Three People Indicted In $400 Million FTX Crypto Hack Conspiracy (cnbc.com) 20
When FTX filed for bankruptcy in November 2022, the defunct cryptocurrency exchange suffered a hack that resulted in more than $380 million in crypto stolen from FTX's virtual wallets. It turns out that FTX was hit with a SIM-swapping scam orchestrated by ringleader Robert Powell. Powell, along with Carter Rohn and Emily Hernandez, have been indicted and are due to appear in Chicago federal court later Friday for a detention hearing. CNBC reports: The three defendants are charged with conspiracy to commit wire fraud and conspiracy to commit aggravated identity theft and access device fraud, in a scheme that ran from March 2021 to last April, and involved the co-conspirators traveling to cellphone retail stores in more than 15 states. The indictment says the trio shared the personal identifying information of more than 50 victims, created fake identification documents in the victims' names, impersonated them and then accessed their victims' "online, financial and social media accounts for the purpose of stealing money and data."
The scheme relied on duping phone companies into swapping the Subscriber Identity Module of cell phone subscribers into a cellphone controlled by members of the conspiracy, the indictment said. That in turn allowed the conspirators to defeat the multifactor authentication protection on the victims' accounts, giving them access to the money in those accounts. The indictment does not identify FTX by name as the main victim of the conspiracy, but the details of the hack described in that charging document align with the details publicly known about the theft from FTX, which was collapsing at the time of the attack.
The scheme relied on duping phone companies into swapping the Subscriber Identity Module of cell phone subscribers into a cellphone controlled by members of the conspiracy, the indictment said. That in turn allowed the conspirators to defeat the multifactor authentication protection on the victims' accounts, giving them access to the money in those accounts. The indictment does not identify FTX by name as the main victim of the conspiracy, but the details of the hack described in that charging document align with the details publicly known about the theft from FTX, which was collapsing at the time of the attack.
timing looked like an insider (Score:2)
I really thought this would have been an insider, due to the timing of it.
Re: (Score:2)
I guessed the regulators, an awful lot goes up in smoke **every** time the regulators come down on one of these scams and generally is never found.
That's gotta sting (Score:2)
It must be really annoying to stand trial for scamming scammers.
SMS protecting $380 Million? (Score:2)
Re: (Score:2)
Another, far more interesting because unrelated to Dunning-Krugerrands, question would be why cell carriers are still susceptible to this kind of parlor trick. It's virtually unheard of over here in Europe, just US phone companies are too stupid and/or careless to keep their users secure.
Make them liable for the damage done in such a case and this crap clears up pretty fucking quickly.
Re: (Score:2)
> and involved the co-conspirators traveling to cellphone retail stores in more than 15 states. The indictment says the trio shared the personal identifying information of more than 50 victims, created fake identification documents in the victims' names, impersonated them and then accessed their victims' "online, financial and social media accounts for the purpose of stealing money and data.
They showed up in store with fake IDs. Apparently, good enough to fool the staff. What would you expect the staff t
Re: (Score:2)
So the problem is that your IDs are too easy to fake. Ok, let's move the problem to a federal level.
Re: (Score:2)
Re: (Score:2)
Lots of conspiracy theorists that government IDs are the first step to a total surveillance state
Yeah, I guess you'd read that a lot on Facebook...
Re: (Score:2)
While I'm generally very much in favor of US citizens not getting passports and thus not being able to travel outside their country, I would say that ship has sailed.
Re: (Score:2)
Pretty tough to do business in the US without a social security number. Mark of the Taxed.
Re: (Score:1)
Re: (Score:2)
IMHO, what FTX should have done, because they were supposedly a leading edge crypto company, was to see about pushing FIDO tokens, or at least the Google TOTP Authenticator with offering programmable tokens (so the shared secret can be added to a hardware token). Ideally, FIDO tokens.
Doing things with hardware tokens would have gotten rid of security issues in the first place.
As for recovery, maybe "m out of n" methods. For example, SMS + an email + challenge questions, or in some cases, a letter sent reg
Now we know what creimer has been up to (Score:2)
Any news from him? It's not normal for him to be so quiet for this long.
SBF is innocent! (Score:2)
Re: (Score:2)
Who?
It's indeed concerning to hear about the indictmen (Score:1)