09/Athena%20Complaint.pdf


The DC AG goes further, with a very significant accusation:

"Athena also has allowed elderly consumers to deposit very large amounts of cash over short time periods into wallets that Athena knew had already been used by other scam victims. Athena’s ineffective oversight procedures have created an unchecked pipeline for illicit international fraud transactions." 


 The DC AG's lawsuit claims that the average age of the victims who were enticed to depositing fraud funds into an Athena BTM in their district was 71 and that half of them deposited at least $8000!

Despite included statistics showing only 1.2% of elders invest in Bitcoin, the vast majority of BTM deposits are made by those over the age of 60. The FBI’s IC3.gov in 2023 reported $124 Million in Bitcoin ATM scams against those over 60, compared to $33 Million for all other ages combined.

In response to the common claim that Bitcoin ATMs are intended to help the "unbanked", there is nothing to support that claim. Compare that statistic to an FDIC Survey of "unbanked" Americans, which showed that only 1.2% of "unbanked" citizens use crypto for any reason other than "Investment." I loved this survey question by the FDIC in their 2023 survey.

https://www.fdic.gov/household-survey/2023-fdic-national-survey-unbanked-and-underbanked-households-report


The FDIC Survey also broke down crypto usage by household income.

While the DC AG's lawsuit is significant, it was not the first. Iowa's Attorney General filed two similar lawsuits, one against Coinflip and the other against Bitcoin Depot. (Click to see a list of the Factual Allegations for each.) Iowa's lawsuits show that Coinflip BTMs in Iowa were used to assist in the theft of $13 Million from scam victims between Jan 2021 and June 2024, while Bitcoin Depot BTMs in Iowa were used to assist in the theft of $7.2 Million between October 2021 and July 2023. That's $20 Million in scams in a state with only 3.2 million residents.

My favorite quote from Iowa:

“At best, Bitcoin Depot is a willfully blind participant in the victimization of hundreds of Iowans. At worst it is a silent partner to many scammers’ preying on Iowans, taking a cut of each scam with its excessive and deceptive BTM fees that are further paired with a lack of refunds.”

This analyst would believe that statement could be applied to every “Bitcoin ATM” in every state.

Coinflip Lawsuit
Bitcoin Depot Lawsuit

While the process of using a BTM involves the display of several warnings and disclaimers, the lawsuits point out that the elderly victims of these scams are almost always on the phone with a scammer while they conduct the transaction, who is warning them to ignore all of these disclaimers. But the disclaimer itself is given as evidence that the BTM providers are fully aware that their company is being used to facilitate significant volumes of fraud against the elderly, and that this fraud is providing significant revenue to said companies. These images are from the DC AG v. Athena complaint:

Bitcoin Depot has over 8,000 BTMs, but boasts more than 16,000 locations where you can buy cryptocurrency (including their "BDCheckout" where you can purchase crypto at a cash register.) Here's a location breakdown by state, including 414 Iowa locations (and 399 in my home state, Alabama!):

http://branches.bitcoindepot.com/

Coinflip has over 5500+ BTM locations and claims to have processed at least $4 Billion in transactions. But what percentage of those transactions are fraudulent?

https://coinflip.tech/about

Saturday, January 20, 2024

Book Review: The Crypto Launderers: Crime and CryptoCurrencies

The Crypto Launderers: Crime and Cryptocurrencies from the Dark Web to DeFi and Beyond - by David Carlisle   

I wish I had a way to review this book without having first read last year’s “Tracers in the Dark.” While Tracers talked about the people involved in investigating various crypto-based crimes and those early researchers who made the tracing process possible, Carlisle tells many of the same stories, but in a less engaging way. The facts are there, and when they talk about the same cases, they align nicely. But Andy Greenberg’s Tracers makes those cases stories about people, while Carlisle portrays facts without character development which I would not have realized was necessary or useful in a book on Money Laundering had I not read Tracers first. 

 As to the facts? I learned a ton, especially by feeding my ADD nature by chasing interesting footnotes — more than 350 references are provided! Thank you!!! In the early part of the book he covers all of the mandatory cases: Silk Road, Mt. Gox, etc. 

Where this book is great, and it is far superior to Tracers as an educational resource in this regard, is how money-laundering works in Crypto. Mixers and Coinswaps are explained well, with several of the related cases such as Helix and Bitcoin Fog, being explained. The importance of regulation and how regulators have followed behind crypto developments is a major theme of the book. From regulating exchanges, to Bitcoin ATMs, to privacy wallets such as Wasabi Wallet, and the debate on whether privacy wallets can or should be regulated. The attempts of FinCEN to introduce further regulations and the (in my opinion) Astroturfed outcry against them is especially interesting. 

An example of what I believed to be a very rational and necessary AML policy would be the FinCEN Draft Rule-Making Proposal, introduced 18dev2020 for “requirements for certain transactions involving convertible virtual currencies or digital assets” tried to require transactions greater than $3k to require proof of the identity of the recipient if sent to a private wallet, and would have required a currency transaction report on any movement above $10k. The outlash was severe and the rule-making placed on hold. 

A nice coverage of the history of crypto sanctions by OFAC is also portrayed, from Suex, Chatex, Garantex, Bitzlato, and IRGC-related ransomware. And a history of the evolution of ransomware, which would not be possible without those unidentified and unaccounted for large currency transactions that cryptocurrency has enabled (and that FinCEN has been TRYING to prevent!) 

One example of sanctioning crypto was the OFAC sanctions against Lazarus Group Ethereum addresses, sanctioned along with one of their chosen Mixers, Blender.io. (Sanctioned addresses are listed here.)  I appreciated some of the additional details Carlisle provided on Lazarus Group crypto hacker money launderers Tian Yinyin and Li Jaidong (snowjohn and khaleesi) who moved at least $100M, including purchasing at least $1.4 M in Apple iTunes gift cards! (Though again, no “characters”, just names.) 

