He trained cops to fight crypto crime and allegedly ran a dark-web drug market

  • >Lin tried to swap his bitcoins for harder-to-trace monero before cashing out the cryptocurrency at an exchange, the criminal complaint points to timing and amount correlations that nonetheless allowed the FBI to follow his funds to a crypto exchange where he allegedly liquidated the dirty funds

    The police was somehow able to trace the ransoms received by the psychotherapy Vastaamo hacker despite his similar efforts of blockchain hopping. Likely same technique.

  • > Although the FBI says Lin tried to swap his bitcoins for harder-to-trace monero before cashing out the cryptocurrency at an exchange, the criminal complaint points to timing and amount correlations that nonetheless allowed the FBI to follow his funds to a crypto exchange where he allegedly liquidated the dirty funds. That exchange account, too, was registered in Lin's real name, according to the DOJ.

    almost, but he did it backwards.

    always swap to monero with new clean funds straight from an exchange, let it sit in Monero for a week, and then swap to new unseen addresses, in several different amounts than you initially sent. This thwarts the timing attacks.

    additionally, either access the nodes you are using via TOR, or only access nodes with Onion addresses

    use the funds in the previously unseen addresses to buy goods and services such as your domain names and other things

    just completely segregate them in their own subnet of addresses unlinked from anything besides the swap/mixer

    everyone has nearly infinite addresses on every blockchain, there's no reason not to do this, there's no rush and transaction fees have dropped as block space has improved

  • > That allowed investigators to identify a bitcoin wallet stored there, which the FBI says Lin had also carelessly used to pay web registrar Namecheap for four web domains—including one that tracked which dark-web markets were online or down—and register them under his own name.

    What an idiot.

  • Similar to a situation I lived in the past where a security engineer implemented weaknesses while reviewing environments for companies...

  • https://archive.ph/fz2Gt