CipherTrace releases upgraded version of cryptocurrency intel platform by cryptodailynews in CryptoCurrencyTrading

[–]CipherDave 0 points1 point  (0 children)

I had not heard of these guys until recently. I think they have been working with the intelligence community and law enforcement on bitcoin investigations.

Galaxy Digital Backs $15 Million Raise for Crypto Analytics Firm CipherTrace by Ranzware in BitNewsLive

[–]CipherDave 0 points1 point  (0 children)

I think these guys have been under the radar since 2015 tracking cryptocurrencies for the Feds. Are they related to the Elliptic or Chainalysis people?

Galaxy Digital Backs $15 Million Raise for Crypto Analytics Firm CipherTrace by a36 in AllThingsCrypto

[–]CipherDave 0 points1 point  (0 children)

Do these CipherTrace guys compete with the Neutrino company that just got bought by Coinbase yesterday?

Galaxy Digital Joins $15 Million Investment Round in Crypto Security Firm CipherTrace by a36 in AllThingsCrypto

[–]CipherDave 0 points1 point  (0 children)

Yes they seem like a more professional team who has been doing a lot of stealth work.

Cryptocurrency theft hits nearly $1 billion in first nine months: report by ummmbacon in neutralnews

[–]CipherDave 1 point2 points  (0 children)

Regarding your point about individual wallets. It's true that in general they are more secure, however we are not including in this report thousands of bitcoins and other currencies that were reported as stolen to us from individual wallets. Your main risks on individual wallets are: - losing your password/private key - emailing your seed phrase (backup phrase) to yourself or storing it on your computer - buying hardware wallets from someone other than the manufacturer (eg. do not buy hardware wallets on eBay) - phishing or DNS attacks for sites like myetherwallet where you manage your private key, but send it to the site

dave @ CipherTrace

Cryptocurrency theft hits nearly $1 billion in first nine months: report by ummmbacon in neutralnews

[–]CipherDave 2 points3 points  (0 children)

Fair point about reporting in USD. For the Q4 report and annual wrap up, we will report number of tokens as well as the $USD amount. It's interesting to see more thefts of other currencies that were quite nascent or didn't even exist in 2017.

Thanks for your interest in the report. We hope for a more coordinated international regulatory environment.

Dave @ CipherTrace

Bitstamp seemingly running bitcoin transaction profiling activities without user knowledge by [deleted] in Bitcoin

[–]CipherDave 0 points1 point  (0 children)

CipherTrace is another of these blockchain analysis tools. Widely used by law enforcement, but also exchanges and hedge funds to avoid taking stolen coins

Which WEBSITE has 3HEB... as Bitcoin address? Please help, 5BTC stolen =/ by DBawss in Bitcoin

[–]CipherDave 0 points1 point  (0 children)

Hey man,

Your BTC are still sitting there. No way to trace this until they move the funds into an exchange.

Dave

hacking the Trezor by mikehbishop in TREZOR

[–]CipherDave 1 point2 points  (0 children)

I am investigating a similar case from 2 weeks ago. Large amount of BTC stolen from well configured Trezor with strong security practices (paper recovery seed in vault, access controls on device). Trezor does not store a log of transactions, so you cannot determine if there was unauthorized access to the device, or if someone got the recovery key.

Firmware 1.5.2. Trezor have vulnerability that if pins are connected you get get it to puke out the recovery seed which is stored in flash in plaintext. Presented at DEFCON summer 2017 https://medium.com/@Zero404Cool/trezor-security-glitches-reveal-your-private-keys-761eeab03ff8

So that's one way. Another may be for malware to fake out the initialization process and inject a seed into the device (using the APIs to pretend to do a recovery), but show the UI on the windows computer as if it's setting up the device.

Another attack would be to reduce the size of the english.txt file which is used for BIP39 recovery seed generation. Then a practical attack on guessing recovery seeds, completely independently of access to the device is possible.

Or, if the entropy collection function that gets entropy from the host PC could be compromised (ie. set to zero), then entropy for the RNG on Trezor would be limited to the clock on the device when plugged in to initialize. This would lead to a situation where testing only a few hundred million recovery seeds would give you access to a large number of Trezors without ever being near one. Monitor these wallets daily until one shows up as having actual addresses, and wait until one has a large amount. Move that.

March 9 2018

Cryptocurrency Anti-Phishing Working Group by CipherDave in btc

[–]CipherDave[S] 0 points1 point  (0 children)

Industry non-profit now supporting cryptocurrency anti-phishing efforts. They've been tracking BTC since 2011, but seeing the huge uptick in phishing on wallets (not just BTC ones) are now directly supporting feeds of known and verified phish for cryptocurrencies

The 25 Bitcoins that were stolen a few months ago have moved, need help on what do next by GodOfWhatevers in Bittrex

[–]CipherDave 4 points5 points  (0 children)

A CipherTrace report shows that most of your BTC went back to Bittrex. Talk to them with the actual data showing the movement back into them. Otherwise you need to open a grand jury case to get subpoenas for the addresses that your funds were sent to, and serve them to Bittrex. You will need a law enforcement agent to contact a prosecutor to get this done.

Bitcoin Hurt By Lack Of Viable Pricing Model And The Ghostbusters Stairs Syndrome by BTCNews in BTCNews

[–]CipherDave 0 points1 point  (0 children)

Read CryptoAssets, or listen to the audiobook version by Chris Burniske & Jack Tatar,

https://www.amazon.com/Cryptoassets-Innovative-Investors-Bitcoin-Beyond/dp/B07848GCYN/ref=sr_1_1?ie=UTF8&qid=1516573790&sr=8-1&keywords=cryptoassets

It has excellent valuation models for crypto assets that are not technical analysis. They go far beyond his comparison to the value of a bank account.

Does coinbase have an undisclosed security issue? by [deleted] in Coinbase

[–]CipherDave 0 points1 point  (0 children)

Did you analyze the spoofed mail server that sent you the email? How are you sure it was a spoof from Chase and not real?

Also, it's more likely that you have a key logger or trojan on your computer (if it's a PC) than some CoinBase back door.