The latter part of the book does a nice job explaining the way Ethereum opened up a number of possibilities with Smart Contracts. Carlisle does a great job explaining Ethereum and ERC-20 tokens and how DAOs, DEXs, and DApps are built using the Smart Contracts of Ethereum with more on the DeFi system including how Bridges work. He also explains NFTs and how they also were supercharged by ERC-721 (and abused by thieves, fraudsters, insiders, and money launderers.)  This was the best introduction to that whole ecosystem that I’ve read. Great job! 

The Bitfinex hack, which opens the book, focused on 94,643.29 BTC from 2016 sitting under a microscope, untouched for six years, until it moved in Feb 2022 leading to the arrest of Dutch and Razzlekhan with $3.5 Billion seized, felt like it was set up as the climax of the book as we returned to the story from the opening chapter. The intermediary chapters helped us understand the now-revealed mechanisms, but again, it was facts without characters, which is fine - I just got ruined by the engagement of Tracers. 

The final chapter seems like something the Elliptic marketing department forced on him. (The other major crypto industry players all do the same thing, so not picking on Elliptic. It was the first crypto tracing tool I ever used!) The obligatory industry toeing the line of “oh, but less than 1% of crypto transactions are illicit!” was a frustrating end to an otherwise decent book. No one will ever convince me that the vast majority of crypto transactions involve no “transaction” at all, but are wash trading at an inconceivable scale designed to manipulate the value of cryptocurrencies to encourage investment and enrich the HODLers and corporations whose livelihood crypto is. 

Fantastic content - even possibly as an accompanying text for a crypto crime course at a university (yes, my wheels are turning!) especially with the rich depth of referenced articles, policies, and cases. But for a fun crypto crime STORY I would still go with “Tracers In the Dark.”

Tuesday, May 02, 2023

Mirror Trading International's Cornelius Johannes Steynberg and his $3.4 Billion USD Default Judgement

Some of you may have heard that students in UAB's Investigating Online Crimes class have been researching Crypto Investment Scam websites.  You can find a list of some of the sites we've identified so far on URLScan.io using our tag "CryptoScam" (as of this writing we have 3600+ sites on the list -- hosting companies and registrars, please take action!) 

Mirror Trading International and a $3.4 Billion Fine

You may have never heard of the U.S. Government agency, the Commodity Futures Trading Commission, but that doesn't mean they don't have power.  Last week the CFTC announced an order of default judgment against Cornelius Johannes Steynberg of Stellenbosch, Western Cape, South Africa. The order states that Steynberg must pay $1,733,838,372 USD in restitution and an additional $1,733,838,372 as a civil monetary penalty for defrauding 23,000 Americans of 29,421 Bitcoin.  (That's $3.4 Billion USD, or R63.6 Billion South African Rand.)

I'm proud to say that this action was brought in part by the Alabama Securities Commission, who joined Texas, North Carolina, and Mississippi in taking action.  I've met their director (who just retired this week! Thank you Joe Borg for 30 years of service!) and some of their investigators and they fight hard to protect the citizens of Alabama from fraud. 

Mirror Trading International claimed that their members could earn 10% per month in interest on their investments.  A typical ad of theirs boasted of this advantage over traditional bank accounts and other investment vehicles: 




Ponzi Scam or Affiliate Program: Tomato / Tomato

Like many other Crypto Investment Scams, MTI was an affiliate program.  MTI encouraged members to create an account, after which they would be granted an affiliate code. By sharing a link to the main MTI website using their affiliate code, anyone who clicked the link and made an investment would begin generating "passive weekly income" to the member. 

Dozens of webpages, Telegram channels, and Facebook pages were filled with ads claiming how easy it was to earn money.  Here's one that was shared on a Facebook page operated by affiliate "Themba2000." 


This affiliate regularly posted updates supposedly showing how much money they were earning, as well as testimonials where the people they had recruited supposedly thanked them for their newfound financial freedom:



Like many other Crypto Investment Scams, the affiliates were encouraged to share videos claiming that Artificial Intelligence-based training was part of the secret of their success: 


South Africa's Court Order Outlines a Problem: Greed

While the terms of the South African court order against MTI may seem like victim-shaming, Greed is truly one of the factors involved in many of these Crypto Investment Scams.




"People all over the world, and South Africans are no exception, are bewitched and fascinated by any idea or scheme promising, in most cases, instant wealth, new homes, new cars, holidays abroad and all material possessions that can be acquired with an abundance of money. A further attraction of these schemes is the perception that the money will keep rolling in with little or no effort by the participants, the hardest part being to count one's money." 

The conclusion of that case summarized their findings as follows: 

[137] MTI's business clearly amounted to an unlawful ponzi-scheme, i.e. a fraudulent investing scam promising high rates of return to investors and generating returns for earlier investors with investments taken from later investors. 

[138] It would appear that there is no pool of member bitcoin, Trade 300 does not exist, the artificial intelligence bot never existed or traded and the remarkable trading results presented to investors were prima facie false. 

(ordered by A De Wet, Acting Judge of the High Court) 

What?  The AI Magic Bitcoin Genie isn't real?  I'm shocked!

Scammers or Victims:  Why Not Both? 

Unfortunately, many of the people who became involved in the scam are innocent victims while others made fake Facebook accounts in order to scam others into signing up.  As long as they signed up others, they had a good chance of making money, until the whole scheme collapsed.  It took about five minutes to find fifty affiliates with a simple Facebook search:


So will everyone get their money back?  Highly unlikely. 

Steynberg Arrested in Brazil

Mr. Steynberg was arrested in 2022 by the Brazilian Military Police of the state of Goias: 

Assurances from MTI CEO Steynberg: I am not a Ponzi Scheme!

When Mirror Trading was first accused of being a Ponzi Scheme by the Texas Securities Commission, their CEO replied to queries using a form letter like this one, shared by Global Crypto in a story called "MTI Announces It Is Working With the FSCA": 

Dear Kratika,

I unfortunately only received your email this morning, Tuesday 14 July 2020.

As I have declared to the Texas Commissioner in writing, I wish to state and declare from the outset that Mirror Trading International (Pty) Ltd (hereinafter referred to as “MTI”), a privately held company registered in the Republic of South Africa, is not a Ponzi scheme (new money feeding old) or a scam, with which a holder of funds suddenly disappears.

It is also most unfortunate that because MTI is operating in the online passive income building industry, which has a notorious and demonstrated reputation for scams and Ponzi schemes, and, due to the nature and Modus-Operandi of the robust MTI referral-based business model, that MTI is automatically by default behaviour of the media and some regulators, and maybe the behaviours of some members, is being perceived by associative conclusion that MTI is but another of these.

This unfortunate and misinformed perception is far from the reality of what MTI is as a newly formed (15 month old) highly innovative referral-business and brand that the founders would like to see growing over many years into a global, iconic and heritage brand in the market trading sector.

For instance, the Texas Commissions states that …The actual value of the commissions depends on their success in recruiting new investors and multilevel marketers. … While this may apply to Ponzi schemes, this is not correct for MTI.

Daily trading returns using top regulated trading brokers determine the quantum of rewards, which can vary and if there is a negative trading day, there are no rewards. The point is that with MTI, that the funding of MTI referral payments is derived from daily trading profits and not from the funds of new members.

Another important point which differentiates MTI from Ponzi’s and scams is that members have full control over their funds (Bitcoin) at all times. Members are able to add or withdraw their funds (Bitcoin) at any time, with no complications and no fees. If you do research, you will find not a single member of the 75,000+ MTI members worldwide has ever complained or not been able to withdraw their BTC whenever they have opted to.  

It is the aim of MTI and its innovative, unique referral-based business model and MTI’s operating Modus Operandi of trading on world markets to generate real growth and returns on a daily basis, to work with and co-operate with regulators in every regard, in the process of taking MTI along a path that will see MTI fully and properly regulated.
There are three reasons for this.

1. My Founding Vision for MTI: Build a preferred iconic and heritage global brand in the financial services sector that delivers sustainable growth and value creation for all stakeholders, including for the little man in the street:
2. Professional and Compliant:  Ensure that MTI is a professionally managed business and brand that is regulatory compliant and which delivers sustainable growth and value creation for all stakeholders. My team and I are committed to this.
3. Change the reputation of the on-line passive income generating industry: We and myself personally, are extremely tired of this industry having a negative and darkly clouded reputation. And yes, some 99.9% of online passive income building services are scams and  / or Ponzi’s. I am personally very driven to be part of changing this perception once and for all, by showing and demonstrating to regulators, to the media and to consumers that such a business model can on a Bona Fida basis, exist, successfully operate and grow on an organic and sustainable basis, which is what MTI is doing.

To this end, MTI will in the coming period be placing great emphasis on engaging with and working with any regulator with a clear purpose at all times;  be fully compliant as a professionally managed company and brand that delivers sustainable growth and value creation to its stakeholders, and which intends to be around for many years to come.

MTI is already in discussion with the South Africa Financial Services Conduct Authority (FSCA) and will be meeting with the FSCA in a week’s time. MTI is also fully committed to co-operating with the Texas State Securities board and is in correspondence with them on this matter.

We trust that the above gives you some insight into MTI.

Should you wish to correspond further, please use my private email address: [REDACTED]
Your sincerely,

Johann Steynberg
Chief Executive Officer
Mirror Trading International (Pty) Ltd
South Africa












Thursday, January 05, 2023

SIM Swapping, Crypto Theft, and Sentencing in the United States

As you know from the title of my blog, "CyberCrime & Doing Time," I'm very interested in cybercrime and the criminal justice system. This week I've been looking at SIM Swapping cases and wanted to share what I learned from reading the sentencing memos sentencing transcript for Ricky Handschumacher.

Ricky was one of the members of "The Community" - a group of six OGUsers/HackForums punks who decided to go into the crypto theft business. They haunted crypto community forums gathering data on people who over-shared about their crypto earnings and then did the social media intelligence (SOCMINT) work to id their target, assess their holdings, get their online credentials, and then pay a phone company contractor or employee to SIM Swap their device and steal their crypto.

They stole over $50 Million dollars.

Ricky was the last guy to get sentenced.  The other members of the group (not their phone store patsies, but the core group) were: 

  • Conor Freeman, 20, of Dublin, Ireland.  Conor was sentenced to three years in Ireland.
  • Colton Jurisic, 20, of Dubuque, Iowa. He was sentenced to 42 months and restitution in the amount of $9,517,129.
  • Reyad Gafar Abbas, 19, of Rochester, New York.  He was sentenced to 24 months and restitution in the amount of $310,791.
  • Garrett Endicott, 21, of Warrensburg, Missouri.  He was sentenced to 10 months and restitution in the amount of $121,549.
  • Ryan Stevenson, 26, of West Haven, Connecticut.  He got two years probation.  Minor player.

Ricky pleads guilty to a single count of "18 USC § 1349 - Conspiracy to Commit Wire Fraud" and in exchange the court agrees to drop several additional charges of: 
18 USC §§ 1343 and 2 - Wire Fraud, Aiding and Abetting 
18 USC §§ 1028A(a)(1) and 2 - Aggravated Identity Theft, Aiding and Abetting

Anyway, Guilty plea is received, family all lines up to say what a good boy Ricky is, blah blah blah, and how he was such a good boy while he was out on bond.

Sentencing Guidelines 

Here's how our sentencing Guidelines work ...

The base crimes each have a number of "sentencing points" that they are assigned.  Then there are a whole host of modifications that can be applied based on other factors.  This score is then further modified by how many prior criminal convictions the individuals have.

Conspiracy to Commit Wire Fraud has a base score of 7.  With no criminal history, that would give a sentence of 0-6 months. But that would be a crime with no victims, no losses, and the most basic conspiracy.  All of the other factors add points. 

The following modifications are then applied.

+2 - the number of victims matter.  In this case, they are charging "ten or more victims." 

Ricky's score is now a 9.  Sentencing guideline: 4-10 months.

+2 - sophisticated means. Because this was a high-tech crime with a lot of technology and a lot of moving parts.

Ricky's score is now an 11.  Sentencing guideline: 8-14 months. 

+2 illicit authentication.  To curb identity theft and the flippant use of stolen credentials, crimes that involve stolen identities get an automatic +2. 

Ricky's score is now a 13.  Sentencing guideline: 12-18 months.

+18 - Theft of between $3.5 million and $9.5 million.  The two greatest "adjustments" in the sentencing world are Number of Victims, and Amount Stolen. This is a huge modification, however, they stole a lot of money!  Many victims lined up to say they lost 100% of their life savings.  One of them even appeared at the Sentencing hearing and said so.  He told the court he had lost everything, and had been waiting FOUR YEARS for justice to be served.  It definitely needs consideration.  

Ricky's score is suddenly a 31.  108-135 months.  That's 9 to 11 years.

-3 - Because Ricky was cooperative and accepted responsibility for his crimes, apologizing to the court and to the victims, his sentencing guideline score is dropped by three points.  That's huge, actually.

Ricky's score is now 28.  78-97 months. 

In their sentencing memo, the prosecution says they would be happy to accept the "mid-point" of that range and asks for an 88 month sentence.

The Judge Speaks

The judge in this case is The Honorable Denise Page Hood in the Eastern District of Michigan.  I appreciate that she puts a great deal of explanation in before rendering her verdict.  She shares with us each of the things she is charged with considering as she builds her decision on what sentence to impose.  All of the following is quoted from the Sentencing Transcript available on PACER, although the emphasis added is mine.  

1. "The factors I'm supposed to consider are these: The nature and circumstances of the offense and the history and characteristics of the Defendant, and I'm satisfied that, while I don't think that -- well, I think the age of the other individuals involved really didn't have anything to do with you. What it really has to do with is whether or not you were a more mature person and maybe should have had some other indication of this wrongdoing and made a better judgment than someone who perhaps is still young and a bit naive might be. Like I know one of the people, I was convinced that person was much more naive than other individuals involved in this. You, however, aren't one of those.


"I have here also that I think that the nature and circumstances the offense are serious, because there's a lot of money stolen, and it's stolen from individuals who, number one, are unsuspecting, and, number two, some of them are like Mr. S.S., who is here in court today, that this was not, you know, some organization or anything. It was an individual and their personal money, their, as he describes it, his life savings that were involved, and I think that makes it a little bit different than stealing from a company that might have some other means of recovering that than an individual. I'm also satisfied that it seemed like kind of a we're going to go out there and just do these things. We're just going to hack. We don't have any sense of caring very much, until it's over, about people who might be involved in this and where the money might be coming from and where it might go, and so, to some extent, on the part of everybody involved, it seemed like it was kind of a relaxed look at what you were doing and just kind of like a greed thing. I mean it wasn't -- particularly in your case, it wasn't that you were destitute or anything. You had some education, and you had the ability to have a job. So it wasn't that you couldn't go out and make money on your own, and that is kind of the nature of these kind of things, but I think it's a very serious offense in this particular scheme of things.

2. I'm also to look at the history and characteristics of the Defendant, and, for that, I would note that in the scheme of people who come into court,  you're on the young end of that. You may not think you are, but you really are on the young end of those people who commit crimes within our system.

I'm satisfied that you had a decent childhood. I had some notes here that you were and athlete and well-integrated into your experiences as a youth, and, also, that, unlike some other people, you did not seem to be someone who was just, you know, isolating themselves and unliked by others and, therefore, kind of a person who might reach out to do something like this because of a bad situation that they were in. Not that that excuses that behavior, which is exactly what I told them, that it doesn't excuse that behavior.

I'm also satisfied that -- I don't know whether it's better or worse that there are hackers out there that don't know one another, and maybe that adds a little bit to the frivolousness and the unaccountability of it relative to one another. Otherwise, I don't think there's anything in your history or characteristics that is a negative to you. I had one thing I wanted to note here. Okay, I wanted to note that it does not appear that you have any physical problems or that you have any mental health diagnosis or received any mental health treatment. It does not appear that you have any substance abuse problems.

It appears that you graduated from high school and that you were able to have some employment, including an employment from July of 2019, on Paragraph 44, until – at least at the time that this report was written, and that prior to that, that you have worked -- you had been unemployed for a time but that you were also employed by the city of Port Richey, and, prior to that, in a grocery store, and for the short period of time that you've been an adult, that's a significant amount, as far as I'm concerned, of employment.

The other thing I want to say is thatI'm to consider whether or not the sentence that I'm going to craft will reflect the seriousness of the offense. I've already spoken to that. Promotes respect for the law and provides just punishment, and I'm sure that you're aware now of the seriousness of the offense. That may be enough to promote respect for the law. I don't know that. You know, I don't know that in these particular kind of instances whether people look at it and say, you know, I've been involved in this. It was easy. I just happened to get caught. I'm never going to get caught again because of the nature of how this is done and how hard it is to investigate and to find out what each person involved in it is doing. So I don't know that my sentence will promote respect for the law, but at least I have taken it into consideration.

I'm also to fashion a sentence that provides just punishment, and I know that in all of the cases during the pandemic, where people have been on bond, they have noted I've been, you know, really good, in quotes, on pretrial release, and that shows that I am rehabilitated, and, to some extent, that may be true. To the other extent, the opportunity was that you would not be on pretrial release and you would be in custody where everyone else is attempting to get out of custody because of Covid-19. So I see that people would be, to a very great extent, well-behaved on pretrial release at this time, especially when they don't want to be incarcerated. So I don't give that a lot of weight. I know it's a long time to wait, but I'm sure it is far less onerous conditions than if you were waiting in jail to be able to proceed.

5. I'm also to consider whether or not I will afford adequate deterrence to criminal conduct, and I recognize that this may have been an opportunistic crime, but it's still illegal. You still have to answer for it, and some of it, the deterrence, I think, is not only deterring yourself, meaning that something happens to you that makes you not want to do this ever again even if you think the opportunity to be caught is very small, and it's going to become less small. The Government is going to get better at uncovering this type of crime and uncovering it earlier, but I also think that we deter others by letting them know that we're not going to just let this kind of crime go unaddressed


6. I'm also to fashion a sentence that protects the public from the further crimes of the  Defendant, and I will do that in this case by requiring, since it's your first contact with law enforcement, and to some extent the presentence report indicates it's a deviation from your otherwise law-abiding life, that you will have to participate in the Computer Internet Monitoring Program for the entire time that you're connected to the Court by being incarcerated, if you're put in a halfway house, or while you're on supervised release, and you'll have to abide by that agreement, which addresses all of the computers to which you would have any contact, okay, and it allows them to not only search but at reasonable times and places, but to also be for you to provide other people using the computers with the understanding if you're using their computer, it's subject to search as well.

 
7. I'm to fashion a sentence that provides you with needed education and vocational training, medical care, or other correctional treatment in the most effective manner, and it does not appear that you're unhealthy, or, as I said, have any mental health or substance abuse concerns. I know you have a high school diploma, and you have had some employment that's consistent with that, and so I would note that you should have the opportunity to engage in any programs that you think are beneficial to you to enhance that, but I don't have any that I'm going to particularly point out.

8. I also have to consider the kinds of sentences available, and that is the 78 to 97 months of incarceration, and that it will be followed by a term of supervised release, and I'm also to consider the need to avoid unwarranted sentencing disparities among defendants with similar records having been found guilty of similar kinds of conduct, and I have these other codefendants, all of whom seem to have various roles in conducting this conspiracy, and I think that my sentence will reflect how I think the various roles and the history and characteristics and other factors have impacted those people, all of whom, so far, have received a sentence that is below the guideline range. 

9. I'm also to consider the need to provide restitution to any victims of the offense, and I am going to order a restitution against you relative to this. I will also recommend that the amount that you're forfeiting go against the restitution, but, you know, part of it is that, you know, the amount of restitution is really high, and I think it's really difficult for anybody, although you're a young person and so are the others, to pay back seven-and-a-half-million dollars. That's a tremendous amount of money, and the amount that it is apparent that you're forfeiting doesn't really approach that. It doesn't approach $7 million, and so, you know, the Court is always wondering what happened to the money that was stolen away from people and whether or not people have spent it or they hid it away, especially if there's nothing really apparent. There is, in some cases, something apparent to show for it, but I have considered that as well.

I've said in the other sentences, because in the other instances, people also ask for  noncustodial sentences, that I don't think that a noncustodial sentence is appropriate in these cases. I mean we think, kind of like we do in other kinds of cyber crimes, that you don't see what's happening. It's not done with some -- it's not like you went in and robbed a place where some people were standing there and you had to deal with the actual people that you might be stealing the money from, or had to confront an actual bank teller who might be afraid or anything like this. This is kind of done on your own on the computer. You don't really have any real people in front of you. It's not maybe very -- it does not seem very personal to the people committing the crime, but it's really personal against the people that the crime is committed, and so I don't think that a noncustodial sentence is appropriate.  Even with the halfway house and the like, I don't think it's appropriate, and I think you can tell that from the other sentences that I've imposed.

The Sentence

And, therefore -- but I should also say that I think the 78 to 97 months is driven, as many as of these monetary crimes are, by the amounts of loss, and I think, in this particular instance, where I have people before me and you who don't have prior serious offenses or any offenses at all, that I give credit for that in most other instances of fashioning a sentence, and the credit for it actually goes to the amount of time that you have to be incarcerated usually, and I don't see any reason why I shouldn't do that in this particular instance. In all of these instances, I think I have before me people who have the ability to do one of two things. They can grow and become productive members of society and attempt to pay back the victims the money that was, you know, secretly stolen from them and computers used to do that, and, therefore, I think that a sentence within the guideline range is too much for the charges that I'm presented with here for the reasons that I've stated.

 
And, therefore, with respect to Count 1 of the indictment, pursuant to the Sentencing Reform Act of 1984, the Court, having considered the advisory guidelines and the factors contained in 18 U.S.C. §3553(a), commits the Defendant to the custody of the Bureau of Prisons for a term of 48 months. And, upon release from imprisonment, the Defendant will be placed on supervised release for a term of three years. 


... I'm ordering that you pay that restitution to the clerk of the court for disbursement to the victims identified below in the amounts below for a combined restitution order of $7,681,570.03, which is due immediately. While on supervised release, payments must be made at a rate and schedule determined by the probation department, approved by the Court, and they are going to these victims:
Victim with initials D.M. in the amount of $116,387.12;
Mr. S.S. in the amount of $1,967,146.57;
And S.B. in the amount of $5,598,036.34.

Thoughts on Sentencing 

I am always frustrated when judges choose to depart from the recommended sentence, especially in a way that I feel does not take cybercrime seriously.  As we look at the rationale behind the sentence though, I think it boils down to this:


In the world of Big Crypto and with the pathetic security in place that means a kid in a phone shop can facilitate a $5.5 Million theft, how do we balance the trivial means of stealing that money with the fact that someone's life savings have been destroyed?

In this case, restitution will start with the fact that Ricky is giving up 38 BTC and 900 Ethereum from what he stole.  At the time of this writing that is about $1.8 Million.  How is a kid with a high school degree and a criminal record going to pay back the other $5.8 Million?  He's not.  The parole board will come up with a garnishment of future wages, but if he ends up in a minimum wage job, that is likely to be repaid at a rate of $100 per month, so the victims will get the rest of their money slowly over the next four thousand eight hundred years or so.

I would really like to hear your thoughts on this.  Feel free to comment below.  Thank you!

Monday, September 19, 2022

The new DOJ Law Enforcement Crypto Reports (TL;DR)

TL;DR? Good news!  I read them for you! 

 On 15SEP2022, the Department of Justice released their report "The Role of Law Enforcement in Detecting, Investigating, and Prosecuting Criminal Activity Related to Digital Assets" (66 pages).  The first of the nine reports ordered by President Biden's Executive Order 14067 "Ensuring Responsible Development of Digital Assets" was also released by the DOJ back on 06JUN2022, "How To Strengthen International Law Enforcement Cooperation for Detecting, Investigating, and Prosecuting Criminal Activity Related to Digital Assets" (58 pages). 


Since then, we have seen the Department of Treasury release three reports:

Treasury also provided to the White House in July a "Framework for International Engagement on Digital Assets" which is described in their press release, but not provided to the public. 

Earlier this month, the Department of Commerce released their report:
 "Responsible Advancement of US Competitiveness in Digital Assets" (19 pages). 

The Office of Science & Technology Policy also released three reports:
In this blog post, we'll focus on the two DOJ reports, which we will address in the reverse order of  their release, as it seems that it is required to define the role of law enforcement in digital assets before discussing the international cooperation one would seek in this area.

The Role of Law Enforcement in Digital Assets


Despite the Executive Order, it is important to note that the Department of Justice did not need the urging of the White House to establish procedures for addressing Cryptocurrency.  The department created the Attorney General's Cyber-Digital Task Force in 2018, which produced their original report, published in October 2020, titled the CryptoCurrency Enforcement Framework (83 pages).  That original report characterized the illicit uses of cryptocurrency into three broad categories of criminality: 
  1. financial transactions associated with the commission of crimes, such as buying and selling drugs or weapons, leasing servers used in the commission of cybercrime, soliciting funds to support terrorist activity, or ransom, blackmail and extortion. 
  2. money laundering and the shielding of legitimate activity from tax, reporting, sanctions, or other legal requirements, including operating unlicensed, unregistered, or non-compliant exchanges. 
  3. crimes, such as theft, directly implicating the cryptocurrency marketplace itself, such as stealing cryptocurrency from exchanges or defrauding unwitting investors. 
The original report listed many case studies involving indictments, seizures, and arrests in the scenarios above, including SamSam ransomware, Welcome to Video and DarkScandals child sexual abuse services, terrorist funding both through direct donation and via sales of fake medical equipment (PPE during COVID), the Bitcoin Maven case (Theresa Tetley), BTC-e, Operation DisrupTOR (Wall Street Market), DeepDotWeb, DreamMarket, the Lazarus group hacks, HeroCoin ATMs, the Helix mixer, and others. 

The new report points out something that I've recently been mentioning as well.  Bitcoin and other block-chain-based crypto currencies are neither the first digital currency, nor the first one that has facilitated a great deal of criminal trade.  The report mentions E-Gold (1996) and Liberty Reserve (2006) as "pre-crypto" examples of digital currencies, but could have as easily mentioned Webmoney (1998) or PerfectMoney (2007). Many of the points of the new report echo of those of the prior, although the cases have been updated, such as  Bitfinex, Helix, and Hydra Market, estimated at one point to perform 80% of all darknet market-place transactions, and Garantex, the Estonia-based Exchange that laundered more than $100 million of the funds associated with darknet markets. The Colonial Pipeline ransomware and the use by indicted GRU agents of bitcoin, the theft of $600 Million by Lazarus Group hackers in March 2022 are all used to update the original report. 

Two significant additions are the section on the Growth of Decentralized Finance (DeFi) and Non-Fungible Tokens (NFTs). In this area, the discussion of "Decentralized Autonomous Organizations" as opposed to a traditional corporate structure, and the insider trading, money laundering, and tax evasion aspects of NFT trading are discussed.  (Examples of Nathaniel Chastain of OpenSea and Ishan Wahi of Coinbase are provided as insider examples.) 

Section II of the report discusses DOJ efforts such as the National Crypto Enforcement Team (NCET) and its predecessors such as the Money Laundering and Asset Recovery Section's Digital Currency Initiative, and the Internation Virtual Currency Initiative. A few interesting statistics from the FBI, including that as of July 2022, the FBI had worked 1,100 separate investigations across 100 investigative program categories that involved a digital assets nexus. Since their first digital assets seizure in 2014, the FBI has seized $427 million in virtual assets (as valued at time of seizure.)  In February 2022, the FBI created the Virtual Assets Unit.  The Department of Justice has also created a Digital Asset Coordinators Network which is composed of designated prosecutors in U.S. Attorney's Offices across the country who work closely with CCIPS, MLARS, and NCET.  The program is based on the successful CHIP Network (Computer Hacking and Intellectual Property) and the National Security Cyber Specialist (NSCS) Network which each designate prosecutors in every field office to be specially trained and equipped to handle the relevant case types for their office. 

Cryptocurrency fraud investigations are listed as well, including the Baller Ape Club NFT rug pull case, the EmpiresX crypto Ponzi case, the Circle Society crypto commodities case, and the Titanium Blockchain Infrastructure Services Initial Coin Offering case. The Bitqyck case and the $2.4 Billion BitConnect Ponzi scheme case serve as an example of an IRS Cyber tax evasion cases, with the latter also being charged civilly by the SEC. 

The DEA's Cyber Support Section is described as performing cryptocurrency analysis related to the use of cryptocurrency to facilite drug trafficking, while the US Marshals Service is the group manages and liquidates seized crypto funds. HSI has been a key player in many crypto cases, with at least 500 currently active investigations, especially via their Financial Crimes Unit, Cyber Crimes Center, and Asset Forfeiture Unit. The US Secret Service is also involved, with 302 cases involving digital assets and at least 535 seizures of digital assets valued at more than $113 Million at time of seizure.  The US Secret Service is also a top trainer of state and local law enforcement via the National Computer Forensics Institute (NCFI) headquartered here in Hoover, Alabama! They also operate a Digital Assets Awareness Hub to educate the public on crypto risks. 

Regulatory Agencies also play their part, with FinCEN working to enforce Bank Secrecy Act (BSA) guidelines and regulations related to Anti-Money Laundering and Countering Financing of Terrorism (AML/CFT) requirements. Treasury manages the OFAC office, which includes sanctioning mixer and state-sponsored crypto hackers. The SEC regulates crypto scams that are structured as "investment contracts, such as BlockFi Lending LLC or the DeFi Money Market. The Commodity Futures Trading Commission (CFTC) regulates the trade of commodities in interstate commerce. They have brought 50+ enforcement actions against organizations such as Coinbase, Payward Ventures (Kraken), Blockratize (Polymarket).  BitMEX is one cryptocurrency derivatives exchange targeted for CFTC enforcement, after $209 Million in darknet market transactions were cashed out via BitMEX, who paid a $100 Million fine, with three co-founders pleading guilty to criminal charges and paying a $10 million fine. 

One last organization of note is IVAN, the Illicit Virtual Asset Notification platform, being built by FinCEN and the FBI's National Cyber Investigative Joint Task Force. The goal of IVAN is to be a public-private information exchange to allow industry to collaborate on timely detection and disruption of the use of virtual assets in furtherance of illicit activity. 

Requests for Legislation 

The Justice report does make several requests for additional legislation, in five categories: 

  1. extend the prohibition against disclosing subpoenas (currently in effect for financial institutions) to VASPs (Virtual Asset Service Providers), strengthen the laws against operating an unlicensed money transmitting business, and extend the statutes of limitations from 5 to 10 years for certain crimes. 
  2. support for initiatives that would aid investigators in gathering evidence
  3. strengthening sentencing guidelines for certain BSA violations
  4. extend BSA record keeping rules to VASPs 
  5. ensuring that law enforcement has resources to conduct and staff sophisticated digital asset-related investigations. 
The details for this legislative proposals are in section IV of the report, LEGISLATIVE AND REGULATORY ACTIONS THAT COULD ENHANCE EFFORTS TO DISRUPT, INVESTIGATE,

International Considerations 

One of the main observations of the report on International Law Enforcement Cooperation is the standard complaint that the Mutual Legal Assistance treaties are too slow, and that faster methods of international law enforcement cooperation, such as the "24-7 Network" often do not have a standard way of sharing requests regarding Virtual Asset Service Providers. (VASPs). 

Next, while the western-friendly nations of the world have largely standardized cybercrime laws under the Budapest Convention on Cybercrime, the way in which the nations of the world define, regulate, and enforce actions against VASPs are varied and inconsistent.  Under the concept of Dual Criminality, where one nation may only ask another to enforce laws which are similar in both countries, much of crypto-crime enforcement lacks such standards. 


While the Cybercrime laws may not have caught up, the International body that deals with Anti-Money Laundering, FATF or the Financial Action Task Force, are clear thought leaders on the Virtual Assets guidelines. (We wrote about FATF in 2019, please see: Money Laundering and Counter-Terrorist Financing: What is FATF? ) Unfortunately, as of July 2021, only 35 participating nations had implemented the FATF suggestions regarding virtual assets and VASPs into their national laws. 

My favorite part of the "Strengthening International Law Enforcement" report is Annex B: "Examples of Successful Cross-Border Collaboration on Digital Asset Investigations." 

Liberty Reserve
BTC-e
Helix 
Silk Road 
Operation Bayonet (AlphaBay and Hansa)
Dream Market
Wall Street Market 
DeepDotWeb
Welcome To Video 
Operation DisrupTOR
Hydra Market 
Twitter hack 
Sodinokibi/REvil Ransomware 
NetWalker Ransomware 
BitConnect 

For each example above, details are shared about which international law enforcement agencies partnered with which US agencies in order to reach the successful resolution.  Inspiring reading! 

Wednesday, October 16, 2019

"Welcome to Video" raid leads to 337 arrests due to Bitcoin Exchanges that use strong KYC

The darkweb child sexual exploitation video site, "Welcome to Video", first came onto Law Enforcement's attention as a result of a case in the UK, where a geophysicist Matthew Falder was arrested.  When the National Crime Agency was looking into his hard drive, they found he had been a member of "Welcome to Video" which at the time used the dark web address mt3plrzdiyqf6jim .onion.  Anyone visiting that website recently would have seen this banner instead:


Law enforcement actually got the website through a silly webmaster error.  One of the webpages on the website linked some of its component files by the server's IP address instead of its onion URL address.  The IP address, 121.185.153.45, was a Korea Telecom address.  They got the owner's address details and were able to confirm his identity.

After establishing undercover addresses, searches on the website for some common child sexual exploitation searches, and received indications that there were THOUSANDS of matching videos.  I don't know that we should share the terms with our readers, but some search terms resulted in more than 7,000 or even 10,000 matching videos.  Searches for videos involving children as young as four years old or even two years old yielded 4,000 matching videos each.

 Anyone could view "thumbnails" on the site, but to download or view the related videos, you had to have Points.  You could buy points for bitcoin, or you could "earn" points by uploading a unique video, or having a friend sign up and use your referral code.

 On multiple occasions, including September 28, 2017 and February 23, 2018, federal agents made payments on the website, and within 48 hours, the money had been moved to another Bitcoin wallet.  That wallet turned out to be a Coinbase wallet.  When they asked Coinbase who paid for that Bitcoin account, it was Jong Woo Son. To be able to buy Coinbase from a bank account, Jong was required to provide KYC (Know Your Customer) information, so he provided and confirmed an email address and telephone number, both of which were found to belong to Jong.

That gave law enforcement enough to raid Jong's residence, where they found the server in his bedroom, containing 8 TB of child sexual exploitation images, and log files indicating that MORE THAN A MILLION videos had been downloaded from the site.  The raid was conducted by US IRS-CI, US HSI, UK NCA, and the South Korean National Police.  By comparing the hashes of these videos to the collection at NCMEC (The National Center for Missing and Exploited Children), they found that 45% of these videos had never been seen before.

MANY of the users of the site were "creating" videos by abusing children they had access to. The United States has indicted Jong Woo Son, but he is already serving time for charges brought in South Korea.  The indictment does provide a great deal of information about the case that helps us understand what happened:


(from the Jong Woo Son indictment)
We know from other sources that the "exchanger in the United States" is Coinbase (see below).  Every time Welcome To Video presented an opportunity for payment to a visitor, it generated a new potential Bitcoin wallet address.  Until someone makes a payment, however, it is more like a "potential" wallet.  If the visitor wasn't sure how to get Bitcoin, Jong's website recommended that an easy way was to set up a Coinbase account!
By tracing other addresses that also moved small payments to the same wallet that the undercover payments were moved to, they were able to identify a "cluster" of 221 frequently used bitcoin addresses that had been used to receive payments that were then sent to the website owner, Jong Woo Son.  Later, they asked Coinbase, and two other major Bitcoin Exchanges, to identify accounts that had sent payments to any of that pool of 221 bitcoin addresses.  Why so many?  To make sure which payment belongs to which user, when a user indicates they are about to make a payment, they are assigned a bitcoin address to use for their transaction.  This is fairly common practice on darkweb markets. To avoid conflicts, Jong had many such addresses that would receive the payment from a specific user, probably created at transaction time. Jong would consolidate these bitcoin "wallets" by moving the funds to his primary account, from which he sometimes withdrew funds directly to his bank account. Because transacting against a bitcoin address creates new addresses, those at least 7,300 small payments were paid to different addresses controlled by Jong over time.
This was really spelled out in detail as the prosecutor, and then the FBI agent, tried to explain bitcoin to the judge in the Gratowski case.   That was the Texas case involving former HSI Agent Richard Nikolai Gratowski.  Same thing.  He used his own USAA Credit card to pay Coinbase to buy his bitcoin.  I have the 100 page transcript of his court hearing, which was fascinating to read.  He was sentenced to 70 months (and has already appealed to the 5th circuit.)  Most of the court documents referred to "Bitcoin Exchange 1" -- but the transcript names Coinbase 84 times!  I think they deserve a lot of the credit for making this case possible through their strict KYC implementation!


Subpoenas asking for "who has been sending money to these 221 bitcoin wallets?" is where they got their hitlist of 337 site users who were arrested.  They including pedophiles residing in Alabama, Arkansas, California, Connecticut, Florida, Georgia, Kansas, Louisiana, Maryland, Massachusetts, Nebraska, New Jersey, New York, North Carolina, Ohio, Oregon, Pennsylvania, Rhode Island, South Carolina, Texas, Utah, Virginia, Washington State and Washington, D.C. as well as the United Kingdom, South Korea, Germany, Saudi Arabia, the United Arab Emirates, the Czech Republic, Canada, Ireland, Spain, Brazil and Australia.  MOST of those users were identified because of the strict "Know Your Customer" rules that reputable bitcoin exchanges are now requiring of their customers. 

As a result of all of the investigations so far, at least 23 underage children were rescued in the US, UK, and Spain!

In ALL of the US cases I pulled court records for, that was the process.  Find a username on the seized server, prove that they had transacted bitcoin from a KYC-friendly exchange, such as Coinbase, then subpoena the bitcoin exchange to see who owned the account.  Coinbase and other reputable Bitcoin Exchanges, requires "strong Know Your Customer" as a means of reducing fraudulent or criminal behavior.  For Coinbase, that includes a drivers license scan, and a response to both an email and an SMS message to confirm that they know your real email and real telephone number.  For the accounts found, they could then check the Korean server to see which user had made a payment at that time and date, and how much activity they had on the server.  Then law enforcement would either confront the pedophile or conduct a search warrant to get confirmation of the evidence from the customer.  Priority was placed on anyone who seemed to be CREATING the content, or who had previous related charges.

Michael Ezeagbor was found to have used the identity "mikeexp1" on the site.  He had earned points by uploading 10 videos, and had downloaded 42 videos.  He paid 0.1 BTC on Jan 29, 2016 (which at the time was only $38.)  The Bitcoin exchange he used provided his DOB, SSN, address, and a Yahoo email account.  He had bought the bitcoin on the exchange using his A+ FCU account.

Eric Wagner paid 0.06 BTC on November 5, 2016 (about $43 at the time).  He had downloaded 40 videos and uploaded 84 videos.  His bitcoin exchange revealed his email was "wagnered@comcast.net" and he was using a DFCU debit card which matched the name, address, and SSN on file with the bitcoin exchange.

Brian James LaPrath was identified in the same way.  Because he had NOT uploaded, choosing just to pay, and had downloaded very little, he was allowed to plea to money laundering, although he is doing probation with sex offender style limitations in place.


The most troubling case I reviewed was that of Nicholas Stengel who had PREVIOUSLY been arrested for possession of child pornography and had served 41 months, followed by 36 months supervised release.  His supervised release included all of the above, and more.  He relapsed during that time, refusing to take his court ordered polygraph, and was charged with using a computer in violation of his parole to seek child pornography and with public masturbation.  In his first case he was charged with possessing 79,335 images and 230 videos.  When an HSI Cybercrime Special Agent hit his door with a warrant, Stengel's wife stalled the agents at the door while Stengel got into his bathtub with a knife and slit his own wrists and throat!  He was given emergency medical care, but now found to possess 805,457 images and 6,884 videos!
Stengel attempts suicide during his search warrant

Several others who were charged with PRODUCING child sexual exploitation imagery to upload to the site were listed in The Daily Mail's story on the case:

Paul Casey Whipple, 35, of Hondo, Texas, a U.S. Border Patrol Agent, was arrested in the Western District of Texas, on charges of sexual exploitation of children/minors, production, distribution, and possession of child pornography. Whipple remains in custody awaiting trial in San Antonio

Michael Lawson, 36, of Midland, Georgia, was arrested in the Middle District of Georgia on charges of attempted sexual exploitation of children and possession of child pornography. He was sentenced to serve 121 months in prison followed by 10 years of supervised release following his plea to a superseding information charging him with one count of receipt of child pornography

Nader Hamdi Ahmed, 29 of Jersey City, New Jersey, was arrested in the District of New Jersey, for sexual exploitation or other abuse of children. Ahmed pleaded guilty to an information charging him with one count of distribution of child pornography. He is scheduled to be sentenced Oct. 1, 2019

Jeffrey Lee Harris, 32, of Pickens, South Carolina, pleaded guilty in the District of South Carolina for producing, distributing, and possessing child pornography

Nikolas Bennion Bradshaw, 24, of Bountiful, Utah, was arrested in the State of Utah, and charged with five counts of sexual exploitation of a minor, and was sentenced to time served with 91 days in jail followed by probation;